Last updated: September 11, 2026
This HIPAA Notice describes how AllianceMedex handles protected health information (“PHI”) when we provide medical billing and revenue cycle services as a business associate to covered entities (and, where applicable, to other business associates).
1. Our role
AllianceMedex is a third-party medical billing and RCM service provider. When we create, receive, maintain, or transmit PHI on behalf of a client who is a covered entity (or business associate), we act as a business associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”).
2. Business associate agreements
Before handling PHI for a client, we enter into a Business Associate Agreement (“BAA”) (or equivalent contractual terms) that sets permitted uses and disclosures of PHI, required safeguards, breach notification duties, and other HIPAA obligations.
3. Permitted uses and disclosures
We use and disclose PHI only as permitted or required by the BAA, applicable law, and instructions from our client, typically to perform billing, claims submission, payment posting, denial management, reporting, and related RCM functions.
- We do not use PHI for our own marketing unrelated to contracted services.
- We do not sell PHI.
- Workforce members access PHI only as needed for assigned job duties.
4. Safeguards
We maintain administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of PHI, consistent with the HIPAA Security Rule and our internal policies. Safeguards may include access controls, encryption where appropriate, workforce training, and vendor oversight.
5. Subcontractors
If we engage subcontractors who create, receive, maintain, or transmit PHI on our behalf, we require appropriate written agreements that impose HIPAA-comparable protections.
6. Breach notification
If we discover a breach of unsecured PHI, we will notify the affected client without unreasonable delay and as required by HIPAA and the BAA, and will cooperate with investigation and mitigation efforts.
7. Individual rights
Patients generally exercise HIPAA rights (access, amendment, restrictions, and accounting of disclosures) through the covered entity. If we receive such a request, we will forward it to the appropriate client and assist as required by the BAA and law.
8. Website contact forms
Our public website contact forms are not intended for submission of PHI. Please do not include diagnosis details, claim identifiers, or other PHI in general website messages. Use secure channels designated in your client relationship for PHI-related communications.
9. No medical advice
AllianceMedex provides administrative billing and RCM support. We do not practice medicine and do not provide medical advice.
10. Contact
HIPAA-related questions for AllianceMedex: hello@alliancemedex.com. Clients should also consult their own privacy officer and BAA for matter-specific guidance.