Legal
How Gravita Solutions collects, uses, shares, retains, and protects personal information — and how that sits alongside our obligations as a HIPAA Business Associate.
At a glance
- Effective date
- September 16, 2026
- Last updated
- September 16, 2026
- Entity
- Gravita Solutions LLC
- Applies to
- www.gravitasolutions.llc
Gravita Solutions LLC (“Gravita Solutions,” “we,” “us,” or “our”) provides revenue cycle management, medical coding, OASIS review, clinical documentation review, claims support, authorization support, denial management, and related services to home health agencies and healthcare organizations in the United States.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit or use www.gravitasolutions.llc (the “Website”), contact us, request information or services, submit an inquiry, apply for employment, or otherwise interact with us.
Section 01
About Gravita Solutions
Gravita Solutions LLC
A subsidiary of Gravita Oasis Review Solutions
- 212 N. 2nd St., STE 100Richmond, KY 40475United States
- +91 80191 98037India
- +1 (813) 708-1643United States
Gravita Solutions provides business-to-business services primarily to home health agencies and other healthcare organizations.
Section 02
Scope of This Privacy Policy
This Privacy Policy applies to personal information we collect through:
- Our Website
- Contact and inquiry forms
- Service or consultation requests
- Free 10-chart review requests
- Email and telephone communications
- Client and prospective-client interactions
- Recruitment and employment applications
- Other business interactions with Gravita Solutions
This Privacy Policy primarily addresses personal information collected through our Website and ordinary business interactions.
Protected Health Information
In providing healthcare-related services, Gravita Solutions may receive, access, maintain, or process Protected Health Information (“PHI”) on behalf of healthcare organizations.
When we act as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), PHI is handled in accordance with HIPAA, applicable regulations, and the applicable Business Associate Agreement (“BAA”).
This Privacy Policy does not replace, modify, or override any BAA or other contractual agreement governing PHI.
A healthcare organization that engages Gravita Solutions generally remains responsible for determining how patient information is collected, used, and disclosed.
Patients who have questions about their health information or wish to exercise HIPAA rights should contact the healthcare provider or home health agency responsible for their records.
Section 03
Information We Collect
Information You Provide
Depending on how you interact with us, we may collect:
- Name
- Job title or professional role
- Agency or organization name
- Business email address
- Telephone number
- Business address
- Information about your organization’s services or requirements
- EMR or technology information
- Information included in contact or consultation requests
- Information submitted through a 10-chart review request
- Information provided during client onboarding
- Information provided through email or telephone communications
- Resume and employment history
- Education, qualifications, certifications, and other information submitted during recruitment
Information Collected Automatically
When you visit our Website, we may automatically collect certain technical and usage information, including:
- IP address
- Browser type and version
- Device type
- Operating system
- Referring URL
- Pages visited
- Date and time of visits
- Approximate location derived from technical information
- Website interaction information
- Information collected through cookies and similar technologies
We use this information to operate, secure, analyze, and improve our Website and services.
Information You Should Not Submit Through Public Forms
Our public Website forms are not intended for submitting patient PHI.
Do not submit patient names, medical records, clinical notes, insurance information, Social Security numbers, or other patient-identifying health information through a public Website form.
If patient information is required for a service, it should be provided only through secure systems and channels authorized under the applicable client agreement and BAA.
Section 04
How We Use Personal Information
We may use personal information to:
- Respond to inquiries and consultation requests
- Provide requested information, evaluations, and services
- Communicate with prospective and existing clients
- Understand prospective clients’ business and service requirements
- Provide RCM, coding, OASIS, clinical review, claims, authorization, and denial-management services
- Manage client relationships
- Provide reports, project updates, and other business communications
- Process invoices and payments
- Manage contractual and account-related matters
- Recruit and evaluate employees and contractors
- Send educational, informational, or marketing communications where permitted by law
- Operate, maintain, and improve our Website
- Analyze Website traffic and performance
- Maintain information security
- Detect and prevent fraud, misuse, or unauthorized access
- Investigate security incidents
- Comply with legal, regulatory, tax, accounting, and contractual obligations
- Establish, exercise, or defend legal claims
- Protect our rights, property, personnel, clients, and systems
We do not sell personal information for monetary consideration.
We do not knowingly disclose personal information to third parties for their own independent advertising purposes.
Section 05
Legal Bases for Processing
Where applicable privacy laws require us to identify a legal basis for processing personal information, we may rely on one or more of the following:
Contract
We may process information when necessary to provide requested services, manage a business relationship, perform a contract, or take steps at your request before entering into a contract.
Legitimate Interests
We may process information where reasonably necessary for legitimate business purposes, including responding to business inquiries, managing business relationships, maintaining security, improving our services, and protecting our legal interests.
Consent
Where applicable law requires consent, we will obtain consent before conducting the relevant processing.
Legal Obligations
We may process information where necessary to comply with applicable laws, regulations, court orders, legal processes, or other legal obligations.
Other Lawful Bases
Where applicable law provides another lawful basis for processing, we may rely on that basis.
Where processing is based on consent, you may withdraw your consent subject to applicable legal limitations.
Section 06
Cookies and Similar Technologies
Our Website may use cookies and similar technologies for purposes including:
- Essential Website functionality
- Security
- Remembering preferences
- Website analytics
- Measuring Website performance
- Improving Website content and functionality
- Marketing or advertising measurement, where applicable
Third-party providers may also use cookies or similar technologies when providing services to us.
You can control or delete cookies through your browser settings. Disabling certain cookies may affect Website functionality.
Where required by applicable law, we will provide appropriate cookie consent and preference mechanisms.
Where required by applicable law, we will recognize legally recognized browser-based privacy signals, including Global Privacy Control.
Section 08
HIPAA and Protected Health Information
When Gravita Solutions acts as a HIPAA Business Associate, we handle PHI in accordance with HIPAA, applicable regulations, and the applicable BAA.
Our HIPAA-related practices include safeguards and procedures designed to:
- Limit PHI access to authorized personnel
- Use PHI only for permitted purposes
- Apply appropriate access controls
- Protect electronic PHI through appropriate administrative, physical, and technical safeguards
- Maintain appropriate confidentiality obligations
- Provide privacy and security training to personnel who require access to PHI
- Maintain procedures for identifying and responding to security incidents
- Report applicable security incidents and breaches to the covered entity as required by HIPAA and the applicable BAA
- Return or securely destroy PHI when required by the applicable BAA or law
- Require appropriate agreements with applicable subcontractors that have access to PHI
HIPAA requires business associates to have appropriate written arrangements with covered entities and imposes direct obligations on business associates concerning certain privacy and security requirements.
Patients who wish to exercise HIPAA rights concerning their health information should generally contact the healthcare provider or home health agency responsible for their records.
Section 09
Data Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information from unauthorized access, disclosure, alteration, loss, or destruction.
Depending on the information and system involved, our safeguards may include:
- Role-based access controls
- Multi-factor authentication
- Encryption in transit and, where appropriate, at rest
- Endpoint and network security measures
- Secure remote-work procedures
- Access and activity monitoring
- Security reviews
- Employee privacy and security training
- Incident response procedures
- Access restrictions based on business need
No method of transmitting or storing information is completely secure. Therefore, we cannot guarantee absolute security of information transmitted over the Internet.
Section 10
Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy or as required by:
- Contractual obligations
- Legal requirements
- Tax and accounting requirements
- Regulatory requirements
- Audit requirements
- Dispute resolution
- Legal claims
- Security and business continuity requirements
Retention periods vary depending on the type of information, the purpose for which it was collected, contractual requirements, and applicable law.
PHI is retained, returned, or destroyed in accordance with applicable law, the applicable BAA, and client agreements.
When information is no longer required, we take reasonable steps to securely delete, destroy, or de-identify it where appropriate.
Section 11
International Data Processing
Gravita Solutions has business operations and personnel in the United States and India.
Depending on the nature of our services and business relationships, personal information may be accessed or processed by authorized personnel in different countries.
Where applicable law requires safeguards for international transfers, we will use an appropriate lawful transfer mechanism and applicable contractual or organizational safeguards.
Client-specific requirements concerning data locations and access may also be addressed in applicable service agreements and BAAs.
Section 12
Your Privacy Rights
Depending on your location and applicable law, you may have certain rights regarding your personal information.
These rights may include:
- The right to know whether we process your personal information
- The right to access personal information we hold about you
- The right to request correction of inaccurate personal information
- The right to request deletion of personal information
- The right to obtain a copy of certain personal information
- The right to withdraw consent where processing is based on consent
- The right to opt out of certain marketing communications
- The right to opt out of certain forms of sale or sharing where applicable
- The right to object to or restrict certain processing where applicable
- The right to appeal certain privacy decisions where required by law
- The right to lodge a complaint with an applicable privacy regulator
These rights are subject to applicable legal exceptions and limitations.
To submit a privacy request
- Subject
- Privacy Request
We may need to verify your identity before completing certain requests.
We will respond within the timeframe required by applicable law.
We will not discriminate against individuals for exercising privacy rights available to them under applicable law.
Section 13
California Privacy Rights
If you are a California resident and the California Consumer Privacy Act (“CCPA”), as amended, applies to our processing of your personal information, you may have additional rights.
Depending on the circumstances, these may include:
- The right to know about personal information collected, used, disclosed, or otherwise processed
- The right to request deletion
- The right to request correction
- The right to opt out of the sale or sharing of personal information where applicable
- The right to limit certain uses and disclosures of sensitive personal information where applicable
- The right to appeal certain privacy-request decisions
- The right not to receive discriminatory treatment for exercising applicable privacy rights
We do not sell personal information for monetary consideration.
If our practices constitute “sharing” under applicable California law, we will provide the disclosures and opt-out mechanisms required by law.
California residents may submit privacy requests using
- Subject
- California Privacy Request
We may verify your identity before processing a request.
California privacy requirements include specific requirements concerning privacy-policy disclosures and consumer rights.
Section 14
Other U.S. State Privacy Rights
Residents of other U.S. states may have additional rights under applicable state privacy laws.
Depending on the applicable law and circumstances, these rights may include:
- Access
- Correction
- Deletion
- Data portability
- Consent withdrawal
- Objection
- Opting out of certain processing
- Appeals of privacy-request decisions
Where required by applicable law, we will provide additional notices, disclosures, or mechanisms for exercising these rights.
Section 15
Marketing Communications
We may send newsletters, educational materials, service information, or marketing communications where permitted by applicable law.
You may unsubscribe from marketing communications by:
- Clicking the unsubscribe link in the applicable email; or
- Contacting us at info@gravitasolutions.llc.
Unsubscribing from marketing communications does not prevent us from sending transactional, contractual, security, or service-related communications that are necessary for our business relationship.
Section 16
Job Applicants
If you apply for employment or another position with Gravita Solutions, we may collect:
- Name and contact information
- Resume
- Employment history
- Education
- Professional qualifications
- Certifications
- Skills
- References
- Interview information
- Other information reasonably necessary to evaluate your application
We use applicant information to:
- Evaluate qualifications
- Communicate with applicants
- Manage recruitment
- Consider applicants for future positions where permitted
- Comply with applicable employment laws
We may retain applicant information for a reasonable period where permitted by law.
Please do not submit unnecessary sensitive personal information as part of your application.
Section 17
Children’s Privacy
Our Website and services are intended for businesses, healthcare organizations, professionals, and adult users.
We do not knowingly collect personal information from children through our Website.
If you believe a child has provided personal information to us, please contact info@gravitasolutions.llc.
Where required by applicable law, we will take reasonable steps to delete the information.
Section 18
Third-Party Websites and Services
Our Website may contain links to third-party websites, healthcare technology platforms, EMR providers, social media platforms, or other external resources.
We are not responsible for the privacy or security practices of third-party websites or services.
You should review the privacy policies of those third parties before submitting personal information to them.
Section 19
Privacy Signals
Some browsers and devices provide privacy preference signals.
Where required by applicable law, we will recognize legally recognized privacy signals, including Global Privacy Control.
Such signals may not apply to all processing activities, including processing necessary to provide requested services, comply with legal obligations, maintain security, or perform other activities permitted by applicable law.
Section 20
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in:
- Our business
- Our services
- Technology
- Privacy practices
- Legal or regulatory requirements
When we update this Privacy Policy, we will change the Last Updated date at the top of this page.
Where required by law, we will provide additional notice of material changes.
We encourage you to review this Privacy Policy periodically.
Section 21
Contact Us
If you have questions about this Privacy Policy or how Gravita Solutions handles personal information, please contact us:
Gravita Solutions LLC
A subsidiary of Gravita Oasis Review Solutions
- 212 N. 2nd St., STE 100Richmond, KY 40475United States
- +91 80191 98037India
- +1 (813) 708-1643United States
Use the right subject line so it reaches the right desk
- Privacy requests
- Privacy Request
- HIPAA or BAA inquiries
- HIPAA Inquiry
Last updated September 16, 2026
Back to top