Who We Are
MeBilling Inc. is a healthcare Revenue Cycle Management company incorporated under the laws of the State of Texas, with its principal office at 100 Glenborough Dr, Houston, TX 77067. We provide medical billing, coding, credentialing, denial management, payment posting, audit services, and related administrative services to healthcare providers, physician groups, hospitals, ambulatory surgical centers, laboratories, and other covered entities throughout the United States.
In the course of providing these services, MeBilling functions as a Business Associate as defined under 45 CFR § 160.103 of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act. This means we access, use, and disclose Protected Health Information (PHI) solely on behalf of, and as permitted by, our covered entity clients.
Definitions
- PHIProtected Health Information: any individually identifiable health information created, received, maintained, or transmitted by MeBilling on behalf of a covered entity client, in any form or medium, as defined under 45 CFR § 160.103.
- ePHIElectronic Protected Health Information: PHI that is created, received, maintained, or transmitted in electronic form, subject to the HIPAA Security Rule 45 CFR Part 164, Subparts A & C.
- Covered EntityA healthcare provider, health plan, or healthcare clearinghouse that transmits health information electronically, as defined under 45 CFR § 160.103. Our clients are covered entities.
- Business AssociateA person or entity that performs functions or activities on behalf of a covered entity that involve the use or disclosure of PHI. MeBilling is a Business Associate.
- BAABusiness Associate Agreement: the written contract between MeBilling and each covered entity client that governs our use and disclosure of PHI, as required by 45 CFR § 164.308(b).
- Personal InformationNon-PHI data about individuals we may collect through our website or business operations, such as contact information of prospective clients or website visitors.
- TMRPATexas Medical Records Privacy Act, codified at Texas Health & Safety Code Chapter 181 (H.B. 300), which imposes stricter privacy requirements than HIPAA in certain respects.
Information We Collect
3.1 Protected Health Information (PHI) — As Business Associate
In performing Revenue Cycle Management services for our covered entity clients, we receive, access, and process PHI on their behalf. This information is provided directly by our clients or transmitted from their electronic health record (EHR) and practice management systems. Types of PHI we handle include:
- Patient demographics: full name, date of birth, address, telephone number, Social Security Number (last four digits for billing purposes), and insurance identification numbers
- Clinical data necessary for billing: diagnosis codes (ICD-10), procedure codes (CPT/HCPCS), dates of service, place of service, rendering provider identifiers (NPI), and clinical notes required for coding accuracy
- Insurance and financial information: payer names, member IDs, group numbers, Explanation of Benefits (EOB), remittance advice, and payment records
- Prior authorisation numbers, referral documentation, and eligibility verification results
All PHI is collected and processed solely to perform contracted services on behalf of the client covered entity and only to the minimum extent necessary for that purpose, as required by 45 CFR § 164.502(b) (the Minimum Necessary Standard).
3.2 Provider & Practice Information — From Clients
We collect practice and provider information from our clients, including: practice legal name, Tax Identification Number (TIN), National Provider Identifier (NPI), licensure information, payer contract details, DEA numbers (where applicable), credentialing documentation, and banking or EFT information for payment posting purposes.
3.3 Personal Information — Website Visitors & Prospective Clients
When individuals visit our website or submit an inquiry through our contact form, we may collect: full name, email address, phone number, organisation name, and the content of any message submitted. This information is used solely to respond to inquiries and is not combined with PHI.
3.4 Technical Information — Automatic Collection
Our website automatically collects limited technical data including: IP address, browser type, pages visited, time and date of visits, and referring URLs. We use this information to maintain website security, improve user experience, and compile aggregate statistics. We do not use this data to identify individual users for marketing purposes.
How We Use Information
4.1 PHI — Permitted Uses Only
MeBilling uses and discloses PHI exclusively as permitted or required by the applicable BAA and by HIPAA. Our permitted uses include:
Healthcare Operations and Treatment Payment
45 CFR § 164.506Submitting and managing insurance claims, processing payments, managing denials and appeals, performing coding and documentation reviews, and all other activities directly related to healthcare payment on behalf of a covered entity client.
Performance of BAA-Permitted Functions
BAAAny use specifically authorised in the written BAA between MeBilling and the client, including quality assurance, compliance auditing, and training activities that require access to PHI.
Required by Law
45 CFR § 164.512Disclosures to comply with valid legal process, court orders, regulatory investigations by the HHS Office for Civil Rights (OCR), or other lawful government authority.
Management and Administration of MeBilling
45 CFR § 164.504(e)(4)Internal use by MeBilling's workforce to manage our own legal and business obligations, only to the extent permitted.
4.2 What We Will Never Do With PHI
MeBilling will never sell, rent, lease, or trade PHI or any personal information. We will never use PHI for marketing purposes without explicit written authorisation. We will never use PHI for any purpose not expressly permitted by the applicable BAA and HIPAA, including any use that would constitute a violation of the Anti-Kickback Statute 42 U.S.C. § 1320a-7b or the False Claims Act 31 U.S.C. §§ 3729-3733.
4.3 Personal Information — Website and Business Use
Non-PHI personal information collected through our website or business development activities is used solely to: respond to inquiries and requests for information; communicate about our services; and, where applicable, comply with our legal obligations. We do not sell, share, or monetise this information in any way.
HIPAA & HITECH Compliance
5.1 Governing Framework
MeBilling's data handling practices are governed by the full HIPAA Administrative Simplification framework, as amended and strengthened by the HITECH Act of 2009:
- HIPAA Privacy Rule45 CFR Part 164, Subpart E— governs the permissible uses and disclosures of PHI and requires us to implement privacy policies and procedures
- HIPAA Security Rule45 CFR Part 164, Subparts A & C— requires administrative, physical, and technical safeguards to protect ePHI
- HIPAA Breach Notification Rule45 CFR Part 164, Subpart D— requires notification to covered entity clients of any breach of unsecured PHI within 60 days of discovery
- HITECH ActPub. L. 111-5, § 13001 et seq.— directly extended HIPAA obligations to Business Associates, strengthened enforcement, and increased civil and criminal penalties
- HITECH § 13405(d)— requires compliance with patient requests to restrict disclosures for self-pay services, as enforced through our covered entity clients
5.2 Direct HIPAA Liability
Under the HITECH Act, Business Associates like MeBilling are directly liable for compliance with the HIPAA Security Rule and the applicable provisions of the Privacy Rule. We are subject to civil monetary penalties enforced by the HHS Office for Civil Rights (OCR) and, in cases of knowing violations, criminal penalties under 42 U.S.C. § 1320d-6. We take this liability seriously and maintain a full internal compliance programme accordingly.
5.3 Minimum Necessary Standard
Consistent with 45 CFR § 164.502(b), MeBilling limits all PHI access to the minimum information necessary to perform each specific service. Access controls are implemented at the role and function level, so that individuals within MeBilling only access PHI relevant to their assigned tasks. We do not grant broad access to PHI as a default.
Texas Privacy Laws
6.1 Texas Medical Records Privacy Act (TMRPA)
As a company headquartered in Texas, MeBilling is subject to the Texas Medical Records Privacy Act Texas Health & Safety Code, Chapter 181, enacted as H.B. 300 (2011). The TMRPA applies to a broader category of "covered entities" than HIPAA and imposes additional requirements, including:
- Mandatory annual HIPAA and TMRPA privacy training for all employees who access protected health information — MeBilling conducts this training without exception
- Written authorisation requirements for disclosure of PHI for marketing purposes — MeBilling does not engage in such disclosures
- The right of patients to request electronic copies of their health information, enforceable against Business Associates operating in Texas
Where Texas law is more stringent than HIPAA, MeBilling complies with the stricter Texas standard.
6.2 Texas Data Breach Notification
In the event of a breach of personal information, MeBilling complies with the Texas Identity Theft Enforcement and Protection Act Texas Business & Commerce Code § 521.053, which requires notification to affected Texas residents as promptly as practicable and no later than 60 days after the date of discovery of a breach. Notification will also be provided to our covered entity clients as required by the HIPAA Breach Notification Rule, and to the Texas Attorney General's office when required by law.
6.3 Texas Health & Safety Code Chapter 182
MeBilling also complies with Texas Health & Safety Code Chapter 182, which governs the confidentiality of medical records maintained in Texas, including requirements relating to the disclosure of confidential information and penalties for unlawful disclosure.
6.4 FTC Act Compliance
MeBilling's data security practices are designed to comply with Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45), which prohibits unfair or deceptive acts or practices in or affecting commerce, including inadequate data security that causes or is likely to cause substantial consumer harm.
Business Associate Agreement (BAA)
MeBilling executes a written Business Associate Agreement (BAA) with every covered entity client before performing any services that involve access to PHI. The BAA is a legally required contract under 45 CFR § 164.308(b)(3) and 45 CFR § 164.504(e) that specifies:
- The permitted and required uses and disclosures of PHI by MeBilling
- MeBilling's obligation not to use or disclose PHI in a manner inconsistent with the BAA or HIPAA
- Safeguards MeBilling must maintain to prevent unauthorised use or disclosure of PHI
- MeBilling's obligation to report any use or disclosure not permitted by the BAA, including breaches
- MeBilling's obligation to comply with the HIPAA Security Rule for ePHI
- Subcontractor BAA requirements — MeBilling does not share PHI with subcontractors; all services are performed in-house
- Requirements for the return or destruction of PHI upon termination of the services agreement
MeBilling performs all services in-house. We do not share PHI with subcontractors, offshore processors, or third-party vendors who are not subject to our own internal controls. If you are a covered entity and do not have an executed BAA with MeBilling, please contact us immediately at privacy@mebilling.com before transmitting any PHI.
Data Security Safeguards
MeBilling maintains a comprehensive information security programme designed to satisfy the requirements of the HIPAA Security Rule 45 CFR Part 164, Subparts A & C. Our safeguards operate across three required domains:
8.1 Administrative Safeguards 45 CFR § 164.308
- • Designated Privacy Officer and Security Officer with defined accountability for HIPAA compliance
- • Comprehensive workforce training: annual mandatory HIPAA, TMRPA, and information security training for all staff who access PHI, with completion tracking and disciplinary policies for non-compliance
- • Access management: role-based access controls ensuring each workforce member accesses only the PHI necessary for their assigned function
- • Risk analysis and risk management: annual formal risk assessment identifying threats and vulnerabilities to ePHI, with documented mitigation plans § 164.308(a)(1)
- • Contingency planning: documented backup and disaster recovery procedures including a business continuity plan for critical billing functions § 164.308(a)(7)
- • Evaluation: periodic technical and non-technical evaluation of security practices to ensure ongoing compliance § 164.308(a)(8)
8.2 Physical Safeguards 45 CFR § 164.310
- • Facility access controls: secured office environments with restricted access to workstations and servers that process ePHI
- • Workstation security: policies governing the proper use and placement of workstations that access ePHI, including screen lock requirements and clean desk policies
- • Device and media controls: documented procedures for the disposal of hardware containing ePHI, including NIST-compliant data destruction
8.3 Technical Safeguards 45 CFR § 164.312
- • Encryption: all ePHI transmitted electronically is encrypted using TLS 1.2 or higher; all stored ePHI is encrypted at rest using AES-256 or equivalent
- • Access controls: unique user identification for all workforce members accessing ePHI, with automatic logoff after periods of inactivity § 164.312(a)(2)
- • Multi-factor authentication (MFA) required for all remote access and privileged account access to systems containing ePHI
- • Audit controls: automated audit logs recording all access to ePHI systems, with regular review for anomalous activity § 164.312(b)
- • Integrity controls: mechanisms to authenticate ePHI and detect unauthorised alteration or destruction § 164.312(c)
- • Transmission security: end-to-end encryption for all electronic transmission of ePHI, including email, EDI, and API-based data exchanges § 164.312(e)
Breach Notification
MeBilling maintains documented breach response procedures consistent with the HIPAA Breach Notification Rule 45 CFR Part 164, Subpart D and applicable Texas law.
9.1 What Constitutes a Breach
A "breach" is the acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI, as defined under 45 CFR § 164.402. The presumption is that any impermissible use or disclosure of PHI is a breach unless MeBilling can demonstrate, through a four-factor risk assessment, that there is a low probability the PHI has been compromised.
9.2 Notification Timelines
To the Covered Entity Client
MeBilling will notify the affected covered entity without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.
45 CFR § 164.410To HHS
Notification to HHS is made by the covered entity client. MeBilling will provide all required information to facilitate timely notification.
45 CFR § 164.408To Texas Residents
If a breach affects Texas residents' personal information, MeBilling will comply with notification requirements within 60 days.
TX Bus. & Com. Code § 521.0539.3 Contents of Breach Notification
Our breach notification to covered entity clients will include, to the extent known: the nature of the PHI involved; the unauthorised persons who used or received PHI; whether PHI was actually acquired or viewed; and the extent to which the risk of harm has been mitigated. We will provide this information in written form, supplemented by a verbal briefing for significant incidents.
Disclosure & Third-Party Sharing
10.1 PHI — No Subcontracting
MeBilling does not share PHI with any subcontractors, offshore processors, or third-party service providers in connection with delivering our RCM services. All billing, coding, credentialing, and related functions are performed entirely by MeBilling's own employed workforce operating under our direct supervision and compliance programme.
10.2 Technology Vendors
MeBilling uses cloud-based practice management and billing platforms to perform services within our clients' environments. We do not transmit PHI to these platforms independently; rather, we operate within platforms that our clients already use and have contracted for independently. Any vendor MeBilling independently engages that may incidentally access ePHI (such as hosted infrastructure providers) is subject to a signed BAA with MeBilling prior to any such access.
10.3 Required Disclosures
MeBilling may disclose PHI or personal information as required by applicable law, including: valid court orders, subpoenas, or warrants; lawful requests from law enforcement agencies consistent with 45 CFR § 164.512(f); and oversight activities by the HHS Office for Civil Rights or other regulatory authorities with jurisdiction over MeBilling's operations.
10.4 No Sale of Information
MeBilling will never sell, rent, barter, exchange, or otherwise disclose PHI, personal information, or any information derived from PHI for commercial, marketing, or data monetisation purposes. This prohibition is absolute and without exception.
Data Retention & Destruction
MeBilling retains PHI and related billing records for the period specified in the applicable BAA and as required by law. As a general standard:
- Medical Billing RecordsRetained for a minimum of seven (7) years from the date of service or the last date of treatment, consistent with CMS billing record requirements and applicable state laws
- Medicare and Medicaid RecordsRetained for a minimum of ten (10) years as recommended under the OIG Compliance Program Guidance for Third-Party Medical Billing Companies and required by certain state Medicaid programmes
- Credentialing RecordsRetained for the duration of the provider's engagement and for a minimum of five (5) years thereafter
- Website Inquiry DataRetained for a maximum of 24 months, unless the inquiry results in an ongoing business relationship
Upon termination of a services agreement, MeBilling will return or destroy all PHI in its possession in accordance with the BAA terms and within the timeframe specified therein. Destruction of physical and electronic PHI is performed using NIST SP 800-88-compliant methods that render the data unrecoverable.
Individual Rights
12.1 Rights Regarding PHI
Rights relating to PHI (such as rights of access, amendment, accounting of disclosures, and restriction of use) are held by patients and are enforceable against the covered entity (your healthcare provider or practice), not against MeBilling directly. As a Business Associate, MeBilling will cooperate with covered entity clients to facilitate patients' exercise of their HIPAA rights under 45 CFR §§ 164.524, 164.526, 164.528. Please direct all PHI rights requests to your healthcare provider directly.
12.2 Rights Regarding Personal Information (Non-PHI)
If you are a prospective client, current client contact, or website visitor whose personal (non-PHI) information MeBilling holds, you have the right to:
- Request confirmation of whether MeBilling holds personal information about you
- Request a copy of the personal information MeBilling holds about you
- Request correction of inaccurate personal information
- Request deletion of your personal information, subject to our legal retention obligations
- Withdraw consent to our use of your personal information for communications you did not initiate
To exercise any of these rights, contact MeBilling's Privacy Officer at privacy@mebilling.com. We will respond within 30 business days of receiving a verifiable request.
Website Data, Cookies & Analytics
Our website (mebilling.com) uses limited session-based cookies to facilitate navigation and form functionality. We do not use persistent tracking cookies, cross-site tracking technologies, or behavioural advertising platforms. We do not participate in any advertising network that would enable third parties to collect data about visitors to our website.
We may use a privacy-respecting web analytics tool (configured without IP address logging) to understand aggregate traffic patterns. The analytics data collected does not identify individual users and is not shared with any third party for commercial purposes. You may disable cookies in your browser settings without affecting your ability to access our website or contact us.
MeBilling's website does not collect or process PHI. No health information should be submitted through any website contact form. If you need to transmit PHI to MeBilling, please use only the secure channels established in your services agreement and BAA.
Our email communications are conducted in compliance with the CAN-SPAM Act 15 U.S.C. § 7701 et seq. All commercial emails include a clear identification of the sender, a physical postal address, and a functioning opt-out mechanism that we honour within 10 business days.
Children's Privacy
MeBilling's website is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13 through our website. As required by the Children's Online Privacy Protection Act (COPPA) 15 U.S.C. § 6501 et seq., if we discover that we have inadvertently collected personal information from a child under 13, we will delete it promptly.
Please note that MeBilling processes PHI relating to minor patients as part of our billing services on behalf of covered entity clients. This processing is governed by the applicable BAA and HIPAA, not by COPPA, and is performed solely at the direction of the healthcare provider or facility responsible for the minor's care.
Policy Updates
MeBilling reviews this Privacy Policy at least annually and whenever applicable laws change in ways that affect our obligations. Material changes to this Policy will be communicated to active clients at least 30 days before they take effect, through written notice to the client's designated compliance or privacy contact. The "Last Revised" date at the top of this page reflects the most recent update.
Continued engagement with MeBilling's services after the effective date of a material policy change constitutes acknowledgement of the updated Policy. We encourage clients and website visitors to review this Policy periodically.
Contact & Complaints
MeBilling has designated a Privacy Officer responsible for overseeing HIPAA compliance and this Privacy Policy. If you have questions, concerns, or a complaint regarding this Policy or our data practices, please contact us through any of the following channels:
If you believe your privacy rights under HIPAA have been violated, you also have the right to file a complaint directly with the HHS Office for Civil Rights at www.hhs.gov/ocr/privacy/hipaa/complaints or by calling 1-800-368-1019. MeBilling will not retaliate against any person for filing a good-faith complaint with HHS OCR or any other regulatory authority.
