Privacy Policy

RCM Automation respects your privacy and is committed to protecting your personal information and the sensitive healthcare data you entrust to us. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our website, use our services, and interact with our AI agents.

By accessing or using our Services, you agree to the terms of this Privacy Policy.

Scope and Applicability

This policy applies to all personal information collected through our website, platform, forms, APIs, and related services. It governs how we handle data across RCM Automation AI agents, including ELIXA, PRIA, CODIN, CLAIR, DEXA, ARIS, and REMITA.

We are committed to maintaining privacy, security, and confidentiality of personal and protected health information (PHI) in compliance with applicable data protection laws and healthcare regulations.

Information We Collect

A. Information You Provide Directly

We collect information you voluntarily submit when:

  • Signing up for consultations and demos
  • Filling forms (name, email, phone, practice name)
  • Contacting us for support or inquiries
  • Creating an account or profile

Examples include:

  • Contact Data: First name, last name, email, phone
  • Practitioner Data: Practice name, specialty, business address
  • Communication Data: Messages, requests, support interactions

B. Automatically Collected Information

We may automatically collect:

  • IP address and device data
  • Browser type, session duration, clickstream data
  • Cookie identifiers and analytics data

This information helps us run, analyze, and improve our Services responsibly.

C. Healthcare and RCM-Related Data

When you engage with our billing automation tools, the system processes:

  • Eligibility verification responses
  • Insurance and payer data
  • Claim details, coding (CPT/ICD-10), and remittance information
  • Denials and appeal outcomes

We treat this data, particularly any PHI, with strict confidentiality and secure processing.

How We Use Your Information

RCM Automation uses collected data to:

  • Provide and enhance our RCM automation services
  • Operate AI agents that automate billing tasks
  • Verify patient coverage and payer eligibility
  • Improve claims accuracy and prior-authorization processing
  • Communicate with users about their accounts and service updates
  • Monitor and analyze trends to improve platform performance
  • Protect against fraud, misuse, and security threats

We will not use your information for unrelated purposes without your consent.

Data Sharing and Disclosure

RCM Automation does not sell, rent, or trade personal information or Protected Health Information (PHI).

We may share information only when necessary and under strict safeguards, including:

  • Service Providers and Vendors
  • Healthcare and Payer Interactions
  • Legal and Regulatory Requirements
  • Business Transfers

Data Retention

RCM Automation retains personal information and healthcare data only for as long as necessary to:

  • Deliver and support our Services
  • Fulfill contractual and legal obligations
  • Comply with healthcare, billing, and financial record-keeping requirements
  • Resolve disputes and enforce agreements

Retention periods are determined based on:

  • Data type and sensitivity
  • Regulatory requirements (including HIPAA and payer rules)
  • Operational and audit needs

When data is no longer required, it is securely deleted, anonymized, or archived in accordance with industry-standard data destruction practices.

Security and Data Protection

We implement robust safeguards to protect your data, including:

  • Encryption: All sensitive data is encrypted in transit and at rest
  • Access Controls: Role-based access with multi-factor authentication
  • Network Security: Firewalls and intrusion detection systems
  • Infrastructure Hardening: Regular monitoring and vulnerability scans
  • Privacy Training: Ongoing staff training on security and privacy best practices

Despite these efforts, no system is completely immune to risk. We continuously improve security measures to stay current with threats.

Compliance and Certifications

RCM Automation is built with healthcare-grade security and compliance at its core. Our platform supports HIPAA compliance and is designed to meet the requirements of covered entities and business associates handling Protected Health Information (PHI). We apply administrative, technical, and physical safeguards, enforce role-based access controls, and secure data using encryption in transit and at rest.

In addition, our security program is aligned with SOC 2 Trust Services Criteria, focusing on security, availability, and confidentiality. These controls help ensure patient data, billing records, and financial information remain protected and resilient across all AI-driven RCM workflows.

User Consent and Data Control

By accessing or using our Services, you consent to the collection, processing, and use of information as described in this Privacy Policy.

Where required by law or applicable regulations:

  • We obtain explicit consent before processing sensitive data or PHI
  • Users may withdraw consent at any time, subject to legal or contractual limitations
  • Users may request access, correction, or deletion of their personal information

Policy Updates

We may update this Privacy Policy to reflect legal changes or operational needs. The updated date will appear at the top of this Policy.