Access
Staff desk is team-email only. A consumer sees only their own portal file. Share codes are revocable and open only inside ops.
Licensed agents available — Mon–Fri 9am–6pm ET
+1 908-827-6223NAIC 673 · BAA
The written program for this website, portal, and staff desk. Not a certificate. Not the agency’s office-network binder — that lives with the Privacy Official.
NAIC Model 673 requires a licensee to have a written information security program for customer information. This page is that program for the public site, the consumer portal, and the BRIDGEt Console. The HIPAA and GLBA notices are the consumer-facing maps. This is the internal-facing one, published so a carrier can read it.
Staff desk is team-email only. A consumer sees only their own portal file. Share codes are revocable and open only inside ops.
No Social Security or Medicare-number fields. Free text that looks like either is rejected.
Production is HTTPS. Scripted cross-site requests are blocked. Security headers include nosniff.
Team lead alerts carry name, phone, email, zip, and window only. Doctors and medications stay on the desk.
Live BRIDGEt chat cannot open the needs file. Training or site improvement uses a service-provider contract, de-identified data, or authorization.
Categories, not a signed-vendor roster. A name goes on a roster only after the contract is executed.
The public site and data store. PHI stays in the agency database, not in marketing tools.
Phone, email, and optional lead-alert webhooks. Alerts are minimum-necessary.
BRIDGEt voice/chat vendors, if enabled, process a live turn. They do not receive the needs file unless a BAA and a service-provider contract are in place.
The Privacy Official reviews this program at least annually, and after a material system change or a security event. Last reviewed August 25, 2026.
Last reviewed August 25, 2026. 3550 Buschwood Park Dr, Ste 180, Tampa, FL 33618.