HIPAA Privacy Policy for Right Medical Billing LLC

1. Introduction

Right Medical Billing LLC (“RMB,” “we,” “us,” or “our”) is committed to protecting the privacy of your Protected Health Information (“PHI”). We are a medical billing and revenue cycle management company located at 5530 Long Prairie Trace, Suite 600, Richmond, TX 77407. This Privacy Policy outlines how we collect, use, disclose, and safeguard your PHI, as required by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and its related regulations.

2. Definitions

  • Protected Health Information (PHI): Any information, whether oral or recorded in any form or medium, that is created or received by a health care provider, health plan, public health authority, employer, life insurer, school or university, or health care clearinghouse; and relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual; and that identifies the individual; or with respect to which there is a reasonable basis to believe the information can be used to identify the individual.
  • Business Associate: An entity that performs certain functions or activities on behalf of, or provides certain services to, a Covered Entity that involve the use or disclosure of protected health information. RMB is a Business Associate.
  • Covered Entity: Health plans, health care clearinghouses, and health care providers who transmit health information in electronic form in connection with transactions for which the Secretary of Health and Human Services has adopted standards under HIPAA.

3. Uses and Disclosures of PHI

As a Business Associate, RMB may use and disclose your PHI as necessary to perform our services for Covered Entities. These services include, but are not limited to, billing and revenue cycle management. The specific uses and disclosures of your PHI are governed by our Business Associate Agreements with the Covered Entities we serve.

Permitted Uses and Disclosures:

  • Treatment, Payment, and Health Care Operations: We may use and disclose your PHI to facilitate the Covered Entity’s treatment, payment, and health care operations. For example, we may submit claims to payers on behalf of the Covered Entity.
  • As Required By Law: We will disclose your PHI when required to do so by federal, state, or local law.
  • Public Health Activities: We may disclose your PHI to public health authorities for activities such as preventing or controlling disease, injury, or disability; reporting births and deaths; reporting child abuse or neglect; reporting reactions to medications or problems with products; notifying people of recalls of products they may be using; and notifying a person who may have been exposed to a disease or may be at risk for contracting or spreading a disease or condition.
  • Health Oversight Activities: We may disclose your PHI to a health oversight agency for activities authorized by law, such as audits, investigations, inspections, licensure, or disciplinary actions; civil, administrative, and criminal proceedings or actions; and other activities necessary for the government to monitor the health care system, government programs, and compliance with civil rights laws.
  • Judicial and Administrative Proceedings: We may disclose your PHI in response to a court or administrative order, subpoena, discovery request, or other lawful process.
  • Law Enforcement Purposes: We may disclose your PHI to law enforcement officials for certain law enforcement purposes, such as identifying or locating a suspect, fugitive, material witness, or missing person; in connection with a criminal investigation; in response to a court order or subpoena; and other law enforcement purposes.
  • Coroners, Medical Examiners, and Funeral Directors: We may disclose your PHI to a coroner or medical examiner for identification purposes, determining cause of death, or for other duties as authorized by law. We may also disclose PHI to funeral directors as necessary to carry out their duties.
  • Organ, Eye or Tissue Donation: Consistent with applicable law, we may disclose your PHI to organ procurement organizations or other entities engaged in the procurement, banking, or transplantation of organs, eyes, or tissue for donation and transplant.
  • Research: Under certain circumstances, we may use and disclose your PHI for research purposes.
  • To Avert a Serious Threat to Health or Safety: We may use or disclose your PHI when necessary to prevent a serious threat to your health and safety or the health and safety of the public or another person.
  • Workers’ Compensation: We may disclose your PHI for workers’ compensation or similar programs that provide benefits for work-related injuries or illness.

4. Your Rights Regarding Your PHI

As a patient, you have certain rights regarding your PHI. These rights are ultimately managed by the Covered Entity, but RMB will assist Covered Entities in fulfilling these rights.

  • Right to Access: You have the right to access and obtain a copy of your PHI in a designated record set, except in limited circumstances.
  • Right to Request Amendment: You have the right to request that the Covered Entity amend your PHI if you believe it is inaccurate or incomplete.
  • Right to an Accounting of Disclosures: You have the right to receive an accounting of certain disclosures of your PHI made by the Covered Entity.
  • Right to Request Restrictions: You have the right to request that the Covered Entity restrict the use or disclosure of your PHI for treatment, payment, or health care operations.
  • Right to Receive Confidential Communications: You have the right to request that the Covered Entity communicate with you about your health matters in a certain way or at a certain location.
  • Right to a Copy of This Notice: You have the right to receive a copy of this Notice of Privacy Practices.

5. RMB’s Responsibilities

RMB is required to:

  • Maintain the privacy of your PHI.
  • Provide you with this Notice of our duties and privacy practices with respect to your PHI.
  • Abide by the terms of this Notice.
  • Notify affected individuals following a breach of unsecured PHI.

6. Safeguards

RMB has implemented administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of your PHI. These safeguards include:

  • Administrative Safeguards: Policies and procedures to manage and control the use and disclosure of PHI, including workforce training, security awareness, and incident response planning.
  • Physical Safeguards: Measures to protect physical facilities and electronic equipment from unauthorized access, including facility access controls, workstation security, and device and media controls.
  • Technical Safeguards: Technology and related policies and procedures used to protect electronic PHI, including access controls, audit controls, integrity controls, and transmission security.

7. Changes to This Privacy Policy

We reserve the right to change this Privacy Policy. We reserve the right to make the revised or changed Privacy Policy effective for PHI we already have as well as any PHI we receive in the future. We will post a copy of the current Privacy Policy on our website. If we make a material change to this Privacy Policy, we will provide notice of the revised Privacy Policy as required by law.

8. Contact Information

Right Medical Billing LLC

5530 Long Prairie Trace, Suite 600, Richmond, TX 77407

Phone: (281) 864-0448

Email: sales@rightmedicalbilling.com