HIPAA Compliance

Our Process, Your Peace — how MediCloud Billing Solution LLC protects health information

Our HIPAA Compliance Commitments

MediCloud Billing Solution LLC acts as a Business Associate to the healthcare providers, practices, and organizations we serve. This means that whenever we create, receive, maintain, or otherwise have access to Protected Health Information (PHI) on behalf of a client, we are contractually and legally bound by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH). Below is a summary of the compliance commitments we uphold for every client relationship.

Recognition of HITECH Requirements

We formally recognize and comply with HITECH and its implementing regulations, which strengthen HIPAA's privacy and security protections and extend certain obligations directly to Business Associates like us.

Equivalent Standard to Our Clients

We hold ourselves to the same disclosure standards our clients must meet. We will never use or disclose PHI in a way that would violate HIPAA if the healthcare provider had done it directly.

Prompt Breach and Security Incident Reporting

If we become aware of any security incident, or any unauthorized use or disclosure of PHI, we report it promptly to the affected client so they can meet their own regulatory notification obligations.

Standard Transaction Compliance

When we conduct HIPAA-defined "Standard Transactions" (e.g., electronic claims submission, eligibility verification, remittance advice) on behalf of a client, we comply with the formatting and processing requirements under 45 C.F.R. Part 162.

Cooperation with HHS Oversight

We make our internal practices, books, and records related to PHI use and disclosure available to the U.S. Department of Health and Human Services (HHS) upon request, to help verify compliance on behalf of our clients.

Restricted Use and Disclosure of PHI

We do not use or further disclose PHI — any individually identifiable health information — except where explicitly permitted by law or required to perform the billing services we've been engaged to provide.

Patient Rights to PHI Access

We support patients' rights under HIPAA, including facilitating access to their PHI when required, consistent with individual rights provisions in the HIPAA Privacy Rule.

Subcontractor & Agent Accountability

Any subcontractor or agent who receives or is exposed to PHI — electronic or otherwise — is informed of these same HIPAA obligations and must agree to the same restrictions and conditions we operate under.

Six-Year Disclosure Accounting

Upon a client's request, we can account for PHI disclosures going back up to six (6) years, including dates of disclosure and relevant details tied to security, audit, and integrity controls under 45 C.F.R. §§ 164.308, 164.310, 164.312, and 164.316.

PHI Correction & Amendment Support

When notified of necessary amendments or corrections to PHI, we incorporate those changes to help maintain accurate patient records.

Administrative, Physical & Technical Safeguards

We maintain a layered security approach for electronic PHI (ePHI), including:
Administrative safeguards — policies, workforce training, access management procedures
Physical safeguards — secured facilities, restricted access to systems and devices
Technical safeguards — encryption, access controls, audit logging, secure transmission protocols

Additional Protections We Provide

Breach & Termination

A client may terminate services immediately upon a determined breach, or issue written notice with a 5-business-day cure period. Clients may also immediately suspend further PHI disclosures if a breach is reasonably suspected.

Return or Destruction of PHI

Upon termination of services, all PHI is returned or destroyed, with no retained copies — unless doing so is infeasible, in which case protections continue to apply for as long as the data is retained.

De-Identified Data

We may use or disclose de-identified data (data stripped of identifiers, with no re-identification mechanism) for purposes such as reporting and analytics, consistent with HIPAA de-identification standards.

Survival of Obligations

All HIPAA-related duties, obligations, responsibilities, confidentiality requirements, and data protection provisions described above shall survive the termination or expiration of any service agreement.

Official Regulatory Sources

The obligations above are grounded in the following official U.S. federal sources:

  • HHS.gov — The HIPAA Privacy Rule
  • HHS.gov — Summary of the HIPAA Privacy Rule
  • eCFR — 45 CFR Part 160 (General Administrative Requirements)
  • HHS.gov — Combined Regulation Text (45 CFR Parts 160, 162, 164)
  • eCFR — 45 CFR Part 164 (Security & Privacy Standards)

This page is a general summary of our HIPAA Business Associate obligations and does not constitute legal advice. Specific commitments to individual clients are governed by the applicable Business Associate Agreement (BAA) executed between MediCloud Billing Solution LLC and that client.