HIPAA Privacy Policy & PHI Safeguards

Effective Date: January 1, 2026 | HIPAA Title II Standard

1. Scope of Policy & BAA Binding

Syllavera Medical Billing ("we," "our," or "us") operates as a Business Associate as defined under the Health Insurance Portability and Accountability Act (HIPAA) of 1996. This policy describes how we collect, store, transmit, and protect Protected Health Information (PHI) and personal business metadata on behalf of our covered entity provider clients. All data processing is bound strictly by the terms of our signed Business Associate Agreements (BAAs).

2. Protected Health Information (PHI) We Handle

In executing medical billing, claim scrubbing, and denial appeal services, we access and process the following clinical and administrative details:

  • Patient demographics (name, date of birth, address, phone number).
  • Insurance carrier details, member policy IDs, and group benefit metrics.
  • Clinical coding data (ICD-10 diagnostic codes, CPT/HCPCS procedural codes, modifiers).
  • Financial details including ERA/EOB remittance codes, copay statements, and collections logs.

3. Technical and Administrative Safeguards

We implement physical, technical, and administrative safeguards strictly aligned with HHS Health Information Security standards:

  • Encryption: PHI is encrypted with AES-256 at rest in databases, and encrypted via TLS 1.3 in transit during API or clearinghouse transmissions.
  • Access Control: System entry operates strictly on the principle of least privilege. Biller access is secured with Multi-Factor Authentication (MFA) and isolated by practice tenant.
  • Audit Logs: Unmodifiable log records track database access, modifications, and transmissions of patient records under HITECH regulations.

4. Disclosure & Clearinghouse Transfers

We share claims data strictly for billing, treatment eligibility verification, and payment processing purposes:

  • Clearinghouses & Payers: Claims are routed via secure SFTP to accredited clearinghouses (e.g., Availity, Change Healthcare) and commercial/governmental payers (Medicare, BlueCross).
  • No Commercial Sale: Patient records and practice billing data are never rented, sold, or shared for third-party marketing, analytics, or model training.

5. Contact & Privacy Officer

If you have questions regarding our HIPAA compliance protocols, BAA execution, or data rights, please contact our Compliance Officer at:

Email: compliance@syllavera.com | General Inquiries: contact@syllavera.com