MBW RCM (“MBW,” “we,” “us,” or “our”) provides revenue cycle management, medical billing, coding, and related administrative services to healthcare providers, medical groups, and health systems (our “Clients”). In the course of providing these services, MBW may create, receive, maintain, or transmit Protected Health Information (“PHI”) on behalf of our Clients. This Notice explains how MBW handles PHI under the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations (collectively, “HIPAA”).
Our Role Under HIPAA
MBW acts as a Business Associate, not a Covered Entity, under HIPAA. We do not provide direct medical care, and we do not maintain a treatment relationship with patients. Our obligations regarding PHI are governed primarily by the Business Associate Agreements (“BAAs”) we enter into with each Client, which incorporate and supplement the requirements described in this Notice.
If you are a patient of one of our Clients and have questions about how your specific health information is used or disclosed, please contact your healthcare provider directly. Your provider’s Notice of Privacy Practices governs their use and disclosure of your PHI, and MBW acts on their behalf and under their instructions.
How We Use and Disclose PHI
MBW uses and discloses PHI only as permitted or required by our BAAs and by law, including to:
• Perform billing, coding, claims submission, payment posting, denial management, accounts receivable follow-up, and related revenue cycle functions on behalf of our Clients.
• Carry out prior authorization, eligibility verification, and patient access support services on behalf of our Clients.
• Meet our management, administrative, legal, and data safeguarding obligations, consistent with each BAA.
• Comply with applicable law, respond to a subpoena, court order, or other valid legal process, or as otherwise required by regulatory authorities.
We do not use or disclose PHI for marketing purposes, and we do not sell PHI. We limit our use and disclosure of PHI to the minimum necessary to accomplish the intended purpose, consistent with the HIPAA Minimum Necessary Standard.
Safeguards We Maintain
MBW maintains administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI, consistent with the HIPAA Security Rule. These include, among others: role-based access controls, encryption of data at rest and in transit, audit logging, workforce training on privacy and security obligations, and regular risk assessments. MBW maintains SOC 2 Type II and ISO 27001 certifications covering our information security practices.
Subcontractors
Where MBW engages subcontractors that create, receive, maintain, or transmit PHI on our behalf, we require those subcontractors to agree in writing to protections at least as stringent as those that apply to MBW under our BAAs with Clients.
Breach Notification
In the event MBW discovers a breach of unsecured PHI, we will notify the affected Client(s) without unreasonable delay, consistent with the timeframes and requirements set out in the applicable BAA and the HIPAA Breach Notification Rule, so that our Clients can meet their own notification obligations to affected individuals and, where applicable, regulators.
Individual Rights
Because MBW acts as a Business Associate and not the Covered Entity, individual requests to access, amend, or restrict PHI, or to receive an accounting of disclosures, should be directed to the healthcare provider or health plan that treated you or holds your records. MBW will support our Clients in fulfilling such requests as required under our BAAs.
Complaints
If you believe your privacy rights have been violated, you may file a complaint with your healthcare provider or with the U.S. Department of Health and Human Services, Office for Civil Rights. MBW will not retaliate against anyone for filing a complaint.
Changes to This Notice
MBW may update this Notice from time to time to reflect changes in our practices or in applicable law. The most current version will always be posted on this page.
Contact Information
Questions about this Notice or MBW’s HIPAA compliance program may be directed to our Privacy & Compliance Officer at info@mbwrcm.com or +1 (214) 252 7994.