πŸ”’ Your Privacy Matters

Privacy Policy

Effective Date: March 1, 2026
Last Updated: February 28, 2026
πŸ“‹ Quick Summary

Elite Square Medical Billing is committed to protecting your privacy and handling your personal and medical information with the highest standards of security and confidentiality. This policy explains how we collect, use, and safeguard your information when you use our medical billing services.

πŸ”
HIPAA Compliant
πŸ›‘οΈ
256-bit Encryption
πŸ“‹
BAA Available
1

Introduction

Welcome to Elite Square Medical Billing (“Company,” “we,” “our,” or “us”). We are a professional medical billing service provider dedicated to helping healthcare practices optimize their revenue cycle management while maintaining the highest standards of privacy and security.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our medical billing services, or interact with us in any way. It applies to healthcare providers who use our services, their patients, and any other individuals whose information we may process in connection with our services [citation:1].

We understand the sensitive nature of medical and billing information and are committed to protecting it with the utmost care. This policy outlines our practices in compliance with applicable privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA), state privacy regulations, and other relevant data protection laws [citation:4].

πŸ₯

For Healthcare Providers

If you are a healthcare provider using our services, we act as your Business Associate under HIPAA [citation:9].

πŸ‘€

For Patients

If you are a patient, your information is processed on behalf of your healthcare provider. Please refer to their privacy policy for more information [citation:1].

🌐

For Website Visitors

If you are visiting our website, this policy explains how we handle your personal information [citation:6].

By using our services or accessing our website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our services [citation:6].

2

Information We Collect

We collect various types of information depending on your interaction with us. This may include personal information, protected health information (PHI), and technical data [citation:3][citation:4].

2.1 Information You Provide Directly

Category Examples Purpose
Contact Information Full name, email address, phone number, practice name, mailing address To communicate with you, provide services, and respond to inquiries [citation:4]
Account Information Username, password, account preferences, security questions To create and manage your account, authenticate your identity [citation:1]
Billing Information Payment details, billing address, insurance information, financial data To process payments, submit claims, and manage your account [citation:7]
Professional Information Medical specialty, license number, NPI number, DEA number, practice details To verify credentials, process claims, and provide specialty-specific services [citation:1]

2.2 Protected Health Information (PHI)

βš•οΈ Protected Health Information

As a medical billing company, we handle Protected Health Information (PHI) as defined by HIPAA. This includes any information that relates to an individual’s past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare, and that can be used to identify the individual [citation:5][citation:7].

PHI we may process includes:

βœ“
Patient demographics (name, address, date of birth, Social Security number)
βœ“
Medical history and diagnosis codes (ICD-10)
βœ“
Procedure codes (CPT/HCPCS)
βœ“
Insurance information and policy numbers
βœ“
Treatment records and clinical documentation
βœ“
Payment history and billing records

Important: When we process PHI on behalf of healthcare providers, we act as a “Business Associate” under HIPAA and have entered into Business Associate Agreements (BAAs) with our provider clients [citation:7][citation:9].

2.3 Information Collected Automatically

When you visit our website, we may automatically collect certain information about your device and usage patterns [citation:4][citation:6]:

  • Log Data: IP address, browser type, operating system, referring URLs, pages viewed, and timestamps
  • Device Information: Device type, screen resolution, unique device identifiers
  • Usage Data: How you interact with our website, features used, time spent on pages
  • Cookies and Similar Technologies: We use cookies to enhance your experience and analyze site traffic [citation:3]

2.4 Information from Third Parties

We may receive information about you from third parties, including [citation:1]:

  • Healthcare Providers: When they engage our services, they may provide patient information necessary for billing
  • Insurance Companies and Payers: To verify coverage, process claims, and resolve payment issues
  • Clearinghouses: To facilitate electronic claim submissions
  • Service Providers: Who assist us in delivering our services
3

HIPAA Compliance & Protected Health Information

As a medical billing company, HIPAA compliance is the foundation of our operations. We take our obligations to protect PHI seriously and have implemented comprehensive measures to ensure compliance with all applicable HIPAA rules [citation:9].

3.1 Our Role as a Business Associate

Under HIPAA, Elite Square Medical Billing acts as a “Business Associate” to covered entities (healthcare providers, hospitals, clinics). This means we perform services involving the use or disclosure of PHI on behalf of our healthcare clients [citation:5][citation:7].

Our responsibilities as a Business Associate include [citation:4][citation:8]:

  • Entering into written Business Associate Agreements (BAAs) with all healthcare provider clients
  • Using PHI only for the purposes permitted by the BAA and as required by HIPAA
  • Implementing administrative, physical, and technical safeguards to protect PHI
  • Reporting any security incidents or breaches to covered entities as required by law
  • Ensuring that any subcontractors who handle PHI also comply with HIPAA requirements
  • Making PHI available for access, amendment, and accounting of disclosures as required
  • Returning or destroying all PHI at the termination of the BAA

3.2 Permitted Uses and Disclosures of PHI

We use and disclose PHI only for permitted purposes under HIPAA, primarily for [citation:2]:

πŸ’°

Payment Activities

Claims submission, billing, collections, payment processing, eligibility verification, and utilization review [citation:2]

βš•οΈ

Healthcare Operations

Quality assessment, compliance monitoring, business management, and customer service [citation:2]

πŸ“‹

Treatment Coordination

Coordinating with other providers as necessary for billing and payment purposes

3.3 Minimum Necessary Standard

We adhere to the HIPAA “minimum necessary” standard, meaning we make reasonable efforts to limit PHI access, use, and disclosure to the minimum amount necessary to accomplish the intended purpose [citation:5][citation:9].

3.4 Breach Notification

In the event of a breach of unsecured PHI, we have protocols in place to [citation:5]:

  • Investigate the breach promptly
  • Notify affected covered entities without unreasonable delay
  • Provide necessary information to facilitate patient notifications
  • Document all breaches and our response actions
  • Implement corrective measures to prevent future occurrences
4

How We Use Your Information

We use the information we collect for various purposes related to providing our medical billing services and operating our business [citation:1][citation:4]:

Purpose Description Legal Basis
Service Delivery To provide medical billing services, including claims submission, payment posting, denial management, and revenue cycle optimization Contract performance, HIPAA permitted uses [citation:2]
Communication To respond to inquiries, provide customer support, send service updates, and communicate about your account Legitimate business interests, consent
Compliance To comply with legal obligations, including HIPAA requirements, tax laws, and regulatory reporting [citation:4] Legal obligation
Improvement To analyze usage, improve our services, develop new features, and enhance user experience Legitimate business interests
Security To protect our systems, detect fraud, prevent unauthorized access, and ensure data integrity [citation:8] Legitimate business interests, legal obligation
Marketing To send promotional materials, newsletters, and information about our services (with opt-out option) Consent [citation:5]

4.1 No Sale of Information

We do not sell, rent, or trade your personal information or PHI to third parties for marketing purposes [citation:4][citation:6].

5

Information Sharing and Disclosure

We may share your information in the following circumstances [citation:4][citation:8]:

5.1 With Healthcare Providers

We share PHI with the healthcare providers who engage our services, as they are the covered entities responsible for your care.

5.2 With Insurance Companies and Payers

We share information necessary for claims processing, payment, and coordination of benefits with insurance companies and other payers [citation:10].

5.3 With Service Providers

We may share information with third-party service providers who assist us in delivering our services, such as [citation:4][citation:6]:

  • Technology Providers: Hosting services, software platforms, and IT support
  • Clearinghouses: Electronic claims transmission services
  • Payment Processors: Secure payment processing (e.g., Stripe)
  • Analytics Providers: Website analytics and performance monitoring

All service providers are required to sign confidentiality agreements and comply with applicable privacy laws, including HIPAA where relevant [citation:8].

5.4 Legal Requirements

We may disclose information if required to do so by law or in response to valid legal requests, such as [citation:4][citation:10]:

  • Court orders, subpoenas, or other legal processes
  • Requests from government or regulatory authorities
  • To comply with tax or reporting obligations

5.5 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, customer information may be transferred as part of the transaction. We will notify affected individuals of any such change [citation:4].

6

Data Security and Safeguards

We implement comprehensive security measures to protect your information from unauthorized access, use, or disclosure [citation:3][citation:9]:

πŸ”

Encryption

All sensitive data, including PHI, is encrypted in transit (TLS 1.3) and at rest (AES-256) [citation:3][citation:8]

πŸ‘₯

Access Controls

Strict role-based access controls, multi-factor authentication, and unique user credentials [citation:9]

πŸ“‹

Audit Logs

Comprehensive logging of all access to PHI, with regular review [citation:9]

πŸ›‘οΈ

Firewalls & Security

Enterprise-grade firewalls, intrusion detection systems, and regular security testing [citation:3]

πŸŽ“

Staff Training

Mandatory HIPAA and security awareness training for all employees [citation:7][citation:9]

πŸ“

Risk Assessments

Regular security risk assessments and vulnerability scanning [citation:9]

While we implement strong safeguards, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we continuously work to maintain the highest standards [citation:4][citation:6].

7

Your Rights

Depending on your relationship with us and applicable laws, you may have certain rights regarding your information [citation:3][citation:4]:

πŸ‘οΈ

Access

Request access to your personal information

✏️

Correction

Request correction of inaccurate information

πŸ—‘οΈ

Deletion

Request deletion of your information

⏸️

Restriction

Request restriction of processing

πŸ“¦

Portability

Receive your data in portable format

🚫

Opt-Out

Opt out of marketing communications

πŸ”™

Withdraw Consent

Withdraw previously given consent

⚠️

Complaint

File a complaint with regulatory authorities

7.1 For Patients

If you are a patient whose information we process on behalf of your healthcare provider, please direct your requests to your healthcare provider directly. They are the “covered entity” responsible for your PHI [citation:1].

7.2 How to Exercise Your Rights

To exercise your rights, please contact us using the information in Section 12. We will respond to all legitimate requests within the timeframes required by law [citation:4].

8

Cookies and Tracking Technologies

Our website uses cookies and similar technologies to enhance your experience, analyze traffic, and improve our services [citation:3][citation:6].

Cookie Type Purpose Duration
Essential Cookies Required for website functionality and security Session
Analytics Cookies Track website usage and performance (Google Analytics) Up to 2 years
Preference Cookies Remember your settings and preferences Up to 1 year

You can control cookies through your browser settings. However, disabling cookies may affect certain website functionality [citation:6].

9

Data Retention

We retain information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law [citation:3][citation:4].

9.1 Retention Periods

  • PHI: Retained in accordance with federal and state record retention requirements (typically 6-10 years)
  • Account Information: Retained for the duration of your account plus a reasonable period afterward
  • Website Data: Retained for analytics purposes for up to 26 months

9.2 Data Destruction

When information is no longer needed, we securely destroy or anonymize it using methods that prevent reconstruction or read access [citation:1].

10

Children’s Privacy

Our services are not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us, and we will take steps to delete such information [citation:6][citation:8].

11

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or industry standards [citation:3][citation:4].

When we make changes, we will:

  • Update the “Effective Date” at the top of this policy
  • Post the revised policy on our website
  • Provide additional notice for material changes (such as email notification) as required by law

We encourage you to review this policy periodically to stay informed about how we protect your information [citation:6].

12

Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us [citation:3][citation:4]:

Privacy & Compliance Team

We’re here to help with any questions about your privacy rights or our data practices.

πŸ“ 15218 Reeds Street
Overland Park, KS 66223-3240

Privacy Officer

For privacy-specific concerns, you may contact our designated Privacy Officer directly:

πŸ‘€ Privacy Officer
Elite Square Medical Billing
πŸ” HIPAA Compliance Inquiries