Privacy Policy
Effective date: September 13, 2026
Last updated: September 13, 2026
RR RUEAUSA
DE RUEHFL #0412 2621422
ZNY CCCCC
R 191422Z SEP 26
FM FIELD GRADE ADVISORY GROUP HQ FLORIDA//OPS//
TO RUEAUSA/ALL CLIENT RECIPIENTS//
INFO RUEHFL/FIELD GRADE ADVISORY GROUP FL//SUPPORT//
BT
CONFIDENTIAL // NOFORN
SUBJ/OPERATION SAFEGUARD: IMPLEMENTATION OF REVISED DATA PROTECTION POLICY//
REF/A/DOC/FIELD GRADE ADVISORY GROUP PRIVACY POLICY/13SEP26//
RMKS/
1. (U) PURPOSE. THIS MESSAGE SERVES TO ESTABLISH OPERATIONAL PROTOCOLS FOR THE SECURE HANDLING, REDACTION, AND TRANSMISSION OF SENSITIVE CLIENT
DATA UNDER OPERATION SAFEGUARD.
Field Grade Advisory Group presents its Privacy Policy using a military SMEAC (Situation, Mission, Execution, Administration & Logistics, Command & Signal) framework under Operation Safeguard, effective September 13, 2026.
Summary of Operational Order
Situation: Defines the digital threat environment targeting Personally Identifiable Information (PII) and Protected Health Information (PHI). Field Grade operates independently for administrative and records consulting and does not provide legal representation or medical diagnoses.
Mission: To collect, secure, utilize, and permanently dispose of sensitive client information across approved platforms while maintaining strict regulatory compliance.
Execution: Outlines a three-phase data lifecycle (Collection, Processing, Retention/Disposal). It mandates strict client data sanitization, a communications blackout on sensitive data (prohibiting ordinary email, text, or consumer AI tools like ChatGPT for PHI), and guidelines for optional assisted redaction.
Administration & Logistics: Specifies secure document upload procedures via the official website, outlines payment security, details privacy rights (access, deletion, correction) via support@fieldgradeadvisorygroup.com, and notes cookie/third-party policies.
Command & Signal: Establishes leadership governance, third-party vendor review, and primary communication protocols through official channels.
//
Annex A: Client Data Sanitization Summary
Annex A outlines high-value targets for redaction (SSNs, VA file numbers, medical IDs, full dates of birth, signatures, etc.) and warns that digital black boxes, blurring, or cropping are insufficient methods. Step-by-step tactical tracks using Adobe Acrobat Pro and Foxit PDF Editor are provided to permanently apply redactions and sanitize hidden metadata. Users can find the complete step-by-step software instructions and validation checklists in the referenced operational document.
Effective date: September 13, 2026
Last updated: September 13, 2026
Field Grade Advisory Group (“Field Grade,” “we,” “our,” or “us”) respects your privacy and is committed to protecting the personal information entrusted to us. This Privacy Policy explains what information we collect, how we use and protect it, when it may be disclosed, and the choices available to you.
This policy applies to fieldgradeadvisorygroup.com, our forms, booking features, secure document-upload tools, communications, and administrative consulting services.
1. Information We May Collect
Depending on how you interact with us, we may collect:
• Your name, email address, telephone number, and mailing address.
• Information you provide through inquiries, bookings, forms, questionnaires, or communications.
• Appointment and service information.
• Billing and transaction information. Payment-card information is generally processed by our payment provider rather than stored directly by Field Grade.
• Files and documents you intentionally upload through an approved secure process.
• Technical information such as browser type, device type, IP address, approximate location, referring page, and website activity.
• Cookie, analytics, and consent preferences.
• Communications and administrative records related to services you request.
Please provide only information that is reasonably necessary for your inquiry or purchased service.
2. Health and Other Sensitive Information
Certain services may involve personal medical records or other sensitive information. These materials may contain health information, Social Security numbers, VA file numbers, dates of birth, addresses, signatures, insurance information, medical-record numbers, photographs, or other personal identifiers.
Our Wix website has PHI Protection activated, and a Business Associate Agreement has been executed with Wix. These measures support our handling of protected health information when HIPAA applies. However, HIPAA compliance also depends on how the website, applications, devices, vendors, and internal procedures are configured and used.
Do not send medical records, Social Security numbers, VA file numbers, unredacted identification documents, or sensitive clinical information through ordinary email, text message, social media, website chat, or an AI tool.
If you are a healthcare covered entity or business associate requesting that we handle protected health information on your behalf, contact us before uploading documents so we can determine whether an additional written agreement or Business Associate Agreement is required.
3. Authorization to Provide Information
You should upload only records belonging to you or records you are legally authorized to provide.
By submitting information about another person, you represent that you have the authority, permission, or other lawful basis necessary to provide that information to Field Grade.
4. How We Use Information
We may use information to:
• Respond to inquiries.
• Schedule appointments and provide requested services.
• Organize client-provided records and administrative materials.
• Provide general educational and healthcare-system navigation resources.
• Process payments and maintain transaction records.
• Communicate about appointments, service updates, and requested follow-up.
• Maintain, secure, and improve our website and services.
• Detect misuse, fraud, security incidents, or technical problems.
• Meet contractual, insurance, accounting, and legal obligations.
• Protect the rights, safety, and property of clients, Field Grade, and others.
Field Grade provides independent administrative, educational, logistical, and records-organization services. We do not use client information to provide legal representation, medical diagnoses, or unaccredited preparation, presentation, or prosecution of VA claims.
5. Secure Document Uploads
Sensitive documents should be uploaded only through the secure upload method identified by Field Grade.
Before uploading:
• Confirm that you are using the official Field Grade Advisory Group website.
• Remove information that is not necessary for the requested service whenever reasonably possible.
• Upload only the files specifically requested.
• Do not place sensitive information in filenames.
• Verify that you selected the correct files before submitting them.
• Keep an unmodified original securely stored for your own records.
Uploading a document does not authorize Field Grade to use it for purposes unrelated to the service requested.
6. Redacting Documents Before Upload
Redaction permanently removes visible information from a document. Proper redaction is different from covering information with a black box, highlighting it, blurring it, cropping it, or changing the text color. Those methods may leave the underlying information accessible.
Examples of information that may need to be removed when it is not required include:
• Social Security numbers.
• VA file or claim numbers.
• Medical-record and patient-identification numbers.
• Health-insurance or beneficiary numbers.
• Financial-account and payment-card numbers.
• Full dates of birth.
• Home addresses, personal email addresses, and telephone numbers.
• Signatures.
• Driver’s-license, passport, military-identification, and other identification numbers.
• Full-face photographs or comparable identifying images.
• Barcodes, QR codes, document properties, content, attachments, and hidden metadata.
Redaction does not automatically mean that a document has been formally de-identified under HIPAA. HIPAA de-identification has specific requirements, including the Safe Harbor and Expert Determination methods.
Field Grade does not certify that a client-redacted document satisfies formal HIPAA de-identification requirements.
7. Commercial Redaction Software for Mac and Windows
You need only one proper PDF-redaction program. Download software directly from the developer’s official website. Product features and menu names may change between versions.
Adobe Acrobat Pro
Available for Mac and Windows:
https://www.adobe.com/acrobat/
- 1. Create a working copy of the original document.
2. Open the copy in Adobe Acrobat Pro.
3. Select All tools and then Redact a PDF.
4. Select Redact text and images.
5. Select every item that must be removed.
6. Review every page, including headers, footers, attachments, barcodes, and images.
7. Select Apply.
8. Enable the option to sanitize and remove hidden information when offered.
9. Select Continue.
10. Save the completed document under a new name, such as ClientName_Redacted.pdf.
11. Close and reopen the saved document.
12. Confirm that the removed information cannot be viewed, searched, selected, copied, or recovered.
Do not use Acrobat’s AI Assistant or another AI feature with documents containing sensitive health information.
Foxit PDF Editor
Available for Mac and Windows:
https://www.foxit.com/pdf-editor/
- 1. Create a working copy of the original document.
2. Open the copy in Foxit PDF Editor.
3. Select Protect.
4. Select Mark for Redaction and then Text & Images.
5. Select or drag over every item that must be removed.
6. Review every page before continuing.
7. Select Protect, Mark for Redaction, and then Apply Redactions.
8. Select Protect, Hidden Data, and then Sanitize Document.
9. Save the completed document under a new name, such as ClientName_Redacted.pdf.
10. Close and reopen the saved document.
11. Confirm that the removed information cannot be viewed, searched, selected, copied, or recovered.
Do not submit sensitive documents to Foxit AI or another AI feature.
Final Redaction Check
- Before uploading a redacted file:
• Search the document for each removed name or identifier.
• Try selecting and copying text from the redacted areas.
• Check every page, attachment, comment, layer, image, barcode, and QR code.
• Remove unnecessary metadata and hidden information.
• Verify that the redacted copy opens correctly.
• Upload only the verified redacted copy.
• Keep the original document securely stored.
Field Grade is not affiliated with or compensated by Adobe or Foxit. These products are provided only as examples. Field Grade does not warrant their performance, security, availability, pricing, or suitability. Your use of third-party software is governed by that provider’s terms and privacy practices.
8. Optional Assisted Document Redaction
If you cannot redact documents independently, Field Grade may offer an optional Assisted Document Redaction service through an approved secure process.
This service is not included automatically with a general inquiry or other service. It must be expressly offered, purchased, and documented before unredacted files are submitted.
When this service is available:
• You will identify the information you want removed.
• Field Grade will perform administrative redaction according to the agreed written scope.
• Field Grade will not determine which information is relevant to a VA claim, legal matter, diagnosis, or medical decision.
• Field Grade will not evaluate documents as medical or legal evidence.
• You must inspect and approve the completed files.
• Field Grade cannot guarantee that every identifier, hidden item, or re-identification risk has been eliminated.
• The service does not constitute formal HIPAA de-identification, legal advice, medical review, or VA claims assistance.
• Do not email unredacted records to request this service. Wait until Field Grade provides the approved secure submission method.
9. Artificial Intelligence Tools
Protected health information and other sensitive client records are not intentionally entered into public or consumer AI tools.
Clients must not submit PHI, medical records, Social Security numbers, VA file numbers, or other sensitive information through Wix AI features, website chatbots, ChatGPT, Adobe AI Assistant, Foxit AI, or similar tools.
Field Grade may use AI for nonsensitive administrative or drafting activities only when client PHI and confidential records are excluded.
10. Disclosure of Information
We may disclose information only as reasonably necessary to:
• Wix and approved providers supporting our website, secure forms, bookings, payments, communications, or data storage.
• Contractors or professional advisers subject to appropriate confidentiality requirements.
• Process a transaction or deliver a service requested by you.
• Comply with a valid legal obligation, subpoena, court order, or governmental request.
• Prevent fraud, misuse, security threats, or harm.
• Enforce our agreements or protect legal rights.
• Complete a business transfer, merger, reorganization, or sale, subject to appropriate protections.
We do not knowingly sell protected health information.
We do not sell personal information for monetary consideration. Some privacy laws may define “sale,” “sharing,” or targeted advertising more broadly. Where applicable, visitors may exercise the rights provided under their state’s law.
11. Service Providers and External Platforms
Our website is hosted through Wix. We may also use approved vendors for payment processing, scheduling, communications, document handling, professional services, security, and other operational purposes.
Each third-party provider maintains its own terms and privacy practices. Enabling Wix PHI Protection does not automatically make every external application, browser extension, integration, computer program, or service HIPAA compliant.
Field Grade reviews vendors before intentionally using them to process sensitive information. We do not intentionally use unsupported applications to handle PHI.
12. Cookies and Website Analytics
Our website may use essential cookies and similar technologies needed for security, site operation, account access, bookings, preferences, and transactions.
Subject to your consent and applicable law, we may also use analytics or performance technologies to understand general website activity and improve the visitor experience.
Where required, visitors may accept, reject, or manage nonessential cookies through the site’s cookie-consent tools. Disabling certain cookies may affect website functionality.
13. Data Retention and Secure Disposal
We retain personal information only as long as reasonably necessary to:
• Provide requested services.
• Complete our contractual responsibilities.
• Maintain appropriate business and transaction records.
• Resolve disputes.
• Meet insurance, accounting, tax, regulatory, or legal obligations.
• Protect against fraud or security incidents.
Retention periods may differ depending on the type of information and service involved.
When information is no longer required, we take reasonable steps to delete, destroy, or render it inaccessible. Backup systems, legal holds, or regulatory obligations may temporarily delay complete deletion.
Clients should retain their own original records.
Field Grade should not be treated as the permanent custodian of a client’s only copy.
14. Information Security
We use reasonable administrative, technical, and physical safeguards intended to protect information against unauthorized access, use, alteration, disclosure, loss, or destruction.
Safeguards may include:
• Restricted access.
• Strong authentication and account controls.
• Encryption where supported.
• Secure upload tools.
• Device and software updates.
• Access logging and monitoring.
• Staff confidentiality requirements.
• Secure retention and disposal practices.
• Review of applications used with sensitive information.
No website, storage platform, transmission method, or security procedure can guarantee absolute security. If we identify a security incident affecting your information, we will investigate and provide notifications when required by applicable law.
15. Your Privacy Choices and Rights
16. Email and Communications
Administrative and transactional messages may be sent regarding appointments, purchases, document requests, service delivery, security, or account activity.
Marketing communications, if used, will include an available method to unsubscribe. Opting out of marketing does not prevent necessary transactional or service-related communications.
Email is not an appropriate method for transmitting unredacted medical records or other highly sensitive information.
17. Third-Party Links
Our website may link to government agencies, accredited-representative directories, educational resources, software vendors, social-media services, or other independent websites.
A link does not constitute an endorsement. Field Grade does not control and is not responsible for another organization’s content, security, accessibility, terms, or privacy practices.
18. Children’s Privacy
Our website and services are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13 without appropriate authorization.
If you believe that a child’s information has been submitted improperly, contact us so we can review and address the situation.
19. Changes to This Policy
We may update this Privacy Policy to reflect changes in our services, technology, vendors, business practices, or legal obligations.
The revised policy will be posted on this page with an updated effective date. Material changes may also be communicated through the website or another reasonable method.
20. Contact Us
Questions, concerns, privacy requests, or complaints may be directed to:
Field Grade Advisory Group
Please do not include protected health information, medical records, Social Security numbers, VA file numbers, or other sensitive documents in an ordinary email.