Legal

Privacy Policy

Your privacy and data security are our top priorities. Here's how we protect your information.

Last Updated: March 3, 2026

Medfolio Billing Solutions ("Medfolio," "we," "us," or "our") is committed to protecting your privacy and maintaining the confidentiality of your information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our services.

By using our website or services, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

1. Information We Collect

Personal Information

We collect information that you provide directly to us, including:

  • Contact Information: Name, email address, phone number, mailing address
  • Professional Information: Practice name, specialty, NPI number, tax ID, medical license information
  • Financial Information: Bank account details for payment processing (encrypted and securely stored)
  • Service Information: Claims data, patient billing information, coding records

Automatically Collected Information

When you visit our website, we automatically collect certain information about your device, including:

  • • IP address and browser type
  • • Operating system and device information
  • • Pages visited, time spent, and referring website
  • • Cookies and similar tracking technologies

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our medical billing and credentialing services
  • Process claims, submit to insurance payers, and manage revenue cycle operations
  • Communicate with you about services, updates, and important notices
  • Respond to your inquiries and provide customer support
  • Analyze usage patterns to improve website functionality and user experience
  • Comply with legal obligations and prevent fraud
  • Send marketing communications (with your consent, and you may opt-out anytime)

3. HIPAA Compliance

Protected Health Information (PHI): As a business associate under HIPAA, we maintain strict compliance with all applicable regulations for handling protected health information.

We implement comprehensive safeguards to protect PHI, including:

  • Administrative Safeguards: Written policies, workforce training, and access controls
  • Physical Safeguards: Secure facilities with restricted access and surveillance
  • Technical Safeguards: Encryption, secure authentication, audit controls, and automatic logoff
  • Business Associate Agreements: All subcontractors sign BAAs ensuring HIPAA compliance

PHI is only used for treatment, payment, and healthcare operations as permitted under HIPAA. We never sell or share PHI for marketing purposes without explicit authorization.

4. Information Sharing and Disclosure

We may share your information in the following circumstances:

  • With Insurance Payers:

    To submit claims, verify eligibility, and process payments

  • With Service Providers:

    Third-party vendors who assist with billing software, data storage, and analytics (all under signed BAAs)

  • For Legal Compliance:

    When required by law, court order, or governmental regulation

  • Business Transfers:

    In connection with a merger, acquisition, or sale of assets (with notice to affected parties)

  • With Your Consent:

    For any other purpose disclosed to you at the time of collection

We do not sell your personal information to third parties.

5. Data Security

We implement industry-standard security measures to protect your information from unauthorized access, disclosure, alteration, or destruction. Our security practices include:

Technical Controls

  • • 256-bit SSL/TLS encryption
  • • Encrypted data storage (at rest)
  • • Multi-factor authentication
  • • Regular security audits
  • • Intrusion detection systems

Operational Controls

  • • Role-based access restrictions
  • • Employee background checks
  • • Mandatory security training
  • • Incident response protocols
  • • Regular data backups

Important: While we use reasonable efforts to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our website. Cookies are small data files stored on your device.

Types of Cookies We Use

  • Essential Cookies: Required for website functionality and security
  • Analytics Cookies: Help us understand how visitors use our site (Google Analytics)
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Note that disabling cookies may limit website functionality.

We do not track personal health information through cookies. Analytics cookies only track general website usage patterns.

7. Your Rights and Choices

You have certain rights regarding your personal information:

  • Access:

    Request a copy of the personal information we hold about you

  • Correction:

    Request correction of inaccurate or incomplete information

  • Deletion:

    Request deletion of your information (subject to legal retention requirements)

  • Opt-Out:

    Unsubscribe from marketing communications at any time

  • Data Portability:

    Request your data in a structured, machine-readable format

To exercise these rights, please contact us at privacy@medfolio.us or call us at (347) 600-9911. We will respond within 30 days.

8. Data Retention

We retain your information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law.

  • Active Accounts: Retained for the duration of the service relationship
  • Financial Records: Minimum 7 years per IRS requirements
  • PHI Records: Minimum 6 years per HIPAA requirements (varies by state)
  • Marketing Data: Until you opt-out or withdraw consent

After the retention period expires, we securely delete or anonymize your information.

9. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.

10. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately so we can delete it.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

  • • Posting the updated policy on our website with a new "Last Updated" date
  • • Sending an email notification to registered users
  • • Displaying a prominent notice on our homepage

Your continued use of our services after such changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Medfolio Billing Solutions

Privacy Officer

For HIPAA-related privacy concerns or to file a complaint, please contact our designated Privacy Officer at the email and phone number listed.