Legal

HIPAA Notice

Effective date: August 5, 2026 · Last updated: August 5, 2026
This HIPAA Notice applies to the SimplyRPM remote patient monitoring software platform and related applications (together, the “Service”), operated by ReimburseRPM LLC d/b/a SimplyRPM (“SimplyRPM,” “we,” “us,” or “our”). ReimburseRPM LLC d/b/a SimplyRPM is a limited liability company doing business as SimplyRPM.

1. Purpose of This Notice

ReimburseRPM LLC d/b/a SimplyRPM (“SimplyRPM”) takes the privacy and security of health information seriously. This HIPAA Notice explains how SimplyRPM handles protected health information (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”), as amended by the HITECH Act.

2. Our Role Under HIPAA

When SimplyRPM provides SimplyRPM to or on behalf of a HIPAA “covered entity” (such as a health care provider or health plan), SimplyRPM generally acts as a Business Associate. In that role, we create, receive, maintain, or transmit PHI in order to provide the Service, and we do so in accordance with a Business Associate Agreement (“BAA”) with the covered entity and with HIPAA's Privacy, Security, and Breach Notification Rules.

For provider customers, the terms of the BAA and our Business Associate obligations govern our handling of PHI. Any questions about your own Notice of Privacy Practices should be directed to your provider. We handle non-PHI information under our Privacy Policy.

3. How We Use and Disclose PHI

As a Business Associate, we use and disclose PHI only as permitted by our BAA and HIPAA, including to:

We do not use or disclose PHI in ways that the covered entity would not be permitted to, and we do not sell PHI or use it for marketing except as permitted by HIPAA and authorized in writing.

4. Safeguards

We maintain administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI, consistent with the HIPAA Security Rule. These include access controls, encryption of data in transit and at rest, audit logging, workforce training, and risk management processes.

5. Subcontractors

Where we engage subcontractors that create, receive, maintain, or transmit PHI on our behalf, we require them by written agreement to apply protections at least as stringent as those that apply to us under our BAA and HIPAA.

6. Breach Notification

If we discover a breach of unsecured PHI, we will notify the applicable covered entity without unreasonable delay and consistent with HIPAA's Breach Notification Rule and our BAA, so that required notifications can be made.

7. Your Rights Regarding PHI

HIPAA gives individuals rights over their PHI, including rights to access, request amendment of, and receive an accounting of certain disclosures of their PHI. Because SimplyRPM typically acts as a Business Associate, these rights are generally exercised through the covered entity (your health care provider). If you make a request directly to us, we will work with your provider to fulfill it as required by our BAA. To reach us, email [email protected].

8. Minimum Necessary

We apply the “minimum necessary” standard, limiting our use, disclosure, and requests of PHI to the minimum reasonably needed to accomplish the intended purpose, except where HIPAA provides otherwise (for example, for treatment).

9. Changes to This Notice

We may revise this HIPAA Notice to reflect changes in our practices or the law. The current version will always be posted here with an updated date.

10. Contact & Complaints

To ask questions about this Notice or our handling of PHI, contact ReimburseRPM LLC d/b/a SimplyRPM at [email protected]. If you believe your privacy rights have been violated, you may also contact your health care provider or file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate against anyone for filing a complaint.