HIPAA compliance
FlowClaim RCM LLC operates as a HIPAA-compliant business associate to every practice we serve. This page summarises the safeguards we work under. It is not a certification: HIPAA has no certifying body, and we are happy to walk through specifics during your due diligence.
Email us for a copy of our standard Business Associate Agreement or with questions about our safeguards.
Request the BAAOur safeguards
Business Associate Agreement
We sign a BAA with every client practice before any protected health information is shared or handled, as a standard part of onboarding, not an optional add-on.
Access controls
Access to PHI is limited by role. Staff working on a given account can see the data required for that account and no more. Access is reviewed and adjusted as roles change.
Secure transmission
Claims data, reporting, and any PHI in transit is handled over encrypted, secure channels. We do not send PHI over unsecured email.
Staff training
Staff complete HIPAA training covering PHI handling, breach recognition, and account-specific access rules before working on an account, and on a recurring schedule after that.
Audit logging
Access to systems holding PHI is restricted by role and logged, in line with the safeguards required of a business associate handling claims and billing data.
Breach protocol
We maintain a documented breach response protocol defined in advance, covering identification, containment, and notification, consistent with HIPAA breach notification requirements.
Internal audits
We run internal chart and process audits periodically, covering both security controls and billing accuracy, so gaps are caught internally rather than by an external audit. Compliance and coding accuracy are reviewed together because they are related: a documentation gap is both a billing risk and a compliance risk.
Questions
For a copy of our standard BAA or questions about our compliance posture, contact info@flowclaimrcm.com.