Effective Date: 6/8/2026 · Last Updated: 7/13/2026
Advocate Health Services (“Advocate Health Services,” “we,” “us,” or “our”) sells discounted vouchers for healthcare procedures and services offered by hospitals with which we contract. We are committed to protecting the privacy and security of the personal information entrusted to us. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when individuals interact with our services, website, applications, and related offerings.
By accessing our services or providing personal information to Advocate Health Services, you acknowledge that you have read and understood this Privacy Policy.
We may collect the following categories of personal information:
When you purchase a voucher, we collect and generate the type of medical procedure or service selected (for example, an orthopedic office visit, X-ray, or MRI) and a unique voucher code, so that the voucher can be issued, verified, and redeemed with the applicable hospital partner. This information may constitute protected health information (“PHI”) under HIPAA when combined with your identity. We collect and hold this information as a Business Associate of the hospital, under a signed Business Associate Agreement (“BAA”), and only to the extent necessary to sell and administer the voucher.
Payment card transactions are processed by a PCI DSS-compliant third-party payment processor. We do not store credit card numbers on our own servers.
When you visit our website or use our online services, we may automatically collect:
We may collect information contained in:
We collect personal information through:
We collect and use personal information for legitimate business and legal purposes, including:
We may process personal information to:
Where applicable, we process personal information based on:
We do not sell personal information.
We may disclose personal information under the following circumstances:
We share the minimum necessary information — generally your name, voucher code, and the procedure or service selected — with the hospital from which you purchased your voucher, so that your voucher can be issued, verified, and redeemed. This sharing is governed by our Business Associate Agreement with that hospital.
We may share information with trusted third parties who assist us in:
These providers are required to protect personal information and use it only for authorized purposes.
We may disclose personal information:
If Advocate Health Services undergoes a merger, acquisition, restructuring, or sale of assets, personal information may be transferred as part of the transaction, subject to applicable privacy protections and our Business Associate obligations.
We may disclose information when necessary to:
Our website may use:
These technologies help us:
Users may adjust browser settings to manage cookies; however, some website features may not function properly if cookies are disabled.
We retain personal information only as long as necessary to provide services, fulfill legal obligations, resolve disputes, and enforce agreements. Specifically:
When information is no longer needed, it will be securely deleted, destroyed, or anonymized.
As a HIPAA Business Associate, we maintain administrative, technical, and physical safeguards designed to meet the requirements of the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). Security measures may include:
We maintain compliance with the Payment Card Industry Data Security Standard (PCI DSS) in connection with payment card information.
In the event of a breach involving unsecured protected health information, we will notify the applicable hospital partner without unreasonable delay and in accordance with the HIPAA Breach Notification Rule (45 C.F.R. Part 164, Subpart D) and our Business Associate Agreements. For breaches involving other personal information not governed by HIPAA — such as payment card or contact information — we will provide notification as required by applicable state data breach notification laws, including the law of Kansas.
While we strive to protect personal information, no method of electronic transmission or storage can be guaranteed to be completely secure.
Depending on applicable law, individuals may have the right to:
Request access to personal information we maintain about them.
Request correction of inaccurate or incomplete information.
Request deletion of personal information, subject to legal and regulatory requirements.
Request a copy of personal information in a portable format where applicable.
Request limitations on certain uses of personal information.
Exercise privacy rights without receiving discriminatory treatment.
To exercise these rights, individuals may contact us using the information provided below. We may require identity verification before processing requests.
Our services are intended for use by adults age 18 or older who are purchasing vouchers on their own behalf or on behalf of a minor for whom they are the parent or legal guardian. We do not knowingly collect personal information directly from children under 13 through our website. If you purchase a voucher for care to be provided to a minor, you represent that you are the minor’s parent or legal guardian and are authorized to provide their information for this purpose.
Our website or communications may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or security of third-party websites. Users should review the privacy policies of those organizations before providing personal information.
If personal information is transferred outside the jurisdiction in which it was collected, Advocate Health Services will implement appropriate safeguards and comply with applicable data protection laws governing cross-border transfers.
Advocate Health Services does not provide healthcare services; it is not a covered entity as defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). However, because Advocate Health Services does create or maintain protected health information (PHI) on behalf of hospital partners under signed Business Associate Agreements, it acts as a Business Associate as defined under HIPAA, and is subject to HIPAA’s applicable privacy, security, and breach notification rules with respect to that information.
This section is not a Notice of Privacy Practices as defined under 45 C.F.R. § 164.520 — that notice is a covered entity’s obligation, and you may request it directly from the hospital that issued your voucher. This section instead describes, for your information, how Advocate Health Services handles protected health information in its role as a Business Associate.
This Privacy Policy is governed by the laws of the State of Kansas, without regard to its conflict of laws principles. Any dispute, claim, or controversy arising out of or relating to this Privacy Policy or our collection, use, or disclosure of personal information shall be brought exclusively in the state or federal courts located in Atchison County, Kansas, and you consent to the personal jurisdiction of such courts.
We may update this Privacy Policy periodically to reflect changes in legal requirements, technology, or business practices. Updated versions will be posted with a revised “Last Updated” date. Continued use of our services after changes become effective constitutes acceptance of the revised Privacy Policy.
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact:
Privacy Officer
Advocate Health Services
705 Commercial Street
Atchison, Kansas 66002
Email: support@advocatehealthservices.org
By using Advocate Health Services’ services, website, or platforms, you acknowledge that you have read and understand this Privacy Policy and consent to the collection, use, disclosure, and management of your personal information as described herein, where consent is required by law.