Legal

HIPAA & security

How we protect patient information

Last updated September 1, 2026

Rivius works for medical practices as a HIPAA business associate. This page explains, in plain words, how we handle the protected health information (PHI) that practices share with us. It does not replace our Business Associate Agreement, which is the binding document.

The short version

  • We sign a Business Associate Agreement with every practice before we receive any patient information. You can read it before you sign.
  • We only ask for what the work needs: mainly your remittances (835 files or EOBs), and specific records for appeals.
  • Patient information is stored encrypted, in the United States.
  • Only named, trained people on our team can see it, and every access is logged.
  • We never sell patient information, never use it for marketing, never contact your patients, and never use it to train AI models.

What patient information we receive

  • Remittance advice (ASC X12 835 files) and explanations of benefits, from you, your clearinghouse or your billing company.
  • For appeals, the specific records needed for that appeal.
  • We do not need, and ask you not to send, full medical records unless an appeal requires them, substance use disorder treatment records protected by 42 CFR Part 2, or psychotherapy notes.

Where it is stored

  • In the United States. Patient information is stored in data centres in the United States, operated by a US-based, HIPAA-eligible cloud provider. (Texas law has required this since January 1, 2026 for electronic health records held by Texas "covered entities", a term that includes business associates: Tex. Health & Safety Code 181.001(b)(2) and 183.002(a), added by SB 1188 (2025).)
  • Under a BAA with our cloud provider. Our cloud provider has signed a business associate agreement with us.
  • Encrypted. Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
  • Backups are encrypted, kept in the United States and deleted on a 35-day cycle.
  • Not on laptops or email. We do not keep patient information on personal devices or in ordinary email.

Who can see it

  • Access is limited to named members of our team who need it for your work, each with an individual account and multi-factor authentication. Access is reviewed quarterly and logged.
  • Everyone with access has completed HIPAA privacy and security training and signed a confidentiality agreement.
  • No offshore teams. We do not hand your files to outsourced or offshore billing, coding or processing staff.
  • US-based access only. Access to patient information is limited to named, US-based personnel whose access is logged and reviewed. Nobody outside that group can see it.

How filings are made

  • Disputes are submitted through the federal IDR portal (the IDR Gateway) by a verified US operator on our team, under your written authorisation. CMS requires Gateway users to verify their identity and to be physically located in the United States.
  • CMS's rules tell users not to type patient information into Gateway fields, and to remove it from uploaded documents. We follow those rules and send only what each federal step requires.

Use of software and AI

  • We use software, including AI tools, to read remittances, check eligibility and prepare filings. A person reviews every submission.
  • Any AI or software provider that processes patient information does so under a business associate agreement with us, in the United States, and is not permitted to keep it or use it to train its models.

Our HIPAA program

  • A written HIPAA security risk analysis, reviewed at least once a year.
  • Written privacy and security policies, including incident response.
  • A named security official, accountable for our HIPAA privacy and security program.
  • Business associate agreements with every subcontractor that handles patient information.
  • We do not hold a SOC 2 report or HITRUST certification.

If something goes wrong

If we discover a breach of unsecured patient information, we will tell the affected practice without unreasonable delay and within 5 business days of discovery, well within the 60 days HIPAA allows (45 CFR 164.410), and help it meet its own notification duties.

Your money

Insurers pay you directly. We never receive or hold payments to your practice; we only invoice our fee. You pay the federal IDR fees yourself, and the arbiter refunds them to you directly, as section 5 of the Client Service Agreement sets out.

When you leave

You can export all your data at any time. When our work ends, we return or destroy patient information as the Business Associate Agreement requires, after first giving you a full export.

Contact

Security or privacy questions, or to report a concern: support@riviushealth.com.

Rivius Health