HIPAA Compliance Statement
At MedBill Florida, protecting the privacy and security of patient health information is one of our highest priorities. We comply fully with the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and all related federal regulations concerning the use, disclosure, and safeguarding of Protected Health Information (PHI).
As a medical billing and healthcare support service provider, we act as a Business Associate to Covered Entities and are committed to upholding the confidentiality, integrity, and availability of all patient data shared with us.
Our HIPAA Compliance Commitment
MedBill Florida complies with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. Our internal processes, employee training, data handling systems, and security infrastructure are designed to meet or exceed HIPAA standards.
- Administrative Safeguards: Written policies and ongoing training ensure controlled access and accountability for handling PHI.
- Technical Safeguards: We implement secure logins, role-based access, end-to-end encryption, and activity logging.
- Physical Safeguards: We enforce facility access controls, secure data storage, and proper disposal protocols for sensitive materials.
Business Associate Agreements (BAAs)
MedBill Florida enters into Business Associate Agreements with all Covered Entities and vendors that support our operations. These agreements ensure that all parties are legally bound to protect PHI in accordance with HIPAA rules.
Employee Training and Awareness
All MedBill Florida employees receive HIPAA training during onboarding and through regular refresher sessions. Our staff are trained to recognize, report, and prevent privacy and security violations.
Data Handling and Security Measures
We implement robust technical and administrative safeguards to secure all electronic PHI (ePHI), including:
- Multi-factor authentication and secure access control
- Encryption for data at rest and in transit
- Regular vulnerability testing and audits
- Secure server environments and monitored infrastructure
Breach Notification Procedure
In the event of a data breach involving unsecured PHI, MedBill Florida will notify affected clients, individuals, and authorities as required under HIPAA’s Breach Notification Rule. We will also conduct a root cause analysis and take corrective measures.
Your Rights and Access
Patients have the right to:
- Access their health records
- Request corrections to inaccurate data
- Know how their data is being used
- Request restrictions or alternate communication methods
- File complaints regarding their privacy rights
Note: MedBill Florida does not release PHI directly to patients unless authorized by the Covered Entity.
Contact Information
If you have questions regarding our HIPAA compliance practices, please contact:
HIPAA Compliance Officer MedBill Florida Email: compliance@medicalbillingservicesfl.us
Updates to This Statement
We reserve the right to update this HIPAA Compliance Statement as necessary to reflect changes in regulations, operations, or best practices. All updates will be posted to this page with an updated effective date.