01. What Data We Collect
We collect information in three operational contexts: (a) direct interactions through our marketing website, consultation requests, and customer support channels; (b) client operational engagement where healthcare provider clients transmit billing files; and (c) automated technical telemetry when you navigate our platform.
A. Information You Voluntarily Provide
- Contact & Identification Data: Full name, professional title, healthcare organization or clinic name, work email address, telephone number, and postal address when you schedule a consultation or submit an inquiry.
- Practice Operational Metrics: Specialty domain, monthly claim volume, current denial rate approximations, and billing clearinghouse preferences disclosed during assessment sessions.
- Client Account Credentials: Usernames, encrypted passwords, authentication tokens, and multi-factor authorization keys issued to authorized provider personnel.
B. Healthcare & Patient Information (Protected Health Information - PHI)
Under contracts with Covered Entities (healthcare providers, hospitals, clinics), Indiquer RCM receives PHI solely for performing healthcare operations, billing, clean claim submission, and payment posting. Such data includes:
- Patient demographic data (name, date of birth, policy subscriber ID, contact information).
- Clinical diagnosis and procedure codes (ICD-10-CM, CPT, HCPCS, and relevant medical modifiers).
- Insurance eligibility verification records, prior authorization approvals, and Explanation of Benefits (EOB / EDI 835 remittances).
- Charge capture records, billing histories, and patient balance statements.
C. Automated Device & Telemetry Data
When visiting our website, our servers automatically log technical metadata including Internet Protocol (IP) addresses, browser classification, operating system details, referring/exit URLs, session durations, and interaction telemetry. See our Cookie Policy for complete details.
02. Why We Collect It (Legal Grounds & Purposes)
We process personal and operational data only where permitted by applicable statutory frameworks, including HIPAA (45 CFR § 164.506), the General Data Protection Regulation (GDPR Article 6), the Indian DPDP Act 2023, and UAE PDPL. Specifically, processing occurs under:
| Category | Legal Ground | Operational Purpose |
|---|---|---|
| RCM Execution & Billing | Contractual Necessity & HIPAA Treatment/Payment/Operations (TPO) | Generating EDI 837 claims, scrubbing errors, submitting to payers, managing appeals and accounts receivable. |
| Consultation & Support | Legitimate Interests & Consent | Responding to inquiries, conducting free revenue cycle audits, presenting custom recovery proposals. |
| System Security & Compliance | Legal Obligation | Maintaining audit trails under SOC-2 Type II, preventing unauthorized access, fulfilling regulatory audits. |
| Web Experience | Legitimate Interests / Consent | Optimizing site rendering, diagnosing server anomalies, tracking aggregate user analytics. |
03. HIPAA Business Associate Standards & PHI Handling
In compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act:
- Minimum Necessary Standard: We restrict workforce and algorithmic access to PHI to only what is strictly required to verify eligibility, code encounters, adjudicate claims, or pursue denial remediation.
- Workforce Safeguards: 100% of Indiquer RCM billing specialists, AAPC-certified coders, and technical administrators undergo mandatory annual HIPAA security awareness training and background screening.
- No Commercial Commercialization: We do not sell, rent, commercialize, or monetize patient lists or clinical records under any circumstances.
04. Data Storage, Encryption & Security Controls
Indiquer RCM maintains a multi-tier defense-in-depth security infrastructure designed to prevent unauthorized access, exposure, modification, or destruction of sensitive information:
- Cryptographic Standards: All data in transit is encrypted using Transport Layer Security (TLS 1.3/1.2) with strict cipher suites. All data at rest is protected via AES-256 bit hardware-accelerated encryption across databases, file stores, and backup archives.
- Zero-Trust Network Access (ZTNA): Cloud environments enforce role-based access control (RBAC), multi-factor authentication (MFA) with FIDO2 hardware keys, and continuous IP allowlisting.
- Vulnerability Management: Continuous automated vulnerability scanning, quarterly penetration testing by independent third-party cybersecurity auditors, and continuous SOC-2 Type II telemetry logging.
- Disaster Recovery: Geo-redundant, air-gapped backup snapshots with sub-1-hour Recovery Time Objective (RTO) and Recovery Point Objective (RPO) metrics.
05. Data Sharing & Third-Party Disclosures
We disclose personal and healthcare data only to authorized entities necessary to achieve our core healthcare service objectives:
- Accredited Clearinghouses & Payers: Electronic claims (EDI 837) and remittance queries (EDI 276/277) are routed to authorized health plans (commercial, Medicare, Medicaid) and clearinghouses (e.g., Change Healthcare, Availity, Waystar) under secure SFTP and AS2 conduits.
- Vetted Infrastructure Sub-processors: Cloud hosting infrastructure (SOC-2/HIPAA compliant AWS, Google Cloud, or Microsoft Azure data centers physically situated within the United States).
- Legal & Regulatory Mandates: Where compelled by valid subpoena, court order, or binding directive from the Department of Health and Human Services (HHS) Office for Civil Rights (OCR).
For an exhaustive list of our third-party integrations, visit our Third-Party Services Disclosure.
06. Your Privacy Rights & International Frameworks
Depending on your jurisdiction and relationship with Indiquer RCM, you hold specific statutory rights regarding your personal data:
| Statute / Jurisdiction | Recognized Rights | Fulfillment Window |
|---|---|---|
| HIPAA (US Healthcare) | Right to inspect billing records, request accounting of disclosures, and request confidential communications. (Must be requested via your primary healthcare provider). | 30 Calendar Days |
| GDPR / UK GDPR (Europe) | Right of access (Article 15), rectification (16), erasure (17), restriction (18), data portability (20), and objection (21). | 30 Calendar Days |
| India DPDP Act 2023 | Right to access summary of personal data, right to correction and erasure, right to grievance redressal, right to nominate representative. | 30 Calendar Days |
| UAE PDPL (Decree 45/2021) | Right to obtain personal data, right to stop processing, right to erasure, and right to object to automated decisions. | 30 Calendar Days |
To exercise any applicable rights, please use our dedicated Data Deletion & Access Request Portal.
07. Data Retention & Permanent Deletion
We retain personal data only for the duration required to satisfy the operational purposes outlined in this policy or to comply with statutory retention imperatives:
- Healthcare Billing Records & Audit Logs: Retained for a minimum of 6 to 7 years in strict accordance with CMS regulations, False Claims Act statutes of limitations, and state medical board retention guidelines.
- Marketing Inquiries & Consultations: Retained for 24 months following the last recorded interaction, unless earlier deletion is requested by the data subject.
- Cryptographic Sanitization: Upon expiration of statutory retention windows, digital records are permanently expunged utilizing NIST SP 800-88 Rev. 1 compliant cryptographic erasure methodologies.
08. Contact Our Data Protection & Privacy Officer
If you have inquiries, concerns, or formal grievance notifications regarding our privacy practices or data processing activities, please reach our designated Privacy Officer:
Attn: Chief Privacy & Compliance Officer
Email: privacy@indiquerrcm.com
Direct Hotline: +1 (469) 577-1619
Online Portal: indiquerrcm.com/data-deletion-request.html
Headquarters: Dallas, Texas, United States