Privacy Policy
Introduction
Information We Collect
2.1 Information You Provide Directly
- Full name, job title, and professional contact information
- Practice name, organization name, and business address
- Phone number and email address
- Information submitted through our contact forms or consultation requests
- Email correspondence and communication records
- Billing preferences, service requirements, and account information
2.2 Information Collected Automatically
- IP address and approximate geographic location
- Browser type, device type, and operating system
- Pages visited, time spent on site, and navigation patterns
- Referring website or search terms that brought you to our site
- Cookies and similar tracking technologies (see Section 12)
2.3 Protected Health Information (PHI)
HIPAA Note on PHI
As a medical billing company, we may access, process, and transmit Protected Health Information (PHI) on behalf of our healthcare provider clients solely to perform our contracted billing services. All PHI is handled strictly in accordance with HIPAA regulations and our signed Business Associate Agreements (BAAs). We do not collect PHI through our public website - PHI is only accessed through our secure, contracted billing systems.
How We Use Your Information
3.1 To Provide Our Services
- Processing medical billing and coding on behalf of healthcare providers
- Submitting and following up on insurance claims with payers
- Managing accounts receivable and handling denial appeals
- Credentialing and payer enrollment services
- Providing eligibility and benefits verification
- Delivering complete Revenue Cycle Management (RCM)
3.2 To Communicate With You
- Responding to inquiries, consultation requests, and support questions
- Sending service updates, billing reports, and account information
- Notifying you of changes to our services, policies, or terms
- Sending marketing communications only with your prior consent
3.3 To Improve and Operate Our Business
- Analyzing website usage to improve user experience
- Monitoring service performance and identifying technical issues
- Conducting internal research and quality improvement initiatives
- Complying with legal, regulatory, and contractual obligations
- Preventing fraud, abuse, and unauthorized access
HIPAA Compliance
4.1 Business Associate Agreements (BAA)
4.2 PHI Safeguards We Implement
- Administrative Safeguards: Comprehensive staff training, defined access controls, and documented security policies and procedures
- Physical Safeguards: Secure facility access, workstation controls, and media handling procedures
- Technical Safeguards: Encrypted data transmission (TLS/SSL), role-based access controls, audit logs, and automatic logoff
- Minimum Necessary Standard: We only access, use, or disclose the minimum PHI necessary to perform our contracted services
4.3 Breach Notification
How We Share Your Information
|
With Your Consent
|
Service Providers
|
Insurance Payers
|
Legal Requirements
|
Business Transfers
|
|---|---|---|---|---|
|
We share your information with third parties only when you have provided explicit, informed consent.
|
Trusted vendors who help us operate (e.g., IT infrastructure, billing software, secure cloud storage). All are contractually bound to protect your data.
|
We submit claims to insurance companies, Medicare/Medicaid, and clearinghouses strictly on behalf of our healthcare provider clients to fulfill our billing obligations.
|
We may disclose information when required by law, court order, or governmental authority or to protect the rights, safety, or property of RMBServ, clients, or the public.
|
In the event of a merger or acquisition, your information may be transferred. You will be notified before any transfer and given options regarding your data.
|
Data Security
SSL/TLS encryption for all data in transit
Role-based access controls (RBAC)
Firewall protection & intrusion detection
Multi-factor authentication (MFA)
Encrypted storage for all sensitive data at rest
Regular security audits & vulnerability testing
Employee security training & background checks
Secure data destruction procedures
California Residents CCPA Rights
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions permitted by law.
- Right to Opt-Out of Sale: We do not sell personal information. However, you have the right to direct us not to sell your personal information at any time.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights.
- Right to Correct: You may request correction of inaccurate personal information we maintain about you.
Your Privacy Rights
Right to Access
Request a copy of the personal data we hold about you
Right to Correct
Request correction of inaccurate or incomplete information
Right to Delete
Request deletion of your personal data (subject to legal obligations)
Right to Opt-Out
Opt out of marketing communications at any time
Data Portability
Request your data in a portable, machine readable format
Restrict Processing
Request that we limit how we process your information
Data Retention
- Client service & billing records: Minimum 7 years (as required by medical billing and CMS regulations)
- HIPAA-related PHI records: 6 years from the date of creation or the date it was last in effect
- Website analytics data: Up to 26 months
- Marketing contact information: Until you opt out or request deletion
- Legal and compliance records: As required by applicable federal and state law
- Financial records: 7 years in accordance with IRS requirements
Children's Privacy
Third-Party Links
Cookies & Tracking Technologies
12.1 Types of Cookies We Use
|
Essential Cookies
|
Analytics Cookies
|
Functional Cookies
|
Marketing Cookies
|
|---|---|---|---|
|
Required for the website to function properly (e.g., session management, security). These cannot be disabled as they are necessary for the site to work.
|
Help us understand how visitors interact with our website (e.g., Google Analytics). Data is collected anonymously and used to improve site performance.
|
Remember your preferences and settings to provide a more personalized and efficient browsing experience.
|
Used to show relevant content and measure campaign effectiveness. These are only activated with your explicit consent.
|
12.2 How to Manage Cookies
Changes to This Privacy Policy
- Update the "Last Updated" date at the top of this pag
- Post a prominent notice on our website homepage
- Notify existing clients via email for any significant changes that affect their rights
By using rmbserv.com or any of our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you have any questions or concerns, please contact us before continuing to use our services.