Legal
Privacy Policy
Last updated: December 22, 2024
Introduction
VitalBridge ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal and health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our revenue cycle management and behavioral health billing services.
By using our services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
Information We Collect
We collect several types of information to provide and improve our services:
Personal Information
- Name, email address, phone number, and business address
- Company name and job title
- Billing and payment information
- Professional credentials and NPI numbers
Protected Health Information (PHI)
- Patient demographic information
- Insurance and coverage details
- Clinical documentation for billing purposes
- Claims and payment history
Technical Information
- IP address and browser type
- Device information and operating system
- Usage data and access logs
How We Use Your Information
We use the information we collect for the following purposes:
- To provide revenue cycle management and billing services
- To process insurance claims and manage accounts receivable
- To verify insurance benefits and obtain authorizations
- To communicate with payers regarding claims and appeals
- To generate reports and analytics for your practice
- To improve our services and develop new features
- To comply with legal and regulatory requirements
- To protect against fraud and unauthorized access
HIPAA Compliance
As a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA), VitalBridge is committed to protecting the privacy and security of Protected Health Information (PHI).
Our HIPAA Commitments:
- We maintain a signed Business Associate Agreement (BAA) with all covered entity clients
- We implement administrative, physical, and technical safeguards to protect PHI
- We limit PHI use and disclosure to the minimum necessary for billing purposes
- We train all employees on HIPAA privacy and security requirements
- We conduct regular risk assessments and security audits
- We maintain incident response procedures for potential breaches
We are SOC 2 Type II certified, demonstrating our commitment to the highest standards of data security and privacy.
Data Security
We implement comprehensive security measures to protect your information:
- 256-bit encryption for data in transit and at rest
- Multi-factor authentication for system access
- Role-based access controls limiting data access to authorized personnel
- Regular security assessments and penetration testing
- Secure, SOC 2 certified data centers
- Continuous monitoring and intrusion detection
- Regular data backups with encrypted off-site storage
Your Rights and Choices
You have certain rights regarding your information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your information (subject to legal retention requirements)
- Restriction: Request restriction of processing in certain circumstances
- Portability: Request transfer of your data in a machine-readable format
- Objection: Object to processing based on legitimate interests
To exercise these rights, please contact us using the information provided below.
Third-Party Services
Our services may integrate with third-party platforms and services. These third parties have their own privacy policies, and we encourage you to review them. We are not responsible for the privacy practices of third-party services.
We carefully vet all third-party service providers to ensure they meet our security and privacy standards, and we maintain appropriate agreements to protect your information.
Children's Privacy
Our services are designed for healthcare providers and business professionals. We do not knowingly collect personal information directly from individuals under 18 years of age. If you believe we have inadvertently collected information from a minor, please contact us immediately.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website and updating the "Last updated" date. We encourage you to review this policy periodically.
Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
VitalBridge
Email: privacy@vitalbridgecrm.com
Phone: (855) 848-2500
Questions About Our Privacy Practices?
We're committed to transparency. Contact us anytime with questions about how we protect your data.
Contact Us