This Privacy Policy explains how Rivius Health ("Rivius", "we", "us") collects, uses and shares information through our website at riviushealth.com (the "Site"), our practice lookup and report pages, the emails we send, and our online sign-up.
If you are a patient: this policy is not about your medical information. When a medical practice uses Rivius, we handle its patients' health information only as the practice's HIPAA business associate, under a written Business Associate Agreement. Your rights over that information are described in your provider's Notice of Privacy Practices. Please contact your provider directly.
1. Who we are
Rivius Health is a US company. You can reach us about privacy at
support@riviushealth.com.
Rivius helps out-of-network medical practices in the United States file federal No Surprises Act payment disputes, follow up on unpaid awards and appeal denied claims. Our Site is meant for people who work for or with those practices. It is not directed at patients or consumers.
2. Two kinds of information, handled differently
| Website and account information | Patient health information (PHI) | |
|---|---|---|
| What it is | Information about you and your practice as a business: your name, work email, practice name, NPI, messages, sign-up and billing details, Site usage | Remittances (835 files, EOBs), claim details and any records a client practice gives us to do the work |
| Where it comes from | You, your browser, and public sources described below | Only a client practice (or its clearinghouse or biller) that has signed our Business Associate Agreement |
| What governs it | This Privacy Policy | Our Business Associate Agreement with the practice, HIPAA, and the practice's own privacy notice |
| Where you send it | The Site, our forms and email | Only our secure client upload or connection, after sign-up |
Please do not send us patient information through the Site, the lookup box, the contact form or ordinary email. If you send it by mistake, tell us and we will delete it from those channels.
3. Information we collect
3.1 Information you give us
- Contact form and email: your name, practice name, work email, NPI (optional) and your message.
- Sign-up and account: your name, job title, work email and phone; the practice's legal name, address, tax ID (TIN) and NPIs; the name and title of the person signing for the practice; and your answers to sign-up questions (for example, whether the practice has an existing exclusive dispute or recovery contract).
- Electronic signatures: when you sign or accept our agreements online, we keep a record of the document version, your name, your email, the date and time, and your IP address and browser details, so we can show what was agreed and by whom.
- Payment details: payments are handled by our payment processor, Stripe. Stripe collects your card or bank details directly. We do not receive or store full card numbers. We receive limited details such as the card brand, the last four digits, the expiry date and the billing address. Stripe's own privacy policy, at >stripe.com/privacy, applies to the information it collects.
3.2 What you type into the practice lookup
When you enter an NPI or a practice name to see a report, we record what you entered, the time, and technical details about your request (such as IP address and browser type). We use this to show the report, to prevent abuse, and to understand which practices are interested in our service.
3.3 Public information we use to build reports
Our lookup and report pages are built from public data, including federal Independent Dispute Resolution public use files published by the Centers for Medicare & Medicaid Services (CMS) and the National Plan and Provider Enumeration System (NPPES) NPI registry, together with the sources named on each report page. These sources describe disputes and providers at an aggregate or business level. They do not identify patients, and we do not add patient information to them.
Some public provider records name individual clinicians (for example, a sole practitioner's NPI record). We treat those records as business information about the practice and use them only to prepare the practice's report and to contact the practice about our service.
3.4 Business contact information for outreach
We may send emails to people who work at practices that appear in public CMS data. To do that, we collect names, job titles and work email addresses from public sources: practice and facility websites, public professional directories, and public licensing and registry records. Every such email identifies us, includes our postal address and has a working unsubscribe link (see section 8).
3.5 Personalised report pages
Some of our emails link to a report page prepared for one practice. The link contains a random code so that the page is not listed publicly. The report uses only the public data described in section 3.3. Anyone who has the link can open the page, so please don't forward it if you'd rather keep it private. You can ask us to disable a report link at any time.
We record the date and time a report page is opened and which link was used, together with the IP address and browser type of the request. Because each link is prepared for one practice, we can see which practice's report was opened.
3.6 Information collected automatically
- Log data: like most websites, our servers and our hosting provider record IP addresses, browser type, pages visited, referring pages and the date and time of each visit.
- Analytics: we use a privacy-focused website analytics provider to understand how visitors use the Site. We do not use it to follow visitors across other websites, and we name the provider on request.
- Cookies: we use cookies and similar technologies that are needed for the Site to work and, if you allow them, analytics cookies. We do not use advertising or cross-site tracking cookies, and no advertising pixel is installed on the Site.
- Email: our emails do not contain open-tracking pixels. A link to a practice’s report page carries the random code described in section 3.5, so opening it tells us that the report was opened.
4. How we use information
We use the information above to:
- run the Site, the lookup and the report pages;
- answer your questions and send you information you ask for;
- set up and manage client accounts, sign agreements, and verify who is signing for a practice;
- provide the service described in our Service Agreement;
- invoice our fee and charge the payment method on file, as described in the Service Agreement;
- send service emails (for example, account notices, reports and invoices);
- send marketing emails to practices, which you can unsubscribe from at any time;
- keep the Site and our systems secure and prevent fraud and misuse;
- comply with law and enforce our agreements; and
- improve the Site and our service, using aggregated or de-identified information where we can.
We do not use patient health information for marketing, and we do not use it for any purpose other than those allowed by our Business Associate Agreement with the practice.
5. How we share information
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We share website and account information only with:
- Service providers who work for us under contract and only on our instructions: our website hosting provider, our business email and email-delivery provider, our electronic signature provider, our payment processor (Stripe), our website analytics provider, and the US-based, HIPAA-eligible cloud hosting provider that runs our systems and has signed a business associate agreement with us. We name the current provider in each category on request.
- Government bodies and dispute entities, when we act for a client: to file disputes, we submit the practice's business details (such as legal name, TIN, NPI and contact details) and our own details as its representative to the federal IDR portal and to certified IDR entities, as the federal process requires. This happens only under the practice's written authorisation.
- Legal and safety reasons: when required by law, subpoena or court order, or to protect our rights, our clients or others.
- Business transfers: if we are involved in a merger, acquisition or sale of assets, subject to this policy. Any patient health information would move only as HIPAA and our Business Associate Agreements allow.
- With your permission: for example, if a client opts in to being named as a client on our Site.
6. Where information is stored and who can see it
We are a United States company, and the Site is intended for users in the United States. Website and account information is stored by our service providers in the United States.
Access to website and account information (such as contact-form messages, sign-up details and invoices) is limited to named members of our team who need it for their work, each with an individual account and multi-factor authentication. Patient health information is handled more strictly still: it stays in the United States and only our US-based team can see it, as our HIPAA security statement describes.
7. How long we keep information
- Contact-form messages and lookup logs: up to 24 months, unless they become part of a client relationship.
- Account, signature and billing records: for as long as the client relationship lasts, then for 7 years for legal, tax and audit purposes. HIPAA documentation we have to keep is kept for at least the 6 years required by 45 CFR 164.316(b)(2).
- Outreach contact data: until you unsubscribe or ask us to delete it. We keep a minimal record of an unsubscribe so we can honour it.
- Patient health information: as set out in the Business Associate Agreement, which requires its return or destruction when the relationship ends where feasible.
8. Emails and unsubscribing
Every marketing email we send names Rivius as the sender, includes our postal address () and has a working unsubscribe link. We honour unsubscribe requests within 10 business days, as US law requires, and usually much sooner. You can also email support@riviushealth.com with the word "unsubscribe". Unsubscribing from marketing does not stop service emails that clients need (such as invoices and dispute notices).
9. Security
We use reasonable administrative, technical and physical safeguards to protect information, including encryption in transit and at rest, access controls and multi-factor authentication. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Our handling of patient health information is described in our HIPAA security statement.
10. Your choices and rights
- Access, correction and deletion: you can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it, by emailing support@riviushealth.com. We will verify your request before acting on it and answer within 45 days. Some information we must keep (for example, signed agreements and billing records).
- Report pages: you can ask us to disable a practice's report page or remove your details from it.
- Marketing emails: see section 8.
- Cookies: you can block or delete cookies in your browser. The Site works without analytics cookies.
- Do Not Track and Global Privacy Control: we do not track visitors across other websites. We treat a Global Privacy Control signal as a request to opt out of any sale or sharing of personal information, although we do not sell or share it.
- State privacy rights: residents of some US states, including California, may have additional rights under state law, such as the right to know, delete and correct personal information and to opt out of sales, sharing or targeted advertising. We will honour these rights where the law applies to us, and we will not discriminate against you for using them. You may use an authorised agent to make a request.
11. Children
The Site is for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we will delete it.
12. Links to other sites
The Site links to other websites, including CMS and other government sources. Their privacy practices are their own.
13. Changes to this policy
We may update this policy. We will post the new version on this page with a new "Last updated" date. If a change is material, we will tell clients by email before it takes effect.
14. Contact us
Rivius Health
support@riviushealth.com
Rivius is not affiliated with, endorsed by or acting for CMS, the U.S. Department of Health and Human Services, the U.S. Department of Labor, the U.S. Department of the Treasury, the Office of Personnel Management or any certified IDR entity.