Home/Privacy Policy
Last updated · April 22, 2026

Scope of this policy

This Privacy Policy describes how Evident RCM ("Evident," "we," "our," or "us") collects, uses, discloses, and protects information when you visit our website, contact us, or engage our revenue-cycle services.

It applies to information we handle in our role as a business partner to healthcare providers. It does not govern information handled directly by payers, clearinghouses, or your own practice management system.

Information we collect

We collect two categories of information:

Information you provide directly. When you request a claims review, contact us, or enter into a service agreement, we collect your name, practice name, email, phone number, role, and the details you share about your claim volume and specialty.

Information we receive to perform services. Once engaged, we receive claim-level data from you or your systems to perform negotiation and IDR work. This may include protected health information (PHI) as defined under HIPAA. PHI is handled under a Business Associate Agreement (BAA) and our HIPAA Notice of Privacy Practices.

We also collect limited, standard technical information when you visit our website — IP address, browser type, pages visited, and referring URL — primarily for security and to improve the site.

How we use information

We use the information we collect to:

  • Respond to your inquiry and deliver the services you've requested
  • Prepare, submit, and support negotiation and IDR filings on your behalf
  • Communicate with you about your account, results, and relevant updates
  • Improve our services, security, and website performance
  • Comply with legal, regulatory, and contractual obligations

We do not sell your information, and we do not use PHI for marketing purposes.

How we share information

We share information only as necessary to deliver our services or meet our legal obligations:

  • Service providers. Cloud hosting, document storage, and analytics providers that are bound by confidentiality and, where applicable, Business Associate Agreements.
  • Payers and IDR entities. Information required to negotiate payment or file an IDR case on your behalf.
  • Legal authorities. When required by law, subpoena, or to protect our rights.

We do not share your information for third-party marketing.

Security

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, or disclosure. Access to PHI and sensitive business data is limited to personnel who need it to perform their role.

No system is perfectly secure. If we identify a breach affecting your information, we will notify you consistent with applicable law and contractual requirements.

Your choices and rights

You may request to access, correct, or delete information you have provided to us by emailing hello@evidentrcm.com. Some information must be retained to meet legal or contractual obligations.

Patients whose PHI is processed by Evident should contact the treating provider; we act only at the provider's direction under a BAA.

Cookies and analytics

Our website uses a small number of cookies and analytics tools to understand traffic patterns and improve the experience. You can block or delete cookies in your browser settings; some features may not work without them.

Changes to this policy

We may update this policy to reflect changes in our practices or legal requirements. The "last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated to active clients as required by contract.

Questions about this policy? Email hello@evidentrcm.com.