HIPAA & Data Privacy

Last updated: June 10, 2026

Service Area

Quinable's services, platform, and website are offered solely to users located in the United States, excluding the State of California. Quinable does not offer, market, or direct its services to residents of the State of California, does not conduct business in California, does not accept California residents as users of its platform, and does not knowingly collect personal information from California residents. Any access to this website from California is neither solicited nor authorized, and no services will be provided to California residents.

Quinable reserves the right, in its sole discretion, to determine, limit, restrict, suspend, or discontinue the availability of its services, platform, or website in any state, territory, or jurisdiction, in whole or in part, at any time and without notice. The availability or visibility of this website in any jurisdiction does not constitute an offer to provide services in that jurisdiction, and no person acquires any right to access or use Quinable's services by virtue of the website being accessible from their location.

Our Commitment to HIPAA Compliance

At Quinable, protecting client and patient information is a top priority. We operate as a HIPAA-compliant Business Associate to healthcare providers and home care agencies across the U.S. Our platform adheres to the privacy, security, and breach notification requirements of the Health Insurance Portability and Accountability Act (HIPAA).

We implement administrative, technical, and physical safeguards to protect Protected Health Information (PHI), and we enter into Business Associate Agreements (BAAs) with every Covered Entity we support.

To request a copy of our HIPAA Privacy and Security Policy or a Business Associate Agreement, please contact our compliance team at [email protected].

We Limit Our Data Collection

Quinable is a healthcare technology marketplace designed to connect professionals with providers efficiently and securely. We do not collect or store protected health information (PHI), such as clinical health records.

For scheduling and coverage purposes, we only collect a client's name, address, and phone number, shared solely with the assigned care provider. Our legal team has determined that this data is not PHI under HIPAA, as it is used solely for administrative purposes and not linked to health information.

Information We Collect Through Our Mobile Application

When you use the Quinable mobile application (available on iOS and Android), we collect the following categories of information to provide and improve our services:

  • Account Information: Full name, email address, phone number, mailing address, date of birth, and profile photograph
  • Professional Credentials: State licenses, certifications, National Provider Identifier (NPI), employment history, education, and professional references
  • Payment Information: Banking details and tax identification numbers (W-9, SSN/EIN) for processing payments and generating tax documents
  • Device Information: Device type, operating system, unique device identifiers, browser type, and mobile network information
  • Usage Data: Features used, actions taken, frequency and duration of activities, and interaction patterns within the app
  • Camera and Photo Library: With your permission, we access your device camera or photo library solely to allow you to upload a profile photograph. We do not access your camera or photos for any other purpose.

Location Data

The Quinable mobile application collects and processes location data from your device to provide core functionality of the platform. This includes:

  • Precise Location (GPS): With your permission, we access your device's GPS to determine your real-time geographic location. This is used to show you nearby shift and visit opportunities, calculate distance and travel time to work locations, verify attendance and check-in/check-out at job sites, and display relevant opportunities based on your geographic area.
  • Approximate Location (Network-Based): We may infer your approximate location from your IP address or Wi-Fi network to provide region-appropriate content and opportunities.
  • Background Location: With your explicit consent, the app may access your location in the background to provide timely notifications about nearby opportunities and to support check-in verification for active shifts.

You can control location permissions through your device settings at any time. Disabling location services may limit certain features of the app, such as the ability to view nearby opportunities or verify shift attendance.

Push Notifications

With your consent, we send push notifications to your mobile device regarding new opportunities, shift reminders, schedule updates, payment confirmations, and platform announcements. You can manage your notification preferences through your device settings or within the app at any time.

SMS / Text Messaging

Quinable sends SMS text messages to users who provide a mobile number and initiate an action on our platform — including one-time verification and two-factor authentication (2FA) passcodes, login and password-reset codes, and transactional or operational notifications related to your account and shifts. By providing your mobile number, you consent to receive these messages.

Message frequency varies based on your activity. Message and data rates may apply. You can opt out at any time by replying STOP; reply HELP for assistance, or contact us at [email protected].

We do not share, sell, or otherwise provide your mobile phone number or messaging consent information to any third parties or affiliates for marketing or promotional purposes. We share this information only with our messaging service providers (e.g., our SMS carrier) solely to deliver the messages you have requested.

Business Associate Agreements

Quinable is committed to supporting our clients' HIPAA compliance needs. We are happy to execute Business Associate Agreements (BAAs) with healthcare providers, such as home care agencies, upon request. These agreements formalize our commitment to protecting any sensitive data we may handle.

We also require BAAs with our vendors and third-party partners who may interact with protected data, ensuring a secure ecosystem for our clients.

Security Safeguards

  • Encrypted Data Storage and Transmission: All client data is protected with AES-256 encryption at rest and in transit, using HIPAA-compliant cloud providers who sign BAAs.
  • Role-Based Access and User Permissions: Only authorized personnel can access client information, with strict role-based permissions.
  • System Audit Logs: We maintain detailed logs of platform activity to monitor and ensure data integrity.
  • Platform Activity Controls: Robust security measures, including multi-factor authentication, prevent unauthorized access.
  • Incident Response: In the unlikely event of a data incident, we have protocols to promptly investigate, mitigate, and notify affected parties as needed.

How We Share Your Information

We do not sell your personal information to third parties. We may share your information in the following circumstances:

  • Between Agencies and Professionals: When a professional accepts an opportunity, relevant professional information (name, credentials, profile photo, reliability score) is shared with the agency. Agency information (name, location, shift details) is shared with professionals browsing opportunities.
  • Service Providers: We share information with third-party vendors who perform services on our behalf, including payment processing, background checks, credential verification, cloud hosting, and analytics. These providers are contractually obligated to protect your data.
  • Legal Compliance: We may disclose information when required by law, subpoena, or court order, or when necessary to protect our rights, your safety, or the safety of others.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. After account termination, we retain transaction and billing records for 7 years for tax compliance, credential records as required by healthcare regulations, and communication records for 3 years for dispute resolution. You may request deletion of your data by contacting [email protected].

Your Rights and Choices

You may access, update, or delete your personal information at any time. You can also control location permissions, camera access, and push notification preferences through your device settings. To exercise your privacy rights, contact [email protected]. We will respond within 30 days.

Privacy Commitment

Quinable follows best practices to protect client information and support our partners' HIPAA obligations. Our team undergoes regular training on data security and privacy protocols, ensuring compliance with industry standards and regulatory expectations and applicable privacy laws.

We continuously review and update our policies to stay aligned with evolving regulations, providing a secure and reliable technology solution for healthcare providers.

Children's Privacy

The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us at [email protected].

Contact Us

Have questions about our privacy and security practices? We're here to help.

  • Privacy inquiries: [email protected]
  • Compliance and BAA requests: [email protected]
  • General inquiries: [email protected]
  • Website: quinable.com
Quinable

The healthcare technology marketplace built for agencies that demand more.

Solutions

Home CareSenior Care