HIPAA Notice of Privacy Practices
Last updated: June 2026 · Rcmaxis Health Services
Our Commitment to Your Privacy
Rcmaxis Health Services is committed to protecting the privacy and security of Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations.
Business Associate Status
Rcmaxis operates as a Business Associate to healthcare providers and practices. We access and process PHI solely for the purpose of providing contracted revenue cycle management and medical billing services on behalf of our clients (Covered Entities).
We don't function as a Covered Entity directly treating patients. Our privacy obligations arise through Business Associate Agreements (BAAs) with each client practice.
How We Use Protected Health Information
PHI accessed by Rcmaxis is used exclusively to:
- Submit claims to insurance payers on behalf of your practice
- Follow up on denied, rejected, or unpaid claims
- Post payments and reconcile remittance advice
- Generate financial reports and analytics for your practice
- Perform coding reviews and compliance audits
Safeguards
Rcmaxis implements administrative, physical, and technical safeguards required under the HIPAA Security Rule, including:
- Role-based access controls limiting PHI access to authorized personnel only
- Encrypted data transmission and storage
- Regular workforce training on HIPAA privacy and security
- Breach notification procedures per 45 CFR § 164.410
No Unauthorized Disclosure
We don't sell PHI. We don't use PHI for marketing purposes. Disclosures are limited to what is required to perform contracted services or as required by law.
Breach Notification
In the event of a breach of unsecured PHI, Rcmaxis will notify the affected Covered Entity within 60 days of discovery, as required by the HIPAA Breach Notification Rule.
Contact Our Privacy Officer
For HIPAA-related questions, concerns, or to report a potential privacy issue, contact our Privacy Officer at info@rcmaxis.com.