Privacy Policy
Revenify HealthCare is committed to protecting the privacy of our clients, their patients, and all individuals whose information we handle.
Effective Date: June 20, 2025
HIPAA Notice: Revenify HealthCare operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We handle Protected Health Information (PHI) solely on behalf of our covered entity clients under executed Business Associate Agreements. This policy explains how we handle all information — including PHI — in the course of providing RCM and medical coding services.
This Privacy Policy applies to information collected through our website at revenifyhealthcare.com, our MRR platform, and in the course of providing contracted Revenue Cycle Management (RCM) and Medical Coding services. By using our website or engaging our services, you agree to the practices described herein.
If you have questions about this policy or wish to exercise any of your rights, contact us at info@revenifyhealthcare.com.
Information We Collect
Personal & Contact Information
We collect information you voluntarily provide when contacting us, requesting a demo, or entering into a service agreement — including name, email address, phone number, job title, and organization name.
Protected Health Information (PHI)
As a Business Associate under HIPAA, we may receive, process, and transmit PHI on behalf of our clients (Covered Entities). This includes patient demographics, insurance information, diagnosis and procedure codes, claim data, Explanation of Benefits (EOBs), and remittance data — strictly for the purpose of delivering contracted RCM and medical coding services.
Technical & Usage Data
We collect device and browser information, IP addresses, pages visited, session duration, and referring URLs when you access our website or platform — using cookies and similar tracking technologies.
Business & Financial Information
Information needed to provide billing and RCM services, including provider NPI numbers, payer IDs, fee schedules, and practice management system credentials supplied by our clients.
How We Use Your Information
Service Delivery
To perform medical billing, medical coding, denial management, accounts receivable follow-up, credentialing, and other contracted RCM services on behalf of our healthcare provider clients.
Communication
To respond to inquiries, send service updates, deliver audit reports, and communicate billing performance metrics to authorized client representatives.
Compliance & Reporting
To meet our legal obligations under HIPAA, applicable state laws, and contractual Business Associate Agreements (BAAs) with our covered entity clients.
Platform Improvement
Aggregate, de-identified data may be used to improve our MRR platform, refine internal workflows, and benchmark performance — never in a way that identifies individual patients or clients.
HIPAA Compliance & Business Associate Agreements
Business Associate Status
Revenify HealthCare functions as a Business Associate (BA) as defined under the Health Insurance Portability and Accountability Act (HIPAA). We execute a Business Associate Agreement (BAA) with every covered entity client prior to handling any PHI.
Minimum Necessary Standard
We access, use, and disclose PHI only to the minimum extent necessary to perform contracted services — consistent with the HIPAA Privacy Rule's minimum necessary standard.
Security Safeguards
We implement the administrative, physical, and technical safeguards required by the HIPAA Security Rule, including access controls, audit logging, encryption in transit and at rest, and workforce training.
Breach Notification
In the event of a discovered breach of unsecured PHI, we will notify affected covered entities within the timeframes specified under the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414) and as required by our BAA.
Information Sharing & Disclosure
Authorized Disclosures
We share PHI only as permitted or required by our BAA and HIPAA — such as submitting claims to payers, clearinghouses, and government programs (Medicare/Medicaid) on behalf of our clients.
Subcontractors
Any subcontractor or technology vendor that handles PHI on our behalf is required to execute a BAA and maintain equivalent HIPAA safeguards.
No Sale of Data
We do not sell, rent, or trade personal information or PHI to third parties for marketing, advertising, or any purpose unrelated to contracted services.
Legal Requirements
We may disclose information when required by law, court order, or government authority, or to protect the rights, property, or safety of Revenify HealthCare, our clients, or the public.
Data Security
Encryption
All data in transit is encrypted using TLS 1.2 or higher. Stored data — including PHI — is encrypted at rest using AES-256 encryption.
Access Controls
Access to PHI and client data is restricted on a role-based, need-to-know basis. All staff undergo HIPAA training and sign confidentiality agreements before accessing any client data.
Infrastructure Security
Our systems are hosted in HIPAA-eligible cloud environments with SOC 2 Type II compliant infrastructure, regular penetration testing, and 24/7 security monitoring.
Incident Response
We maintain a formal incident response plan and conduct periodic risk assessments in accordance with the HIPAA Security Rule's risk analysis requirements.
Data Retention & Deletion
Retention Period
We retain PHI and client data for the duration of the service agreement plus the period required by applicable law — typically seven (7) years for medical billing records, or longer where state law requires.
Post-Termination
Upon contract termination, we will return or securely destroy all PHI and client data in accordance with the terms of our BAA and as directed by the covered entity.
Website Data
Contact form submissions and inquiry data are retained for up to two (2) years unless you request earlier deletion.
Your Rights
Access & Correction
You may request access to personal information we hold about you and ask us to correct any inaccuracies by contacting us at the address below.
Deletion Requests
You may request deletion of your personal information where we are not legally required to retain it. Note: PHI deletion rights are governed by your healthcare provider's HIPAA policies — contact your provider directly for patient-record requests.
Children's Privacy
Our website and services are not directed to individuals under 18. We do not knowingly collect personal information from minors.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, operations, or legal obligations. Material changes will be communicated to active clients via email at least thirty (30) days before they take effect. The updated policy will always be available on this page with a revised effective date.
Continued use of our website or services after any update constitutes acceptance of the revised policy.
Privacy Questions or Requests
For privacy-related inquiries, BAA requests, or to exercise your data rights, contact our compliance team directly.