Legal & Compliance

Privacy Policy

This Privacy Policy explains how Reviora Healthcare LLC collects, uses, safeguards, and discloses information — including how we handle Protected Health Information (PHI) on behalf of the physician practices and specialty clinics we serve as a HIPAA Business Associate.

Effective Date: August 7, 2026 Applies To: reviorahealthcare.co and all Reviora Healthcare RCM services Governing Framework: HIPAA (45 CFR §160, §164) & HITECH Act

Straight Answers

The Short Version, Before the Legal Detail

These summaries are for quick reference only. The full policy below is the governing document.

Does Reviora Healthcare own or sell patient data?

No. Patient PHI processed through our billing and RCM services always remains the property of our client — the covered entity. We process it strictly under a signed Business Associate Agreement (BAA) and never sell it.

Is Reviora Healthcare a HIPAA Business Associate?

Yes. As a company that creates, receives, maintains, or transmits PHI on behalf of covered-entity clients, Reviora Healthcare is legally required to comply with the HIPAA Privacy, Security, and Breach Notification Rules, and enters into a BAA with every client.

Where is patient data processed?

Reviora Healthcare's specialist billing and coding team is based in the Philippines and operates under contractual, technical, and administrative safeguards consistent with HIPAA requirements for offshore Business Associate subcontractors. See Section 10 below.

What if I just visited the website, and I'm not a patient?

If you're a website visitor or a prospective client contact, we collect only standard business information — name, email, phone, and site analytics — governed by applicable state privacy laws such as the CCPA/CPRA and the Maryland Online Data Privacy Act.

The Full Policy

Complete Privacy Policy

Tap any section to expand it.

01Who We Are
+

Reviora Healthcare LLC ("Reviora Healthcare," "we," "us," or "our") is a Maryland-based Managed Service Provider offering medical billing and Revenue Cycle Management (RCM) services to specialty clinics and physician groups across the United States. This Policy covers our website (reviorahealthcare.co), our client-facing services, and our internal handling of information connected to those services.

Where we process Protected Health Information on behalf of a client practice, we act as that client's HIPAA Business Associate — the client remains the HIPAA Covered Entity and data owner.

02Scope of This Policy
+

This Policy applies to two distinct categories of people, and treats them differently:

  • Website visitors and prospective clients — individuals browsing reviorahealthcare.co, submitting a contact form, or booking a consultation. This is standard business-contact information, governed by applicable state consumer privacy laws.
  • Patients of our client practices — individuals whose PHI is processed through our billing and RCM services. Reviora Healthcare does not have a direct relationship with these individuals; our handling of their data is governed by the BAA with their provider and by HIPAA itself, not by the general consumer-facing terms of this website.

If you are a patient with a question about your own medical records or billing, please contact your healthcare provider directly — they control that information.

03Information We Collect
+

From website visitors: name, email address, phone number, practice or organization name, and any details submitted through contact forms or our consultation booking tool. We also collect standard technical data (IP address, browser type, pages viewed, referring URL) through website analytics.

From client practices, under a Business Associate Agreement: Protected Health Information necessary to perform billing, coding, claims submission, denial management, AR recovery, and credentialing services — which may include patient demographic information, insurance and payer information, diagnosis and procedure codes, and claims data. We collect and process only what is necessary to perform the contracted RCM function.

From job applicants: resume, contact details, and application materials, used solely for recruitment purposes.

04Our Role as a HIPAA Business Associate
+

For every client engagement involving PHI, Reviora Healthcare operates under a signed Business Associate Agreement (BAA) that defines the permitted uses and disclosures of PHI, required safeguards, breach notification obligations, and terms for return or destruction of data at the end of the engagement — consistent with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule (45 CFR Parts 160 and 164, as amended by the HITECH Act).

We use and disclose PHI only as permitted by the BAA and by law — principally to perform billing, coding, claims submission, and collections functions on the client's behalf. We do not use PHI for our own marketing purposes, and we do not sell PHI under any circumstance.

Where we engage subcontractors who may touch PHI (see Section 7), those subcontractors are bound by equivalent written safeguards, as HIPAA requires.

05How We Use Information
+

Website and business-contact information is used to: respond to inquiries, schedule consultations, provide requested materials, deliver contracted RCM services, communicate about your account, and improve our website and services.

PHI is used exclusively to perform the RCM functions authorized under the applicable BAA — for example, submitting claims, working denials, posting payments, and reporting performance against agreed benchmarks (such as those in our Managed Outcomes Agreement) back to the client.

We do not use website analytics or business-contact data to build advertising profiles, and we do not participate in third-party ad-targeting networks that sell personal data.

06How We Share Information
+

We do not sell personal information or PHI. We share information only in these limited circumstances:

  • With the client practice that owns the data, as part of standard RCM reporting;
  • With payers, clearinghouses, and other parties strictly necessary to submit and process claims on the client's behalf;
  • With vetted subcontractors and service providers bound by written confidentiality and, where applicable, HIPAA Business Associate obligations;
  • Where required by law, subpoena, or court order; and
  • In connection with a business transaction (such as a merger or acquisition), subject to confidentiality protections.
07Third-Party Service Providers & Subprocessors
+

We work with a limited number of technology and infrastructure providers to deliver our services (for example, secure hosting, practice management/clearinghouse connectivity, and communication tools). Any such provider that may create, receive, maintain, or transmit PHI on our behalf is contractually bound by HIPAA-equivalent safeguards.

[A current, named list of subprocessors that touch PHI will be maintained here and made available to clients under NDA/BAA, consistent with contractual disclosure obligations.]

08Cookies, Analytics & Website Technologies
+

Our website uses cookies and similar technologies to understand how visitors use the site and to support core functionality (such as our consultation booking tool). These tools collect technical information — not PHI — such as pages visited, time on site, and general location.

You can control cookies through your browser settings. Disabling cookies may affect some website functionality but will not affect our RCM services.

09Data Security Safeguards
+

We maintain administrative, technical, and physical safeguards designed to align with the HIPAA Security Rule, including access controls limiting PHI exposure to authorized personnel on a need-to-know basis, staff training on HIPAA and confidentiality obligations, and documented incident-response procedures.

No method of electronic transmission or storage is 100% secure. We continuously evaluate and update our safeguards, but we cannot guarantee absolute security, and we encourage clients and website users to also follow sound data-security practices on their end.

10Data Retention
+

PHI is retained only for as long as necessary to perform the contracted RCM services and to meet legal, regulatory, and contractual recordkeeping obligations, and is returned or securely destroyed at the end of an engagement as specified in the applicable Business Associate Agreement.

Website and business-contact information is retained only as long as needed to respond to your inquiry, maintain our business relationship, or meet legal requirements.

11Cross-Border Data Processing
+

Reviora Healthcare's dedicated Account Managers and RCM Specialist team operate from the Philippines. Where PHI or personal information is accessed or processed by our Philippines-based team, that access occurs under the same contractual safeguards, confidentiality obligations, and HIPAA-aligned security controls described in this Policy, and is governed by the terms of the applicable Business Associate Agreement with each client.

We do not store PHI on personal devices, and remote access to client systems is controlled, logged, and limited to authorized, trained personnel.

12Your Privacy Rights
+

If you are a website visitor or business contact, depending on your state of residence you may have rights under applicable state consumer privacy law — including California (CCPA/CPRA), Virginia (VCDPA), and Maryland (Maryland Online Data Privacy Act), among the 20-plus states that now have comprehensive privacy statutes. These commonly include the right to know what personal information we hold, request correction or deletion, and opt out of certain data uses. To exercise a request, contact us using the details in Section 15.

If you are a patient of one of our client practices, HIPAA gives you rights regarding your medical records and PHI — but those rights are exercised through your healthcare provider, who is the Covered Entity and legal custodian of your records, not through Reviora Healthcare directly.

13Breach Notification
+

In the event of a breach involving unsecured PHI, Reviora Healthcare will notify the affected client practice without unreasonable delay, consistent with the timelines and procedures set out in the HIPAA Breach Notification Rule and in the applicable Business Associate Agreement, so the client can meet its own notification obligations to patients and regulators.

14Children's Privacy
+

Our website is intended for healthcare business audiences and is not directed to children. We do not knowingly collect personal information from individuals under 13 through our website. Any PHI relating to minor patients processed through our RCM services is handled solely on behalf of, and under the direction of, the client practice.

15Changes to This Policy
+

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The "Effective Date" at the top of this page will always reflect the most recent version. Material changes affecting client PHI handling will also be communicated through the applicable Business Associate Agreement process.

At A Glance

Two Different Sets of Rights, Depending On Who You Are
W

Website Visitors & Business Contacts

Rights under state consumer privacy laws (e.g., CCPA/CPRA, VCDPA, Maryland ODPA): access, correction, deletion, and opt-out requests. Contact us directly to exercise these.

P

Patients of Client Practices

Rights under HIPAA regarding your medical and billing records — exercised through your healthcare provider, who is the legal custodian of your PHI, not Reviora Healthcare.

C

Our Client Practices

Rights and obligations defined by your executed Business Associate Agreement, including audit, reporting, and data-return provisions at the end of engagement.

Questions About This Policy

Reach Our Team Directly

For privacy questions, data requests, or to report a concern, contact Reviora Healthcare using any of the details below.

Email

info@reviorahealthcare.co

Phone

+1 (240) 393-9664

Company

Reviora Healthcare LLC
Maryland, United States

Book a Consultation →