Privacy Policy
Last updated: July 14, 2026
1. Introduction
Astral Medical Billing (“Astral,” “we,” “us,” or “our”) provides medical billing, revenue cycle management, and healthcare digital marketing services to healthcare providers and practices across the United States. We respect your privacy and are committed to protecting the personal information you share with us. This Privacy Policy explains what information we collect, how we use and safeguard it, and the choices you have.
This policy applies to information collected through our website at astralmedbilling.net, when you contact us, and in the course of providing our services. By using our website or services, you agree to the practices described in this policy.
2. Information We Collect
We collect the following categories of information:
- Information you provide. When you request a consultation, fill out a form, subscribe to updates, or contact us, we may collect your name, practice or business name, email address, phone number, specialty, and any details you include in your message.
- Information collected automatically. When you visit our website, we may automatically collect technical data such as your IP address, browser type, device information, referring pages, and how you interact with our site.
- Service information. When you engage us as a client, we collect the information necessary to perform billing, coding, and marketing services, which may include practice, payer, and patient billing data as described in the HIPAA section below.
3. How We Use Your Information
We use the information we collect to:
- Respond to your inquiries and provide consultations;
- Deliver, maintain, and improve our services;
- Process billing, coding, and claims on behalf of clients;
- Communicate with you about your account, updates, and relevant offerings;
- Analyze website usage to improve performance and user experience;
- Comply with legal, regulatory, and contractual obligations.
4. HIPAA & Protected Health Information
In the course of providing medical billing and revenue cycle services, Astral may handle Protected Health Information (PHI) on behalf of covered entities. In these engagements, we act as a Business Associate as defined under the Health Insurance Portability and Accountability Act (HIPAA).
We handle PHI in accordance with HIPAA and the terms of a Business Associate Agreement (BAA) entered into with each client. We use and disclose PHI only as permitted by the BAA and applicable law, apply administrative, physical, and technical safeguards to protect it, and limit access to personnel who require it to perform their duties. We do not sell PHI, and we do not use it for marketing purposes.
5. How We Share Your Information
We do not sell your personal information. We may share information in the following limited circumstances:
- Service providers. With trusted vendors who perform functions on our behalf (such as hosting, analytics, or communication tools) under obligations of confidentiality.
- Client engagements. As necessary to perform the billing, coding, and marketing services you have requested.
- Legal requirements. When required by law, regulation, subpoena, or to protect our rights, safety, or property.
- Business transfers. In connection with a merger, acquisition, or sale of assets, subject to applicable safeguards.
6. Cookies & Tracking Technologies
Our website may use cookies and similar technologies to remember your preferences, understand how the site is used, and improve your experience. You can control cookies through your browser settings. Disabling cookies may affect certain features of the site.
7. Data Security
We maintain administrative, technical, and physical safeguards designed to protect the information we hold against unauthorized access, disclosure, alteration, and destruction. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this policy, to provide our services, and to comply with our legal, tax, and regulatory obligations. When information is no longer needed, we take reasonable steps to delete or de-identify it.
9. Your Rights & Choices
Depending on your location, you may have rights to access, correct, update, or delete your personal information, or to object to or restrict certain processing. You may also opt out of marketing communications at any time by using the unsubscribe link or by contacting us. To exercise any of these rights, please reach out through the details in the Contact section below. Requests involving PHI are handled in accordance with HIPAA and the relevant Business Associate Agreement.
10. Third-Party Links & Services
Our website may contain links to third-party websites or services that we do not control. This Privacy Policy does not apply to those third parties, and we encourage you to review their privacy practices before providing them with any information.
11. Children's Privacy
Our website and services are intended for healthcare providers and businesses, not for children. We do not knowingly collect personal information from children under the age of 13. If you believe a child has provided us with information, please contact us so we can remove it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review this policy periodically.
13. Contact Us
If you have questions about this Privacy Policy or how we handle your information, please reach out through our Contact page. We will respond to your inquiry as promptly as reasonably possible.