Hima Tech RCM

HIPAA Compliance

Hima Tech RCM's commitment to protecting patient health information under HIPAA.

HIPAA Compliance

Last Updated: January 2026

Hima Tech RCM is fully committed to protecting the privacy, security, and integrity of Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations. This page outlines our commitment and the safeguards we have in place.

Our Commitment

We maintain comprehensive policies and procedures designed to ensure the confidentiality, integrity, and availability of PHI. Our workforce is trained on HIPAA requirements, and we regularly audit our practices to ensure continued compliance with all applicable federal and state regulations.

Protected Health Information (PHI)

PHI includes any individually identifiable health information such as names, medical record numbers, dates of birth, Social Security numbers, diagnoses, treatment records, and insurance information. We collect, use, and disclose PHI only as permitted or required by HIPAA and as necessary to provide healthcare revenue cycle, credentialing, and enrollment services.

Administrative Safeguards

We have implemented administrative safeguards including:

  • Designation of a HIPAA Privacy and Security Officer
  • Workforce training on HIPAA policies and procedures
  • Risk assessments and security management processes
  • Contingency planning and disaster recovery procedures
  • Regular evaluation and updating of security measures

Technical Safeguards

We employ technical safeguards to protect electronic PHI (ePHI), including:

  • Encryption of data in transit and at rest
  • Access controls and unique user identification
  • Audit logging and activity monitoring
  • Secure network infrastructure and firewalls
  • Automatic session timeout and screen lock policies

Physical Safeguards

We maintain physical safeguards to restrict access to facilities and workstations that contain ePHI, including facility access controls, workstation use and security policies, and device and media controls for the disposal and reuse of hardware containing PHI.

Business Associate Agreements

We execute Business Associate Agreements (BAAs) with all third-party vendors and service providers who may have access to PHI. These agreements ensure that our business associates maintain appropriate safeguards for the protection of PHI in accordance with HIPAA requirements.

Breach Notification

In the event of a breach of unsecured PHI, Hima Tech RCM will notify affected individuals, the Department of Health and Human Services (HHS), and, where required, the media, in accordance with HIPAA Breach Notification Rule requirements. We maintain incident response procedures to ensure timely detection, investigation, and notification.

Contact Us

If you have questions about our HIPAA compliance practices, please contact our Privacy Officer at:

info@himatechrcm.com
+1 (214) 613-8150