Last updated: August 10, 2026
HMH Holdings LLC d/b/a Itemizeit (“Itemizeit,” “we,” “our,” or “us”) is committed to protecting your privacy. Itemizeit provides medical bill review and consumer billing advocacy services. This Privacy Policy explains what information we collect, how we use and share it, and the choices you have when using our website, bill review tools, case portal, and related services (“Services”).
Because medical bills and related documents may contain sensitive health and financial information, we treat this information with additional care.
If you are a Washington or Nevada consumer, please also review our separate Consumer Health Data Privacy Policy, which describes how we handle consumer health data and the specific rights available to you.
Itemizeit is a direct-to-consumer service. We are not a healthcare provider, health plan, or healthcare clearinghouse, and we are not a business associate of one. That means Itemizeit is not a covered entity or business associate under HIPAA, and the information you provide to us is not protected by HIPAA.
Your information is instead protected by this Privacy Policy, by our agreements with the service providers who help us operate Itemizeit, and by applicable federal and state privacy and consumer health data laws.
Your medical records held by your provider or insurer remain protected by HIPAA in their hands. Copies you send to us do not.
Depending on how you use Itemizeit, we may collect the following categories of information:
When you electronically sign or authorize an action, we may collect information necessary to document that authorization, including your name, signature, date and time, verification information, IP address, and related audit information.
Payments are handled by our payment processor. We may receive transaction details such as the amount paid, payment status, and transaction identifier. We do not store your complete payment card number.
We may collect information such as your IP address, browser and device information, session activity, security events, cookies, and general usage information.
Most information we process comes directly from you or from documents you provide. We may also receive information from a person legally authorized to act on your behalf, healthcare providers, insurers, billing departments, or other organizations responding to communications you authorized, and service providers helping us operate the Services.
We use information to:
We use consumer health information only for purposes related to providing, supporting, securing, and administering Itemizeit, or as otherwise authorized by you.
Itemizeit uses automated technology, including artificial intelligence, to assist with medical bill review, document processing, and generation of billing-related information. Information may be processed by contracted technology providers when necessary to provide these features.
We do not use your documents, medical information, or case content to train artificial intelligence models, and our contracts with our AI service providers prohibit them from using your information to train or improve their models. Your information is processed only to return a result to you.
AI-assisted results may be incomplete or incorrect and are subject to the limitations described in our Terms of Service. We do not sell consumer health information and we do not use identifiable medical billing information for targeted advertising.
We do not sell or rent your personal information or consumer health information. We may share information when reasonably necessary to provide the Services you request. This may include sharing with categories of service providers that support technology and hosting, AI and document processing, payment processing, email and text communications, postal mail and correspondence, security and fraud prevention, and customer support.
When you authorize Itemizeit to communicate about your case, relevant information may also be shared with healthcare providers, insurers, billing departments, or other recipients involved in your billing matter.
We may also disclose information when required by law, legal process, or a valid government request, or when reasonably necessary to protect Itemizeit, our users, or the security of the Services. If Itemizeit is involved in a merger, acquisition, restructuring, or sale of business assets, information may be transferred as part of that transaction subject to applicable privacy requirements.
Medical bills and related documents may contain information considered consumer health data under applicable state privacy laws. We process consumer health information to provide the medical bill review, billing advocacy, case management, document generation, and communication services you request.
Itemizeit does not sell consumer health data. Itemizeit does not use consumer health data for targeted advertising. We do not permit third parties to collect consumer health data through Itemizeit over time and across unrelated websites or online services for targeted advertising.
Washington and Nevada consumers should also review our separate Consumer Health Data Privacy Policy.
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information and consumer health information. These measures include encryption of information in transit and at rest, access controls, authentication, secure document handling, monitoring, and restrictions on access to sensitive information. Access to consumer health information is limited to systems, service providers, and authorized personnel who reasonably need that access. No online service can guarantee absolute security.
If we discover a security breach affecting your unsecured personal information or health information, we will notify you without unreasonable delay and within the time required by applicable law. Depending on the nature and scale of the incident, we will also notify the Federal Trade Commission, state attorneys general, and, where a breach affects 500 or more individuals, prominent media in the affected area, as required by the FTC Health Breach Notification Rule and applicable state breach notification laws. Notice will describe what happened, the types of information involved, the steps we are taking, and what you can do to protect yourself.
We retain information only for as long as reasonably necessary to provide the Services, maintain active cases, complete authorized communications, meet legal or financial recordkeeping obligations, resolve disputes, and protect the security of Itemizeit.
Our standard retention periods are:
| Information type | Retention period |
|---|---|
| Uploaded bill documents and EOBs | 30 days after upload, or until case closure if longer |
| Analysis results and case records | 12 months after case closure |
| Letters and correspondence sent on your behalf | 3 years, for audit and dispute purposes |
| Electronic authorization records | 3 years |
| Payment and transaction records | 7 years, as required for tax and financial recordkeeping |
| Account and contact information | Until you delete your account, then 30 days |
| Backups | Overwritten through normal lifecycle within 90 days |
You may request earlier deletion at any time as described in Section 14, subject to the exceptions noted there. When information is no longer reasonably necessary, we delete or de-identify it. Information may remain temporarily in protected backup systems until those backups are overwritten through their normal lifecycle.
Itemizeit uses cookies and similar technologies for authentication and account security, maintaining sessions, and remembering preferences. We do not use advertising cookies, cross-site tracking technologies, or third-party analytics platforms. We do not use medical bills, case contents, or consumer health information for targeted advertising. Because we do not engage in the sale of personal data or cross-context behavioral advertising, browser-based opt-out signals such as Global Privacy Control (GPC) do not change how we handle your data, we do not conduct the activities those signals are designed to restrict.
If you choose to receive text messages or other electronic communications, we may use your contact information to send case updates, account notifications, document updates, security alerts, and other communications related to the Services. We do not sell or provide your phone number to third parties for their own marketing purposes. You may opt out of supported SMS communications by replying STOP. Message and data rates may apply.
Depending on where you live and which laws apply, you may have the right to ask whether we maintain information about you, access information we maintain about you, request correction of inaccurate information, request deletion of information, request that we stop certain collection or sharing, withdraw consent where applicable, request a list of third parties with whom your consumer health information has been shared, obtain a portable copy of your information, and be free from discrimination for exercising a privacy right.
California residents have the rights described above under the CCPA as amended by the CPRA. Medical bills, health information, insurance information, and financial account information are treated as sensitive personal information. We use sensitive personal information only to provide the Services you requested, to secure your account, and for the other limited purposes permitted by law. We do not sell personal information and we do not share personal information for cross-context behavioral advertising.
Consumer health data rights, including the right to withdraw consent and the right to appeal a denied request, are described in our separate Consumer Health Data Privacy Policy.
Residents of states with comprehensive privacy laws, including Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and others, have access to the rights listed above to the extent those laws apply, including the right to appeal a denied request.
To exercise a privacy right, contact: hello@useitemizeit.com using the subject line Privacy Request. We may need to verify your identity before completing a request. We will respond within the period required by applicable law, and in most cases within 45 days.
Where a deletion request is authenticated and no legal exception applies, we will delete the covered information from our active records within 30 days and direct our service providers to do the same. We may retain information after a deletion request where required or permitted by law, including to maintain records of correspondence already sent, to comply with tax and financial recordkeeping obligations, to resolve disputes, or to protect against fraud. We will tell you if this applies to your request.
If we decline to act on your request and applicable law gives you the right to appeal, email hello@useitemizeit.com with the subject line Privacy Request Appeal. We will respond in writing within 45 days explaining the reasons for our decision. If we deny the appeal, we will tell you how to contact your state attorney general to submit a complaint.
You may delete your Itemizeit account at any time from your account settings or by contacting us. Deleting your account does not retract correspondence that has already been sent on your behalf, and does not stop a provider, insurer, or billing department from replying to that correspondence. We will retain records of authorizations you signed and correspondence already sent for the periods described in Section 11. Everything else is deleted or de-identified according to Sections 11 and 15.
Itemizeit accounts are intended for individuals age 18 and older. We do not knowingly permit children under 18 to create their own Itemizeit accounts. An adult parent, guardian, or other legally authorized representative may provide information concerning a minor when legally authorized to do so.
We may update this Privacy Policy as Itemizeit, our Services, or applicable laws change. We will update the Last Updated date when changes are made. If we make material changes affecting how consumer health information is collected, used, or shared, we will provide notice through the website, your account, email, or another reasonable method before the change takes effect, and we will obtain your consent where required by law.
Questions about this Privacy Policy or our privacy practices:
HMH Holdings LLC d/b/a Itemizeit
Email: hello@useitemizeit.com
Website: useitemizeit.com
We use cookies to keep sign-in secure and the site working. With your consent, we may also use cookies for extra features and to understand how the site is used. You can change your choice any time via “Cookie Preferences” in the footer.