Referralogix
How It Works Who We Connect Pricing Log In Get Started Free →

Referralogix

Privacy Policy & Terms of Service

Privacy Policy Terms of Service

Privacy Policy

Last Revised: 01/01/26

Referralogix ("Referralogix", "RLX", "we", "us", or "our") values the privacy of our users and clients. This Privacy Policy explains how we collect, use, disclose, and safeguard information, including protected health information (PHI), and how we comply with healthcare regulatory obligations, including HIPAA.

  1. Information We Collect
  2. Use of Information
  3. HIPAA and PHI Handling
  4. Business Associate Agreement (BAA)
  5. Cybersecurity Assurance
  6. Data Retention and De-Identified Data
  7. Multi-Location Client Assurances
  8. Vendor Data Access
  9. Security Measures
  10. Users' Rights
  11. Changes to This Privacy Policy
  12. Contact Us

1. Information We Collect

RLX collects the following information:

  • Patient Referral Data: Medical documents, referral information, and provider data submitted through our communication platform.
  • De-Identified Data: Patient identifiers are removed or generalized for analytics and benchmarking.
  • User Information: Name, email, organization, role, and usage data for operational and marketing purposes.
  • Vendor Engagement Data: Interaction metrics for marketing spotlights, clicks, and duration on screens. Vendors cannot access PHI unless contractually approved.

2. Use of Information

RLX uses collected information for:

  • Providing referral communication and operational services to clinics and healthcare organizations.
  • Operating and improving the platform, including security, troubleshooting, and support.
  • Marketing, analytics, benchmarking, and aggregated data reporting using de-identified data.
  • Compliance with regulatory obligations and execution of Business Associate Agreements (BAA).

3. HIPAA and PHI Handling

  • PHI is handled only within the communication platform, which is HIPAA-compliant.
  • Marketing services, including the CRM, do not process PHI, even though the CRM is HIPAA-compliant.
  • RLX executes BAAs with all covered entities.

4. Business Associate Agreement (BAA)

RLX enters into a BAA with covered entities in accordance with HIPAA and HITECH.

5. Cybersecurity Assurance

RLX is approved by a third-party cybersecurity and HIPAA compliance authority, which validates our security and regulatory compliance programs. This approval ensures:

  • Secure platform architecture and tenant isolation
  • Safeguards against unauthorized PHI access
  • Continuous monitoring, risk management, and adherence to HIPAA requirements

6. Data Retention and De-Identified Data

  • PHI and referral content are retained for operational purposes.
  • Upon client termination, PHI may be returned or destroyed in accordance with the BAA (fees may apply).
  • RLX may retain de-identified data for analytics, benchmarking, network intelligence, service deployment, and operational insights. Vendors may access only aggregated, anonymized metrics. RLX does not sell data.

7. Multi-Location Client Assurances

RLX supports multi-location clients with:

  • Centralized and delegated admin controls
  • Reporting across locations and departments
  • Segregation of PHI between locations and clinics

Clients cannot restrict access to vendors or other clinics for their users.

8. Vendor Data Access

Vendors may access aggregated, de-identified activity metrics for marketing purposes, including spotlight clicks, screen duration, and network engagement. Vendors cannot access PHI unless specifically approved by the clinic in the BAA or contract. Vendor spotlights do not influence referral placement, priority, or directory order.

RLX does not sell data.

9. Security Measures

RLX implements administrative, technical, and physical safeguards to protect PHI and other sensitive information, including:

  • Tenant isolation between clinics, vendors, and marketing services
  • Employee access controls and audit procedures
  • Subprocessor agreements ensuring HIPAA compliance
  • Security practices verified by a third-party cybersecurity authority

10. Users' Rights

Clients may request access, amendments, or accounting of disclosures of PHI in accordance with HIPAA regulations. Requests are processed per the timelines specified in the BAA.

11. Changes to This Privacy Policy

RLX may update this Privacy Policy to reflect changes in operations, legal requirements, or cybersecurity compliance. Updated policies will be posted on the RLX website, and continued use constitutes acceptance of the updated policy.

12. Contact Us

For questions:
Referralogix (XBD, LLC)
Email: [email protected]

Terms of Service

Effective: 10/05/26

These Terms of Service ("Terms") govern access to and use of the Referralogix platform, website, and related services (together, the "Platform") provided by XBD, LLC, doing business as Referralogix ("Referralogix", "RLX", "we", "us", or "our"). By creating an account, accessing, or using the Platform, you agree to these Terms on behalf of yourself and any organization you represent. If you do not agree, do not use the Platform.

1. The Platform

Referralogix is a healthcare communication platform that connects healthcare organizations, departments, and staff for real-time communication, document exchange, and workflow coordination. Referralogix does not replace an electronic medical record (EMR) and is not a substitute for an organization's own clinical, record-keeping, or compliance systems.

2. Eligibility and Accounts

  • The Platform is intended for healthcare organizations, their authorized workforce members, and approved vendors. You must be at least 18 years old and authorized by your organization to use it.
  • You are responsible for keeping login credentials confidential, for all activity under your account, and for promptly notifying us of any unauthorized access.
  • Organization administrators are responsible for adding, managing, and removing their users, including promptly removing access for individuals who leave the organization.

3. Protected Health Information

  • Use of the Platform to create, receive, maintain, or transmit PHI on behalf of a covered entity is governed by the Business Associate Agreement (BAA) between Referralogix and that covered entity. If these Terms conflict with a BAA regarding PHI, the BAA controls.
  • Users are responsible for sharing only the minimum necessary PHI, sending information only to appropriate recipients, and complying with their own organization's policies and applicable law.
  • PHI must be shared only within the communication platform. Do not submit PHI through website forms, marketing channels, or general email.

4. No Medical Advice; Clinical Responsibility

Referralogix provides communication and workflow tools only. It does not provide medical advice, make clinical decisions, or guarantee the accuracy, completeness, or timeliness of information exchanged between users. Healthcare organizations and their professionals remain solely responsible for patient care, clinical decisions, referral choices, and verifying information received through the Platform.

5. Memberships, Fees, and Trials

  • Some Platform features are available at no cost through RLX Basic. Paid memberships, additional services, and vendor programs are subject to the pricing, billing terms, and minimum terms stated in the applicable order form, agreement, or checkout page.
  • Free trials, when offered, convert or end as described at sign-up. We may change or discontinue free features or trial offers with notice.
  • Unless your agreement says otherwise, fees are billed in advance and are non-refundable except as expressly stated.

6. Vendors and Advertising

Approved vendors may appear in the Platform directory and in marketing spotlights. Vendor placements are paid advertising and do not influence referral placement, priority, or directory order for healthcare organizations. Vendors may not access PHI unless specifically approved by the clinic in a BAA or contract. Referralogix does not endorse any vendor, and organizations are responsible for evaluating vendors before doing business with them. Vendor programs may be offered through authorized dealers, whose separate terms govern those programs.

7. Acceptable Use

You agree not to:

  • Access or attempt to access accounts, data, or organizations you are not authorized to access;
  • Upload malicious code or interfere with the security or operation of the Platform;
  • Use the Platform to send unsolicited marketing to users or to harass, mislead, or impersonate anyone;
  • Copy, scrape, resell, or reverse engineer the Platform or its directory data; or
  • Use the Platform in violation of HIPAA, anti-kickback or self-referral laws, or any other applicable law.

8. Faxing and Third-Party Services

The Platform supports communication with organizations outside the network, including by fax, and relies on third-party infrastructure and subprocessors. Referralogix is not responsible for delays, failures, or errors caused by recipients, carriers, fax lines, or other third-party systems outside our control.

9. Availability and Changes

We work to keep the Platform available and secure, but we do not guarantee uninterrupted or error-free operation. We may perform maintenance, update features, or modify the Platform from time to time.

10. Intellectual Property

Referralogix and its licensors own the Platform, including its software, design, logos, and content. You may use the Platform only as permitted by these Terms. Your organization retains ownership of the content it submits, and grants Referralogix the rights needed to host, transmit, and process that content to provide the Platform and as described in the Privacy Policy.

11. Disclaimer of Warranties

THE PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE." TO THE FULLEST EXTENT PERMITTED BY LAW, REFERRALOGIX DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT, EXCEPT AS EXPRESSLY STATED IN A WRITTEN AGREEMENT.

12. Limitation of Liability

TO THE FULLEST EXTENT PERMITTED BY LAW, REFERRALOGIX WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, OR DATA. REFERRALOGIX'S TOTAL LIABILITY FOR ANY CLAIM RELATED TO THE PLATFORM WILL NOT EXCEED THE AMOUNTS YOU PAID REFERRALOGIX IN THE TWELVE MONTHS BEFORE THE CLAIM AROSE. NOTHING IN THIS SECTION LIMITS OBLIGATIONS UNDER A BAA.

13. Indemnification

You agree to defend and indemnify Referralogix against claims, losses, and expenses, including reasonable attorneys' fees, arising from your misuse of the Platform, your violation of these Terms, or your violation of any law or the rights of a third party.

14. Suspension and Termination

We may suspend or terminate access for violations of these Terms, security risks, or non-payment. You may stop using the Platform at any time, subject to the terms of any paid membership or agreement. On termination, handling of PHI is governed by the BAA and the Privacy Policy.

15. Governing Law

These Terms are governed by the laws of the state in which XBD, LLC is organized, without regard to its conflict of law rules, unless a written agreement between you and Referralogix states otherwise.

16. Changes to These Terms

We may update these Terms from time to time. Updated Terms will be posted on the RLX website with a new effective date, and continued use of the Platform constitutes acceptance of the updated Terms.

17. Contact Us

For questions:
Referralogix (XBD, LLC)
Email: [email protected]
Phone: (888) 474-8882

Referralogix

Connecting healthcare organizations, departments and staff through one shared network for real-time communication, document exchange and workflow coordination.

Contact

[email protected] (888) 474-8882

Get Started

Get Started Free →
Schedule a Demo

© 2026 Referralogix. All rights reserved.

Privacy Policy & Terms of Service