Home/HIPAA Notice
Last updated · April 22, 2026

Our role as a Business Associate

Evident RCM operates as a "Business Associate" as defined by the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the HITECH Act, when providing revenue-cycle services to healthcare providers ("Covered Entities").

In that role, we handle Protected Health Information (PHI) only as permitted under a signed Business Associate Agreement (BAA) with the provider.

What PHI we handle

To perform negotiation and Independent Dispute Resolution work, we receive claim-level information that may include:

  • Patient names, dates of birth, and demographic identifiers
  • Procedure and diagnosis codes
  • Dates and locations of service
  • Charge and payment information
  • Insurance information and Explanation of Benefits data

We do not receive direct clinical records unless specifically required to support a case and authorized by the provider.

Permitted uses of PHI

We use PHI only to perform the specific services described in our BAA and Services Agreement with the provider, including:

  • Reviewing claims for recovery opportunity
  • Preparing negotiation correspondence with payers
  • Preparing and filing IDR cases
  • Producing reports and analytics for the provider

We do not use or disclose PHI for marketing, and we do not sell PHI under any circumstances.

Safeguards

We maintain administrative, physical, and technical safeguards that comply with the HIPAA Security Rule, including:

  • Role-based access controls and least-privilege policies
  • Encryption of PHI in transit and at rest
  • Workforce HIPAA training and confidentiality agreements
  • Audit logging and regular security review
  • Incident response procedures and breach notification protocols

Subcontractors

When we engage subcontractors who will receive or access PHI, we require them to sign agreements that impose the same restrictions and safeguards required of us as a Business Associate. We maintain a current list of such subcontractors and provide it to our clients on request.

Breach notification

If we discover a breach of unsecured PHI, we will notify the affected Covered Entity without unreasonable delay and in any case within the timeframe required by our BAA and applicable law. Our notice will include the information required under HIPAA so the Covered Entity can fulfill its own notification obligations.

Individual rights

Individual rights regarding PHI — including access, amendment, accounting of disclosures, and restrictions — are administered by the Covered Entity (the provider who treated the patient). If you are a patient seeking to exercise these rights, please contact the provider directly.

Evident will support the Covered Entity in meeting these obligations as required under our BAA.

HIPAA contact

Questions about our HIPAA practices can be directed to our Privacy Officer at hello@evidentrcm.com. For complaints, you may also contact the U.S. Department of Health and Human Services Office for Civil Rights.

Questions about this policy? Email hello@evidentrcm.com.