Privacy Policy

Alera, Inc. d/b/a Citeline Health

Effective Date: March 2026

1. Introduction

At Citeline Health, safeguarding your privacy and the privacy of your patients is a core commitment. This Privacy Policy describes the privacy practices of Alera, Inc., a Delaware corporation, doing business as Citeline Health (referred to collectively as "Citeline Health," "Citeline," "us," "we," and "our") in connection with your use of our websites, mobile applications, and AI-powered prior authorization call management platform (collectively, the "Services").

This Privacy Policy explains how we collect, use, disclose, transfer, secure, and retain information about you and the patients on whose behalf you use the Services, and the rights and choices you have regarding these activities.

By accessing or using the Services, you acknowledge that you have read and understand this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein. If you do not agree with this Privacy Policy, you should not access or use the Services.

This Privacy Policy is incorporated into and forms a part of our Terms of Service.

2. What Constitutes Personal Information

"Personal Information" in this Privacy Policy refers to any information or data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to a particular identifiable natural person, or any other information that constitutes "personal information," "personal data," or "personally identifiable information" under applicable data protection laws.

3. Information We Collect

3.1 Information You Provide Directly.

(a) Registration Information. To use the Services, you must register an account and provide certain Personal Information, including your name, email address, National Provider Identifier (NPI) number, specialty, practice name, practice location, and other information as specified during registration.

(b) Case Data. When you initiate a prior authorization call through the Services, you provide patient-related information including: patient name, date of birth, medical record number (MRN), diagnosis, contested order, insurance provider, insurance plan, group/BIN number, case ID, and callback number. Case Data constitutes Protected Health Information ("PHI") under HIPAA.

(c) Payment Information. If and when billing is enabled, we collect payment and billing information through secure payment processing methods. We do not store full payment card details on our systems.

(d) Communications. We collect information you provide when you contact us for support, submit feedback, or otherwise communicate with us.

3.2 Information Generated Through the Services.

(a) Call Data. When the Services place an outbound call on your behalf, we generate and collect: audio recordings of calls, call transcripts, call metadata (including duration, hold times, timestamps, and call outcomes), and records of interactions with insurance company phone systems.

(b) Insurance Callback Numbers. Callback numbers submitted by Users are aggregated by insurance provider and plan. These numbers are maintained as a shared resource and are not associated with individual patient information.

3.3 Information Collected Automatically.

(a) Usage Data. We automatically collect information about your use of the Services, including: access dates and times, features used, pages or screens viewed, actions taken within the platform, and session duration.

(b) Device Information. We collect information about the device you use to access the Services, including: IP address, browser type and version, operating system, device identifiers, and general location information derived from IP address.

(c) Cookies and Similar Technologies. We use cookies and similar technologies on our websites for essential functions (authentication, security, session management) and analytics. See Section 8 for details.

4. How We Use Your Information

We use the information we collect for the following purposes:

(a) Providing the Services. To operate, maintain, and deliver the Services, including: authenticating your identity and credentials, placing and managing outbound calls on your behalf, navigating insurance company phone systems, providing Case Data to insurance company personnel, detecting medical reviewer connections, and notifying you for call handoff.

(b) Account Management. To create and manage your account, respond to inquiries, fulfill requests, and send administrative communications about the Services.

(c) Service Improvement. To analyze usage patterns, diagnose technical issues, develop new features, and improve the performance and reliability of the Services, including the AI agent's phone tree navigation and hold management capabilities.

(d) De-Identification and Aggregation. To de-identify PHI in accordance with HIPAA (45 C.F.R. Sections 164.502(d) and 164.514(a)-(c)) and to create aggregated, de-identified, or anonymous data for the purposes of improving our products and services, developing statistical analyses, and generating insights (such as average hold times by insurance carrier or common phone tree structures).

(e) Insurance Callback Database. To maintain and improve a shared database of insurance company callback numbers organized by provider and plan, available to all Users. No PHI is associated with callback number records.

(f) Security and Compliance. To detect, investigate, and prevent fraudulent, unauthorized, or illegal activity, enforce these Terms, and comply with legal obligations.

(g) Legal Obligations. To comply with applicable laws, regulations, legal processes, or governmental requests.

5. How We Share Your Information

We share information about you in the following limited circumstances:

(a) Insurance Companies. When the AI agent places a call on your behalf, it provides Case Data (including patient information) to insurance company automated systems, intake staff, and other personnel as necessary to advance the prior authorization process. This disclosure is made as your Business Associate acting within the scope of treatment, payment, and healthcare operations.

(b) Service Providers. We work with third-party service providers who assist in delivering the Services, including: telecommunications and telephony providers (for placing and managing calls), cloud infrastructure and hosting providers (for data storage and processing), analytics providers (for service performance monitoring), and payment processors (for billing, when applicable). We require these service providers to agree to use Personal Information and PHI only for the purposes of providing services to us and to maintain appropriate safeguards. Service providers who handle PHI are bound by Business Associate Agreements or equivalent protections.

(c) Aggregated and De-Identified Data. We may share aggregated, de-identified, or anonymous data with third parties for any purpose. Such data cannot reasonably be used to identify any individual.

(d) Business Transfers. In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, we reserve the right to transfer your information to the successor entity. In such event, your information will continue to be treated in accordance with this Privacy Policy.

(e) Legal Requirements. We may disclose Personal Information when we believe disclosure is: (i) required to comply with applicable law, regulation, legal process, or governmental request; (ii) necessary to enforce these Terms; (iii) necessary to detect, prevent, or address fraud, security, or technical issues; or (iv) necessary to protect the rights, property, or safety of Citeline Health, our Users, or the public.

(f) With Your Consent. We may share your information with third parties when you have given us your explicit consent to do so.

We do not sell, rent, or lease your Personal Information or Protected Health Information to third parties. We do not share your information with advertisers, pharmaceutical companies, or data brokers. We do not use your information for targeted advertising.

6. Security of Information

We implement appropriate technical, administrative, and physical safeguards designed to protect the Personal Information and PHI under our control from unauthorized access, use, disclosure, and accidental loss. These measures include:

(a) Encryption of PHI and Personal Information in transit and at rest;

(b) Access controls limiting access to authorized personnel on a need-to-know basis;

(c) Employee training on data privacy and security;

(d) Regular security assessments and monitoring; and

(e) Incident response procedures for potential security events.

No method of transmission over the internet or electronic storage is completely secure. While we take reasonable measures to protect your information, we cannot guarantee absolute security. Any transmission of information is at your own risk. You are responsible for maintaining the security of your account credentials.

7. Data Retention

We retain Personal Information and PHI for as long as reasonably necessary to fulfill the purposes outlined in this Privacy Policy, provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.

Specific retention practices include:

(a) Registration Information is retained for the duration of your active account and for a reasonable period thereafter for legal and compliance purposes.

(b) Case Data and Call Data are retained for the period necessary to support the associated prior authorization case and any related appeals, plus an additional period as required by applicable law and our legal obligations.

(c) Aggregated, de-identified, or anonymous data may be retained indefinitely.

Upon account termination, we will handle PHI in accordance with the Business Associate Agreement provisions in our Terms of Service. We may retain Personal Information in backup or archival systems for a limited period as necessary for legal, regulatory, or audit purposes.

8. Cookies and Tracking Technologies

We use cookies and similar technologies on our websites for the following purposes:

(a) Essential Cookies. Required for authentication, security, and session management. These cannot be disabled.

(b) Analytics Cookies. Used to understand how visitors interact with our websites, measure performance, and improve user experience. We may use third-party analytics services such as Google Analytics for these purposes.

You can manage cookie preferences through your browser settings. Disabling non-essential cookies may limit certain functionality but will not prevent you from using the Services.

Our websites do not currently respond to "Do Not Track" browser signals.

9. Your Privacy Rights

Depending on your location, you may have certain rights regarding your Personal Information:

(a) Right to Access. You may request access to the Personal Information we hold about you.

(b) Right to Correction. You may request that we correct inaccurate or incomplete Personal Information.

(c) Right to Deletion. You may request that we delete your Personal Information, subject to certain exceptions (such as legal retention requirements).

(d) Right to Data Portability. You may request a copy of your Personal Information in a portable, machine-readable format.

(e) Right to Object. You may object to certain processing of your Personal Information.

(f) Right to Opt-Out. You may opt out of the sale or sharing of your Personal Information. Note that Citeline Health does not sell Personal Information.

To exercise any of these rights, contact us at privacy@citelinehealth.com or write to:

Alera, Inc. d/b/a Citeline Health

Attn: Privacy Office

251 Little Falls Drive

Wilmington, DE 19808

Email: privacy@citelinehealth.com

We will verify your identity before processing any request. We will respond to verified requests within the timeframes required by applicable law. We will not discriminate against you for exercising your privacy rights.

10. California Privacy Rights

If you are a California resident, the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA") provide you with specific rights regarding your Personal Information, in addition to the rights described in Section 9.

10.1 Right to Know.

You may request that we disclose the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your information.

10.2 Right to Delete.

You may request deletion of your Personal Information, subject to certain legal exceptions.

10.3 Right to Correct.

You may request correction of inaccurate Personal Information.

10.4 Right to Opt-Out of Sale/Sharing.

Citeline Health does not sell your Personal Information and does not share your Personal Information for cross-context behavioral advertising.

10.5 Non-Discrimination.

We will not discriminate against you for exercising your CCPA/CPRA rights.

10.6 Exercising Your Rights.

Submit requests to privacy@citelinehealth.com or by mail to the address in Section 9. You may designate an authorized agent to make requests on your behalf, provided you supply written authorization and verify your identity.

11. Children's Privacy

The Services are designed for use by adult healthcare professionals and are not intended for nor designed to be used by individuals under the age of 18. We do not knowingly collect Personal Information from anyone under the age of 18. If we become aware that we have collected Personal Information from a child under 18, we will take steps to delete it promptly.

12. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Changes will be effective upon posting, and we will update the "Effective Date" at the top of this page. We will use reasonable efforts to notify you of material changes by email or through the Services before they become effective. Your continued use of the Services after changes are posted constitutes your acceptance of the modified Privacy Policy. If you do not agree, you must stop using the Services and close your account.

13. Contact Us

If you have questions about this Privacy Policy or how your information is used, please contact us:

Alera, Inc. d/b/a Citeline Health

Attn: Privacy Office

251 Little Falls Drive

Wilmington, DE 19808

Email: privacy@citelinehealth.com

Stop waiting for permission to treat your patients.

Join Waitlistarrow_forward
© 2026 Citeline Health. All rights reserved.Alera, Inc. d/b/a Citeline Health

Citeline Health is an AI prior authorization platform for physicians, built by Alera, Inc. We are not affiliated with Citeline (formerly Informa Pharma Intelligence), the biopharma intelligence firm at citeline.com. Citeline Health was founded by Roheet Kakaday, MD, MS, and operates in the United States.