Privacy Policy
Elite Square Medical Billing is committed to protecting your privacy and handling your personal and medical information with the highest standards of security and confidentiality. This policy explains how we collect, use, and safeguard your information when you use our medical billing services.
Introduction
Welcome to Elite Square Medical Billing (“Company,” “we,” “our,” or “us”). We are a professional medical billing service provider dedicated to helping healthcare practices optimize their revenue cycle management while maintaining the highest standards of privacy and security.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our medical billing services, or interact with us in any way. It applies to healthcare providers who use our services, their patients, and any other individuals whose information we may process in connection with our services [citation:1].
We understand the sensitive nature of medical and billing information and are committed to protecting it with the utmost care. This policy outlines our practices in compliance with applicable privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA), state privacy regulations, and other relevant data protection laws [citation:4].
For Healthcare Providers
If you are a healthcare provider using our services, we act as your Business Associate under HIPAA [citation:9].
For Patients
If you are a patient, your information is processed on behalf of your healthcare provider. Please refer to their privacy policy for more information [citation:1].
For Website Visitors
If you are visiting our website, this policy explains how we handle your personal information [citation:6].
By using our services or accessing our website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our services [citation:6].
Information We Collect
We collect various types of information depending on your interaction with us. This may include personal information, protected health information (PHI), and technical data [citation:3][citation:4].
2.1 Information You Provide Directly
| Category | Examples | Purpose |
|---|---|---|
| Contact Information | Full name, email address, phone number, practice name, mailing address | To communicate with you, provide services, and respond to inquiries [citation:4] |
| Account Information | Username, password, account preferences, security questions | To create and manage your account, authenticate your identity [citation:1] |
| Billing Information | Payment details, billing address, insurance information, financial data | To process payments, submit claims, and manage your account [citation:7] |
| Professional Information | Medical specialty, license number, NPI number, DEA number, practice details | To verify credentials, process claims, and provide specialty-specific services [citation:1] |
2.2 Protected Health Information (PHI)
As a medical billing company, we handle Protected Health Information (PHI) as defined by HIPAA. This includes any information that relates to an individual’s past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare, and that can be used to identify the individual [citation:5][citation:7].
PHI we may process includes:
Important: When we process PHI on behalf of healthcare providers, we act as a “Business Associate” under HIPAA and have entered into Business Associate Agreements (BAAs) with our provider clients [citation:7][citation:9].
2.3 Information Collected Automatically
When you visit our website, we may automatically collect certain information about your device and usage patterns [citation:4][citation:6]:
- Log Data: IP address, browser type, operating system, referring URLs, pages viewed, and timestamps
- Device Information: Device type, screen resolution, unique device identifiers
- Usage Data: How you interact with our website, features used, time spent on pages
- Cookies and Similar Technologies: We use cookies to enhance your experience and analyze site traffic [citation:3]
2.4 Information from Third Parties
We may receive information about you from third parties, including [citation:1]:
- Healthcare Providers: When they engage our services, they may provide patient information necessary for billing
- Insurance Companies and Payers: To verify coverage, process claims, and resolve payment issues
- Clearinghouses: To facilitate electronic claim submissions
- Service Providers: Who assist us in delivering our services
HIPAA Compliance & Protected Health Information
As a medical billing company, HIPAA compliance is the foundation of our operations. We take our obligations to protect PHI seriously and have implemented comprehensive measures to ensure compliance with all applicable HIPAA rules [citation:9].
3.1 Our Role as a Business Associate
Under HIPAA, Elite Square Medical Billing acts as a “Business Associate” to covered entities (healthcare providers, hospitals, clinics). This means we perform services involving the use or disclosure of PHI on behalf of our healthcare clients [citation:5][citation:7].
Our responsibilities as a Business Associate include [citation:4][citation:8]:
- Entering into written Business Associate Agreements (BAAs) with all healthcare provider clients
- Using PHI only for the purposes permitted by the BAA and as required by HIPAA
- Implementing administrative, physical, and technical safeguards to protect PHI
- Reporting any security incidents or breaches to covered entities as required by law
- Ensuring that any subcontractors who handle PHI also comply with HIPAA requirements
- Making PHI available for access, amendment, and accounting of disclosures as required
- Returning or destroying all PHI at the termination of the BAA
3.2 Permitted Uses and Disclosures of PHI
We use and disclose PHI only for permitted purposes under HIPAA, primarily for [citation:2]:
Payment Activities
Claims submission, billing, collections, payment processing, eligibility verification, and utilization review [citation:2]
Healthcare Operations
Quality assessment, compliance monitoring, business management, and customer service [citation:2]
Treatment Coordination
Coordinating with other providers as necessary for billing and payment purposes
3.3 Minimum Necessary Standard
We adhere to the HIPAA “minimum necessary” standard, meaning we make reasonable efforts to limit PHI access, use, and disclosure to the minimum amount necessary to accomplish the intended purpose [citation:5][citation:9].
3.4 Breach Notification
In the event of a breach of unsecured PHI, we have protocols in place to [citation:5]:
- Investigate the breach promptly
- Notify affected covered entities without unreasonable delay
- Provide necessary information to facilitate patient notifications
- Document all breaches and our response actions
- Implement corrective measures to prevent future occurrences
How We Use Your Information
We use the information we collect for various purposes related to providing our medical billing services and operating our business [citation:1][citation:4]:
| Purpose | Description | Legal Basis |
|---|---|---|
| Service Delivery | To provide medical billing services, including claims submission, payment posting, denial management, and revenue cycle optimization | Contract performance, HIPAA permitted uses [citation:2] |
| Communication | To respond to inquiries, provide customer support, send service updates, and communicate about your account | Legitimate business interests, consent |
| Compliance | To comply with legal obligations, including HIPAA requirements, tax laws, and regulatory reporting [citation:4] | Legal obligation |
| Improvement | To analyze usage, improve our services, develop new features, and enhance user experience | Legitimate business interests |
| Security | To protect our systems, detect fraud, prevent unauthorized access, and ensure data integrity [citation:8] | Legitimate business interests, legal obligation |
| Marketing | To send promotional materials, newsletters, and information about our services (with opt-out option) | Consent [citation:5] |
4.1 No Sale of Information
We do not sell, rent, or trade your personal information or PHI to third parties for marketing purposes [citation:4][citation:6].
Information Sharing and Disclosure
We may share your information in the following circumstances [citation:4][citation:8]:
5.1 With Healthcare Providers
We share PHI with the healthcare providers who engage our services, as they are the covered entities responsible for your care.
5.2 With Insurance Companies and Payers
We share information necessary for claims processing, payment, and coordination of benefits with insurance companies and other payers [citation:10].
5.3 With Service Providers
We may share information with third-party service providers who assist us in delivering our services, such as [citation:4][citation:6]:
- Technology Providers: Hosting services, software platforms, and IT support
- Clearinghouses: Electronic claims transmission services
- Payment Processors: Secure payment processing (e.g., Stripe)
- Analytics Providers: Website analytics and performance monitoring
All service providers are required to sign confidentiality agreements and comply with applicable privacy laws, including HIPAA where relevant [citation:8].
5.4 Legal Requirements
We may disclose information if required to do so by law or in response to valid legal requests, such as [citation:4][citation:10]:
- Court orders, subpoenas, or other legal processes
- Requests from government or regulatory authorities
- To comply with tax or reporting obligations
5.5 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business, customer information may be transferred as part of the transaction. We will notify affected individuals of any such change [citation:4].
Data Security and Safeguards
We implement comprehensive security measures to protect your information from unauthorized access, use, or disclosure [citation:3][citation:9]:
Encryption
All sensitive data, including PHI, is encrypted in transit (TLS 1.3) and at rest (AES-256) [citation:3][citation:8]
Access Controls
Strict role-based access controls, multi-factor authentication, and unique user credentials [citation:9]
Audit Logs
Comprehensive logging of all access to PHI, with regular review [citation:9]
Firewalls & Security
Enterprise-grade firewalls, intrusion detection systems, and regular security testing [citation:3]
Staff Training
Mandatory HIPAA and security awareness training for all employees [citation:7][citation:9]
Risk Assessments
Regular security risk assessments and vulnerability scanning [citation:9]
While we implement strong safeguards, no method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we continuously work to maintain the highest standards [citation:4][citation:6].
Your Rights
Depending on your relationship with us and applicable laws, you may have certain rights regarding your information [citation:3][citation:4]:
Access
Request access to your personal information
Correction
Request correction of inaccurate information
Deletion
Request deletion of your information
Restriction
Request restriction of processing
Portability
Receive your data in portable format
Opt-Out
Opt out of marketing communications
Withdraw Consent
Withdraw previously given consent
Complaint
File a complaint with regulatory authorities
7.1 For Patients
If you are a patient whose information we process on behalf of your healthcare provider, please direct your requests to your healthcare provider directly. They are the “covered entity” responsible for your PHI [citation:1].
7.2 How to Exercise Your Rights
To exercise your rights, please contact us using the information in Section 12. We will respond to all legitimate requests within the timeframes required by law [citation:4].
Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your experience, analyze traffic, and improve our services [citation:3][citation:6].
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Required for website functionality and security | Session |
| Analytics Cookies | Track website usage and performance (Google Analytics) | Up to 2 years |
| Preference Cookies | Remember your settings and preferences | Up to 1 year |
You can control cookies through your browser settings. However, disabling cookies may affect certain website functionality [citation:6].
Data Retention
We retain information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law [citation:3][citation:4].
9.1 Retention Periods
- PHI: Retained in accordance with federal and state record retention requirements (typically 6-10 years)
- Account Information: Retained for the duration of your account plus a reasonable period afterward
- Website Data: Retained for analytics purposes for up to 26 months
9.2 Data Destruction
When information is no longer needed, we securely destroy or anonymize it using methods that prevent reconstruction or read access [citation:1].
Children’s Privacy
Our services are not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us, and we will take steps to delete such information [citation:6][citation:8].
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or industry standards [citation:3][citation:4].
When we make changes, we will:
- Update the “Effective Date” at the top of this policy
- Post the revised policy on our website
- Provide additional notice for material changes (such as email notification) as required by law
We encourage you to review this policy periodically to stay informed about how we protect your information [citation:6].
Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us [citation:3][citation:4]:
Privacy & Compliance Team
We’re here to help with any questions about your privacy rights or our data practices.
Overland Park, KS 66223-3240
Privacy Officer
For privacy-specific concerns, you may contact our designated Privacy Officer directly:
Elite Square Medical Billing
