Contents
1. Purpose of This Notice
ReimburseRPM LLC d/b/a SimplyRPM (“SimplyRPM”) takes the privacy and security of health information seriously. This HIPAA Notice explains how SimplyRPM handles protected health information (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), as amended by the HITECH Act.
2. Our Role Under HIPAA
When SimplyRPM provides SimplyRPM to or on behalf of a HIPAA “covered entity” (such as a health care provider or health plan), SimplyRPM generally acts as a Business Associate. In that role, we create, receive, maintain, or transmit PHI in order to provide the Service, and we do so in accordance with a Business Associate Agreement (“BAA”) with the covered entity and with HIPAA's Privacy, Security, and Breach Notification Rules.
For provider customers, the terms of the BAA and our Business Associate obligations govern our handling of PHI. Any questions about your own Notice of Privacy Practices should be directed to your provider. We handle non-PHI information under our Privacy Policy.
3. How We Use and Disclose PHI
As a Business Associate, we use and disclose PHI only as permitted by our BAA and HIPAA, including to:
- Perform the services we provide to the covered entity (for example, remote patient monitoring, data aggregation, and reporting);
- Carry out our proper management and administration and meet our legal responsibilities;
- Provide data aggregation services relating to the health care operations of the covered entity, where permitted; and
- Disclose PHI where required by law.
We do not use or disclose PHI in ways that the covered entity would not be permitted to, and we do not sell PHI or use it for marketing except as permitted by HIPAA and authorized in writing.
4. Safeguards
We maintain administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI, consistent with the HIPAA Security Rule. These include access controls, encryption of data in transit and at rest, audit logging, workforce training, and risk management processes.
5. Subcontractors
Where we engage subcontractors that create, receive, maintain, or transmit PHI on our behalf, we require them by written agreement to apply protections at least as stringent as those that apply to us under our BAA and HIPAA.
6. Breach Notification
If we discover a breach of unsecured PHI, we will notify the applicable covered entity without unreasonable delay and consistent with HIPAA's Breach Notification Rule and our BAA, so that required notifications can be made.
7. Your Rights Regarding PHI
HIPAA gives individuals rights over their PHI, including rights to access, request amendment of, and receive an accounting of certain disclosures of their PHI. Because SimplyRPM typically acts as a Business Associate, these rights are generally exercised through the covered entity (your health care provider). If you make a request directly to us, we will work with your provider to fulfill it as required by our BAA. To reach us, email [email protected].
8. Minimum Necessary
We apply the “minimum necessary” standard, limiting our use, disclosure, and requests of PHI to the minimum reasonably needed to accomplish the intended purpose, except where HIPAA provides otherwise (for example, for treatment).
9. Changes to This Notice
We may revise this HIPAA Notice to reflect changes in our practices or the law. The current version will always be posted here with an updated date.
10. Contact & Complaints
To ask questions about this Notice or our handling of PHI, contact ReimburseRPM LLC d/b/a SimplyRPM at [email protected]. If you believe your privacy rights have been violated, you may also contact your health care provider or file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate against anyone for filing a complaint.