ClinicBills
Legal

Privacy Policy

Last updated: April 24, 2026

We treat your information — and your patients' Protected Health Information — with the same care we'd want for ourselves. Here's exactly how.

HIPAA + HITECH

Compliant by design, audited annually.

SOC 2 Type II

Encryption, MFA, monitoring, access logs.

BAA on file

Signed before any PHI is exchanged.

1. Overview

ClinicBills ("ClinicBills", "we", "us", or "our") provides revenue cycle management services to healthcare providers. This Privacy Policy explains how we collect, use, disclose, and safeguard information you provide through our website, our services, and any related communications.

We comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and applicable U.S. state privacy laws. When we handle Protected Health Information (PHI) on behalf of a covered entity, we do so as a Business Associate under a signed Business Associate Agreement (BAA).

2. Information We Collect

Practice & contact information you submit via our forms (name, email, phone, practice name, NPI, EHR, monthly claim volume).

Protected Health Information (PHI) processed under a BAA strictly to perform billing, coding, claims, and related services on behalf of our covered-entity clients.

Website usage data such as pages viewed, referrer, device, and approximate location, collected via privacy-respecting analytics. We do not sell this data.

Communications you send us (email, phone notes, support tickets) so we can respond and improve service quality.

3. How We Use Information

To deliver the services you or your practice has engaged us to perform — including claim submission, denial work, posting, and reporting.

To communicate with you about your account, audits, regulatory changes, and service updates.

To improve our services, train staff (using de-identified data only), and maintain operational security.

To comply with legal, regulatory, and contractual obligations, including audit requests and lawful subpoenas.

4. Protected Health Information (PHI)

PHI is handled exclusively under the terms of the BAA in place with the covered entity. We use PHI only for treatment, payment, and healthcare operations as permitted by HIPAA and the BAA.

We do not use or disclose PHI for marketing, sale, or any purpose unrelated to the services we are contracted to perform.

Access to PHI is limited to workforce members with a documented business need, all of whom complete annual HIPAA training and sign confidentiality agreements.

5. Security Safeguards

Administrative, physical, and technical safeguards are in place under our SOC 2 Type II program. These include role-based access control, multi-factor authentication, encryption in transit (TLS 1.2+) and at rest (AES-256), audit logging, intrusion detection, and 24/7 monitoring.

We conduct annual third-party penetration tests and HIPAA risk assessments. Findings are remediated on a documented timeline.

In the event of a breach involving unsecured PHI, we will notify the affected covered entity within the timeframes required by HIPAA and HITECH, and cooperate fully with any required notifications.

6. How We Share Information

With clearinghouses, payers, and other entities only as necessary to perform the services we are engaged to deliver.

With subcontractors who have signed BAAs and equivalent confidentiality obligations.

When required by law, court order, or to respond to lawful regulatory requests (e.g., HHS Office for Civil Rights audits).

We do not sell, rent, or trade personal information or PHI under any circumstances.

7. Data Retention

We retain PHI for the period required by the BAA and applicable law (typically a minimum of 6 years from creation or last effective date, per HIPAA §164.530(j)).

Marketing and lead-form data is retained only as long as necessary to respond to your inquiry and for a reasonable follow-up period, after which it is deleted or anonymized.

8. Your Rights

Patients seeking to exercise rights under HIPAA (access, amendment, accounting of disclosures, restrictions) should contact the covered entity (your provider) directly. We will support the covered entity's response as required.

Residents of California, Colorado, Virginia, Connecticut, Utah, Texas, and other states with applicable privacy laws may have rights to access, correct, or delete personal information we hold about them. Contact us using the details below to exercise these rights.

We will not retaliate against you for exercising any privacy right.

9. Cookies & Tracking

We use a minimal set of strictly necessary cookies to operate the website and optional analytics cookies to understand aggregate usage. We do not use cross-site advertising trackers.

You can control cookies through your browser settings. Disabling strictly necessary cookies may affect site functionality.

10. International Users

ClinicBills operates from the United States. All data is stored and processed in the U.S. If you access our services from outside the U.S., you consent to this transfer and processing.

11. Children's Privacy

Our services are directed at healthcare practices, not children. We do not knowingly collect personal information directly from children under 13. PHI of pediatric patients is handled solely under the BAA with the treating provider.

12. Changes to This Policy

We may update this policy from time to time. Material changes will be posted here with a revised "Last updated" date, and where appropriate, communicated to active clients in writing.

13. Contact Us

Privacy questions, BAA requests, or to exercise privacy rights: info@clinicbills.com

Email: info@clinicbills.com

Mail: 1521 Blake St STE 12838, Denver, CO 80202

Phone: (716) 342-1002

Questions about your data?

Our Privacy Officer responds to every inquiry within two business days.

Get in touch