Skip to content
uTuTransplant
  • Privacy Request
  • Privacy
  • Consumer Health Data
Legal

uTransplant Secure Privacy-Request Verification Notice

Effective date: March 30, 2026
Last updated: August 19, 2026

The effective date is the original effective date of this notice; the Last updated date identifies this text. A revision applies prospectively when published and does not become retroactive merely because the original effective date remains unchanged.

This notice applies only when Bridge Clinical Care PLLC, which operates the uTransplant service and utransplant.com (collectively, “uTransplant,” “we,” “us,” or “our”), gives you a time-limited secure link to provide identity or authority documentation for a privacy or Consumer Health Data request.

Why we requested a document

We do not require government identification for every request. We ask for documentation only when less-intrusive information is not reasonably sufficient to authenticate the requester, prevent an unauthorized disclosure or deletion, verify a representative’s authority, prevent fraud, or comply with law.

The message that supplied your secure link should identify whether we need:

  • an identity document for the person whose information is involved;
  • an authorization, power of attorney, guardianship order, or other authority document for a representative; or
  • another specifically described record reasonably necessary for verification.

Provide only the requested document. Unless we specifically say otherwise, you may cover information not needed for verification, such as an identification number, physical characteristics, or photograph, so long as your name and the requested verification fields remain readable. Do not upload medical records, passwords, payment-card information, Social Security numbers, or unrelated documents.

How we use the upload

We use an uploaded verification document only to authenticate identity or authority, protect the request process, prevent fraud or unauthorized access, comply with law, and document the verification result. We do not use it for matching, Navigator Services, medical decision-making, marketing, advertising, profiling, or artificial-intelligence or machine-learning model training.

We do not use this upload process to generate a biometric identifier or face-geometry template, or to perform automated facial matching. Before any automated measurement used to identify a person, we would publish the required retention and destruction schedule, provide the legally required written notice of collection, purpose, and term, obtain a written release, and implement applicable disclosure, sale-or-profit, and security restrictions.

Who may receive it

Access is limited to authorized privacy, security, legal, or technical personnel who need it for the purposes above and to a contracted provider that securely hosts or supports the verification channel. Before permitting a provider to process Consumer Health Data on our behalf, we require the binding instructions, confidentiality, security, rights-assistance, deletion, and other terms required by applicable law. We may disclose a document when required by valid legal process or reasonably necessary to investigate fraud, a security incident, or an unauthorized request, subject to applicable law.

Retention and deletion

Unless a longer period is required by law or reasonably necessary for a documented fraud, security, dispute, or legal-hold purpose, we delete a government-identification image from active systems as soon as verification is complete and no later than 30 days after verification succeeds, fails, or is abandoned. For an exception, we document the reason, limit access and use to that reason, set a review and deletion date, and retain only the minimum necessary. We may retain a limited record of the verification method, result, and date for the ordinary compliance and limitations period without retaining the image, but only to the extent applicable law permits; if a valid deletion right applies and no exception supports retention, we delete or deidentify the limited record. This limited record does not include the document image, identification number, face template, physical-description fields, or a copy of an authority document.

Signed authorizations, powers of attorney, and other authority documents follow a separately justified schedule because they may be needed to establish who was permitted to act. We delete the complete authority document from active systems as soon as it is no longer needed and no later than 30 days after the privacy request is closed, unless a longer period is required by law or reasonably necessary for a documented fraud, security, dispute, or legal-hold purpose. For an exception, we document the reason, limit access and use to that reason, set a review and deletion date, and retain only the minimum necessary. We may retain only the minimum audit record reasonably necessary to document the authority determination for the ordinary compliance and limitations period without retaining the complete document, but only to the extent applicable law permits; if a valid deletion right applies and no exception supports retention, we delete or deidentify the limited record. That limited record does not include the document image, identification number, face template, physical-description fields, or a copy of the authority document. Residual encrypted backup copies are isolated from ordinary use and expire through the applicable backup rotation and statutory deletion schedule.

Secure-link rules

Your link is personal, time limited, and may be single use. Do not forward it. Close the page after upload. If the link is expired, appears altered, or was sent to the wrong person, do not upload anything; contact privacy@utransplant.com for a replacement. Do not send identity or authority documents by ordinary email.

Submitting a document does not waive a privacy right, authorize unrelated processing, or guarantee that a request will be granted. We will use only information reasonably necessary to authenticate and decide the request, subject to applicable law.

Contact

Privacy requests and verification questions: privacy@utransplant.com
Security concerns: trust@utransplant.com

Bridge Clinical Care PLLC
Attn: uTransplant Privacy
4513 Lincoln Ave, Suite 203C
Lisle, IL 60532
United States

© uTransplant. Operator: Bridge Clinical Care PLLC. Privacy Request · Privacy · Verification notice