HIPAA Compliant & US-Based Standards Denver, CO | Mon - Fri: 8am - 6pm MST
Schedule Consultation Call Now: 0800-564-0911
100% US-Based • HIPAA Compliant
Mon - Fri: 8:00 AM - 6:00 PM MST

Privacy Policy

Last Updated: October 2026 • Strict adherence to HIPAA, HITECH, and federal patient privacy laws.

1. Overview and Commitment to Healthcare Privacy

TBL MedRCM ("we," "our," or "us"), headquartered at 1500 N Grant St STE N, Denver, CO 80203, is committed to safeguarding the privacy and confidentiality of individuals and client healthcare organizations. As a medical billing and revenue cycle management provider, we operate as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the Health Information Technology for Economic and Clinical Health Act ("HITECH").

2. Protected Health Information (PHI) We Handle

In our role as a Business Associate to covered healthcare entities, we process Protected Health Information (PHI) solely to perform authorized revenue cycle functions, including:

  • Patient demographic data (names, contact information, dates of birth, Social Security numbers where required by payers).
  • Clinical encounter documentation (diagnostic codes, procedure CPT codes, provider charting notes).
  • Payer and insurance coverage details (policy IDs, subscriber details, secondary insurance).
  • Billing remittance data (EOBs, 835 ERAs, patient payment receipts, ledger records).

3. Safeguards & Data Security Standards

We implement rigorous administrative, physical, and technical safeguards complying with the HIPAA Security Rule:

  • Encryption: AES-256 bit encryption for all electronic PHI at rest and in transit via TLS 1.3 tunnels.
  • Role-Based Access Control: Only personnel with a documented clinical need can view or process encounter files.
  • Audit Trails: Comprehensive logging of system access, document views, exports, and EDI transmissions.
  • Workforce Training: Semi-annual mandatory compliance certifications for all billers, coders, and technical staff.

4. Business Associate Agreements (BAAs)

We enter into binding Business Associate Agreements with all client healthcare providers prior to receiving any clinical or demographic data. We never sell, rent, commercialize, or disclose patient or practice information to third-party marketers.

5. Website Data & Cookies

When you browse tblmedrcm.com, we collect standard non-identifying telemetry (browser type, session duration, referral sources) solely to optimize website usability. Information submitted through our consultation contact form is encrypted and used exclusively to communicate regarding requested billing audits.

6. Privacy Inquiries & Compliance Officer

For questions regarding this policy or to request our standard Business Associate Agreement documentation, please contact our Compliance Officer:

TBL MedRCM Compliance & Legal Division
1500 N Grant St STE N, Denver, CO 80203
Email: info@tblmedrcm.com • Phone: 0800-564-0911