Healthcare practices trust us with sensitive patient information every day. We treat that trust as the foundation of our business. Our HIPAA program is built around three principles:
HIPAA distinguishes between two main categories of regulated entities:
AllMedex is typically a Business Associate. When we provide medical billing, credentialing, payer enrollment, or revenue cycle management services, we operate under a written Business Associate Agreement (BAA) with each Covered Entity.
Protected health information includes any individually identifiable health information transmitted or maintained in any form. Examples we routinely handle include:
We use and disclose PHI only as necessary to perform the services described in our agreement, or as otherwise permitted or required by law. Common permitted purposes include:
We do not sell PHI. We do not use or disclose PHI for marketing without authorization. We do not use PHI to train external machine learning or AI models.
When using or disclosing PHI, we apply the minimum necessary standard: only the information reasonably needed to accomplish the intended purpose is accessed, used, or shared. Our access controls, role definitions, and workflow design are built around this principle.
We implement administrative, physical, and technical safeguards in line with the HIPAA Security Rule.
Every member of our workforce who may come into contact with PHI completes HIPAA Privacy and Security training as part of onboarding and refreshes that training periodically. Training covers permitted uses and disclosures, minimum necessary, secure handling of PHI, password and device hygiene, social engineering, and incident reporting. Workforce members are bound by confidentiality agreements and a documented sanction policy.
Healthcare practices trust us with sensitive patient information every day. We treat that trust as the foundation of our business. Our HIPAA program is built around three principles:
In the event of a confirmed or suspected breach of unsecured PHI, AllMedex will:
In the event of a confirmed or suspected breach of unsecured PHI, AllMedex will:
Contact our Privacy Officer immediately using the details below.
HIPAA gives patients several rights regarding their PHI. These rights are exercised through the Covered Entity (your healthcare provider or practice), which is the legal custodian of the medical record. These generally include:
Have more questions? We’re here to help! Whether you need details about our billing process, services, or partnership options.
A medical billing company handles the financial side of healthcare for providers by managing patient billing, insurance claims, and reimbursements.
Medical billing services manage every financial touchpoint after a patient visit: verifying coverage, coding procedures, filing claims, appealing denials, and depositing funds to ensure healthcare providers receive full, compliant reimbursement.
Our solutions align with international security standards and regulations, ensuring your business remains compliant while protecting sensitive information.
Our medical billing firm offers a range of services, such as provider enrollment, insurance verification, charge entry, claim submission, payment posting, account receivable management, denial management, appeal management, patient billing, reimbursement tracking, and collection.
Of course. AllmedEx lets providers track the caliber and results of their facility’s billing. We also share reports on daily invoicing, key markers and offer feedback for revenue cycle advancement.
At our company, we have the people and processes to provide independent, specialized medical billing services for Medicaid and Medicare patients. Every state has its own rules for filing and getting paid, and we stay on top of them. We know which forms to fill out, which codes to use, and how to get it right the first time. We watch each claim to make sure it gets paid. If there are problems, we handle appeals so you recoup all owed payments.
For HIPAA questions, BAA requests, audit support, or to report a privacy or security concern:
WhatsApp us