Legal · Privacy

Privacy Policy

MeBilling Inc. — 100 Glenborough Dr, Houston, TX 77067 — info@mebilling.com

Effective: January 1, 2025 | Last Revised: May 1, 2026

This Privacy Policy describes how MeBilling Inc. ("MeBilling," "we," "us," or "our") collects, uses, protects, and discloses information in connection with our Revenue Cycle Management services, website, and client portals. As a Business Associate under HIPAA, we hold ourselves to the highest standards of data privacy and are bound by federal and Texas state law. Please read this Policy carefully.

Section 01

Who We Are

MeBilling Inc. is a healthcare Revenue Cycle Management company incorporated under the laws of the State of Texas, with its principal office at 100 Glenborough Dr, Houston, TX 77067. We provide medical billing, coding, credentialing, denial management, payment posting, audit services, and related administrative services to healthcare providers, physician groups, hospitals, ambulatory surgical centers, laboratories, and other covered entities throughout the United States.

In the course of providing these services, MeBilling functions as a Business Associate as defined under 45 CFR § 160.103 of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act. This means we access, use, and disclose Protected Health Information (PHI) solely on behalf of, and as permitted by, our covered entity clients.

Section 02

Definitions

  • PHI
    Protected Health Information: any individually identifiable health information created, received, maintained, or transmitted by MeBilling on behalf of a covered entity client, in any form or medium, as defined under 45 CFR § 160.103.
  • ePHI
    Electronic Protected Health Information: PHI that is created, received, maintained, or transmitted in electronic form, subject to the HIPAA Security Rule 45 CFR Part 164, Subparts A & C.
  • Covered Entity
    A healthcare provider, health plan, or healthcare clearinghouse that transmits health information electronically, as defined under 45 CFR § 160.103. Our clients are covered entities.
  • Business Associate
    A person or entity that performs functions or activities on behalf of a covered entity that involve the use or disclosure of PHI. MeBilling is a Business Associate.
  • BAA
    Business Associate Agreement: the written contract between MeBilling and each covered entity client that governs our use and disclosure of PHI, as required by 45 CFR § 164.308(b).
  • Personal Information
    Non-PHI data about individuals we may collect through our website or business operations, such as contact information of prospective clients or website visitors.
  • TMRPA
    Texas Medical Records Privacy Act, codified at Texas Health & Safety Code Chapter 181 (H.B. 300), which imposes stricter privacy requirements than HIPAA in certain respects.
Section 03

Information We Collect

3.1 Protected Health Information (PHI) — As Business Associate

In performing Revenue Cycle Management services for our covered entity clients, we receive, access, and process PHI on their behalf. This information is provided directly by our clients or transmitted from their electronic health record (EHR) and practice management systems. Types of PHI we handle include:

  • Patient demographics: full name, date of birth, address, telephone number, Social Security Number (last four digits for billing purposes), and insurance identification numbers
  • Clinical data necessary for billing: diagnosis codes (ICD-10), procedure codes (CPT/HCPCS), dates of service, place of service, rendering provider identifiers (NPI), and clinical notes required for coding accuracy
  • Insurance and financial information: payer names, member IDs, group numbers, Explanation of Benefits (EOB), remittance advice, and payment records
  • Prior authorisation numbers, referral documentation, and eligibility verification results

All PHI is collected and processed solely to perform contracted services on behalf of the client covered entity and only to the minimum extent necessary for that purpose, as required by 45 CFR § 164.502(b) (the Minimum Necessary Standard).

3.2 Provider & Practice Information — From Clients

We collect practice and provider information from our clients, including: practice legal name, Tax Identification Number (TIN), National Provider Identifier (NPI), licensure information, payer contract details, DEA numbers (where applicable), credentialing documentation, and banking or EFT information for payment posting purposes.

3.3 Personal Information — Website Visitors & Prospective Clients

When individuals visit our website or submit an inquiry through our contact form, we may collect: full name, email address, phone number, organisation name, and the content of any message submitted. This information is used solely to respond to inquiries and is not combined with PHI.

3.4 Technical Information — Automatic Collection

Our website automatically collects limited technical data including: IP address, browser type, pages visited, time and date of visits, and referring URLs. We use this information to maintain website security, improve user experience, and compile aggregate statistics. We do not use this data to identify individual users for marketing purposes.

Section 04

How We Use Information

4.1 PHI — Permitted Uses Only

MeBilling uses and discloses PHI exclusively as permitted or required by the applicable BAA and by HIPAA. Our permitted uses include:

Healthcare Operations and Treatment Payment

45 CFR § 164.506

Submitting and managing insurance claims, processing payments, managing denials and appeals, performing coding and documentation reviews, and all other activities directly related to healthcare payment on behalf of a covered entity client.

Performance of BAA-Permitted Functions

BAA

Any use specifically authorised in the written BAA between MeBilling and the client, including quality assurance, compliance auditing, and training activities that require access to PHI.

Required by Law

45 CFR § 164.512

Disclosures to comply with valid legal process, court orders, regulatory investigations by the HHS Office for Civil Rights (OCR), or other lawful government authority.

Management and Administration of MeBilling

45 CFR § 164.504(e)(4)

Internal use by MeBilling's workforce to manage our own legal and business obligations, only to the extent permitted.

4.2 What We Will Never Do With PHI

MeBilling will never sell, rent, lease, or trade PHI or any personal information. We will never use PHI for marketing purposes without explicit written authorisation. We will never use PHI for any purpose not expressly permitted by the applicable BAA and HIPAA, including any use that would constitute a violation of the Anti-Kickback Statute 42 U.S.C. § 1320a-7b or the False Claims Act 31 U.S.C. §§ 3729-3733.

4.3 Personal Information — Website and Business Use

Non-PHI personal information collected through our website or business development activities is used solely to: respond to inquiries and requests for information; communicate about our services; and, where applicable, comply with our legal obligations. We do not sell, share, or monetise this information in any way.

Section 05

HIPAA & HITECH Compliance

5.1 Governing Framework

MeBilling's data handling practices are governed by the full HIPAA Administrative Simplification framework, as amended and strengthened by the HITECH Act of 2009:

  • HIPAA Privacy Rule45 CFR Part 164, Subpart Egoverns the permissible uses and disclosures of PHI and requires us to implement privacy policies and procedures
  • HIPAA Security Rule45 CFR Part 164, Subparts A & Crequires administrative, physical, and technical safeguards to protect ePHI
  • HIPAA Breach Notification Rule45 CFR Part 164, Subpart Drequires notification to covered entity clients of any breach of unsecured PHI within 60 days of discovery
  • HITECH ActPub. L. 111-5, § 13001 et seq.directly extended HIPAA obligations to Business Associates, strengthened enforcement, and increased civil and criminal penalties
  • HITECH § 13405(d)requires compliance with patient requests to restrict disclosures for self-pay services, as enforced through our covered entity clients

5.2 Direct HIPAA Liability

Under the HITECH Act, Business Associates like MeBilling are directly liable for compliance with the HIPAA Security Rule and the applicable provisions of the Privacy Rule. We are subject to civil monetary penalties enforced by the HHS Office for Civil Rights (OCR) and, in cases of knowing violations, criminal penalties under 42 U.S.C. § 1320d-6. We take this liability seriously and maintain a full internal compliance programme accordingly.

5.3 Minimum Necessary Standard

Consistent with 45 CFR § 164.502(b), MeBilling limits all PHI access to the minimum information necessary to perform each specific service. Access controls are implemented at the role and function level, so that individuals within MeBilling only access PHI relevant to their assigned tasks. We do not grant broad access to PHI as a default.

Section 06

Texas Privacy Laws

6.1 Texas Medical Records Privacy Act (TMRPA)

As a company headquartered in Texas, MeBilling is subject to the Texas Medical Records Privacy Act Texas Health & Safety Code, Chapter 181, enacted as H.B. 300 (2011). The TMRPA applies to a broader category of "covered entities" than HIPAA and imposes additional requirements, including:

  • Mandatory annual HIPAA and TMRPA privacy training for all employees who access protected health information — MeBilling conducts this training without exception
  • Written authorisation requirements for disclosure of PHI for marketing purposes — MeBilling does not engage in such disclosures
  • The right of patients to request electronic copies of their health information, enforceable against Business Associates operating in Texas

Where Texas law is more stringent than HIPAA, MeBilling complies with the stricter Texas standard.

6.2 Texas Data Breach Notification

In the event of a breach of personal information, MeBilling complies with the Texas Identity Theft Enforcement and Protection Act Texas Business & Commerce Code § 521.053, which requires notification to affected Texas residents as promptly as practicable and no later than 60 days after the date of discovery of a breach. Notification will also be provided to our covered entity clients as required by the HIPAA Breach Notification Rule, and to the Texas Attorney General's office when required by law.

6.3 Texas Health & Safety Code Chapter 182

MeBilling also complies with Texas Health & Safety Code Chapter 182, which governs the confidentiality of medical records maintained in Texas, including requirements relating to the disclosure of confidential information and penalties for unlawful disclosure.

6.4 FTC Act Compliance

MeBilling's data security practices are designed to comply with Section 5 of the Federal Trade Commission Act (15 U.S.C. § 45), which prohibits unfair or deceptive acts or practices in or affecting commerce, including inadequate data security that causes or is likely to cause substantial consumer harm.

Section 07

Business Associate Agreement (BAA)

MeBilling executes a written Business Associate Agreement (BAA) with every covered entity client before performing any services that involve access to PHI. The BAA is a legally required contract under 45 CFR § 164.308(b)(3) and 45 CFR § 164.504(e) that specifies:

  • The permitted and required uses and disclosures of PHI by MeBilling
  • MeBilling's obligation not to use or disclose PHI in a manner inconsistent with the BAA or HIPAA
  • Safeguards MeBilling must maintain to prevent unauthorised use or disclosure of PHI
  • MeBilling's obligation to report any use or disclosure not permitted by the BAA, including breaches
  • MeBilling's obligation to comply with the HIPAA Security Rule for ePHI
  • Subcontractor BAA requirements — MeBilling does not share PHI with subcontractors; all services are performed in-house
  • Requirements for the return or destruction of PHI upon termination of the services agreement

MeBilling performs all services in-house. We do not share PHI with subcontractors, offshore processors, or third-party vendors who are not subject to our own internal controls. If you are a covered entity and do not have an executed BAA with MeBilling, please contact us immediately at privacy@mebilling.com before transmitting any PHI.

Section 08

Data Security Safeguards

MeBilling maintains a comprehensive information security programme designed to satisfy the requirements of the HIPAA Security Rule 45 CFR Part 164, Subparts A & C. Our safeguards operate across three required domains:

8.1 Administrative Safeguards 45 CFR § 164.308

  • Designated Privacy Officer and Security Officer with defined accountability for HIPAA compliance
  • Comprehensive workforce training: annual mandatory HIPAA, TMRPA, and information security training for all staff who access PHI, with completion tracking and disciplinary policies for non-compliance
  • Access management: role-based access controls ensuring each workforce member accesses only the PHI necessary for their assigned function
  • Risk analysis and risk management: annual formal risk assessment identifying threats and vulnerabilities to ePHI, with documented mitigation plans § 164.308(a)(1)
  • Contingency planning: documented backup and disaster recovery procedures including a business continuity plan for critical billing functions § 164.308(a)(7)
  • Evaluation: periodic technical and non-technical evaluation of security practices to ensure ongoing compliance § 164.308(a)(8)

8.2 Physical Safeguards 45 CFR § 164.310

  • Facility access controls: secured office environments with restricted access to workstations and servers that process ePHI
  • Workstation security: policies governing the proper use and placement of workstations that access ePHI, including screen lock requirements and clean desk policies
  • Device and media controls: documented procedures for the disposal of hardware containing ePHI, including NIST-compliant data destruction

8.3 Technical Safeguards 45 CFR § 164.312

  • Encryption: all ePHI transmitted electronically is encrypted using TLS 1.2 or higher; all stored ePHI is encrypted at rest using AES-256 or equivalent
  • Access controls: unique user identification for all workforce members accessing ePHI, with automatic logoff after periods of inactivity § 164.312(a)(2)
  • Multi-factor authentication (MFA) required for all remote access and privileged account access to systems containing ePHI
  • Audit controls: automated audit logs recording all access to ePHI systems, with regular review for anomalous activity § 164.312(b)
  • Integrity controls: mechanisms to authenticate ePHI and detect unauthorised alteration or destruction § 164.312(c)
  • Transmission security: end-to-end encryption for all electronic transmission of ePHI, including email, EDI, and API-based data exchanges § 164.312(e)
Section 09

Breach Notification

MeBilling maintains documented breach response procedures consistent with the HIPAA Breach Notification Rule 45 CFR Part 164, Subpart D and applicable Texas law.

9.1 What Constitutes a Breach

A "breach" is the acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI, as defined under 45 CFR § 164.402. The presumption is that any impermissible use or disclosure of PHI is a breach unless MeBilling can demonstrate, through a four-factor risk assessment, that there is a low probability the PHI has been compromised.

9.2 Notification Timelines

To the Covered Entity Client

MeBilling will notify the affected covered entity without unreasonable delay and in no case later than 60 calendar days after discovery of a breach.

45 CFR § 164.410

To HHS

Notification to HHS is made by the covered entity client. MeBilling will provide all required information to facilitate timely notification.

45 CFR § 164.408

To Texas Residents

If a breach affects Texas residents' personal information, MeBilling will comply with notification requirements within 60 days.

TX Bus. & Com. Code § 521.053

9.3 Contents of Breach Notification

Our breach notification to covered entity clients will include, to the extent known: the nature of the PHI involved; the unauthorised persons who used or received PHI; whether PHI was actually acquired or viewed; and the extent to which the risk of harm has been mitigated. We will provide this information in written form, supplemented by a verbal briefing for significant incidents.

Section 10

Disclosure & Third-Party Sharing

10.1 PHI — No Subcontracting

MeBilling does not share PHI with any subcontractors, offshore processors, or third-party service providers in connection with delivering our RCM services. All billing, coding, credentialing, and related functions are performed entirely by MeBilling's own employed workforce operating under our direct supervision and compliance programme.

10.2 Technology Vendors

MeBilling uses cloud-based practice management and billing platforms to perform services within our clients' environments. We do not transmit PHI to these platforms independently; rather, we operate within platforms that our clients already use and have contracted for independently. Any vendor MeBilling independently engages that may incidentally access ePHI (such as hosted infrastructure providers) is subject to a signed BAA with MeBilling prior to any such access.

10.3 Required Disclosures

MeBilling may disclose PHI or personal information as required by applicable law, including: valid court orders, subpoenas, or warrants; lawful requests from law enforcement agencies consistent with 45 CFR § 164.512(f); and oversight activities by the HHS Office for Civil Rights or other regulatory authorities with jurisdiction over MeBilling's operations.

10.4 No Sale of Information

MeBilling will never sell, rent, barter, exchange, or otherwise disclose PHI, personal information, or any information derived from PHI for commercial, marketing, or data monetisation purposes. This prohibition is absolute and without exception.

Section 11

Data Retention & Destruction

MeBilling retains PHI and related billing records for the period specified in the applicable BAA and as required by law. As a general standard:

  • Medical Billing RecordsRetained for a minimum of seven (7) years from the date of service or the last date of treatment, consistent with CMS billing record requirements and applicable state laws
  • Medicare and Medicaid RecordsRetained for a minimum of ten (10) years as recommended under the OIG Compliance Program Guidance for Third-Party Medical Billing Companies and required by certain state Medicaid programmes
  • Credentialing RecordsRetained for the duration of the provider's engagement and for a minimum of five (5) years thereafter
  • Website Inquiry DataRetained for a maximum of 24 months, unless the inquiry results in an ongoing business relationship

Upon termination of a services agreement, MeBilling will return or destroy all PHI in its possession in accordance with the BAA terms and within the timeframe specified therein. Destruction of physical and electronic PHI is performed using NIST SP 800-88-compliant methods that render the data unrecoverable.

Section 12

Individual Rights

12.1 Rights Regarding PHI

Rights relating to PHI (such as rights of access, amendment, accounting of disclosures, and restriction of use) are held by patients and are enforceable against the covered entity (your healthcare provider or practice), not against MeBilling directly. As a Business Associate, MeBilling will cooperate with covered entity clients to facilitate patients' exercise of their HIPAA rights under 45 CFR §§ 164.524, 164.526, 164.528. Please direct all PHI rights requests to your healthcare provider directly.

12.2 Rights Regarding Personal Information (Non-PHI)

If you are a prospective client, current client contact, or website visitor whose personal (non-PHI) information MeBilling holds, you have the right to:

  • Request confirmation of whether MeBilling holds personal information about you
  • Request a copy of the personal information MeBilling holds about you
  • Request correction of inaccurate personal information
  • Request deletion of your personal information, subject to our legal retention obligations
  • Withdraw consent to our use of your personal information for communications you did not initiate

To exercise any of these rights, contact MeBilling's Privacy Officer at privacy@mebilling.com. We will respond within 30 business days of receiving a verifiable request.

Section 13

Website Data, Cookies & Analytics

Our website (mebilling.com) uses limited session-based cookies to facilitate navigation and form functionality. We do not use persistent tracking cookies, cross-site tracking technologies, or behavioural advertising platforms. We do not participate in any advertising network that would enable third parties to collect data about visitors to our website.

We may use a privacy-respecting web analytics tool (configured without IP address logging) to understand aggregate traffic patterns. The analytics data collected does not identify individual users and is not shared with any third party for commercial purposes. You may disable cookies in your browser settings without affecting your ability to access our website or contact us.

MeBilling's website does not collect or process PHI. No health information should be submitted through any website contact form. If you need to transmit PHI to MeBilling, please use only the secure channels established in your services agreement and BAA.

Our email communications are conducted in compliance with the CAN-SPAM Act 15 U.S.C. § 7701 et seq. All commercial emails include a clear identification of the sender, a physical postal address, and a functioning opt-out mechanism that we honour within 10 business days.

Section 14

Children's Privacy

MeBilling's website is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13 through our website. As required by the Children's Online Privacy Protection Act (COPPA) 15 U.S.C. § 6501 et seq., if we discover that we have inadvertently collected personal information from a child under 13, we will delete it promptly.

Please note that MeBilling processes PHI relating to minor patients as part of our billing services on behalf of covered entity clients. This processing is governed by the applicable BAA and HIPAA, not by COPPA, and is performed solely at the direction of the healthcare provider or facility responsible for the minor's care.

Section 15

Policy Updates

MeBilling reviews this Privacy Policy at least annually and whenever applicable laws change in ways that affect our obligations. Material changes to this Policy will be communicated to active clients at least 30 days before they take effect, through written notice to the client's designated compliance or privacy contact. The "Last Revised" date at the top of this page reflects the most recent update.

Continued engagement with MeBilling's services after the effective date of a material policy change constitutes acknowledgement of the updated Policy. We encourage clients and website visitors to review this Policy periodically.

Section 16

Contact & Complaints

MeBilling has designated a Privacy Officer responsible for overseeing HIPAA compliance and this Privacy Policy. If you have questions, concerns, or a complaint regarding this Policy or our data practices, please contact us through any of the following channels:

Privacy Officerprivacy@mebilling.com
Legal & Compliancelegal@mebilling.com
Phone+1 (346) 616-0008
Mailing AddressMeBilling Inc., 100 Glenborough Dr, Houston, TX 77067

If you believe your privacy rights under HIPAA have been violated, you also have the right to file a complaint directly with the HHS Office for Civil Rights at www.hhs.gov/ocr/privacy/hipaa/complaints or by calling 1-800-368-1019. MeBilling will not retaliate against any person for filing a good-faith complaint with HHS OCR or any other regulatory authority.