Skip to content
Gravita SolutionsLLC

Legal

How Gravita Solutions collects, uses, shares, retains, and protects personal information — and how that sits alongside our obligations as a HIPAA Business Associate.

At a glance

Effective date
September 16, 2026
Last updated
September 16, 2026
Entity
Gravita Solutions LLC
Applies to
www.gravitasolutions.llc

Gravita Solutions LLC (“Gravita Solutions,” “we,” “us,” or “our”) provides revenue cycle management, medical coding, OASIS review, clinical documentation review, claims support, authorization support, denial management, and related services to home health agencies and healthcare organizations in the United States.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit or use www.gravitasolutions.llc (the “Website”), contact us, request information or services, submit an inquiry, apply for employment, or otherwise interact with us.

Section 01

About Gravita Solutions

Gravita Solutions LLC

A subsidiary of Gravita Oasis Review Solutions

212 N. 2nd St., STE 100Richmond, KY 40475United States
+1 (813) 708-1643United States

Gravita Solutions provides business-to-business services primarily to home health agencies and other healthcare organizations.

Section 02

Scope of This Privacy Policy

This Privacy Policy applies to personal information we collect through:

  • Our Website
  • Contact and inquiry forms
  • Service or consultation requests
  • Free 10-chart review requests
  • Email and telephone communications
  • Client and prospective-client interactions
  • Recruitment and employment applications
  • Other business interactions with Gravita Solutions

This Privacy Policy primarily addresses personal information collected through our Website and ordinary business interactions.

Protected Health Information

In providing healthcare-related services, Gravita Solutions may receive, access, maintain, or process Protected Health Information (“PHI”) on behalf of healthcare organizations.

When we act as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), PHI is handled in accordance with HIPAA, applicable regulations, and the applicable Business Associate Agreement (“BAA”).

This Privacy Policy does not replace, modify, or override any BAA or other contractual agreement governing PHI.

A healthcare organization that engages Gravita Solutions generally remains responsible for determining how patient information is collected, used, and disclosed.

Patients who have questions about their health information or wish to exercise HIPAA rights should contact the healthcare provider or home health agency responsible for their records.

Section 03

Information We Collect

Information You Provide

Depending on how you interact with us, we may collect:

  • Name
  • Job title or professional role
  • Agency or organization name
  • Business email address
  • Telephone number
  • Business address
  • Information about your organization’s services or requirements
  • EMR or technology information
  • Information included in contact or consultation requests
  • Information submitted through a 10-chart review request
  • Information provided during client onboarding
  • Information provided through email or telephone communications
  • Resume and employment history
  • Education, qualifications, certifications, and other information submitted during recruitment

Information Collected Automatically

When you visit our Website, we may automatically collect certain technical and usage information, including:

  • IP address
  • Browser type and version
  • Device type
  • Operating system
  • Referring URL
  • Pages visited
  • Date and time of visits
  • Approximate location derived from technical information
  • Website interaction information
  • Information collected through cookies and similar technologies

We use this information to operate, secure, analyze, and improve our Website and services.

Information You Should Not Submit Through Public Forms

Our public Website forms are not intended for submitting patient PHI.

Do not submit patient names, medical records, clinical notes, insurance information, Social Security numbers, or other patient-identifying health information through a public Website form.

If patient information is required for a service, it should be provided only through secure systems and channels authorized under the applicable client agreement and BAA.

Section 04

How We Use Personal Information

We may use personal information to:

  • Respond to inquiries and consultation requests
  • Provide requested information, evaluations, and services
  • Communicate with prospective and existing clients
  • Understand prospective clients’ business and service requirements
  • Provide RCM, coding, OASIS, clinical review, claims, authorization, and denial-management services
  • Manage client relationships
  • Provide reports, project updates, and other business communications
  • Process invoices and payments
  • Manage contractual and account-related matters
  • Recruit and evaluate employees and contractors
  • Send educational, informational, or marketing communications where permitted by law
  • Operate, maintain, and improve our Website
  • Analyze Website traffic and performance
  • Maintain information security
  • Detect and prevent fraud, misuse, or unauthorized access
  • Investigate security incidents
  • Comply with legal, regulatory, tax, accounting, and contractual obligations
  • Establish, exercise, or defend legal claims
  • Protect our rights, property, personnel, clients, and systems

We do not sell personal information for monetary consideration.

We do not knowingly disclose personal information to third parties for their own independent advertising purposes.

Section 06

Cookies and Similar Technologies

Our Website may use cookies and similar technologies for purposes including:

  • Essential Website functionality
  • Security
  • Remembering preferences
  • Website analytics
  • Measuring Website performance
  • Improving Website content and functionality
  • Marketing or advertising measurement, where applicable

Third-party providers may also use cookies or similar technologies when providing services to us.

You can control or delete cookies through your browser settings. Disabling certain cookies may affect Website functionality.

Where required by applicable law, we will provide appropriate cookie consent and preference mechanisms.

Where required by applicable law, we will recognize legally recognized browser-based privacy signals, including Global Privacy Control.

Section 07

How We Share Personal Information

We may disclose personal information in the following circumstances:

Service Providers

We may use third-party providers for services such as:

  • Website hosting
  • Cloud services
  • Email
  • Customer relationship management
  • Analytics
  • Information technology
  • Cybersecurity
  • Recruiting
  • Business administration
  • Communications

These providers may process personal information on our behalf and are expected to use it only for authorized purposes and in accordance with applicable contractual requirements.

Client Organizations

We may provide reports, documentation, findings, work product, and other information to the client organization that engaged us, as necessary to provide our services.

Subcontractors

We may use authorized subcontractors to assist with providing our services.

Where a subcontractor is permitted to access PHI, we require an appropriate written agreement and applicable HIPAA safeguards before providing such access. HIPAA requires appropriate contractual protections for business associates and applicable subcontractors that handle PHI.

Legal and Regulatory Requirements

We may disclose information where reasonably necessary to:

  • Comply with applicable law
  • Respond to lawful government requests
  • Respond to subpoenas or court orders
  • Protect our rights or property
  • Protect the safety of individuals
  • Investigate fraud or unlawful activity
  • Establish, exercise, or defend legal claims

Business Transactions

Personal information may be transferred or disclosed as part of a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, subject to applicable law.

Section 08

HIPAA and Protected Health Information

When Gravita Solutions acts as a HIPAA Business Associate, we handle PHI in accordance with HIPAA, applicable regulations, and the applicable BAA.

Our HIPAA-related practices include safeguards and procedures designed to:

  • Limit PHI access to authorized personnel
  • Use PHI only for permitted purposes
  • Apply appropriate access controls
  • Protect electronic PHI through appropriate administrative, physical, and technical safeguards
  • Maintain appropriate confidentiality obligations
  • Provide privacy and security training to personnel who require access to PHI
  • Maintain procedures for identifying and responding to security incidents
  • Report applicable security incidents and breaches to the covered entity as required by HIPAA and the applicable BAA
  • Return or securely destroy PHI when required by the applicable BAA or law
  • Require appropriate agreements with applicable subcontractors that have access to PHI

HIPAA requires business associates to have appropriate written arrangements with covered entities and imposes direct obligations on business associates concerning certain privacy and security requirements.

Patients who wish to exercise HIPAA rights concerning their health information should generally contact the healthcare provider or home health agency responsible for their records.

Section 09

Data Security

We maintain administrative, technical, and organizational safeguards designed to protect personal information from unauthorized access, disclosure, alteration, loss, or destruction.

Depending on the information and system involved, our safeguards may include:

  • Role-based access controls
  • Multi-factor authentication
  • Encryption in transit and, where appropriate, at rest
  • Endpoint and network security measures
  • Secure remote-work procedures
  • Access and activity monitoring
  • Security reviews
  • Employee privacy and security training
  • Incident response procedures
  • Access restrictions based on business need

No method of transmitting or storing information is completely secure. Therefore, we cannot guarantee absolute security of information transmitted over the Internet.

Section 10

Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy or as required by:

  • Contractual obligations
  • Legal requirements
  • Tax and accounting requirements
  • Regulatory requirements
  • Audit requirements
  • Dispute resolution
  • Legal claims
  • Security and business continuity requirements

Retention periods vary depending on the type of information, the purpose for which it was collected, contractual requirements, and applicable law.

PHI is retained, returned, or destroyed in accordance with applicable law, the applicable BAA, and client agreements.

When information is no longer required, we take reasonable steps to securely delete, destroy, or de-identify it where appropriate.

Section 11

International Data Processing

Gravita Solutions has business operations and personnel in the United States and India.

Depending on the nature of our services and business relationships, personal information may be accessed or processed by authorized personnel in different countries.

Where applicable law requires safeguards for international transfers, we will use an appropriate lawful transfer mechanism and applicable contractual or organizational safeguards.

Client-specific requirements concerning data locations and access may also be addressed in applicable service agreements and BAAs.

Section 12

Your Privacy Rights

Depending on your location and applicable law, you may have certain rights regarding your personal information.

These rights may include:

  • The right to know whether we process your personal information
  • The right to access personal information we hold about you
  • The right to request correction of inaccurate personal information
  • The right to request deletion of personal information
  • The right to obtain a copy of certain personal information
  • The right to withdraw consent where processing is based on consent
  • The right to opt out of certain marketing communications
  • The right to opt out of certain forms of sale or sharing where applicable
  • The right to object to or restrict certain processing where applicable
  • The right to appeal certain privacy decisions where required by law
  • The right to lodge a complaint with an applicable privacy regulator

These rights are subject to applicable legal exceptions and limitations.

To submit a privacy request

Subject
Privacy Request

We may need to verify your identity before completing certain requests.

We will respond within the timeframe required by applicable law.

We will not discriminate against individuals for exercising privacy rights available to them under applicable law.

Section 13

California Privacy Rights

If you are a California resident and the California Consumer Privacy Act (“CCPA”), as amended, applies to our processing of your personal information, you may have additional rights.

Depending on the circumstances, these may include:

  • The right to know about personal information collected, used, disclosed, or otherwise processed
  • The right to request deletion
  • The right to request correction
  • The right to opt out of the sale or sharing of personal information where applicable
  • The right to limit certain uses and disclosures of sensitive personal information where applicable
  • The right to appeal certain privacy-request decisions
  • The right not to receive discriminatory treatment for exercising applicable privacy rights

We do not sell personal information for monetary consideration.

If our practices constitute “sharing” under applicable California law, we will provide the disclosures and opt-out mechanisms required by law.

California residents may submit privacy requests using

Subject
California Privacy Request

We may verify your identity before processing a request.

California privacy requirements include specific requirements concerning privacy-policy disclosures and consumer rights.

Section 14

Other U.S. State Privacy Rights

Residents of other U.S. states may have additional rights under applicable state privacy laws.

Depending on the applicable law and circumstances, these rights may include:

  • Access
  • Correction
  • Deletion
  • Data portability
  • Consent withdrawal
  • Objection
  • Opting out of certain processing
  • Appeals of privacy-request decisions

Where required by applicable law, we will provide additional notices, disclosures, or mechanisms for exercising these rights.

Section 15

Marketing Communications

We may send newsletters, educational materials, service information, or marketing communications where permitted by applicable law.

You may unsubscribe from marketing communications by:

Unsubscribing from marketing communications does not prevent us from sending transactional, contractual, security, or service-related communications that are necessary for our business relationship.

Section 16

Job Applicants

If you apply for employment or another position with Gravita Solutions, we may collect:

  • Name and contact information
  • Resume
  • Employment history
  • Education
  • Professional qualifications
  • Certifications
  • Skills
  • References
  • Interview information
  • Other information reasonably necessary to evaluate your application

We use applicant information to:

  • Evaluate qualifications
  • Communicate with applicants
  • Manage recruitment
  • Consider applicants for future positions where permitted
  • Comply with applicable employment laws

We may retain applicant information for a reasonable period where permitted by law.

Please do not submit unnecessary sensitive personal information as part of your application.

Section 17

Children’s Privacy

Our Website and services are intended for businesses, healthcare organizations, professionals, and adult users.

We do not knowingly collect personal information from children through our Website.

If you believe a child has provided personal information to us, please contact info@gravitasolutions.llc.

Where required by applicable law, we will take reasonable steps to delete the information.

Section 18

Third-Party Websites and Services

Our Website may contain links to third-party websites, healthcare technology platforms, EMR providers, social media platforms, or other external resources.

We are not responsible for the privacy or security practices of third-party websites or services.

You should review the privacy policies of those third parties before submitting personal information to them.

Section 19

Privacy Signals

Some browsers and devices provide privacy preference signals.

Where required by applicable law, we will recognize legally recognized privacy signals, including Global Privacy Control.

Such signals may not apply to all processing activities, including processing necessary to provide requested services, comply with legal obligations, maintain security, or perform other activities permitted by applicable law.

Section 20

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

  • Our business
  • Our services
  • Technology
  • Privacy practices
  • Legal or regulatory requirements

When we update this Privacy Policy, we will change the Last Updated date at the top of this page.

Where required by law, we will provide additional notice of material changes.

We encourage you to review this Privacy Policy periodically.

Section 21

Contact Us

If you have questions about this Privacy Policy or how Gravita Solutions handles personal information, please contact us:

Gravita Solutions LLC

A subsidiary of Gravita Oasis Review Solutions

212 N. 2nd St., STE 100Richmond, KY 40475United States
+1 (813) 708-1643United States

Use the right subject line so it reaches the right desk

Privacy requests
Privacy Request
HIPAA or BAA inquiries
HIPAA Inquiry

Last updated September 16, 2026

Back to top
Free 10-chart review