Security and compliance
Enrollment runs on facts about your practice. Patient information waits for a signed agreement.
The free review, the Payer Enrollment Sprint and a Service Line answer need nothing about any patient. Billing does, so billing starts only after your practice and Health Revenue Intelligence, LLC sign a business associate agreement.
Read it before you send anything.
Enrollment never touches a patient record. Billing does, under an agreement.
A payer asks about licenses, NPIs, ownership, malpractice cover and each provider's CAQH answers. Some of that is personal to the provider, and we guard it as closely. None of it is about a patient.
| Stage | What we work from | Patient information |
|---|---|---|
| Free review | Your payer list, your providers, your state and where each application stands. | None |
| Payer Enrollment Sprint | Practice and provider documents, CAQH access and the payers' own forms. | None |
| Service Line Made Billable | The service, your specialty, your payer mix and the payers' published rules. | None |
| Billing and revenue cycle | Eligibility checks, authorizations, claims, remittances and the notes a denial turns on. | Yes, after the agreement is signed |
Signed first, every time.
A business associate agreement comes before the first claim.
Under HIPAA, a company that handles patient information for a practice is that practice's business associate. The law expects a written agreement between the two before any of it changes hands.
Ours is signed by Health Revenue Intelligence, LLC, the firm HRI Med is part of. It commits us to use patient information only for the work you hired us to do, to protect it, to tell you if it is ever exposed, and to return or destroy it when the work ends. If your compliance officer has a form of their own, send it.
The people doing your work read what you send.
A request from this site lands in our business inbox and goes straight to the people who run the review. Whoever answers you is doing the work.
Provider documents leave our hands only when an application needs them: to CAQH, to Medicare through PECOS, to your state's Medicaid program and to the commercial payers on your plan.
A practice's working files are kept in Microsoft 365 under its name, shared with the people your practice tells us to include.
Named, so you can check them.
Three outside services carry your messages.
| Service | What it does for HRI Med | What passes through it |
|---|---|---|
| Cloudflare | Hosts these pages over HTTPS, runs the form and its spam check, and counts a few site events.The counts record a page path and an event name. They hold nothing you typed. | Your request, on its way to email |
| Resend | Delivers the request to our inbox and sends you a receipt. | What you typed into the form |
| Microsoft 365 | Our business email and the practice's working files. | Correspondence and provider documents; patient information only under a signed agreement |
The site's own code sets no cookies and loads no advertising trackers. The form asks you to leave patient details out, because an email delivery service is the wrong place for them. How long form data is kept is on the privacy page.
What compliance officers ask us.
Can we send a denial letter for the review?
Please describe it in words instead. A denial letter names a patient, and the review happens before any agreement exists.
What if someone on our staff sends patient details by mistake?
Tell us. We remove the message from our inbox, confirm that to you in writing, and ask for the facts again without the patient in them.
Will you answer our security questionnaire?
Yes, before anything is signed. Where the honest answer is that we do not do something, the answer says so.
Send your security questions with the request.
Put them in the message box beside your payer list. The review itself runs on practice facts alone.
We get back to you as quickly as possible.