HIPAA Notice
Last updated: [DATE]
Medyfi's role under HIPAA
Medyfi, LLC provides revenue cycle management services to healthcare providers. In doing so, Medyfi acts as a business associate as defined by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations. Medyfi is not a healthcare provider and does not treat patients.
Business associate agreements
Medyfi enters into a business associate agreement (BAA) with every client before receiving any protected health information (PHI). Each BAA defines the permitted uses and disclosures of PHI, the safeguards Medyfi maintains, and the obligations of both parties in the event of a security incident.
How we safeguard PHI
- Written HIPAA privacy and security policies, reviewed regularly
- Role-based access limited to the minimum necessary for each job function
- Workforce HIPAA training at hire and annually thereafter, with records kept
- Monthly screening of our workforce against the OIG and SAM exclusion lists
- Encrypted transmission and storage of PHI; no PHI in unsecured email
- A written incident response and breach notification plan consistent with the HIPAA Breach Notification Rule
Patients
If you are a patient with questions about your medical bill or your health information, please contact your healthcare provider directly. Your provider's Notice of Privacy Practices governs how your health information is used and disclosed. Medyfi processes billing information only on behalf of, and at the direction of, your provider.
Questions
Questions about this notice or Medyfi's HIPAA compliance program can be directed to hello@medyfi.com or by mail to Medyfi, LLC, 445 Park Avenue, New York, NY 10022.