1. Introduction
MBS (“MBS,” “we,” “us,” or “our”) provides medical billing and revenue cycle management services to healthcare providers. This Privacy Policy explains how we collect, use, disclose, and protect information through our website at www.mbsrcm.com (the “Site”), our client-facing applications, and our business operations.
Please read Section 2 carefully. It explains the difference between information we collect directly from you and protected health information we handle on behalf of our healthcare provider clients. Different rules apply to each.
2. Two categories of information — an important distinction
Information we control. When you visit our Site, request a demo, contact us, apply for a job, or use our applications as an authorized user, we collect information directly from you. This Privacy Policy governs that information.
Protected health information (PHI) we process for clients. In providing billing and revenue cycle services, MBS acts as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) on behalf of healthcare providers who are Covered Entities. We access and process PHI only as permitted by our Business Associate Agreement with each client and only to perform the services they have engaged us for. We do not own that information, and we do not use it for our own purposes.
3. Information we collect
3.1 Information you provide
- Contact and business information — name, job title, practice or organization name, business email, business phone, mailing address, and the content of messages you send us through contact forms, email, or phone.
- Account information — username, password, mobile number for multi-factor authentication, and access permissions for authorized users of our applications.
- Job applicant information — resume, employment history, education, references, and any information you include in an application.
- Vendor and partner information — contact details, and where applicable payment and tax information.
3.2 Information collected automatically
When you visit the Site, we and our service providers automatically collect:
- IP address and approximate location derived from it
- Browser type and version, operating system, and device type
- Pages viewed, time spent, referring and exit pages, and links clicked
- Date and time of access
- Cookie and similar identifiers (see Section 9)
3.3 Information from third parties
We may receive information from business data providers, marketing platforms, referral partners, and publicly available sources to support our business development and to verify the information you provide.
3.4 Information we do not intentionally collect through the Site
4. How we use information
We use information we control to:
- Provide, operate, maintain, and improve our services and applications
- Authenticate users and secure accounts, including delivering multi-factor authentication codes
- Respond to inquiries, demo requests, and support requests
- Administer contracts, invoicing, and payments
- Send service and administrative communications about your account, our services, security, or changes to our terms
- Send marketing communications about our services, where permitted by law, with the ability to unsubscribe at any time
- Evaluate job applications
- Analyze Site usage and improve content and performance
- Detect, investigate, and prevent fraud, security incidents, and unauthorized access
- Comply with legal, regulatory, and contractual obligations
We use PHI only as authorized by the applicable Business Associate Agreement and as permitted by HIPAA — principally to perform billing, coding, claims submission, payment posting, denial management, and related services, and for our own management and administration and legal responsibilities as permitted under 45 C.F.R. § 164.504(e).
We do not sell personal information, and we do not use PHI for marketing.
6. Security
MBS maintains administrative, physical, and technical safeguards designed to protect information against unauthorized access, use, alteration, and destruction, consistent with the HIPAA Security Rule. These include:
- Encryption of data in transit and at rest
- Role-based access controls and the minimum necessary standard
- Multi-factor authentication for access to systems containing sensitive data
- Audit logging and monitoring
- Workforce security training, including annual HIPAA training
- Background screening of workforce members with access to PHI
- Business Associate Agreements with subcontractors who handle PHI
- Documented incident response and breach notification procedures
- Periodic risk analysis and security assessments
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we discover a breach of unsecured PHI, we will notify the affected Covered Entity in accordance with 45 C.F.R. § 164.410 and the terms of the applicable Business Associate Agreement, so that the Covered Entity can meet its notification obligations.
7. Data retention
We retain information we control for as long as necessary to fulfill the purposes described in this policy, and thereafter as required to comply with legal, tax, accounting, and regulatory obligations, resolve disputes, and enforce agreements. HIPAA-related documentation is retained for at least six years as required by 45 C.F.R. § 164.316(b)(2).
PHI processed on behalf of clients is retained and disposed of in accordance with the applicable Business Associate Agreement and the client’s instructions. On termination, PHI is returned or destroyed as that agreement provides, or retention is extended where return or destruction is infeasible, with protections continuing for as long as it is retained.
8. Your choices and rights
Marketing. You may unsubscribe from marketing email using the link in any message, or by contacting us at marketing@mbsrcm.com. You will continue to receive transactional and service messages related to your account.
SMS. Reply STOP to any message to stop SMS delivery. See our SMS Policy for details.
Account information. Authorized users of our applications may review and update their account details within the application or by contacting their administrator.
State privacy rights. Depending on your state of residence, you may have the right to request access to, correction of, or deletion of personal information we hold about you; to request a copy in a portable format; to opt out of sale, sharing, or targeted advertising; and to be free from discrimination for exercising these rights. To make a request, contact us at privacy@integrityonegroup.co. We will verify your identity before responding and will respond within the timeframe required by applicable law. You may designate an authorized agent to submit a request on your behalf, subject to verification.
Note that information governed by HIPAA is exempt from most state privacy laws. Requests concerning PHI must be directed to the healthcare provider that holds it.
Do Not Track. Our Site honors Global Privacy Control signals, and also treats a legacy Do Not Track signal as a standing opt-out: when either is present, optional analytics and CRM scripts are not loaded.
10. Third-party links
The Site may link to third-party websites, including payer portals and partner sites. We are not responsible for their privacy practices. Review the privacy policy of any site you visit.
11. Children's privacy
The Site and our applications are intended for business use and are not directed to children under 13. We do not knowingly collect personal information from children through the Site. This does not limit our handling of pediatric patient records as PHI on behalf of provider clients, which is governed by HIPAA and the applicable Business Associate Agreement.
12. Location of processing
We operate in the United States and India. Information we collect may be transferred to, stored, and processed in India, which may have data protection laws different from those in your jurisdiction. Where PHI is accessed by workforce members outside the United States, we maintain contractual, technical, and administrative safeguards required by HIPAA and by our agreements with clients, including encryption, restricted access, prohibition on local storage, and monitored access environments.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting a notice on the Site or by email to account holders. Continued use of the Site after changes take effect constitutes acceptance.
14. Contact us
MBS
Email: privacy@integrityonegroup.co
For complaints about our privacy practices, contact us at the address above. If you believe your health information rights have been violated, you may also file a complaint with your healthcare provider or with the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr/complaints. We will not retaliate against you for filing a complaint.
