Privacy Policy

Effective Date: June 20, 2026

At Hillcrest Medical Billing, we are committed to protecting the privacy and security of your personal and medical information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit our website or use our medical billing and revenue cycle management services. It applies to the information we collect from healthcare providers (our clients) and the patients they serve.

We are dedicated to complying with all applicable privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA).

1. Our Role as a Business Associate

Hillcrest Medical Billing acts as a Business Associate to healthcare providers (Covered Entities) . In this role, we receive, process, and transmit Protected Health Information (PHI) strictly for the purpose of providing contracted billing services .

We are not a Covered Entity ourselves, but we are fully bound by HIPAA regulations and the specific terms of our Business Associate Agreements (BAAs) with our clients .

2. Information We Collect

We collect different types of information to provide and improve our medical billing services and to manage our website.

Personal Information You Provide:
We collect personally identifiable information that you voluntarily provide to us, including but not limited to:

  • Healthcare Provider Information: Practice name, National Provider Identifier (NPI), Tax Identification Number (TIN), contact details, and login credentials for our client portal.

  • Patient Information: In the course of billing, we may process patient data necessary for claims, including name, date of birth, address, insurance policy numbers, and treatment codes (e.g., CPT, ICD-10).

  • Billing & Payment Information: Details required for processing payments and ACH transactions .

Protected Health Information (PHI):
As a core function of our services, we access, process, and store PHI to perform billing and revenue cycle management tasks. This information is handled in strict accordance with HIPAA regulations and our BAAs .

Automatically Collected Information:
When you visit our website (e.g., www.hillcrestmedicalbilling.com), we may automatically collect certain non-identifying information, such as:

  • IP address, browser type, and operating system.

  • Pages visited, time spent, and referring URLs.

  • Device identifiers and cookie data .

3. How We Use Your Information

The information we collect is used strictly for authorized purposes :

  • To provide, maintain, and improve medical billing, coding, claims submission, and denial management services .

  • To verify patient eligibility and benefits with insurance payers .

  • To process payments, invoices, and transactions.

  • To communicate with you about your account, support requests, and service updates .

  • To comply with legal and regulatory obligations .

  • To analyze website usage and improve user experience .

We do not sell, rent, or trade your personal information to third parties .

4. HIPAA Compliance

Hillcrest Medical Billing is fully committed to maintaining the confidentiality, integrity, and availability of PHI. Our practices are aligned with the HIPAA Privacy and Security Rules .

Our compliance measures include:

  • Administrative Safeguards: Implementing policies and procedures, training all employees on HIPAA compliance , and designating a Privacy Officer.

  • Physical Safeguards: Securing all facilities and workstations to prevent unauthorized physical access .

  • Technical Safeguards: Using 256-bit SSL/TLS encryption for data transmission, encrypted storage for data at rest, multi-factor authentication, and role-based access controls to ensure only authorized personnel can access PHI .

We sign a Business Associate Agreement (BAA) with all our clients, ensuring we are contractually bound to protect their patients’ PHI .

5. Information Sharing and Disclosure

We do not sell your information. We may share your information only in specific, necessary circumstances:

  • Service Providers: With trusted third-party vendors who assist us in operating our business (e.g., payment processors, cloud hosting, email services). These partners are bound by strict confidentiality and data security agreements .

  • Insurance Payers: As necessary to process claims, appeals, and credentialing on behalf of our clients .

  • Legal Requirements: When required by law, subpoena, court order, or governmental regulation .

  • Business Transfers: In connection with a merger, acquisition, or sale of assets .

  • Consent: When you have given us explicit permission to share your information .

6. Data Security

We employ industry-standard security measures to protect your information from unauthorized access, use, or disclosure:

  • Secure Socket Layer (SSL) with 128-bit or 256-bit encryption .

  • Encrypted storage for sensitive data at rest .

  • Secure firewalls and role-based access controls limiting data access to authorized personnel .

  • Regular security risk assessments and staff training .

  • Automated backup and disaster recovery systems .

While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the internet is 100% secure . However, we are fully prepared to handle and report any suspected breach in accordance with state and federal requirements .

7. Cookies and Tracking Technologies

Our website may use cookies and similar tracking technologies to enhance your browsing experience. You can control cookie preferences through your browser settings .

8. Your Rights

You may have the following rights regarding your data, depending on your location or jurisdiction:

  • Right to Access: Request a copy of the personal information we hold about you .

  • Right to Correction: Request correction of inaccurate information .

  • Right to Deletion: Request deletion of your personal information (subject to legal and regulatory retention requirements) .

  • Right to Opt-Out: Opt out of marketing communications at any time .

  • Right to Restrict: Request a restriction on how your information is used or disclosed .

To exercise any of these rights, please contact our Privacy Officer using the details in the “Contact Us” section below.

9. Data Retention

We retain personal information and PHI for as long as necessary to fulfill the purposes outlined in this policy, as required by our clients, or as mandated by law. Medical billing records are typically retained for a minimum of seven (7) years to comply with federal and state regulations . After this period, data is securely deleted or anonymized .

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. When we do, we will post the new policy on this page and update the “Effective Date” at the top. We encourage you to review this policy periodically .

11. Contact Us

If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices, or if you believe your privacy rights have been violated, please contact our Privacy Officer:

Hillcrest Medical Billing
Attention: Privacy Officer