Legal

Privacy Policy

Revenify HealthCare is committed to protecting the privacy of our clients, their patients, and all individuals whose information we handle.

Effective Date: June 20, 2025

HIPAA Notice: Revenify HealthCare operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We handle Protected Health Information (PHI) solely on behalf of our covered entity clients under executed Business Associate Agreements. This policy explains how we handle all information — including PHI — in the course of providing RCM and medical coding services.

This Privacy Policy applies to information collected through our website at revenifyhealthcare.com, our MRR platform, and in the course of providing contracted Revenue Cycle Management (RCM) and Medical Coding services. By using our website or engaging our services, you agree to the practices described herein.

If you have questions about this policy or wish to exercise any of your rights, contact us at info@revenifyhealthcare.com.

1.

Information We Collect

Personal & Contact Information

We collect information you voluntarily provide when contacting us, requesting a demo, or entering into a service agreement — including name, email address, phone number, job title, and organization name.

Protected Health Information (PHI)

As a Business Associate under HIPAA, we may receive, process, and transmit PHI on behalf of our clients (Covered Entities). This includes patient demographics, insurance information, diagnosis and procedure codes, claim data, Explanation of Benefits (EOBs), and remittance data — strictly for the purpose of delivering contracted RCM and medical coding services.

Technical & Usage Data

We collect device and browser information, IP addresses, pages visited, session duration, and referring URLs when you access our website or platform — using cookies and similar tracking technologies.

Business & Financial Information

Information needed to provide billing and RCM services, including provider NPI numbers, payer IDs, fee schedules, and practice management system credentials supplied by our clients.

2.

How We Use Your Information

Service Delivery

To perform medical billing, medical coding, denial management, accounts receivable follow-up, credentialing, and other contracted RCM services on behalf of our healthcare provider clients.

Communication

To respond to inquiries, send service updates, deliver audit reports, and communicate billing performance metrics to authorized client representatives.

Compliance & Reporting

To meet our legal obligations under HIPAA, applicable state laws, and contractual Business Associate Agreements (BAAs) with our covered entity clients.

Platform Improvement

Aggregate, de-identified data may be used to improve our MRR platform, refine internal workflows, and benchmark performance — never in a way that identifies individual patients or clients.

3.

HIPAA Compliance & Business Associate Agreements

Business Associate Status

Revenify HealthCare functions as a Business Associate (BA) as defined under the Health Insurance Portability and Accountability Act (HIPAA). We execute a Business Associate Agreement (BAA) with every covered entity client prior to handling any PHI.

Minimum Necessary Standard

We access, use, and disclose PHI only to the minimum extent necessary to perform contracted services — consistent with the HIPAA Privacy Rule's minimum necessary standard.

Security Safeguards

We implement the administrative, physical, and technical safeguards required by the HIPAA Security Rule, including access controls, audit logging, encryption in transit and at rest, and workforce training.

Breach Notification

In the event of a discovered breach of unsecured PHI, we will notify affected covered entities within the timeframes specified under the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414) and as required by our BAA.

4.

Information Sharing & Disclosure

Authorized Disclosures

We share PHI only as permitted or required by our BAA and HIPAA — such as submitting claims to payers, clearinghouses, and government programs (Medicare/Medicaid) on behalf of our clients.

Subcontractors

Any subcontractor or technology vendor that handles PHI on our behalf is required to execute a BAA and maintain equivalent HIPAA safeguards.

No Sale of Data

We do not sell, rent, or trade personal information or PHI to third parties for marketing, advertising, or any purpose unrelated to contracted services.

Legal Requirements

We may disclose information when required by law, court order, or government authority, or to protect the rights, property, or safety of Revenify HealthCare, our clients, or the public.

5.

Data Security

Encryption

All data in transit is encrypted using TLS 1.2 or higher. Stored data — including PHI — is encrypted at rest using AES-256 encryption.

Access Controls

Access to PHI and client data is restricted on a role-based, need-to-know basis. All staff undergo HIPAA training and sign confidentiality agreements before accessing any client data.

Infrastructure Security

Our systems are hosted in HIPAA-eligible cloud environments with SOC 2 Type II compliant infrastructure, regular penetration testing, and 24/7 security monitoring.

Incident Response

We maintain a formal incident response plan and conduct periodic risk assessments in accordance with the HIPAA Security Rule's risk analysis requirements.

6.

Data Retention & Deletion

Retention Period

We retain PHI and client data for the duration of the service agreement plus the period required by applicable law — typically seven (7) years for medical billing records, or longer where state law requires.

Post-Termination

Upon contract termination, we will return or securely destroy all PHI and client data in accordance with the terms of our BAA and as directed by the covered entity.

Website Data

Contact form submissions and inquiry data are retained for up to two (2) years unless you request earlier deletion.

7.

Cookies & Tracking Technologies

What We Use

Our website uses cookies, web beacons, and similar technologies to understand visitor behavior, improve site performance, and deliver relevant content.

Types of Cookies

We use strictly necessary cookies (required for the site to function), analytical cookies (to measure page performance and visitor flow), and functional cookies (to remember your preferences).

Your Choices

You may disable cookies through your browser settings. Note that disabling certain cookies may affect site functionality. We do not use cookies on our RCM platform — only on the public marketing website.

8.

Your Rights

Access & Correction

You may request access to personal information we hold about you and ask us to correct any inaccuracies by contacting us at the address below.

Deletion Requests

You may request deletion of your personal information where we are not legally required to retain it. Note: PHI deletion rights are governed by your healthcare provider's HIPAA policies — contact your provider directly for patient-record requests.

Children's Privacy

Our website and services are not directed to individuals under 18. We do not knowingly collect personal information from minors.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, operations, or legal obligations. Material changes will be communicated to active clients via email at least thirty (30) days before they take effect. The updated policy will always be available on this page with a revised effective date.

Continued use of our website or services after any update constitutes acceptance of the revised policy.

Privacy Questions or Requests

For privacy-related inquiries, BAA requests, or to exercise your data rights, contact our compliance team directly.