1. Executive Commitment to Patient Data Security
At TBL MedRCM, safeguarding Protected Health Information (PHI) and electronic PHI (ePHI) is fundamental to our operating model. As an American medical billing and revenue cycle management organization operating as a designated Business Associate to covered healthcare providers, we maintain total adherence to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and the Final Omnibus Rule of 2013.
2. Business Associate Agreement (BAA) Governance
Before ingesting a single patient record, claim file, or electronic remittance, TBL MedRCM executes an exhaustive, bilateral Business Associate Agreement with every medical practice, clinic, or clinical laboratory partner. Our BAA clearly delineates:
- Permitted uses and disclosures strictly confined to billing, coding, claims submission, and financial reconciliation.
- Statutory requirements to apply administrative, technical, and physical safeguards.
- Mandatory immediate incident notification protocols compliant with federal breach notification rules.
- Secure data return or permanent destruction protocols upon contract conclusion.
3. Technical Safeguards (HIPAA Security Rule 45 CFR § 164.312)
Our technical architecture is engineered to resist cyber intrusion and guarantee end-to-end auditability:
- Cryptographic Standards: All data at rest is protected via military-grade AES-256 encryption. Transmission of EDI 837 claim files, 835 remittance data, and API payloads is secured via TLS 1.3 encryption.
- Multi-Factor Authentication (MFA): FIDO2 / hardware-token and TOTP multi-factor authentication are mandatory across all endpoints, billing platforms, and clearinghouse interfaces.
- Immutable Audit Logging: Every user touchpoint, record review, claim edit, and export is recorded in an immutable, time-stamped log reviewed continuously by automated SIEM tools.
- EHR Access Control: Strict Least Privilege Access (LPA) principles guarantee staff only view records necessary for their assigned specialty billing workflow.
4. Physical and Administrative Safeguards
Data security extends beyond our software systems to our physical offices and operational policies:
- Physical Facilities: Denver headquarters and operational nodes enforce biometric access, 24/7 video surveillance, clean-desk policies, and locked data centers.
- Workforce Screening & Background Checks: 100% of staff undergo multi-state background checks, drug screenings, and credential verification prior to onboarding.
- Annual Compliance Certification: All billers, certified coders, and managers complete mandatory semi-annual HIPAA Security, Privacy, and Fraud/Waste/Abuse training.
- Business Continuity & Disaster Recovery (BC/DR): Real-time geo-redundant backups ensure zero data loss and under 1-hour recovery time objectives (RTO).
5. Breach Notification & Incident Response
In accordance with 45 CFR §§ 164.400-414, TBL MedRCM maintains a documented Incident Response Plan. In the improbable event of a suspected security incident involving unsecured PHI, our Incident Response Team initiates root-cause analysis within minutes and notifies affected covered entities without unreasonable delay and well within statutory deadlines.
6. Inquiries and Compliance Contact
To request our Security Whitepaper, verify BAA execution terms, or speak with our Chief Compliance Officer, please reach out to:
TBL MedRCM Privacy & Security Officer
1500 N Grant St STE N, Denver, CO 80203
Toll-Free Phone: 0800-564-0911
Secure Email: info@tblmedrcm.com