Legal Information

Privacy Policy

Medical Accounts Group, LLC

Effective Date: January 1, 2025 | Last Updated: January 1, 2025

At Medical Accounts Group ("MAG," "we," "us," or "our"), we are committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us.

As a medical billing and accounts management company, we handle Protected Health Information (PHI) and are committed to compliance with the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and other applicable privacy laws.

1

Information We Collect

1.1 Protected Health Information (PHI)

In the course of providing medical billing and revenue cycle management services to healthcare providers, we may collect, process, and store PHI on behalf of our clients, including:

  • Patient names, addresses, dates of birth, and contact information
  • Medical record numbers and health insurance information
  • Diagnosis codes, procedure codes, and treatment information
  • Payment and billing records

1.2 Business Contact Information

When you contact us or request information about our services, we may collect business contact information such as your name, email address, phone number, practice name, job title, and any other information you choose to provide.

1.3 Website Usage Information

When you visit our website, we automatically collect certain information about your device and browsing activity, including IP address, browser type, operating system, pages viewed, time spent on pages, and referring website addresses.

1.4 Employment Information

If you apply for a position with MAG, we collect information you provide in your application, resume, cover letter, and during the interview process.

2

How We Use Your Information

2.1 PHI Usage

We use PHI solely for the purposes authorized by our healthcare provider clients and as permitted by HIPAA, including:

  • Processing medical claims and billing insurance companies
  • Managing accounts receivable and payment posting
  • Handling claim denials and appeals
  • Patient billing and collections
  • Revenue cycle reporting and analytics

2.2 Business Operations

We use business contact information to communicate with prospects and clients, respond to inquiries, provide customer service, send service updates, and improve our operations.

2.3 Website Improvement

We use website usage information to analyze trends, administer the site, improve user experience, and enhance our services.

3

HIPAA Compliance

Business Associate Agreement

Medical Accounts Group operates as a Business Associate under HIPAA. We enter into Business Associate Agreements (BAAs) with all healthcare provider clients, establishing our obligations to safeguard PHI and comply with HIPAA Privacy and Security Rules.

Administrative Safeguards

Policies, procedures, and workforce training

Physical Safeguards

Secure facilities and workstation security

Technical Safeguards

Encryption, access controls, and audit logs

Breach Notification

Immediate reporting protocols in place

4

Information Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share information only in the following circumstances:

With Healthcare Providers

We share PHI with the healthcare provider client who engaged our services and as directed by that client.

With Insurance Companies and Payers

We transmit claims and PHI to insurance companies, Medicare, Medicaid, and other payers for payment processing and claim adjudication.

With Service Providers

We may engage trusted third-party service providers (subcontractors) who assist in our operations, such as technology vendors, data storage providers, and payment processors. All subcontractors are bound by BAAs and confidentiality agreements.

Legal Requirements

We may disclose information when required by law, court order, subpoena, or to comply with legal processes, investigate fraud, or protect the rights and safety of MAG, our clients, or others.

5

Data Security

We implement comprehensive security measures to protect the confidentiality, integrity, and availability of all information in our possession:

Encryption

256-bit SSL/TLS encryption for data in transit and AES-256 encryption for data at rest

Access Controls

Role-based access, multi-factor authentication, and minimum necessary access principles

Secure Infrastructure

HIPAA-compliant cloud hosting with redundant backups and disaster recovery plans

Regular Audits

Annual security risk assessments and third-party penetration testing

Staff Training

Mandatory HIPAA and security awareness training for all employees

Activity Monitoring

Comprehensive audit logs and real-time security monitoring systems

Important: While we implement industry-leading security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your information using reasonable and appropriate safeguards.

6

Your Rights and Choices

Patient Rights

If you are a patient of one of our healthcare provider clients, your privacy rights regarding PHI are governed by your healthcare provider's Notice of Privacy Practices. For questions about your PHI, please contact your healthcare provider directly.

Under HIPAA, you generally have the right to access, amend, and request an accounting of disclosures of your PHI. These requests should be directed to your healthcare provider.

Marketing Communications

If you receive marketing emails from us, you may opt out at any time by clicking the "unsubscribe" link in the email or by contacting us at [email protected].

Data Retention

We retain PHI and other information for as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce agreements. PHI retention periods are determined by our BAAs with healthcare providers and applicable federal and state laws (typically 6-7 years).

7

Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand where our visitors are coming from.

Essential Cookies

Required for website functionality and security

Analytics Cookies

Help us understand how visitors use our site

Most web browsers are set to accept cookies by default. You can configure your browser to refuse cookies or alert you when cookies are being sent. However, some features of our website may not function properly without cookies.

8

Children's Privacy

Our website and services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13 through our website. If we learn that we have collected personal information from a child under 13 without parental consent, we will delete that information promptly.

9

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on this page and update the "Last Updated" date at the top.

For material changes that significantly affect how we handle PHI, we will notify our healthcare provider clients in accordance with our BAAs. We encourage you to review this policy periodically.

10

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Privacy Officer

Medical Accounts Group Inc.
6565 W Sunset Blvd, Suite 511
Hollywood, CA 90028
800 Fairway Dr, Suite 400
Deerfield Beach, FL 33441

HIPAA Compliance

For HIPAA-related inquiries, breach notifications, or to report security concerns: