Last updated May 9, 2026.

What we collect

HospitalCost is designed to require as little personal data as possible. The site works without any account, login, or sign-up. The only data we collect:

  1. Patient-reported price submissions — when you fill out the form at /report-price, we store the information you choose to share. Depending on which option you pick ("I called billing," "I had the procedure," or "I'm comparing"), this may include:
    • The hospital and procedure you're reporting on
    • Whether the disclosed cash price was applied (yes / no / partial / not sure)
    • Optional notes about what billing told you
    • Optional dollar amounts (what you paid out of pocket, what insurance paid, total billed)
    • Optional payment type and approximate month of service
    • Optional email address — only if you'd let us follow up with one question
    We also automatically record a one-way hash of your IP address (used to limit duplicate submissions and prevent spam) and your browser's user-agent string.
  2. Standard web analytics via Google Analytics 4 — page views, referrer, approximate location, device type. GA4 anonymizes IP addresses by default. Google Analytics is a service of Google LLC; their privacy practices are described at policies.google.com/privacy.

Email is always optional. Submissions are anonymous unless you choose to provide an email.

What we do with it

  • Patient-reported submissions are reviewed by us before they count toward any published aggregate. Aggregate findings (e.g., "of N reports, X% said the disclosed price was applied") may be published; individual reports are never identified by name or email.
  • If you provided an email and your submission is unclear or surprising, we may follow up with one question to understand what you paid. We never share, sell, or publish emails.
  • Analytics data is used to understand which pages are useful and which are not.

Cookies

We use a minimal set of cookies: a session cookie required for the site to work, and Google Analytics cookies for traffic measurement. We do not use advertising, retargeting, or third-party tracking cookies.

Your rights

You can ask us to delete any information we hold about you at any time. Email richard@hospitalcost.com with "delete my data" in the subject line. We will confirm the deletion within 5 business days.

If you are in California, the EU, or the UK, you have additional rights under CCPA, GDPR, or UK GDPR including the right to access, correct, or port your data. The same email address handles those requests.

Data retention

Aggregate findings from patient-reported submissions are retained indefinitely. Individual submissions (including any email you provided) are retained so we can follow up if needed and so the data layer compounds over time as more patients share what they paid. You can email us anytime to delete your individual submission. Analytics data is retained for 14 months per Google's default.

Children

This site is not directed at children under 13 and we do not knowingly collect information from them. If you believe a child has submitted information to us, email the address above and we will delete it.

Changes to this policy

If we change this policy materially, we will update the "last updated" date at the top and, for active subscribers, email a notice. If you have any questions about what we collect or how we use it, email us.

Contact

Richard Callaghan · richard@hospitalcost.com