HIPAA Privacy Policy for Medical Billing
ClainetRCM - Your Privacy Matters
Introduction
Welcome to ClainetRCM, an independent revenue cycle management organization dedicated to serving healthcare organizations, clinics, solo practices, and healthcare providers directly. We take your privacy extremely seriously and place the highest priority on protecting your confidential information.
Our Privacy Commitment: We do not sell your data, and we do not share it with anyone who is not required to deliver the service you hired us for. Where a vendor is involved and could touch Protected Health Information, that vendor is bound by a signed Business Associate Agreement.
Direct Communication Model: Claims work, eligibility verification and provider enrollment are handled by ClainetRCM staff, not outsourced to an unnamed subcontractor or offshore call center. Where the work requires a clearinghouse or your own practice management system, we use it and disclose it. We are not going to pretend claims reach payers by magic.
Important: By using ClainetRCM's services, you agree to the collection and use of information in accordance with this policy. Your trust is our top priority, and we are committed to maintaining the highest standards of data privacy and security while providing comprehensive revenue cycle management services.
Information We Collect
We collect several types of information to provide and improve our services to you:
1. Personal Information
- Contact Information: Name, email address, phone number, and mailing address
- Account Credentials: Username, password, and security questions
- Professional Information: Job title, organization name, and professional credentials
- Payment Information: Billing address and payment method details (processed securely through third-party payment processors)
2. Health and Medical Information
As a healthcare revenue cycle management platform, we may process Protected Health Information (PHI) in accordance with HIPAA regulations, including:
- Patient demographic information
- Insurance and billing information
- Medical procedure codes and diagnoses
- Healthcare provider information
3. Technical Information
- Device Information: IP address, browser type, operating system, and device identifiers
- Usage Data: Pages visited, features used, time spent on platform, and interaction patterns
- Cookies and Tracking: Information collected through cookies, web beacons, and similar technologies
How We Use Your Information
ClainetRCM uses your information exclusively to provide our revenue cycle management services directly to your organization. We do not involve third-party vendors in processing or handling your data. The information we collect is used strictly for the following purposes:
- Revenue Cycle Management: To manage the complete revenue cycle including claims submission, payment posting, denial management, and collections through direct communication with insurance companies
- Provider Enrollment and Credentialing: To enroll and credential healthcare providers directly with insurance payers, maintaining accurate provider information and network participation
- Insurance Communication: To communicate directly with insurance companies for eligibility verification, prior authorizations, claims status inquiries, and payment reconciliation
- Direct Service Delivery: To provide, maintain, and improve our revenue cycle management services directly to your healthcare organization, clinic, solo practice, or healthcare facility
- Account Management: To create and manage your account, authenticate users, and provide direct customer support from our in-house team
- Direct Communication: To communicate with you, insurance companies, and healthcare providers directly regarding service updates, claims status, payment information, and administrative matters
- Internal Analytics: To analyze usage patterns and optimize platform performance using our internal systems only
- Regulatory Compliance: To comply with HIPAA, healthcare regulations, and legal obligations while keeping all data processing in-house
- Security Protection: To detect, prevent, and address technical issues, fraud, and security vulnerabilities using our internal security systems
- Billing Operations: To facilitate billing and payment processing directly within our organization
What we will not do: We do not sell your data, rent it, or share it with marketing firms or data brokers. We do not use PHI to train anything. Where a vendor is genuinely needed to deliver the service (hosting, a clearinghouse, your own practice management system), that vendor operates under a signed Business Associate Agreement, and we will name our current subprocessors on request.
Information Sharing and Disclosure
Our Sharing Policy: We never sell your information and we never share it with marketing firms or data brokers. We share it only where delivering the service requires it: with the insurance payers we bill on your behalf, with your own practice management or EHR vendor, with a clearinghouse where one is used, and with our hosting provider. Each of those relationships is covered by a Business Associate Agreement where PHI is involved. We will also disclose information where the law compels it, as described below.
Direct Insurance Company Communication
To effectively manage your revenue cycle, ClainetRCM communicates directly with insurance companies for the following purposes:
- Claims submission and processing
- Eligibility verification and benefits confirmation
- Payment posting and reconciliation
- Appeals and denials management
- Prior authorization requests
All communication is direct between ClainetRCM and the insurance companies - no intermediaries or third-party billing services are involved.
Provider Enrollment Services
When managing provider enrollments, ClainetRCM communicates directly with:
- Insurance payers for credentialing and enrollment applications
- Healthcare providers for verification and updates
- Regulatory bodies as required for licensing and certification
We handle all enrollment communications directly without involving third-party credentialing services or intermediaries.
Healthcare Provider Communication
ClainetRCM maintains direct communication with healthcare providers to facilitate revenue cycle operations, including coordination of benefits, referral management, and service verification. These communications are essential for accurate billing and revenue optimization.
No Third-Party Service Providers
Unlike many RCM companies, ClainetRCM does NOT use or share your data with:
- Third-party billing services or clearinghouses
- External vendors, consultants, or contractors
- Data analytics companies or marketing firms
- Cloud service providers or hosting companies (we use our own infrastructure)
- Outsourced call centers or offshore teams
Legal Requirements
In the rare circumstance where we are legally compelled by court order or subpoena to disclose information, we will notify you immediately (unless prohibited by law) and will disclose only the minimum information required. We vigorously protect your privacy rights and challenge overly broad requests.
Business Transfers
ClainetRCM is independently owned and we have no current plans to sell or merge. If that ever changed, your information could transfer to the acquiring entity as part of the transaction. In that event we would require the acquirer to honour this policy, notify you in advance, and give you the option to terminate services and have your data returned. This mirrors the assignment clause in our Terms of Service.
Direct Communication Only: When we share information with insurance companies and healthcare providers, it's always direct communication from ClainetRCM to fulfill our revenue cycle management obligations to you. We never route your data through third-party vendors or intermediaries.
Data Security
We apply the administrative, physical and technical safeguards HIPAA requires of a business associate. Specifically:
- Encryption: Data is encrypted in transit using TLS and encrypted at rest.
- Access controls: Access is role-based and limited to the ClainetRCM staff who need it for your account. Accounts require multi-factor authentication.
- Business Associate Agreement: We execute a signed BAA with every client before we handle any Protected Health Information.
- Workforce training: Every member of staff completes HIPAA privacy and security training and is bound by a confidentiality agreement.
- Payer portal discipline: Credentials for your payer portals and practice management system are stored in an access-controlled password manager, never in email or spreadsheets.
- Incident response: We maintain a written breach-notification procedure that meets the HIPAA Breach Notification Rule timelines.
- Audit logging: Access to client data is logged, and logs are retained for review.
An honest note on infrastructure. Like most firms our size, we run on reputable third-party hosting and software rather than data centers we own outright. We think claiming otherwise would be misleading. What we do commit to is that any vendor with potential access to PHI is under a signed Business Associate Agreement, and we will name our subprocessors on request during due diligence.
Your Rights and Choices
You have several rights regarding your personal information:
- Access: You can request access to the personal information we hold about you
- Correction: You can request correction of inaccurate or incomplete information
- Deletion: You can request deletion of your personal information, subject to legal and contractual obligations
- Data Portability: You can request a copy of your data in a structured, machine-readable format
- Opt-Out: You can opt out of marketing communications at any time
- Cookie Preferences: You can manage cookie settings through your browser preferences
- HIPAA Rights: If applicable, you have rights under HIPAA to access, amend, and receive an accounting of disclosures of your PHI
To exercise these rights, please contact us using the information provided in the Contact Us section below.
Data Retention
We retain your information for as long as necessary to:
- Provide our services and fulfill the purposes described in this policy
- Comply with legal, regulatory, and contractual obligations
- Resolve disputes and enforce our agreements
- Meet healthcare record retention requirements (typically 7-10 years for medical records)
After the retention period expires, we securely delete or anonymize your information in accordance with our data retention policies and applicable laws.
Children's Privacy
ClainetRCM's services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child without parental consent, we will take steps to delete that information promptly.
Data Storage and Location
Domestic Operations Only: ClainetRCM operates exclusively within the United States. All data processing, storage, and management activities occur within our secure, U.S.-based facilities. We do not transfer, store, or process data internationally.
- All servers and data centers are located within the United States
- All ClainetRCM personnel who access data are U.S.-based employees
- We comply with all U.S. federal and state data protection regulations
- Your data never crosses international borders or leaves U.S. jurisdiction
Complete U.S. Control: By keeping all operations domestic, we ensure your data remains under U.S. legal protection and is never subject to foreign data access laws or regulations.
Our Independence and Direct Service Model
Why Choose ClainetRCM: As an independent organization, we offer unique advantages in privacy, security, and service delivery:
Complete Independence from Third-Party Vendors
- Not owned by or affiliated with any larger corporation, insurance company, or healthcare network
- No parent companies or stakeholders with access to your data
- Independent decision-making focused solely on serving our healthcare clients
- No third-party vendors, clearinghouses, or intermediaries involved in our operations
- We don't outsource any services - everything is handled in-house by our team
Direct Communication with Insurance Companies
- ClainetRCM staff communicate directly with insurance payers for all RCM activities
- No third-party clearinghouses or billing services act as intermediaries
- Direct submission and follow-up on all claims, authorizations, and appeals
- Personal relationships with payer representatives for faster resolution
- Complete transparency in all insurance communications
Direct Service to Healthcare Providers
- We work directly with healthcare organizations, clinics, solo practices, and healthcare providers
- All communication, support, and services come from ClainetRCM employees
- No subcontractors, outsourced teams, or external call centers
- Direct accountability and transparent relationship with your organization
- Dedicated account managers who understand your specific needs
Handled by our own team
- Coding, claim submission, AR follow-up and appeals
- Payer communication and provider enrollment
- Customer support, from a named account manager rather than a ticket queue
- Privacy and security oversight
Where we do rely on vendors
We work inside your existing EHR or practice management system rather than forcing a migration, so your software vendor remains your vendor. We also use standard clearinghouse and hosting services where the work requires it. Any vendor that could touch Protected Health Information operates under a signed Business Associate Agreement, and we will provide a current list of those subprocessors on request.
Third-Party Services on This Website
This website uses a small number of third-party services. We list them here in full rather than claiming we use none, because you are entitled to know who receives data when you visit.
- Google Analytics 4 measures which pages visitors read and how they arrived. Sets cookies and receives your IP address and browsing activity on this site.
- Google Ads conversion tracking tells us whether an advertisement led to an enquiry. Sets cookies and may be used for advertising measurement.
- Tawk.to live chat powers the chat widget in the corner of every page. Receives anything you type into that widget, plus your IP address and page location.
- Cloudflare CDN (cdnjs) delivers the icon font used for the site's icons. Receives your IP address as part of serving that file.
Never send patient information through this website. The chat widget, the contact forms and this site generally are not covered by our Business Associate Agreement and are not an appropriate channel for Protected Health Information. If you need to discuss anything involving PHI, call us and we will arrange a secure channel.
These are marketing tools, not billing systems. The services above run on our public website only. They are not connected to the systems in which we process claims or handle PHI for clients under a signed BAA. Client billing data is not exposed to any of them.
How to opt out. You can block analytics and advertising cookies through your browser settings, by using a tracker-blocking extension, or via Google's opt-out add-on at tools.google.com/dlpage/gaoptout. Blocking them does not affect your ability to use this site or to contact us.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Posting the updated policy on our platform with a new Last Updated date
- Sending an email notification to the address associated with your account
- Displaying a prominent notice on our platform
Your continued use of our services after the effective date of the updated policy constitutes acceptance of the changes.
Contact Us About Privacy
The rights described above include access, correction, deletion, portability, opting out of marketing, and requesting a HIPAA accounting of disclosures. To exercise any of them, contact us using any of the methods below. We respond within one business day and will complete verified requests within 30 days.
- Email: info@clainetrcm.com
- Phone: +1 (339) 337-9616
- Location: Boston, MA, United States
- Hours: Mon - Fri, 9:00 AM - 6:00 PM ET
- Online: Contact form
Do not include Protected Health Information in an email or web form. If your request involves patient data, call us and we will arrange a secure channel first.
If you believe we have mishandled Protected Health Information, you may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr/complaints. We will not retaliate against anyone for filing a complaint.