Introduction
MDPoint is committed to protecting the privacy, confidentiality, integrity, and security of personal, financial, and healthcare-related information entrusted to us. This Privacy Policy explains how information is collected, used, disclosed, stored, retained, and protected in connection with:
- Medical billing
- Revenue cycle management
- Credentialing
- Enrollment
- Insurance verification
- Denial management
- Accounts receivable follow-up
- Analytics
- Compliance services
- Website operations
Information We Collect
We may collect the following categories of information:
- Provider information
- Business information
- Patient demographic data
- Insurance information
- Billing records
- Claim details
- Payment records
- Eligibility information
- Medical documentation necessary to support reimbursement activities
- Communications
- Website usage information
- IP addresses
- Browser information
- Cookies
- Other operational data
Information may be received from healthcare providers, patients, health plans, clearinghouses, vendors, public sources, and authorized third parties.
How Information Is Used
Collected information is used to:
- Perform billing and coding services
- Verify insurance eligibility
- Submit electronic claims
- Track claim status
- Appeal denied claims
- Post payments
- Reconcile accounts
- Support credentialing and payer enrollment
- Generate operational reports
- Comply with legal obligations
- Detect fraud
- Maintain service quality
- Improve business operations
- Provide customer support
- Administer contractual relationships
Disclosure of Information
Information may be disclosed to the following parties as necessary to provide contracted services or comply with legal obligations:
- Healthcare providers
- Insurance carriers
- Government healthcare programs
- Clearinghouses
- Revenue cycle management partners
- Technology vendors
- Legal advisors
- Auditors
- Regulators
- Other authorized entities
All disclosures are limited to the information reasonably necessary for the specific business purpose or legal requirement.
HIPAA Compliance
MDPoint maintains policies and procedures designed to support compliance with applicable healthcare privacy and security requirements, including HIPAA obligations where applicable. Workforce members receive privacy and security awareness training, and access to information is restricted based on job responsibilities and business need.
Security Safeguards
We employ administrative, technical, and physical safeguards intended to protect information against unauthorized access, alteration, disclosure, misuse, loss, or destruction. Security measures may include:
- Role-based access controls
- Authentication requirements
- Secure transmission protocols
- Logging and monitoring systems
- Risk assessments
- Vendor oversight
- Incident response procedures
- Secure data disposal practices
Data Retention
Information is retained for as long as necessary to fulfill contractual obligations, support healthcare operations, comply with legal and regulatory requirements, resolve disputes, enforce agreements, maintain business records, and support auditing activities.
Records no longer required are securely deleted, destroyed, or anonymized in accordance with applicable retention policies.
Individual Rights
Where permitted by applicable law, individuals may:
- Request access to certain personal information
- Request corrections of inaccurate information
- Inquire about privacy practices
- Request communication preferences
- Submit privacy-related concerns
Requests may be subject to identity verification and legal limitations.
Third-Party Services
Our services may interact with software vendors, electronic health record platforms, clearinghouses, claims processing systems, cloud providers, and other business partners. Such relationships are governed by contractual safeguards designed to protect information and support confidentiality obligations.
Children's Privacy
MDPoint does not knowingly collect information directly from children through its website except where information is provided by authorized healthcare providers, parents, guardians, or responsible parties in connection with healthcare administration and billing services.
Policy Changes and Contact Information
This Privacy Policy may be updated periodically to reflect operational, legal, regulatory, or technological changes. Updated versions will be posted with a revised effective date.
Questions about this Privacy Policy or privacy practices may be directed to the designated Privacy Officer through MDPoint official communication channels.
Questions about this policy?
Reach our Privacy Officer through official MDPoint channels.