Legal Document

Privacy Policy

How EnVision MD Billing Services collects, uses, and protects your information.

🔒 HIPAA Compliant: EnVision MD operates as a HIPAA-compliant Business Associate. All Protected Health Information (PHI) is handled in accordance with federal law.

Last Updated: March 1, 2025  |  Effective Date: March 1, 2025

1 Overview & Scope

EnVision MD Billing Services ("EnVision MD," "we," "us," or "our") is committed to protecting the privacy and security of the information we handle. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you:

  • Visit our website at envisionmdrcm.com
  • Engage our medical billing or revenue cycle management services
  • Contact us by phone, email, or online form
  • Enter into a service or business associate agreement with us

This policy applies to all information collected through our website and business operations. It does not apply to information collected by third parties whose websites may be linked from ours.

2 Information We Collect

A. Client Business Information

  • Practice name, provider names, and NPI numbers
  • Contact details (name, email, phone, mailing address)
  • Tax ID and billing account information
  • Payer contracts, credentialing documents, and specialty information

B. Patient Billing Information (PHI)

  • Patient name, date of birth, and contact information
  • Insurance information and member ID numbers
  • Diagnosis codes (ICD-10), procedure codes (CPT), and clinical notes needed for billing
  • Explanation of Benefits (EOB) and remittance data

C. Website Visitor Information

  • IP address, browser type, and device information
  • Pages visited, time on site, and referring URLs
  • Information submitted via contact or appointment request forms
We only collect patient information that is strictly necessary to perform contracted medical billing services on your behalf.

3 How We Use Your Information

  • Submitting medical claims to insurance payers on your behalf
  • Processing payments, posting remittances, and managing accounts receivable
  • Conducting credentialing and enrollment with insurance companies
  • Following up on denied or pending claims and submitting appeals
  • Communicating with you about your account, services, and billing status
  • Improving our internal processes, software, and service quality
  • Complying with legal, regulatory, and contractual obligations
  • Responding to inquiries submitted through our website

We do not use patient information for marketing, advertising, or any purpose beyond the contracted scope of our billing services.

4 How We Share Information

EnVision MD does not sell, rent, or trade your information or patient data. We may share information only in the following limited circumstances:

  • Insurance Payers & Clearinghouses: We transmit claim data to payers and clearinghouses as required to perform billing services
  • Credentialing Bodies: We share provider credentials with insurance companies and credentialing organizations as part of enrollment services
  • Service Providers: We may engage HIPAA-compliant subcontractors who assist in service delivery under strict confidentiality agreements
  • Legal Requirements: We may disclose information when required by law, court order, or governmental authority
  • Business Transfers: In the event of a merger or acquisition, data may be transferred subject to the same privacy protections
All third parties who access PHI on our behalf are required to sign a Business Associate Agreement (BAA) and comply with HIPAA regulations.

5 HIPAA & Protected Health Information

EnVision MD acts as a HIPAA Business Associate for all healthcare provider clients. We are legally obligated to:

  • Use and disclose PHI only as permitted by your signed Business Associate Agreement (BAA)
  • Implement appropriate administrative, physical, and technical safeguards to protect PHI
  • Report any PHI breaches to you in accordance with the HIPAA Breach Notification Rule
  • Ensure that any subcontractors who handle PHI also sign BAAs and comply with HIPAA
  • Return or securely destroy PHI upon termination of the service relationship
A signed Business Associate Agreement (BAA) is required before any PHI is shared with EnVision MD. Questions about your BAA? Email us at info@emdrcm.com.

6 Data Security

  • Encrypted data transmission using SSL/TLS protocols
  • Role-based access controls limiting data access to authorized personnel only
  • Secure, HIPAA-compliant billing and practice management software
  • Regular staff training on HIPAA compliance and data privacy
  • Secure disposal of physical and electronic records containing PHI
  • Multi-factor authentication for systems containing sensitive data

While we take every reasonable precaution, no method of electronic transmission or storage is 100% secure. In the unlikely event of a data breach, we will notify you promptly in accordance with applicable law.

7 Data Retention

  • Billing records and claim data: retained for a minimum of 7 years in accordance with CMS and state regulations
  • Credentialing documents: retained for the duration of the provider relationship plus applicable regulatory periods
  • Website inquiry data: retained for up to 2 years unless you request deletion
  • Upon contract termination, we will return or securely destroy PHI per the terms of your BAA

8 Cookies & Website Tracking

Our website may use cookies and similar technologies to improve your experience:

  • Essential Cookies: Required for the website to function properly
  • Analytics Cookies: Help us understand traffic patterns and improve content (e.g., Google Analytics)
  • Functional Cookies: Remember your preferences and settings

You can control cookie settings through your browser preferences. Disabling certain cookies may affect website functionality. We do not use cookies to track patient health information.

9 Your Rights

  • Access: Request a copy of the information we hold about you or your practice
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your information (subject to legal retention requirements)
  • Restriction: Request that we limit how we use your information in certain circumstances
  • Portability: Receive your data in a portable format where technically feasible
  • Opt-Out: Opt out of non-essential communications from us at any time
For patient PHI rights (access, amendment, accounting of disclosures), please contact your healthcare provider directly. EnVision MD processes this data on their behalf.

To exercise any of the above rights, email us at info@emdrcm.com.

10 Third-Party Links

Our website may contain links to third-party websites, including insurance payer portals, clearinghouses, or industry resources. EnVision MD is not responsible for the privacy practices of these external sites. We encourage you to review the privacy policy of any third-party site you visit.

11 Children's Privacy

Our website and business services are directed at healthcare professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal information from minors through our website.

Pediatric patient billing data is handled in accordance with HIPAA, applicable state laws, and with parental/guardian authorization as required by your practice.

12 Updates to This Policy

  • We will update the "Last Updated" date at the top of this page when changes are made
  • Active clients will be notified via email for significant changes
  • Continued use of our services after the effective date constitutes acceptance of the revised policy

13 Contact & Data Requests

For privacy questions, data requests, or concerns, please reach out:

  • Company: EnVision MD Billing Services
  • Address: 720 Seneca Street Suite 720 #256, Seattle, WA 98101
  • Also: 5109 Hollyridge Dr Ste 103, Raleigh, NC 27612
  • Email: info@emdrcm.com
  • Phone: +1 (855) 235-6126
  • Website: envisionmdrcm.com

We aim to respond to all privacy-related requests within 10 business days.

Have a Privacy Question?

Our compliance team is happy to address any concerns about how we handle your data.

Contact Us Today