Company Logo MedBill Advocate
  • Home
  • Services
  • About
  • Contact
← Back to Home

HIPAA Compliance Statement

Last Updated: January 2024

Our Commitment: At MedBill Advocate, we take your privacy seriously. We are committed to protecting your protected health information (PHI) in accordance with the Health Insurance Portability and Accountability Act (HIPAA) and California privacy laws.

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that established national standards to protect individuals' medical records and other personal health information. As a medical billing advocate, we handle sensitive health information and are committed to maintaining the confidentiality and security of your protected health information (PHI).

1. Understanding PHI

Protected Health Information (PHI) is any information in a medical record that can be used to identify an individual and that was created, used, or maintained by a covered entity. This includes:

  • Demographic information (name, address, birth date, Social Security Number)
  • Medical history and treatment information
  • Diagnosis and prognosis
  • Test results and laboratory reports
  • Insurance information and billing records
  • Any other information that could identify you and relates to your health

2. Our HIPAA Compliance Measures

Administrative Safeguards

We have implemented comprehensive administrative safeguards to protect PHI:

  • Employee Training: All staff members receive regular HIPAA training and are educated on privacy and security requirements.
  • Access Controls: Only authorized personnel have access to client information, and access is limited to what is necessary for job functions.
  • Policies and Procedures: We maintain written policies and procedures for handling PHI, including incident response protocols.
  • Business Associate Agreements: We require all third-party service providers who handle PHI to sign Business Associate Agreements (BAAs) that ensure they comply with HIPAA requirements.

Physical Safeguards

We have implemented physical safeguards to protect PHI:

  • Secure Facilities: Our office has controlled access, and client files are stored in locked cabinets when not in use.
  • Device Security: Computers and mobile devices containing PHI are secured with passwords and encryption.
  • Document Disposal: Physical documents containing PHI are securely shredded when no longer needed.
  • Workspace Privacy: We maintain private areas for client consultations to ensure confidentiality.

Technical Safeguards

We have implemented technical safeguards to protect electronic PHI (ePHI):

  • Encryption: All electronic PHI is encrypted both in transit and at rest using industry-standard encryption protocols.
  • Secure Communication: We use secure, encrypted email services and communication platforms when exchanging PHI electronically.
  • Firewall and Antivirus: Our systems are protected by firewalls and up-to-date antivirus software.
  • Access Controls: We use unique user IDs, strong passwords, and multi-factor authentication to control access to ePHI.
  • Audit Controls: We maintain audit logs to track access to and changes in PHI.
  • Automatic Logoff: Computers automatically log off after a period of inactivity.

3. How We Use and Disclose Your PHI

We will only use or disclose your PHI for the following purposes:

  • Treatment: To communicate with healthcare providers about your medical billing dispute.
  • Payment: To negotiate with insurance companies and healthcare providers on your behalf.
  • Healthcare Operations: To improve our services and ensure quality advocacy.
  • With Your Authorization: We will obtain your written authorization before using or disclosing your PHI for any other purpose.

4. Your HIPAA Rights

Under HIPAA, you have the following rights regarding your PHI:

Right to Access

You have the right to inspect and obtain a copy of your PHI that we maintain. We will respond to your request within 30 days.

Right to Amendment

You may request that we amend your PHI if you believe it is incorrect or incomplete. We will review your request and may deny it under certain circumstances.

Right to an Accounting of Disclosures

You have the right to receive a list of certain disclosures we have made of your PHI. This does not include disclosures made for treatment, payment, or healthcare operations.

Right to Request Restrictions

You may request restrictions on certain uses and disclosures of your PHI. While we are not always required to agree to your requested restrictions, we will consider your request.

Right to Request Confidential Communications

You may request that we communicate with you about medical matters in a certain way or at a certain location (e.g., only by email or at a specific phone number).

Right to Revoke Authorization

If you have provided us with written authorization to use or disclose your PHI, you have the right to revoke that authorization at any time, provided the revocation is in writing.

5. Breach Notification

In the event of a breach of unsecured PHI, we will notify you without unreasonable delay, and in no case later than 60 days after discovering the breach. The notification will include:

  • A description of the breach
  • The types of PHI involved
  • Steps you should take to protect yourself
  • What we are doing to investigate and prevent future breaches
  • Contact information for questions

6. California Privacy Laws

In addition to HIPAA, we comply with California privacy laws, including:

  • California Confidentiality of Medical Information Act (CMIA): Provides additional protections for medical information beyond HIPAA.
  • California Consumer Privacy Act (CCPA): Grants California residents additional rights regarding their personal information.
  • California Electronic Communications Privacy Act (CalECPA): Protects electronic communications and data.

7. Complaints

If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services (HHS).

To file a complaint with us:

Phone: 1-415-755-5310
Email: help@tammymedbilling.us
Address: Sausalito, CA 94965

To file a complaint with HHS:

Phone: 1-877-696-6775
Website: https://www.hhs.gov/hipaa/for-individuals/how-to-file-a-complaint/index.html
Mail: U.S. Department of Health and Human Services, 200 Independence Avenue, S.W., Washington, D.C. 20201

We will not retaliate against you for filing a complaint.

8. Designated Privacy Officer

We have designated a Privacy Officer who is responsible for developing and implementing our HIPAA policies and procedures. If you have questions about this notice or our privacy practices, please contact our Privacy Officer using the contact information provided above.

9. Changes to This Notice

We reserve the right to change this notice at any time. If we make material changes to our privacy practices, we will update the "Last Updated" date and provide you with a revised notice. The revised notice will be effective 30 days after the update, unless we specify otherwise.

© 2024 MedBill Advocate. All rights reserved. | Licensed in California