Call UsMake A Payment

Home

About

Consumer Rights

Portfolio Services

Contact Us

Opt In

Security

Data Security

What we hold.

Names, addresses, telephone numbers, account balances and payment history — and, on healthcare placements, information that is protected health information. Card data is tokenized at the gateway and never stored by us in raw form.

GLBA · 15 U.S.C. § 6801 et seq.

What the law requires.

The Safeguards Rule requires a written information security program with named accountability, a risk assessment, access controls, encryption, vendor oversight and an incident response plan. It is a program requirement, not a checklist of products.

16 C.F.R. Part 314 · GLBA

How we work inside it.

Access is granted by role and by business need, logged, and revoked promptly when someone leaves. Data is encrypted in transit and at rest. Retention is bounded by schedule and destruction is documented. Vendors that touch consumer data are held to the same standard and audited.

16 C.F.R. § 314.4 · § 682.3 · CFPB Bulletin 2016-02

Why it matters here.

A collection file is one of the more sensitive records a consumer has, and it is assembled from data they did not choose to give us. Protecting it is the price of holding it.

Compliance

Security Controls

ControlGoverning authorityStatus
Written information security program with named accountability16 C.F.R. § 314.4(a)Maintained
Risk assessment performed and updated16 C.F.R. § 314.4(b)Maintained
Data encrypted in transit and at rest16 C.F.R. § 314.4(c)(3)Enforced
Multi-factor authentication on all platforms16 C.F.R. § 314.4(c)(5)Enforced
Access granted by role and business need, reviewed periodically16 C.F.R. § 314.4(c)(1)Enforced
Access logged, and revoked promptly on termination16 C.F.R. § 314.4(c)(1)Logged
Workstations locked on a short idle timeout; no consumer data on portable mediaInternal control per our furnisher policyEnforced
Card data tokenized at the gateway, never stored in raw formPCI DSSEnforced
Retention bounded by schedule, with documented secure destruction16 C.F.R. § 682.3Scheduled
Physical records in controlled storage; documents shredded, not discarded16 C.F.R. § 682.3Enforced
Vendors and service providers subject to due diligence and monitoring16 C.F.R. § 314.4(f) · CFPB Bulletin 2016-02Audited
Documented incident response plan, with backup restores tested16 C.F.R. § 314.4(h)Tested
Disaster recovery plan with documented recovery objectivesInternal continuity programMaintained
PHI handled under a business associate agreement where one applies45 C.F.R. Parts 160, 164Per engagement
State data-security and breach-notification requirements appliedState data-protection statutesPer matrix

What we do not claim

We do not hold a SOC 2 report and we do not describe ourselves as certified against a standard we have not been audited against. Where a client requires an independent assessment, we support theirs. What is listed above is what we operate, and it is what we can evidence.

Related

Additional Information

Privacy, compliance and consumer rights

What we collect and why is in our Privacy Policy. The full regulatory framework and our licensing are on the Compliance page. What a consumer can ask us to do — including deleting a phone number or disputing an account — is on Consumer Rights.

Resolve your accountSecure portal, open any hour

Make a Payment