Effective July 2026. PlanMax is a not-for-profit research project. This page states the codes of conduct we follow, our security posture, and a plain-language summary of how we handle your data (the ONC Model Privacy Notice).
PlanMax endorses and agrees to the CARIN Trust Framework and Code of Conduct for Consumer-Facing Applications. We commit to its principles of transparency, consent, use and disclosure limitation, individual access, security, provenance, accountability, and education in how we handle your health information.
PlanMax does not currently hold a third-party security certification (such as SOC 2 or HITRUST). As an academic, not-for-profit research project, we instead follow the security practices described in our Privacy Policy: encryption of data in transit (HTTPS/TLS) and at rest, access controls with logging, service providers contractually bound to protect data (including under a HIPAA Business Associate Agreement where applicable), and compliance with applicable breach-notification laws. We will update this page if we obtain a formal certification.
PlanMax does not ask you for or store your insurer password. You authenticate directly with your insurer using the SMART on FHIR / OAuth 2.0 standard, and we rely on your insurer's own portal credential to establish your identity — consistent with the CARIN Code of Conduct's approach to identity assurance.
This follows the ONC Model Privacy Notice (2018) — a standardized, nutrition-label-style summary of our practices. It is a snapshot; our full Privacy Policy and Terms of Use govern.
| Are we a HIPAA covered entity? | No. The health data PlanMax collects is not covered by HIPAA, and no HIPAA Notice of Privacy Practices applies. |
|---|---|
| How we use your data (internally) | Our primary service is estimating what different health plans would cost you. We use your identifiable data to provide that service, to conduct not-for-profit scientific research, and to develop and improve PlanMax. We do not use it to develop marketing materials. |
| How we share your identifiable data | We do not share your identifiable data, except with service providers who process it on our behalf under contract, or as required by law. |
| How we share data after removing identifiers | We may share de-identified data to conduct scientific research and to develop and improve PlanMax. Recipients are contractually barred from re-identifying it. |
| Do we sell your data? | No — not your identifiable data and not de-identified data, now or in the future. |
| Where we store your data | Not on your device. We store it on our servers / a third-party cloud provider that is contractually bound to protect it. |
| How we encrypt your data | Yes — encrypted while transmitted (HTTPS/TLS) and yes — encrypted at rest on our servers. |
| Access to other data on your device | No. PlanMax does not request access to your camera, photos, contacts, location, or microphone. |
| Sharing to social media | No. PlanMax does not let you share your data to social media accounts. |
| Your access, correction & deletion options | Yes. You can ask to access your data, request corrections, and delete it. Email privacy@planmax.org. |
| What happens when you disconnect or go dormant | We stop accessing new data and delete your identifiable data within 30 days. De-identified data that can no longer reasonably be linked to you may be retained for research. |
| How we notify you of policy changes | We post the updated policy with a new effective date; for material changes we ask you to re-affirm your consent before continuing. |
| Breach notification | We comply with applicable breach-notification laws, including the FTC's Health Breach Notification Rule, and will notify you of an improper disclosure. |
| Contact us | PlanMax (Christian Wilson, Boston University) · planmax.org · Privacy Policy · privacy@planmax.org · United States. |
See also our Privacy Policy and Terms of Use.