1. Overview and Commitment to Healthcare Privacy
TBL MedRCM ("we," "our," or "us"), headquartered at 1500 N Grant St STE N, Denver, CO 80203, is committed to safeguarding the privacy and confidentiality of individuals and client healthcare organizations. As a medical billing and revenue cycle management provider, we operate as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH").
2. Protected Health Information (PHI) We Handle
In our role as a Business Associate to covered healthcare entities, we process Protected Health Information (PHI) solely to perform authorized revenue cycle functions, including:
- Patient demographic data (names, contact information, dates of birth, Social Security numbers where required by payers).
- Clinical encounter documentation (diagnostic codes, procedure CPT codes, provider charting notes).
- Payer and insurance coverage details (policy IDs, subscriber details, secondary insurance).
- Billing remittance data (EOBs, 835 ERAs, patient payment receipts, ledger records).
3. Safeguards & Data Security Standards
We implement rigorous administrative, physical, and technical safeguards complying with the HIPAA Security Rule:
- Encryption: AES-256 bit encryption for all electronic PHI at rest and in transit via TLS 1.3 tunnels.
- Role-Based Access Control: Only personnel with a documented clinical need can view or process encounter files.
- Audit Trails: Comprehensive logging of system access, document views, exports, and EDI transmissions.
- Workforce Training: Semi-annual mandatory compliance certifications for all billers, coders, and technical staff.
4. Business Associate Agreements (BAAs)
We enter into binding Business Associate Agreements with all client healthcare providers prior to receiving any clinical or demographic data. We never sell, rent, commercialize, or disclose patient or practice information to third-party marketers.
5. Website Data & Cookies
When you browse tblmedrcm.com, we collect standard non-identifying telemetry (browser type, session duration, referral sources) solely to optimize website usability. Information submitted through our consultation contact form is encrypted and used exclusively to communicate regarding requested billing audits.
6. Privacy Inquiries & Compliance Officer
For questions regarding this policy or to request our standard Business Associate Agreement documentation, please contact our Compliance Officer:
1500 N Grant St STE N, Denver, CO 80203
Email: info@tblmedrcm.com • Phone: 0800-564-0911