Privacy Policy

This Privacy Policy explains how RMBServ collects, uses, and protects your information. We are fully HIPAA-certified and committed to protecting your privacy at every step.

Introduction

RMBServ (“we,” “our,” or “us”) is a US-based, HIPAA-certified medical billing company located at 5187 Dalai Lama Ave, Richmond, CA 94804. We provide comprehensive medical billing and coding, accounts receivable management, credentialing and contracting, out-of-network negotiation, eligibility and benefits verification, and complete Revenue Cycle Management (RCM) services to healthcare providers throughout the United States.
This Privacy Policy explains how we collect, use, disclose, protect, and manage your personal information when you visit our website at rmbserv.com or engage with our services. We are fully committed to protecting your privacy, maintaining transparency, and complying with all applicable laws including the Health Insurance Portability and Accountability Act (HIPAA).
This policy was last updated on March 11, 2026. We encourage you to review it periodically.

Information We Collect

We collect different types of information depending on how you interact with RMBServ:

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Protected Health Information (PHI)

HIPAA Note on PHI

As a medical billing company, we may access, process, and transmit Protected Health Information (PHI) on behalf of our healthcare provider clients solely to perform our contracted billing services. All PHI is handled strictly in accordance with HIPAA regulations and our signed Business Associate Agreements (BAAs). We do not collect PHI through our public website - PHI is only accessed through our secure, contracted billing systems.

How We Use Your Information

We use the information we collect for the following lawful purposes:

3.1 To Provide Our Services

3.2 To Communicate With You

3.3 To Improve and Operate Our Business

HIPAA Compliance

RMBServ takes HIPAA compliance with the utmost seriousness. As a Business Associate under HIPAA, we adhere to all requirements set forth in the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule (45 CFR Parts 160 and 164).

4.1 Business Associate Agreements (BAA)

We enter into a signed Business Associate Agreement (BAA) with every healthcare provider client before accessing any Protected Health Information. This agreement clearly defines our obligations and responsibilities for safeguarding PHI in compliance with 45 CFR § 164.504(e).

4.2 PHI Safeguards We Implement

4.3 Breach Notification

In the event of a data breach involving PHI, we will notify all affected clients in full accordance with the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). Notification will be provided within 60 calendar days of discovery of the breach, or sooner as required by law.

How We Share Your Information

We do not sell, rent, lease, or trade your personal information to any third party ever. We may share your information only in the following limited and specific circumstances:
With Your Consent
Service Providers
Insurance Payers
Legal Requirements
Business Transfers
We share your information with third parties only when you have provided explicit, informed consent.
Trusted vendors who help us operate (e.g., IT infrastructure, billing software, secure cloud storage). All are contractually bound to protect your data.
We submit claims to insurance companies, Medicare/Medicaid, and clearinghouses strictly on behalf of our healthcare provider clients to fulfill our billing obligations.
We may disclose information when required by law, court order, or governmental authority or to protect the rights, safety, or property of RMBServ, clients, or the public.
In the event of a merger or acquisition, your information may be transferred. You will be notified before any transfer and given options regarding your data.

Data Security

We implement industry leading security measures to protect your information from unauthorized access, alteration, disclosure, or destruction. Our security framework includes:

SSL/TLS encryption for all data in transit

Role-based access controls (RBAC)

Firewall protection & intrusion detection

Multi-factor authentication (MFA)

Encrypted storage for all sensitive data at rest

Regular security audits & vulnerability testing

Employee security training & background checks

Secure data destruction procedures

While we apply every reasonable safeguard, no method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining the highest standards of data protection and immediately addressing any security incidents.

California Residents CCPA Rights

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights regarding your personal information:
To exercise your CCPA rights, please contact us at Business@rmbserv.com or call 650-240-0061. We will respond to verified requests within 45 days.

Your Privacy Rights

Regardless of your location, you have the following rights regarding your personal information held by RMBServ:

Right to Access

Request a copy of the personal data we hold about you

Right to Correct

Request correction of inaccurate or incomplete information

Right to Delete

Request deletion of your personal data (subject to legal obligations)

Right to Opt-Out

Opt out of marketing communications at any time

Data Portability

Request your data in a portable, machine readable format

Restrict Processing

Request that we limit how we process your information

To exercise any of these rights, please contact us at Business@rmbserv.com. We will respond within 30 days of receiving your verified request.

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law:
When data is no longer required, we securely delete or anonymize it using industry-standard data destruction methods.

Children's Privacy

Our website and services are intended exclusively for healthcare professionals and business clients. They are not directed to individuals under the age of 18. We do not knowingly collect, solicit, or process personal information from minors. If we become aware that we have inadvertently collected information from a person under 18 years of age, we will promptly delete that information from our records. If you believe we have collected information from a minor, please contact us immediately at Business@rmbserv.com.

Third-Party Links

Our website may contain links to third party websites for your convenience and reference. These links do not indicate our endorsement of, or responsibility for, those websites or their content. RMBServ has no control over the privacy practices or content of third party sites. We strongly encourage you to review the privacy policy of any third party website you visit before providing any personal information. We are not responsible for the privacy practices of external websites.

Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and improve our services.

12.1 Types of Cookies We Use

Essential Cookies
Analytics Cookies
Functional Cookies
Marketing Cookies
Required for the website to function properly (e.g., session management, security). These cannot be disabled as they are necessary for the site to work.
Help us understand how visitors interact with our website (e.g., Google Analytics). Data is collected anonymously and used to improve site performance.
Remember your preferences and settings to provide a more personalized and efficient browsing experience.
Used to show relevant content and measure campaign effectiveness. These are only activated with your explicit consent.

12.2 How to Manage Cookies

You can control or disable cookies through your browser settings at any time. Please note that disabling certain cookies may limit the functionality of our website. You may also opt out of Google Analytics tracking by visiting: https://tools.google.com/dlpage/gaoptout
For more information about how we use cookies, please see our Cookie Policy.

Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, services, or applicable law. When material changes are made, we will:
Your continued use of our website or services following the posting of changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this page periodically to stay informed of any updates.

By using rmbserv.com or any of our services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you have any questions or concerns, please contact us before continuing to use our services.

Scroll to Top