Legal
Privacy Policy
How Nexus VIP Rides collects, uses, discloses and safeguards information through our website and in the course of non-emergency medical transportation (NEMT).
- Effective
- October 1, 2026
- Last Updated
- October 1, 2026
- Version
- 1.1
Please do not send health information through this website.
Our web forms and general email are not secure and not approved for Protected Health Information. To discuss a passenger's needs, call (843) 457-1060. Healthcare facilities should use the secure intake channel in their Business Associate Agreement.
1. Introduction and Scope
Nexus VIP Rides LLC (“Nexus VIP Rides,” “we,” “us,” or “our”) provides non-emergency medical transportation (“NEMT”) services in Myrtle Beach, South Carolina and surrounding areas. We respect the privacy of everyone who visits our website, requests a ride, rides with us, or contacts us on behalf of a patient or family member.
This Privacy Policy describes how we collect, use, disclose, and safeguard information through our website at www.nexusviprides.com (the “Site”) and through our general business operations.
Important — please read carefully.
This Privacy Policy is not our Notice of Privacy Practices under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Protected Health Information (“PHI”) that we receive, create, maintain, or transmit in connection with transportation services is governed by HIPAA, by our internal HIPAA Policies and Procedures, by our Notice of Privacy Practices, and by the Business Associate Agreements we execute with healthcare facilities, transportation brokers, and health plans. Where this Privacy Policy and our HIPAA obligations differ, our HIPAA obligations control with respect to PHI. A copy of our Notice of Privacy Practices is available at www.nexusviprides.com/notice-of-privacy-practices or by request at the contact information in Section 24.
2. Do Not Send Health Information Through This Website
Our website contact forms and general email addresses are not secure channels and are not approved for the transmission of health information. Please do not submit through the Site or by unencrypted email:
- Diagnoses, medical conditions, or treatment details
- Medicaid, Medicare, or insurance identification numbers
- Social Security numbers
- Physician orders, medical necessity forms, or discharge paperwork
- Payment card numbers
- Any other Protected Health Information
To arrange transportation or discuss a patient's needs, please call us at (843) 457-1060. Healthcare facilities and referral sources should use the secure intake channel established under their Business Associate Agreement with us. If you send us health information through an unsecured channel anyway, we will handle it in accordance with our HIPAA policies, but we cannot guarantee its security in transit.
3. Information We Collect
3.1 Information You Provide Directly
Through the Site:
- Name, telephone number, and email address submitted through contact or quote request forms
- General information about the type of service you are inquiring about (for example, ambulatory or facility transport)
- Any message content you choose to write
- Employment application materials, if you apply for a position with us
When arranging or receiving transportation:
- Passenger name, date of birth, and contact information
- Pickup and drop-off addresses
- Appointment date, time, and destination facility
- Mobility status and equipment needs (walker, cane, or oxygen)
- Whether an escort, attendant, or service animal will accompany the passenger
- Special assistance requirements, including cognitive, visual, or hearing impairments relevant to safe transport
- Infection-control precautions disclosed by a facility so we can transport safely
- Emergency contact information
- Payer information, including Medicaid identification number, health plan, or broker trip authorization number
- Documentation of a personal representative's authority, where applicable (see Section 10)
We collect only the information reasonably necessary to transport a passenger safely and to bill for that transport. This is the “minimum necessary” standard required under HIPAA, and we apply it to all passenger information regardless of source.
3.2 Information We Receive From Third Parties
We routinely receive passenger information from sources other than the passenger, including:
- Transportation brokers administering Medicaid or Medicare Advantage transportation benefits, who transmit trip assignments and passenger details to us
- Healthcare facilities — hospitals, dialysis centers, skilled nursing facilities, behavioral health clinics, adult day health centers — that schedule transportation for their patients
- Health plans and managed care organizations
- Case managers, social workers, discharge planners, family members, and legal guardians arranging transportation on a passenger's behalf
Information received from these sources in connection with treatment, payment, or healthcare operations is PHI and is protected under HIPAA and the applicable Business Associate Agreement.
3.3 Information Collected Automatically
When you visit the Site, we and our service providers may automatically collect:
- IP address and general geographic location derived from it
- Browser type, operating system, and device type
- Pages viewed, time spent, and referring website
- Date and time of access
- Cookie and similar identifiers (see Section 8)
3.4 Vehicle and Operational Data
For safety, service quality, regulatory compliance, and defense of claims, our vehicles and dispatch systems may collect:
- GPS location and route data
- Trip timestamps, mileage, and arrival/departure records
- Passenger signature logs confirming trip completion
- Electronic trip records required by brokers and payers for billing and audit
- Dashboard or in-vehicle camera recordings, where installed
Where in-vehicle cameras are used, signage is posted in the vehicle. Recordings are treated as confidential, are accessed only by authorized personnel for the purposes listed above, and are retained according to our Record Retention Policy. We do not use in-vehicle recordings for marketing, and we do not publish them.
3.5 Payment Information
For private-pay customers we collect billing name, billing address, and payment details necessary to process a transaction. See Section 12 for how payment card information is handled.
4. How We Use Information
We use the information we collect to:
- Schedule, dispatch, confirm, and complete transportation
- Assign a vehicle and driver appropriate to the passenger's mobility and assistance needs
- Communicate about pickup times, delays, cancellations, and return trips
- Verify eligibility and obtain trip authorization from brokers and payers
- Submit claims and receive payment for services rendered
- Respond to inquiries, quote requests, and complaints
- Meet the recordkeeping, reporting, inspection, and audit obligations imposed on us as a certificated motor carrier of passengers in South Carolina and as a participating NEMT provider
- Investigate accidents, incidents, service complaints, and insurance claims
- Train and supervise our drivers and staff
- Screen employees and contractors, including required federal healthcare program exclusion screening
- Maintain the safety and security of passengers, staff, and vehicles
- Operate, maintain, secure, and improve the Site
- Comply with applicable law, subpoenas, and lawful government requests
We do not use passenger health information for marketing, and we do not use it to make decisions about anything other than providing and being paid for transportation.
5. How We Disclose Information
We disclose information only as described below.
- To brokers, health plans, and payers. To obtain authorization, confirm trips, submit claims, and respond to audits.
- To healthcare facilities and treating providers. To coordinate pickup, drop-off, discharge timing, and continuity of care.
- To subcontracted transportation providers. If we assign a trip to a subcontracted provider, we share only the information that provider needs to complete the trip safely. Every subcontractor is contractually bound to confidentiality and HIPAA obligations at least as protective as our own.
- To service providers. Dispatch and routing software vendors, billing and clearinghouse vendors, IT and hosting providers, telephone and messaging providers, payment processors, and professional advisors. Vendors with access to PHI execute a Business Associate Agreement with us before receiving any.
- To insurers, defense counsel, and claims administrators. In connection with an accident, incident, or claim.
- To regulators and law enforcement. Including the South Carolina Office of Regulatory Staff, the South Carolina Public Service Commission, the South Carolina Department of Health and Human Services, the U.S. Department of Health and Human Services, and other agencies with lawful authority — in response to inspections, audits, investigations, subpoenas, court orders, or as otherwise required by law.
- In an emergency. To emergency medical services, hospital personnel, or public safety officials when necessary to prevent or lessen a serious and imminent threat to the health or safety of a passenger or others.
- In a business transfer. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to the protections of this Policy and applicable law.
We Do Not Sell Your Information
We do not sell, rent, or trade personal information or health information to any third party. We do not disclose personal information or health information to third parties for their own independent marketing purposes.
6. Text Messaging and Telephone Communications
If you provide a mobile number, you may receive text messages from us about ride confirmations, driver arrival, delays, cancellations, and scheduling. Message and data rates may apply. Message frequency varies. You may opt out at any time by replying STOP. Reply HELP for assistance, or call us at (843) 457-1060. Opting out of text messages may delay how quickly we can reach you about a ride and does not remove you from telephone contact.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Text messages we send contain only the minimum information necessary — typically a pickup time and a driver arrival notice. We do not include diagnoses, treatment details, or destination facility names that would reveal a health condition.
Telephone calls to and from our dispatch line may be recorded or monitored for quality assurance, training, dispute resolution, and accuracy of trip records. Where required, we will notify you at the start of the call.
7. Our Role Under HIPAA
Our obligations depend on the circumstances of a particular trip, and we may act in either or both of the following capacities.
- As a Business Associate. When a hospital, clinic, nursing home, health plan, or transportation broker engages us and discloses PHI so that we can perform transportation on its behalf, we act as a Business Associate of that organization. Our duties are set by HIPAA and by the Business Associate Agreement we execute with it.
- As a Covered Entity. To the extent we conduct standard electronic transactions — such as submitting claims or verifying eligibility electronically — we are a covered healthcare provider under HIPAA in our own right, with independent obligations including maintaining and distributing a Notice of Privacy Practices, designating a Privacy Officer and a Security Officer, and honoring individual rights directly.
Our handling of PHI is authorized and constrained by:
- HIPAA and the HIPAA Privacy, Security, and Breach Notification Rules, 45 C.F.R. Parts 160 and 164
- Business Associate Agreements executed with covered entities that engage us
- Our provider agreements with transportation brokers and health plans
- Section 1557 of the Affordable Care Act and Section 504 of the Rehabilitation Act, as a recipient of federal financial assistance
- Applicable South Carolina law governing confidentiality of medical and personal information
Every member of our workforce — drivers, dispatchers, billing staff, and management — signs a written confidentiality and HIPAA acknowledgment as a condition of employment, receives HIPAA training at hire and annually thereafter, and is subject to documented sanctions, up to and including termination, for unauthorized use or disclosure of passenger information.
9. Photographs, Video, and Social Media
We do not photograph, film, or post images of passengers. A photograph of a person receiving medical transportation reveals that they received healthcare, which makes the image protected health information. We will never post a passenger's image, name, story, testimonial, or trip details on social media, on our website, or in any marketing material without that passenger's prior written authorization — and where the passenger cannot authorize for themselves, without the written authorization of their personal representative.
Our drivers and staff are prohibited from photographing or recording passengers, and from discussing passengers on social media in any form, including in ways intended to be anonymous. This prohibition is part of every workforce confidentiality agreement and is enforced through our sanction policy.
Any authorization you give is voluntary, may be revoked in writing at any time, and is never a condition of receiving transportation from us.
10. Personal Representatives, Guardians, and Family Members
Many of our passengers are assisted by another person. HIPAA treats a personal representative — someone with legal authority to make healthcare decisions for a passenger — as standing in the passenger's shoes for privacy purposes.
Documentation we may request. Before disclosing information to or accepting instructions from a personal representative, we may ask to see a healthcare power of attorney, guardianship or conservatorship order, or other documentation of authority. For a minor, this is generally the parent or legal guardian.
Family members and friends. Where a family member or friend is involved in a passenger's care or in arranging transportation, we may share the limited information directly relevant to that involvement — for example, a pickup time — if the passenger agrees, does not object when given the opportunity, or is not present and we reasonably infer from the circumstances that the passenger would not object.
A passenger may object. A passenger with capacity may tell us not to share information with a particular person. We will honor that request. Tell us and we will note it on the file.
11. Employee and Applicant Information
If you apply to work with us or are employed by us, we collect and maintain information including your application, resume, driver's license, motor vehicle records, criminal background and registry screening results, drug and alcohol testing results, health screening documentation such as tuberculosis testing and immunization records, training and certification records, and payroll and tax information. This information is employment data, not PHI, and is not governed by HIPAA — but we treat it as confidential and protect it with the same safeguards described in Section 16.
We use it to evaluate qualifications, meet the driver qualification and screening requirements imposed on us by South Carolina regulation and by our facility and payer contracts, administer employment, and comply with law. We disclose it only to background screening vendors, testing providers, payroll and benefits administrators, facilities that require vendor credentialing, insurers, and regulators — or as law requires.
Drug and alcohol testing results and medical screening records are maintained separately from general personnel files, with access limited to those who need it.
12. Payment Card Information
Private-pay card payments are processed by a third-party payment processor that maintains PCI DSS compliance. We do not store full payment card numbers, and we do not accept payment card numbers by email, text message, or through a form on this Site. Our records retain only what is necessary to document a transaction, such as the last four digits, the card type, and the amount and date.
13. De-Identified and Aggregate Information
We may create and use de-identified or aggregate information — for example, total monthly trip volume, on-time performance rates, or service area utilization — for operations, quality improvement, reporting to facilities and payers, and describing our business. De-identification is performed in accordance with HIPAA standards. We will not attempt to re-identify de-identified information, and we will not permit a recipient to do so.
14. Marketing Communications
We market to healthcare facilities, brokers, and referral sources — not to patients based on their health information. If you receive business communications from us, you may unsubscribe at any time using the link in the message or by contacting us. We will honor the request promptly. Transactional messages about a scheduled trip are not marketing and will continue. We do not sell or share contact information with third parties for their marketing.
15. Biometric Information
We do not currently collect fingerprints, facial geometry, voiceprints, or other biometric identifiers from passengers or employees. If we adopt any system that does — for example, a biometric timeclock — we will update this Policy, provide notice, and obtain any consent the law requires before collection begins.
16. Data Security
We maintain administrative, physical, and technical safeguards designed to protect information against unauthorized access, use, disclosure, alteration, and destruction. These include:
- Role-based access controls, so staff can access only what their job requires
- Unique user credentials and multi-factor authentication where available
- Encryption of PHI in transit and at rest in our systems
- Encrypted, password-protected mobile devices used by drivers, with remote wipe capability
- Physical security of paper trip records and secure destruction of records at end of retention
- Workforce training, periodic risk assessment, and audit logging
- Written incident response and breach notification procedures
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. Please use the phone for anything sensitive.
17. Breach Notification
If we discover a breach of unsecured Protected Health Information, we will provide notification in accordance with the HIPAA Breach Notification Rule, 45 C.F.R. §§ 164.400–414, and applicable state law — including notice to affected individuals, to the covered entity where we act as a Business Associate, to the U.S. Department of Health and Human Services, and to media outlets where required by the scale of the breach.
For security incidents involving personal information that is not PHI, we will notify affected individuals as required by South Carolina law, including S.C. Code Ann. § 39-1-90.
18. Data Retention
We retain information for as long as necessary to provide services, satisfy our legal, regulatory, contractual, and payer audit obligations, and resolve disputes. Trip records, signature logs, driver qualification records, vehicle inspection and maintenance records, and billing documentation are retained for the longest period required by HIPAA, by our broker and payer contracts, by South Carolina motor carrier regulations, and by applicable statutes of limitation. Details are set out in our Record Retention Policy, available on request.
When information is no longer required, we destroy it securely — shredding for paper records and secure deletion or media destruction for electronic records.
19. Information About Deceased Passengers
HIPAA protects a person's health information for fifty years after death. We continue to safeguard the records of deceased passengers accordingly. We may disclose such information to an executor, administrator, or other person with authority to act on behalf of the estate, and to a family member or other person who was involved in the passenger's care or payment before death, to the extent relevant to that involvement — unless doing so would be inconsistent with a preference the passenger expressed to us. We may also disclose as law requires, including to coroners, medical examiners, and funeral directors.
20. Your Rights
20.1 Rights Regarding Health Information
If we hold PHI about you, HIPAA gives you rights including the right to access and obtain a copy of your records, to request correction of inaccurate information, to request an accounting of certain disclosures, to request restrictions on use and disclosure, to request confidential communications by alternative means, and to file a complaint. Where we act as a Business Associate of a hospital, clinic, health plan, or broker, requests to access or amend records generally must be directed to that organization, which holds the designated record set. We will direct you to the right party and will cooperate with the request. Where we hold the records in our own right, we will respond directly. Full detail on these rights appears in our Notice of Privacy Practices.
20.2 Rights Regarding Other Personal Information
You may contact us to:
- Ask what personal information we hold about you
- Request correction of inaccurate contact information
- Ask us to delete information we are not legally required to keep
- Opt out of text messages or non-essential communications
South Carolina does not currently have a comprehensive consumer privacy statute granting the rights available in some other states. Where a state or federal law does grant you additional rights, we will honor them.
20.3 Filing a Complaint
You may complain to us at the contact information in Section 24. You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at www.hhs.gov/ocr/privacy/hipaa/complaints. We will not retaliate against you, refuse you service, or treat you differently in any way for filing a complaint or exercising any right described in this Policy.
21. Children and Minors
We transport minor passengers when arranged by a parent, legal guardian, healthcare facility, or authorized payer. Information about a minor passenger is collected from that adult or facility, is treated as confidential and protected to the same standard as all passenger information, and is used only to provide transportation safely. The Site is not directed to children under 13, and we do not knowingly collect personal information directly from children under 13 through the Site. If you believe a child has provided information through the Site, contact us and we will delete it.
22. Accessibility
We are committed to making this Site usable by people with disabilities, including passengers who are blind or have low vision. See our Accessibility Statement.
Any service available through the Site is also available by telephone at (843) 457-1060. If any part of this Policy or the Site is not accessible to you, contact us and we will provide the information in an alternative format at no charge.
23. Third-Party Links
The Site may link to third-party websites, including broker portals, healthcare facilities, and payer resources. We do not control those sites and are not responsible for their privacy practices. Review their privacy policies before providing information.
24. Contact Us
Questions, requests, and complaints regarding privacy may be directed to:
Privacy OfficerNexus VIP Rides LLC
6100 Tides Way, Unit 307
Myrtle Beach, SC 29577
Phone: (843) 457-1060
Email: privacy@nexusviprides.com
Web: www.nexusviprides.com
Please do not include health information in email. Call us instead.
25. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last Updated” date at the top reflects the most recent revision. Material changes will be posted prominently on the Site. Continued use of the Site or our services after a change constitutes acceptance of the updated Policy. Changes affecting the handling of PHI will also be reflected in our Notice of Privacy Practices.
This document is a draft prepared for Nexus VIP Rides. It is not legal advice. Have it reviewed by an attorney licensed in South Carolina, and reconcile it against your broker and facility contract requirements, before publishing.
Questions about privacy?
Our privacy officer will help you — or anything here is available by phone.
