HIPAA-Compliant Medical Billing and Revenue Cycle Support
Last Updated: July 6, 2026
Radiant RCM provides medical billing, revenue cycle management, medical coding, provider credentialing, denial management, AR follow-up, payment posting, eligibility verification, prior authorization support, reporting support, and healthcare virtual assistant services for healthcare practices.
Because our work may involve sensitive healthcare information, privacy and security are built into our service delivery process.
Radiant RCM follows HIPAA-aligned administrative, physical, and technical safeguards designed to protect protected health information and electronic protected health information handled during approved client service workflows.
Our Commitment to Healthcare Data Protection
Healthcare providers need a billing and RCM partner they can trust with sensitive patient, provider, payer, billing, coding, and practice information.
Radiant RCM is committed to supporting clients with secure, responsible, and compliant data handling practices.
Our approach focuses on:
- Protecting patient and practice information
- Using information only for approved service purposes
- Limiting access to authorized team members
- Supporting secure billing and RCM workflows
- Following client-specific instructions
- Maintaining confidentiality
- Reducing unnecessary exposure of sensitive data
- Responding responsibly to security concerns
- Using approved communication channels for sensitive information
HIPAA and Business Associate Responsibilities
Radiant RCM may act as a business associate when we create, receive, maintain, or transmit protected health information on behalf of a healthcare provider, covered entity, or another business associate.
When required, Radiant RCM enters into a Business Associate Agreement before handling protected health information.
A Business Associate Agreement helps define how protected health information may be used, disclosed, protected, reported, returned, retained, or destroyed when appropriate.
Radiant RCM uses protected health information only for permitted service purposes, such as:
- Medical billing
- Claim submission support
- Payment posting
- Denial management
- AR follow-up
- Eligibility verification
- Prior authorization support
- Medical coding support
- Provider credentialing support
- Revenue cycle reporting
- Healthcare administrative support
Administrative Safeguards
Radiant RCM uses administrative safeguards to guide how sensitive information is handled inside our organization.
These safeguards may include:
- Workforce confidentiality expectations
- Role-based access procedures
- Security awareness practices
- Internal data handling policies
- Client-specific workflow instructions
- Service scope controls
- Access approval and removal processes
- Vendor and subcontractor review where applicable
- Incident response procedures
- Periodic review of security and compliance practices
The purpose of these safeguards is to make sure sensitive information is handled only by authorized personnel and only for approved business purposes.
Physical Safeguards
Radiant RCM supports physical safeguards designed to reduce unauthorized access to systems, devices, and records used in service delivery.
These safeguards may include:
- Controlled access to work devices
- Secure work environments
- Device protection practices
- Screen privacy practices
- Secure storage of sensitive information where applicable
- Secure disposal of information that is no longer needed
- Restrictions on unauthorized copying, printing, or sharing of sensitive data
The purpose of physical safeguards is to reduce the risk of accidental exposure, unauthorized access, or improper handling of sensitive information.
Technical Safeguards
Radiant RCM uses technical safeguards designed to protect electronic protected health information and other sensitive business information.
These safeguards may include:
- Unique user access where possible
- Role-based permissions
- Password protection
- Secure authentication practices
- Multi-factor authentication where supported
- System access controls
- Secure communication methods
- Activity monitoring where available
- Limited access to client systems
- Secure data storage practices
- Secure file transfer methods where applicable
The purpose of technical safeguards is to protect electronic information from unauthorized access, improper disclosure, alteration, loss, or misuse.
Secure Access to Client Systems
Radiant RCM may need access to EHR systems, practice management platforms, clearinghouses, payer portals, reporting tools, document platforms, billing platforms, or communication systems to perform contracted services.
We encourage clients to provide:
- Unique user accounts
- Role-based permissions
- Limited access based on job duties
- Audit logs where available
- Multi-factor authentication where supported
- Prompt access removal when users no longer need access
- Approved communication and file-sharing methods
Radiant RCM team members use client system access only for approved service purposes.
Minimum Necessary Approach
Radiant RCM follows a minimum necessary approach where applicable.
This means we work to access, use, and share only the information needed to complete the assigned service task.
For example, a billing task may require claim and payer information, while a credentialing task may require provider documents and payer enrollment details.
We do not request sensitive information unless it is needed for the service being performed.
Protected Health Information Handling
When protected health information is involved, Radiant RCM handles it according to applicable agreements, permitted service purposes, and client instructions.
Protected health information may include information connected to:
- Patient identity
- Medical services
- Insurance coverage
- Claims
- Payment details
- Provider documentation
- Diagnosis or procedure information
- Billing and coding records
- Payer communication
Radiant RCM does not use protected health information for unrelated marketing, unauthorized disclosure, or personal purposes.
Website Forms and HIPAA
Radiant RCM's public website forms are intended for general business inquiries, demo requests, and service communication only.
Visitors should not submit patient records, claim files, medical details, insurance information, diagnosis details, Social Security numbers, medical record numbers, patient billing records, or other protected health information through public website forms. If protected health information is required for a contracted service, Radiant RCM will use approved communication methods and appropriate safeguards.
SMS Communications and HIPAA
Radiant RCM may use SMS text messaging for general business communication, demo scheduling, appointment confirmations, consultation reminders, customer care, and service-related updates.
SMS should not be used to send protected health information unless Radiant RCM has approved the communication method under a signed agreement and appropriate safeguards are in place. Visitors, prospects, and clients should not send patient records, claim files, diagnosis details, insurance information, Social Security numbers, medical record numbers, patient billing records, or other protected health information by SMS unless specifically instructed through an approved secure workflow.
Radiant RCM may provide SMS opt-in and opt-out options as part of its communication process. Message frequency may vary. Message and data rates may apply. Users may reply STOP to opt out and HELP for assistance.
Mobile Information and SMS Consent
Radiant RCM does not sell, rent, trade, or share mobile phone numbers, SMS opt-in information, or SMS consent status with third parties or affiliates for their marketing or promotional purposes.
SMS opt-in data and consent are not used for unrelated marketing by third parties. Consent to receive SMS messages from Radiant RCM cannot be transferred, sold, rented, or reused by another company.
Email and Communication Security
Radiant RCM may communicate with clients through email, phone, SMS, meetings, client-approved systems, and secure platforms. When sensitive healthcare information is involved, clients and Radiant RCM should use approved communication methods and avoid sending protected health information through public forms, unsecured channels, SMS, or personal accounts.
Clients are responsible for confirming which communication methods are approved for their practice and service workflow.
Vendor and Subcontractor Controls
Radiant RCM may use approved technology providers, vendors, or subcontractors to support website hosting, communication, workflow management, analytics, security, SMS messaging, or service delivery. Radiant RCM may use Zoom or other communication providers to support phone, meeting, SMS, or customer communication workflows.
Where protected health information is involved, vendors or subcontractors are reviewed and managed according to applicable service needs, confidentiality expectations, client agreements, and compliance requirements. Radiant RCM does not sell protected health information.
Security Incident Response
Radiant RCM maintains procedures for identifying, reviewing, responding to, and documenting security incidents. If Radiant RCM becomes aware of a security incident involving client information, we will review the issue, take appropriate action, reduce harm where possible, and notify affected clients according to applicable agreements and legal requirements.
When a breach of unsecured protected health information occurs at or by a business associate, notification requirements may apply under HIPAA and the applicable Business Associate Agreement.
Staff Confidentiality and Training
Radiant RCM expects team members who handle sensitive healthcare information to follow confidentiality, security, and client workflow requirements.
Team members are expected to:
- Use information only for assigned work
- Protect login credentials
- Avoid unauthorized sharing
- Follow secure communication practices
- Report suspicious activity or security concerns
- Follow client-specific system and workflow instructions
- Avoid sending protected health information through unauthorized channels
Data Retention and Disposal
Radiant RCM keeps sensitive information only for as long as needed for service delivery, reporting, legal, contractual, compliance, security, or business purposes.
When information is no longer needed, Radiant RCM takes reasonable steps to delete, archive, return, de-identify, or securely dispose of it according to applicable agreements and policies.
Data Aggregation and De-Identified Information
Where permitted by applicable law and agreements, Radiant RCM may use aggregated, anonymized, or de-identified information for service improvement, reporting, technical support, operational analysis, and business improvement.
De-identified information does not identify an individual and is not intended to be used to identify an individual. Radiant RCM does not use protected health information for unauthorized marketing or unrelated purposes.
What Clients Should Provide
To support secure and compliant service delivery, clients should provide:
- Signed service agreement
- Business Associate Agreement where required
- Authorized system access
- Role-based permissions
- Correct provider and practice details
- Accurate payer and claim information
- Secure communication channels
- Client-specific compliance instructions
- Approved contacts for PHI-related matters
- Approved process for sharing patient or claim information
Clients should avoid sharing personal passwords or sending protected health information through public website forms, SMS, or unsecured channels.
Our HIPAA Compliance Focus Areas
Radiant RCM focuses on practical compliance controls that support safe billing and RCM operations, including:
- Secure data handling
- Confidentiality controls
- Minimum necessary access
- Role-based system usage
- Approved communication channels
- Business Associate Agreements where required
- Secure workflow practices
- Incident response readiness
- Responsible data retention
- Vendor and subcontractor oversight where applicable
- Protection of SMS opt-in data and communication preferences
Why HIPAA Compliance Matters in Medical Billing
Medical billing and revenue cycle management involve sensitive information. Claim submission, coding, eligibility verification, denial management, payment posting, and AR follow-up may require access to patient, provider, payer, and payment data.
Strong HIPAA-aligned processes help protect patients, reduce risk for healthcare practices, and support responsible revenue cycle operations. Radiant RCM combines billing expertise with privacy-focused workflows so healthcare providers can focus more on patient care and less on administrative burden.
Important Notice
This page describes Radiant RCM's privacy and security approach for healthcare billing and revenue cycle support. This page is for general informational purposes only and does not replace a signed service agreement, Business Associate Agreement, legal advice, or a formal HIPAA risk assessment.
Specific obligations may vary based on the client relationship, service scope, systems used, information handled, and applicable agreements.
Contact Radiant RCM
For HIPAA, privacy, security, or compliance questions, please contact:
3121 West Hartford St, Broken Arrow, OK 74012
Website: radiantrcm.com
Email: info@radiantrcm.com
Phone: +1 918 383 6404
Business Hours: Monday-Friday, 9AM-6PM EST