AAPC & AHIMA Certified · All 50 States · 24-48h Claim Submission
Get a Free Billing Audit

Privacy Policy

At Outsource MedClaim (outsourcemedicalbillingservices.us), your practice’s data integrity and patient confidentiality are our primary obligations across all medical billing services. We operate under a strict compliance framework that aligns with our HIPAA Compliance Notice and the HITECH Act.

This policy outlines how we collect, protect, and manage information for the healthcare providers and medical practices we serve. By engaging our services under our Terms and Conditions, you are partnering with a team that prioritizes security at every level of the revenue cycle management (RCM) process.

Compliancy Group HIPAA verified Compliancy Group SOC 2 verified HIPAA Trained
HIPAA-compliant medical billing data security at Outsource MedClaim

1. Information Collection and Use

We collect only the information necessary to perform high-tier medical billing, coding, and virtual assistance:

✓

Practice Data: Name, NPI, office address, and contact details provided during consultation or onboarding.

✓

Protected Health Information (PHI): Patient demographics, insurance details, and clinical documentation required for accurate claim submission.

✓

Billing Information: Financial records, EOBs, and ERAs used to manage your practice’s accounts receivable.

2. Data Security and HIPAA Compliance

We implement enterprise-grade technical, physical, and administrative safeguards to protect Electronic Protected Health Information (ePHI):

256-bit Encryption:

All data is encrypted both at rest and during transmission to payers like Blue Shield of California or Anthem Blue Cross.

Secure EHR Access:

Our team works directly within your existing systems (Epic, Cerner, athenahealth) via secure VPNs, ensuring data never leaves your controlled environment.

Multi-Factor Authentication (MFA):

Strict access controls ensure only authorized billing specialists and your dedicated account manager can view sensitive files.

Regular Audits:

We conduct internal security risk analyses to identify and mitigate potential vulnerabilities.

3. Business Associate Agreement (BAA)

In accordance with HIPAA regulations, Outsource MedClaim signs a formal Business Associate Agreement (BAA) with every client. This legal document binds us to:

✓

Use PHI only for the purposes outlined in our service agreement.

✓

Report any unauthorized use or disclosure of PHI immediately.

✓

Ensure all subcontractors and VMAs adhere to the same stringent security standards.

4. Disclosure of Information

Outsource MedClaim does not sell, rent, or trade your practice or patient data to third parties. Information is shared only with:

✓

Payers & Clearinghouses: Necessary for the processing and payment of claims.

✓

Regulatory Bodies: When required by law to comply with CMS audits or legal subpoenas.

5. Your Rights and Control

As a practice owner, you retain full ownership and control of your data.

✓

Access & Transparency: You have 24/7 access to real-time KPI dashboards and all billing records.

✓

Data Retention: We retain information only as long as necessary to fulfill our service obligations or as mandated by federal record-keeping laws.

✓

Opt-Out: You may request to update or remove your professional contact information from our marketing communications at any time.

6. FAQ’s

All VMAs undergo rigorous HIPAA training and work on "clean" stations with restricted printing/downloading capabilities and continuous activity monitoring.

We maintain a comprehensive Incident Response Plan. Affected clients will be notified within the timeframes mandated by federal law, typically within 60 days of discovery.

Outsource MedClaim