This HIPAA Notice explains how Reviora Healthcare LLC creates, receives, maintains, and transmits Protected Health Information (PHI) on behalf of the physician practices and specialty clinics we serve as a HIPAA Business Associate — and how we safeguard it under the HIPAA Privacy, Security, and Breach Notification Rules.
These summaries are for quick reference only. The full notice below is the governing document.
Tap any section to expand it.
Under 45 CFR §160.103, a Business Associate is an organization that performs functions or services on behalf of a covered entity — such as a physician group or specialty clinic — that require access to Protected Health Information. Reviora Healthcare LLC's medical billing, coding, claims submission, denial management, AR recovery, and credentialing services fall within this definition. As a Business Associate, we are directly liable under federal law for compliance with specific HIPAA Privacy and Security Rule provisions, independent of the covered entities we serve.
Every client relationship begins with a signed Business Associate Agreement, executed before onboarding starts or any PHI is accessed. The BAA sets out the permitted uses and disclosures of PHI, required safeguards, breach reporting obligations, and terms for return or destruction of data at the end of the engagement, consistent with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule (45 CFR Parts 160 and 164, as amended by the HITECH Act). We use and disclose PHI only as permitted by the BAA and by law, do not use PHI for our own marketing, and do not sell PHI under any circumstance.
We maintain designated Privacy and Security Officers, require mandatory HIPAA training for every team member at onboarding and annually thereafter, limit access to PHI on a minimum-necessary, role-based basis, and maintain documented incident-response and workforce sanction policies for HIPAA violations.
We control access to workstations and facilities where PHI may be viewed, apply managed device policies to any hardware handling PHI, follow secure disposal procedures for physical and electronic media, and restrict workstation use by role and need.
Technical controls include encryption of PHI in transit and at rest, unique user authentication with multi-factor login, ongoing audit logging and activity monitoring, and automatic session timeouts across systems that touch PHI. No method of electronic transmission or storage is 100% secure; we continuously evaluate and update these safeguards but cannot guarantee absolute security.
Reviora Healthcare's dedicated Account Managers and RCM Specialist team operate from the Philippines. Where PHI is accessed or processed by our Philippines-based team, that access occurs under the same contractual, technical, and administrative safeguards described in this Notice, and is governed by the terms of the applicable Business Associate Agreement with each client. We do not store PHI on personal devices, and remote access to client systems is controlled, logged, and limited to authorized, trained personnel. Any subcontractor who may create, receive, maintain, or transmit PHI on our behalf is bound by written, HIPAA-equivalent safeguards, consistent with 45 CFR §160.103, regardless of location.
Under 45 CFR §164.410, a Business Associate that discovers a breach of unsecured PHI must notify the affected covered entity without unreasonable delay, and in no case later than 60 calendar days after discovery. Our internal protocol is designed to act well inside that outer limit:
- Immediate containment — the incident is isolated the moment it is identified.
- Root-cause investigation — scope, cause, and affected records are determined.
- Client notification — the covered entity receives written notice with the information needed to meet its own obligations to patients and HHS.
- Corrective action — findings feed a documented remediation plan to prevent recurrence.
HIPAA gives patients rights regarding their medical records and PHI — including access, amendment, and an accounting of certain disclosures (45 CFR §§164.524, 164.526, 164.528) — but those rights are exercised through your healthcare provider, who is the Covered Entity and legal custodian of your records, not through Reviora Healthcare directly. You may also file a complaint with the HHS Office for Civil Rights at ocrportal.hhs.gov.
We may update this Notice to reflect changes in our practices or legal requirements. The Effective Date at the top of this page always reflects the most recent version. HHS has proposed updates to the HIPAA Security Rule (NPRM, January 2025); this Notice will be updated if and when a final rule takes effect.
Sources: U.S. Department of Health & Human Services, hhs.gov/hipaa — Business Associates (45 CFR §160.103), HIPAA Security Rule safeguard categories, and Breach Notification Rule (45 CFR §§164.400–414).
For HIPAA questions, data requests, or to report a concern, contact Reviora Healthcare using any of the details below.
Maryland, United States
