How Evident RCM handles Protected Health Information under HIPAA in our role as a Business Associate to healthcare providers.
Evident RCM operates as a "Business Associate" as defined by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the HITECH Act, when providing revenue-cycle services to healthcare providers ("Covered Entities").
In that role, we handle Protected Health Information (PHI) only as permitted under a signed Business Associate Agreement (BAA) with the provider.
To perform negotiation and Independent Dispute Resolution work, we receive claim-level information that may include:
We do not receive direct clinical records unless specifically required to support a case and authorized by the provider.
We use PHI only to perform the specific services described in our BAA and Services Agreement with the provider, including:
We do not use or disclose PHI for marketing, and we do not sell PHI under any circumstances.
We maintain administrative, physical, and technical safeguards that comply with the HIPAA Security Rule, including:
When we engage subcontractors who will receive or access PHI, we require them to sign agreements that impose the same restrictions and safeguards required of us as a Business Associate. We maintain a current list of such subcontractors and provide it to our clients on request.
If we discover a breach of unsecured PHI, we will notify the affected Covered Entity without unreasonable delay and in any case within the timeframe required by our BAA and applicable law. Our notice will include the information required under HIPAA so the Covered Entity can fulfill its own notification obligations.
Individual rights regarding PHI — including access, amendment, accounting of disclosures, and restrictions — are administered by the Covered Entity (the provider who treated the patient). If you are a patient seeking to exercise these rights, please contact the provider directly.
Evident will support the Covered Entity in meeting these obligations as required under our BAA.
Questions about our HIPAA practices can be directed to our Privacy Officer at hello@evidentrcm.com. For complaints, you may also contact the U.S. Department of Health and Human Services Office for Civil Rights.