Home / HIPAA Notice
Legal & Compliance
HIPAA Notice

This HIPAA Notice explains how Reviora Healthcare LLC creates, receives, maintains, and transmits Protected Health Information (PHI) on behalf of the physician practices and specialty clinics we serve as a HIPAA Business Associate — and how we safeguard it under the HIPAA Privacy, Security, and Breach Notification Rules.

Effective Date: August 7, 2026
Applies To: reviorahealthcare.co and all Reviora Healthcare RCM services
Governing Framework: HIPAA (45 CFR §160, §164) & HITECH Act
Straight Answers
The Short Version, Before the Legal Detail

These summaries are for quick reference only. The full notice below is the governing document.

Is Reviora Healthcare a HIPAA Business Associate?
Yes. As a company that creates, receives, maintains, or transmits PHI on behalf of covered-entity clients, we are legally required to comply with the HIPAA Privacy, Security, and Breach Notification Rules, and we enter into a signed BAA with every client.
How do you protect PHI day to day?
Through layered administrative, physical, and technical safeguards — role-based access, encryption in transit and at rest, multi-factor authentication, audit logging, and mandatory HIPAA training for every team member touching PHI.
What happens if there's ever a breach?
We notify the affected client practice without unreasonable delay, and in no case later than 60 calendar days after discovery, per 45 CFR §164.410 — providing what they need to meet their own notification obligations to patients and regulators.
I'm a patient — how do I exercise my rights?
Through your healthcare provider directly. Reviora Healthcare is a Business Associate, not a covered entity — your provider is the legal custodian of your records and governs access, amendment, and disclosure requests under their own Notice of Privacy Practices.
The Full Notice
Complete HIPAA Notice

Tap any section to expand it.

01 Our Role as a HIPAA Business Associate +
02 Business Associate Agreements +
03 Administrative Safeguards +
04 Physical Safeguards +
05 Technical Safeguards +
06 Cross-Border Data Processing & Subcontractors +
07 Breach Notification Protocol +
08 Your Rights & Changes to This Notice +

Sources: U.S. Department of Health & Human Services, hhs.gov/hipaa — Business Associates (45 CFR §160.103), HIPAA Security Rule safeguard categories, and Breach Notification Rule (45 CFR §§164.400–414).

At a Glance
Three Roles, Three Sets of Obligations
P
Patients of Client Practices
Rights under HIPAA regarding your medical and billing records — exercised through your healthcare provider, who is the legal custodian of your PHI, not Reviora Healthcare.
C
Our Client Practices
Rights and obligations defined by your executed Business Associate Agreement — including audit, breach notification, and data-return provisions at the end of engagement.
R
Reviora Healthcare
Direct liability under HIPAA as a Business Associate — administrative, physical, and technical safeguards, subcontractor oversight, and breach notification within 60 days of discovery.
Questions About This Notice
Reach Our Team Directly

For HIPAA questions, data requests, or to report a concern, contact Reviora Healthcare using any of the details below.

Email
info@reviorahealthcare.co
Phone
+1 (240) 393-9664
Company
Reviora Healthcare LLC
Maryland, United States
Book a Consultation →