Table of Contents
- About Mediflows Billing Solutions
- Personal Information We Collect
- How We Use Personal Information
- Who We Share Information With
- SMS Consent & Communications
- HIPAA Compliance
- Client Data
- Client Security
- RCM, Credentialing, Coding & VA Services
- Service Fees
- Cookies & Tracking Technologies
- Your Privacy Rights
- Children’s Privacy
- Changes to This Policy
- Contact Us
1. About Mediflows Billing Solutions
Mediflows Billing Solutions is a United States-based medical billing and revenue cycle management company headquartered in the United States. We provide healthcare providers with comprehensive billing, coding, credentialing, virtual assistant (VA), and revenue cycle management (RCM) services.
This Privacy Policy governs how we collect, use, disclose, and safeguard personal information provided by visitors to our website at mediflowsbillingsolutions.com and by clients and prospective clients who interact with our services. By accessing our website or engaging our services, you agree to the terms of this Privacy Policy.
2. Personal Information We Collect
We collect personal information that you voluntarily provide to us and information collected automatically when you interact with our website or services. The categories of personal information we collect include:
Information You Provide Directly
- Identity Information: Full name, title, job position, professional license number, and National Provider Identifier (NPI).
- Contact Information: Email address, mailing address, phone number, and fax number.
- Business Information: Practice name, specialty, Tax Identification Number (TIN), group NPI, payer enrollment details, and insurance credentialing data.
- Financial Information: Bank account and ACH information for service fee payments, billing statements, and remittance data.
- Communications Data: Messages, inquiries, and correspondence you submit via our website forms, email, phone, text message, or other channels.
- SMS and Messaging Consent: Your consent to receive text messages, including the phone number and date/time of consent submission.
Protected Health Information (PHI)
When we provide RCM, coding, or billing services on behalf of covered entity clients, we may have access to Protected Health Information (PHI) as a Business Associate under HIPAA. PHI is collected and processed solely on behalf of and under the written direction of the covered entity client, and is governed by a signed Business Associate Agreement (BAA). See Section 6 for details.
Information Collected Automatically
- Usage Data: Pages visited, time spent on pages, links clicked, and referring URLs.
- Device & Technical Data: IP address, browser type and version, operating system, device identifiers, and screen resolution.
- Cookies and Tracking: Session cookies, analytics cookies, and preference cookies. See Section 11 for details.
3. How We Use Personal Information
We use the personal information we collect for the following purposes:
- To provide, maintain, and improve our medical billing, RCM, credentialing, coding, and virtual assistant services.
- To process service agreements, invoices, and payments for our services.
- To communicate with you regarding your account, service updates, billing inquiries, and support requests.
- To send transactional SMS messages, appointment reminders, account notifications, and service alerts for which you have opted in.
- To conduct payer credentialing, enrollment, and re-credentialing on behalf of healthcare provider clients.
- To submit claims, post payments, manage denials and appeals, and perform other RCM functions for client practices.
- To comply with applicable federal and state laws including HIPAA, the False Claims Act, and state medical billing regulations.
- To analyze website usage data for improving our online presence and marketing effectiveness.
- To respond to legal process, court orders, regulatory inquiries, and law enforcement requests where required by law.
- To protect the security and integrity of our systems and services.
- To send promotional communications about our services, where you have provided consent and have not opted out.
4. Who We Share Personal Information With
We do not sell your personal information. We may share your information in the following limited circumstances:
Service Providers
We engage trusted third-party service providers who assist us in operating our business, including cloud hosting providers, practice management and billing software vendors, electronic health record (EHR) clearinghouses, payment processors, and IT security partners. These vendors are bound by data processing agreements and are prohibited from using your information for any purpose other than to provide services to us.
Insurance Payers and Clearinghouses
In the course of providing billing and credentialing services, we transmit necessary information (including claims data) to insurance payers, Medicare/Medicaid, and healthcare clearinghouses on behalf of our covered entity clients.
Legal and Regulatory Disclosures
We may disclose personal information when required by applicable law, subpoena, court order, or regulatory authority, or when we believe disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of any person.
Business Transfers
In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred to the successor entity, subject to the same privacy protections described in this policy.
SMS Consent Is Not Shared With Third Parties.
SMS opt-in consent, phone numbers collected for SMS communications, and your messaging preferences are not shared with third parties or affiliates for their own marketing or promotional purposes. This information is used solely to deliver the communications you have consented to receive from Mediflows Billing Solutions.
5. SMS Consent & Communications
SMS Terms of Service
By opting into SMS from a web form, phone call, or other medium, you are agreeing to receive SMS messages from Mediflows Billing Solutions. This includes SMS messages for account notifications, billing updates, appointment reminders, and service-related communications.
Important SMS Disclosures:
- Message frequency may vary.
- Message and data rates may apply.
- To opt out at any time, text STOP to any message.
- For assistance, text HELP or visit mediflowsbillingsolutions.com.
- See our privacy policy .
- SMS consent is not shared with third parties.
Types of Messages You May Receive
-
- Account notifications and service updates
- Billing reminders and payment confirmations
- Credentialing status updates
- Appointment reminders
- Claim submission and denial alerts
- Operational alerts relating to your account
- Promotional messages about Mediflows services
MMS and Promotional Messages
We may send MMS (Multimedia Message Service) messages containing images, documents, or other media relevant to our services. Promotional communications via SMS or MMS will only be sent to individuals who have expressly consented to receive such messages. You may opt out of promotional messages at any time by replying STOP.
Phone Calls
By providing your telephone number, you consent to receive calls from Mediflows Billing Solutions regarding your account, services, billing inquiries, and related business matters. Calls may be made using automated dialing technology only to the extent permitted by applicable law, including the Telephone Consumer Protection Act (TCPA). You may revoke consent to autodialed calls at any time by contacting us in writing.
Opt-Out Instructions
To stop receiving SMS messages, reply STOP to any message. You will receive a one-time confirmation and no further messages will be sent, except as required by law. To resume, text START. For help, text HELP or contact us directly.
6. HIPAA Compliance
Mediflows Billing Solutions operates as a HIPAA Business Associate.
When providing medical billing, RCM, coding, and related services to covered entities (healthcare providers, group practices, and health plans), Mediflows Billing Solutions functions as a Business Associate as defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
As a Business Associate, we:
- Enter into a written Business Associate Agreement (BAA) with each covered entity client before accessing, using, or disclosing Protected Health Information (PHI).
- Use and disclose PHI only as permitted under the applicable BAA and consistent with the Privacy Rule (45 CFR Part 164, Subpart E).
- Implement and maintain administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 CFR Part 164, Subpart C) to protect electronic PHI (ePHI).
- Report any known breach of unsecured PHI to the covered entity within the timeframes required by the Breach Notification Rule (45 CFR Part 164, Subpart D).
- Make PHI available to patients and covered entities as required by law.
- Ensure that any subcontractors who access PHI on our behalf agree in writing to the same restrictions and conditions that apply to us under the BAA.
- Return or destroy PHI upon termination of the service agreement, where feasible.
Permitted Uses of PHI
We use PHI solely to perform the billing, coding, credentialing, and RCM services contracted by the covered entity. PHI is not used for our own marketing, analytics, or any purpose beyond what is authorized by the applicable BAA and HIPAA regulations.
7. Client Data
Mediflows Billing Solutions collects and maintains data provided by its business clients (healthcare practices, group practices, hospitals, and individual providers) in the course of delivering contracted services. Client data includes:
- Provider demographic and credentialing data (NPI, DEA, state license numbers, CAQH profiles)
- Patient demographic and insurance information submitted for billing purposes
- Claim data, remittance advice (EOBs/ERAs), and denial and appeal records
- Practice financial data, bank account information, and fee schedules
- Payer contract and enrollment information
All client data is:
- Processed solely for the purpose of delivering contracted services
- Retained only for the period necessary to fulfill our contractual obligations and applicable legal requirements
- Subject to a confidentiality agreement and, where applicable, a Business Associate Agreement
- Not sold, rented, or otherwise disclosed to third parties for commercial purposes
Data Retention
We retain client data in accordance with applicable federal and state laws governing medical billing records, including CMS requirements, and for the duration of our service agreement plus a minimum of seven (7) years unless a longer retention period is required by law or agreed upon in writing.
8. Client Security
The security of client and patient data is a top priority at Mediflows Billing Solutions. We have implemented comprehensive administrative, physical, and technical safeguards consistent with HIPAA Security Rule requirements and industry best practices, including:
Administrative Safeguards
- Designated Security and Privacy Officer responsible for overseeing data protection
- Workforce HIPAA training and privacy awareness programs conducted regularly
- Access control policies limiting PHI access to staff with a job-related need
- Documented incident response and breach notification procedures
- Regular risk assessments and vulnerability analyses
Physical Safeguards
- Controlled access to facilities and workstations where PHI is accessed
- Workstation security policies preventing unauthorized use or viewing of client data
- Secure destruction of physical media containing client information
Technical Safeguards
- Encryption of electronic PHI (ePHI) in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent)
- Multi-factor authentication (MFA) required for access to systems containing PHI
- Role-based access controls and unique user identification
- Audit logging and monitoring of access to ePHI systems
- Automatic session timeouts for inactive sessions
- Regular software patching and vulnerability management
- Firewall protection, intrusion detection, and endpoint security
Breach Notification
In the event of a security incident or breach involving client data or PHI, we will notify the affected covered entity client without unreasonable delay and no later than 60 calendar days of discovery, in compliance with HIPAA’s Breach Notification Rule. We will cooperate fully in any required notifications to patients or regulators.
9. RCM, Credentialing, Coding & Virtual Assistant Services
Revenue Cycle Management (RCM)
In providing RCM services, we handle patient demographic data, insurance information, claim data, denial management records, and remittance data strictly on behalf of our contracted provider clients. All such data is processed under the terms of a signed service agreement and Business Associate Agreement.
Credentialing Services
For credentialing services, we collect provider-specific information including NPI, DEA number, state licenses, board certifications, work history, malpractice history, and CAQH profile information. This data is submitted to payers, hospitals, and credentialing organizations solely for the purpose of completing enrollment and credentialing on the provider’s behalf.
Medical Coding
Our certified coding team accesses clinical documentation and medical records solely for the purpose of assigning accurate ICD-10, CPT, and HCPCS codes for claim submission. Coding staff operate under strict confidentiality obligations and HIPAA-compliant access protocols.
Virtual Assistant (VA) Services
Virtual assistants assigned to client practices may access practice management systems, scheduling platforms, and patient communication tools as directed by the client. All virtual assistants are bound by confidentiality agreements, HIPAA training requirements, and the terms of the applicable BAA. The scope of data access is limited to what is necessary to perform the contracted tasks.
10. Service Fees
When you engage Mediflows Billing Solutions for services, we collect financial information necessary to process service agreements and payments, including:
- Business bank account and ACH payment details for direct deposit of collections
- Credit card or ACH information for payment of our service fees
- Billing contact name and email address for invoice delivery
Financial information is used exclusively for billing and payment processing purposes. We use industry-standard encryption and security practices to protect payment information. We do not store full payment card numbers on our systems. Payment processing may be handled by PCI-DSS compliant third-party payment processors operating under data processing agreements.
Service fee structures, including percentage-of-collections arrangements and flat-fee agreements, are outlined in your individual service contract. Fee-related data is retained for a minimum of seven (7) years for accounting and tax compliance purposes.
11. Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience and gather analytics data. We use the following types of cookies:
- Essential Cookies: Necessary for core website functionality, such as form submission and session management.
- Analytics Cookies: Help us understand how visitors interact with our website (e.g., Google Analytics). Data is aggregated and anonymized.
- Preference Cookies: Remember your settings and preferences for a more personalized experience.
You may control or disable cookies through your browser settings. Note that disabling certain cookies may affect website functionality. We do not use cookies for behavioral advertising or sell cookie data to third parties.
12. Your Privacy Rights
Depending on your state of residence, you may have certain rights with respect to your personal information, including:
- Right to Know: Request information about the categories and specific pieces of personal information we have collected about you.
- Right to Deletion: Request that we delete personal information we have collected, subject to certain exceptions.
- Right to Correction: Request that we correct inaccurate personal information.
- Right to Opt-Out of Sale: We do not sell personal information. If this practice changes, we will provide prior notice.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
California residents may have additional rights under the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA). To exercise any of these rights, please contact us using the information in Section 15.
Requests related to PHI governed by HIPAA should be directed to your healthcare provider (covered entity), who is responsible for responding to patient rights requests regarding their PHI.
13. Children’s Privacy
Our website and services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13 without parental consent, we will take prompt steps to delete such information. If you believe a child has provided us with personal information, please contact us immediately.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. When we make material changes, we will update the “Effective Date” at the top of this page and, where appropriate, notify you by email or by posting a notice on our website. We encourage you to review this policy periodically. Your continued use of our website or services after any update constitutes acceptance of the revised policy.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us.
For HIPAA-related concerns or to report a potential breach, please contact our Privacy Officer directly through the contact information provided in your Business Associate Agreement.
