HIPAA Compliance
At OraMed RCM, protecting the privacy and security of patient information is the foundation of everything we do. As a U.S. medical billing and revenue cycle management company, we operate in full alignment with HIPAA, the HITECH Act, and the applicable privacy and security laws of the states in which our clients practice.
Every claim, remittance, and patient record we handle is governed by HIPAA’s Privacy Rule and Security Rule. We limit the use and disclosure of protected health information (PHI) to the minimum necessary to perform billing, coding, credentialing, and reporting on behalf of our clients — and we never share that information with anyone outside the client’s authorized representatives and the specific team members assigned to their account.
Protecting PHI is a shared responsibility across our entire organization. Our billing and coding specialists, transcription staff, account managers, and every business associate we work with are bound by HIPAA regulations and by OraMed RCM’s own internal privacy and security policies. Each team member who comes into contact with health or financial data completes HIPAA privacy and security training before handling any client information, and refreshes that training on a regular basis.
How we protect your data
If something ever goes wrong
In the unlikely event of a suspected privacy or security incident, we follow a defined response and notification process to contain the issue and inform affected clients promptly, in line with HIPAA’s Breach Notification Rule.
Have questions about our HIPAA practices, or need a signed Business Associate Agreement? Email us at hello@oramedrcm.com and we’ll take care of it.