Data Security & Privacy Policy

Last updated August 16, 2026

On this page (62 sections)

Last Updated: August 16, 2026

ZechionMed (“ZechionMed,” “Company,” “we,” “us,” or “our”) is dedicated to safeguarding information that is provided to us for medical billing, medical coding, revenue cycle management (“RCM”), claims management, and other healthcare administrative services that we provide.

ZechionMed implements administrative, technical and physical safeguards to ensure that information is protected from unauthorized access, use, disclosure, alteration, loss, or destruction, due to the nature of our services that may include the handling of sensitive health care information and/or financial information.

This Data Security & Privacy Policy outlines the general security and privacy principles of how ZechionMed processes information.

If ZechionMed receives Protected Health Information (PHI) on behalf of a HIPAA-covered entity, the terms under which it handles the PHI are specified in the applicable Business Associate Agreement (BAA) and HIPAA requirements.

1Purpose

The aim of this Policy is to provide the framework for ZechionMed to protect:

This Policy sets out expectations regarding the gathering, access, transmission, storage, disclosure and disposal of protected information.

  • Personal Health Information (PHI); or
  • EPHI – Electronic Protected Health Information; and
  • Persons with Personally Identifiable Information (PII); and
  • Personal information
  • Patient information
  • Provider information
  • Insurance information
  • Claims information
  • Billing information
  • Payment-related information
  • Client information
  • Employee and workforce information
  • Confidential business information
  • Authentication credentials
  • Information about the system and its security.

2Scope

This Policy will be relevant to ZechionMed's:

The Policy applies to the use of information regardless of how they are being transmitted electronically, physically or via other authorised means.

  • Employees
  • Contractors
  • Authorized workforce members
  • Consultants
  • Temporary personnel
  • Approved vendors
  • Subcontractors where applicable
  • Information systems
  • Applications
  • Devices
  • Networks
  • Cloud environments
  • Data storage systems
  • Communication platforms
  • The business processes that have protected information.

3Regulatory and Compliance Framework

ZechionMed's privacy and security practices could include support for compliance with applicable requirements such as:

HIPAA (The Health Insurance Portability and Accountability Act); and

The national standards set forth by HIPAA's Security Rule are for administrative, physical, and technical security protections of electronic PHI. HHS — HIPAA Security Rule

Compliance requirements vary depending on: ZechionMed's involvement in the information; services offered; contract; and the legal framework that covers the particular activity.

  • HIPAA (Health Insurance Portability and Accountability Act of 1996)
  • HIPAA Privacy Rule
  • HIPAA Security Rule
  • The HIPAA Breach Notification Rule
  • Federal privacy requirements that apply
  • Applicable U.S. state privacy and data-security laws
  • Applicable contractual obligations
  • Security requirements as agreed (Client specific).

4Information Classification

ZechionMed may categorize information based on its sensitivity and/or value to the business.

Public Information

Information that can be freely provided to the public, on purpose.

Examples include:

Information that may result in damage to the business, a contract, money or operations if it is not disclosed properly.

Restricted Information

Very sensitive data needing additional security restrictions.

Examples may include:

The level of access and security control should match the classification and sensitivity of the information.

  • Website content
  • Public marketing materials
  • Public company information.
  • Internal Information
  • Information for internal business purposes only.
  • Confidential Information
  • PHI
  • ePHI
  • Sensitive PII
  • Financial information
  • Authentication credentials
  • Security information
  • Patient information
  • Certain insurance information.

5Privacy Principles

ZechionMed's privacy practices are based on the following principles:

Information must be gathered and utilized for business fair and legal purpose.

Data Minimization

Collecting, accessing, using or disclosing information should be limited to information reasonably required for the intended purpose.

Need-to-Know Access

Access to be granted only to the authorized person(s) who is/are in need of information for the performance of their duties.

Confidentiality

Sensitive information should be safeguarded from the unauthorized disclosure.

Integrity

Safeguards to be exercised to prevent unauthorized modification or destruction should be observed.

Availability

Appropriate access should be granted to users of information to enable them to perform their legitimate business activity.

Accountability

Security and privacy responsibilities need to be allocated and controlled properly.

  • Purpose Limitation

6Collection of Information

ZechionMed may collect information that it needs to:

ZechionMed does not purposefully gather beyond what is reasonably necessary for any proper business use.

  • Provide medical billing services
  • Supply Medical Coding solutions
  • Process claims
  • Perform RCM activities
  • Communicate with Clients
  • Manage accounts
  • Provide customer support
  • Meet contractual obligations
  • Maintain business records
  • Protect systems
  • Comply with legal requirements.

7PHI Protection

If ZechionMed is a Business Associate, then the handling of PHI will be managed in accordance with:

Access, use, and disclosure of PHI is for authorized uses only.

  • Applicable HIPAA requirements
  • The applicable BAA
  • Client instructions
  • Applicable service agreements
  • Security procedures
  • Federal and State law, as applicable.

8Minimum Necessary Access

Where applicable, ZechionMed will strive to use the HIPAA minimum necessary principle.

Access may be limited by:

Patients' information should not be accessed by employees and authorised persons simply because they are capable of doing so.

  • Job role
  • Service responsibility
  • Client authorization
  • System permissions
  • Business need
  • Regulatory requirements.

9Role-Based Access Control

ZechionMed may employ role-based access controls as appropriate.

The level of access can be determined by:

Access should be reassessed and adjusted as responsibilities evolve.

  • Employee role
  • Department
  • Client assignment
  • Service responsibility
  • Administrative responsibility
  • Security classification.

10User Authentication

ZechionMed may introduce authentication mechanisms as appropriate for the sensitivity of systems and information.

These may include:

Where possible, it is advisable to limit the use of shared user credentials.

  • Unique user accounts
  • Password requirements
  • Multi-factor authentication
  • Session controls
  • Account lockout mechanisms
  • Credential management
  • Privileged-account controls.

11Workforce Access Management

ZechionMed can set up procedures for:

Access shall be terminated or modified expeditiously following the end of an individual's employment, contract or authorized responsibilities.

  • New-user authorization
  • Access modification
  • Access review
  • Employee transfers
  • Role changes
  • Termination of access
  • Privileged-access management.

12Secure and Invest in the Workforce and Training

Staff who have access to protected information should be provided with suitable training on:

Requirements for training may differ depending on job duties.

  • HIPAA
  • Privacy
  • Information security
  • Confidentiality
  • Phishing
  • Password security
  • Secure communication
  • PHI handling
  • Incident reporting
  • Social engineering
  • Acceptable use
  • Data protection.

13Confidentiality Obligations

It is required that personnel and authorized third parties respect the confidentiality of information that is accessed using ZechionMed.

Confidentiality obligations do not end after:

  • Employment ends
  • A contract ends
  • A Client relationship ends when:
  • Access to the system is denied.

14Physical Security

ZechionMed may employ physical security measures that are suitable to the facilities and systems that are used to process protected information.

These may include:

  • Facility access controls
  • Restricted work areas
  • Visitor management
  • Workstation security
  • Secure storage
  • Equipment protection
  • Secure disposal
  • Environmental safeguards.

15Workstation Security

Employees should strive to ensure that unauthorized access to systems containing protected information is not possible.

Examples include:

  • Locking unattended workstations
  • Protecting login credentials
  • Avoiding unauthorized software
  • Using approved devices
  • Keeping private information from being accessed by unauthorized individuals
  • Cleaning desks as required.

16Mobile Devices

When mobile devices are allowed access to protected information, security controls may be necessary.

These may include:

Unapproved personal storage of PHI must not be made unless authorised and securely stored.

  • Device encryption
  • Screen locks
  • Multi-factor authentication
  • Mobile device management
  • Remote wipe capability
  • Approved applications
  • Security updates.

17Encryption

Sensitive information may be transmitted and sometimes be stored encrypted by ZechionMed.

The following factors could influence the type of encryption that is required:

  • Information sensitivity
  • System architecture
  • Client requirements
  • Security risk
  • Applicable law
  • Technical feasibility.

18Secure Transmission

Use of approved communication methods for transmitting sensitive information.

PHI or other highly sensitive information should not be conveyed to personnel by unauthorized or insecure means.

If available, ZechionMed can be used:

  • Secure portals
  • Encrypted communications
  • Approved cloud systems
  • Secure file-transfer mechanisms
  • Other approved methods of communication.

19Email Security

When exchanging e-mail messages with information that could be considered sensitive, ZechionMed will have established a set of security protocols that should be followed.

Staff should be on the lookout for:

If they believe they are receiving or sending phishing or unauthorized communications, they should notify their security or appropriate personnel.

  • Phishing
  • Spoofing
  • Malicious attachments
  • Suspicious links
  • Impersonation
  • Business email compromise.

20Network Security

ZechionMed reserves the right to put in place network security measures suitable to its environment.

Controls may include:

  • Firewalls
  • Network segmentation
  • Intrusion detection
  • Intrusion prevention
  • Secure remote access
  • Monitoring
  • Endpoint protection
  • Access controls.

21Endpoint Security

Devices to access protected information may be subject to security controls including:

It is required to maintain devices according to ZechionMed security needs.

  • Anti-malware protection
  • Endpoint detection
  • Security updates
  • Encryption
  • Device management
  • Application controls
  • Access restrictions.

22Vulnerabilities and patch management

ZechionMed can monitor systems for known vulnerabilities and implement security updates based on:

There could be a higher priority given to critical security issues.

  • Severity
  • Risk
  • System importance
  • Available patches
  • Operational requirements.

23Logging and Monitoring

To detect; where appropriate, ZechionMed can keep system logs and security monitoring, including:

Operational, contractual, legal or security requirements may deem it to be acceptable to retain logs.

  • Unauthorized access
  • Suspicious activity
  • Authentication failures
  • Configuration changes
  • Data access
  • Security events.

24Audit Controls

If applicable, ZechionMed will establish systems that allow it to monitor and review activity involving systems that contain protected information.

Audit capabilities can aid in:

  • Security investigations
  • Compliance reviews
  • Incident response
  • Access monitoring
  • Operational oversight.

25Back up and Disaster Recovery

ZechionMed has backup and recovery policies in place to ensure availability and recovery of critical information.

These are just some of the backup processes that can be performed:

Back-up copies of PHI continue to be covered by the privacy and security requirements.

  • Regular backups
  • Secure backup storage
  • Access restrictions
  • Recovery testing
  • Business continuity procedures.

26Business Continuity

ZechionMed might have business continuity/disaster recovery protocols commensurate to the business.

These processes can be used to deal with:

  • System outages
  • Cybersecurity events
  • Natural disasters
  • Infrastructure failures
  • Service interruptions
  • Other events of significance to critical operations.

27Incident Response

ZechionMed has processes in place to identify, evaluate, contain, investigate, and respond to suspected security incident(s).

These are potential incidents that can occur:

  • Unauthorized access
  • Unauthorized disclosure
  • Malware
  • Ransomware
  • Phishing
  • Credential compromise
  • Lost devices
  • Data leakage
  • System intrusion
  • Improper disposal
  • Accidental disclosure.

28Security Incident Reporting

Any suspected security incidents should be reported immediately by personnel and users of the system.

Reports can be made via:

The Company may have other reporting processes internally.

  • Security Contact: Please contact [Insert Security Email]
  • Phone Number: [Insert HIPAA Phone Number]
  • Emergency Security Contact: (Phone)

29Breach Assessment

A suspected incident involving any PHI will be assessed for compliance with applicable HIPAA requirements to determine if it is a reportable Breach.

The assessment can take into account:

If ZechionMed is a Business Associate, it will notify the Covered Entity in accordance with the conditions of the applicable BAA and HIPAA requirements.

  • Nature of the information
  • Person or entity receiving the information
  • Whether information actually was acquired or looked at
  • Level of exposure risk
  • Mitigation measures
  • Applicable law.

30Breach Notification

As far as is possible, ZechionMed shall comply with the contractual and legal notification requirements in case of breach.

If processed by ZechionMed as a Business Associate, ZechionMed will notify the applicable Covered Entity per the BAA and applicable HIPAA requirements.

The Covered Entity may have other responsibilities for notifying affected individuals, HHS, or others.

31Vendor and Third-Party Security

ZechionMed may rely on third party service providers to assist in its business activities.

Depending on the services involved, vendors may support:

If a third party administers PHI on ZechionMed's behalf, then the necessary contractual and HIPAA requirements will be covered as appropriate.

  • Cloud hosting
  • Software
  • Cybersecurity
  • Communications
  • Data storage
  • Analytics
  • IT support
  • Document management
  • Payment processing
  • Other business operations.

32Business Associate Subcontractors

ZechionMed will enter into appropriate agreements with subcontractors that create, receive, maintain or transmit PHI on behalf of ZechionMed where necessary.

They will expect applicable subcontractors to have proper privacy and security controls in place.

33Cloud Computing

Cloud-based systems may be utilized by ZechionMed.

If electronic PHI is stored and transmitted via a cloud service provider, ZechionMed will cover the applicable HIPAA requirements and safeguards.

Depending on the role, there may be separate contractual and security requirements to be met by cloud providers.

34AI and Automated Technologies

ZechionMed may employ AI-driven processes, automation, analysis or other technologies to enhance administrative and revenue cycle processes.

ZechionMed will take the following factors into account prior to processing protected information through these types of technology:

Unauthorized access to AI systems, applications and services is prohibited.

  • Privacy requirements
  • HIPAA requirements
  • Security risks
  • Contractual restrictions
  • Vendor capabilities
  • Data-processing arrangements
  • Applicable Client requirements.

35Unauthorized Technology

Authorized applications, cloud-storage services, messaging applications, artificial intelligence systems or other technology can not be used to process or store PHI by personnel.

Examples include:

  • Personal cloud storage
  • Unauthorized messaging applications
  • Personal email accounts
  • Unapproved AI platforms
  • Unauthorized file-sharing services
  • Unapproved removable storage.

36Data Retention

ZechionMed keeps information based on the applicable:

The retention periods are subject to change depending on the type of information.

  • Legal requirements
  • Regulatory requirements
  • Contractual obligations
  • Client instructions
  • Operational requirements
  • Security requirements.

37Secure Disposal

ZechionMed may safely destroy information, in a secure manner, when it is no longer needed in compliance with applicable requirements.

Some of the disposal methods are:

Ordinary disposal methods are not suitable for protected information.

  • Secure deletion
  • Data destruction
  • Media sanitization
  • Document shredding
  • Proper disposal with licensed disposal companies.

38Data Return

Upon termination of the Services, ZechionMed may return Client information, if required under a Client agreement or BAA.

The way in which the funds are returned can be:

  • Secure file transfer
  • Authorized data export
  • Secure portal access
  • Other agreed methods.

39Privacy by Design

Whenever possible, ZechionMed tries to take privacy and security into account in the design or implementation of:

New technologies might be explored for workflows that contain sensitive information, and security and privacy issues might be assessed at this stage.

  • New services
  • Technology systems
  • Workflows
  • Software integrations
  • Data-processing activities.

40System Integration

A reasonable level of security can be achieved at the point of integration to Client systems based on:

API credentials, system credentials and integration keys need to be carefully secured.

  • Integration method
  • Data sensitivity
  • Authentication requirements
  • Access requirements
  • Client specifications
  • Security risk.

41Access Reviews

ZechionMed may from time to time audit access to systems which contain sensitive information.

Reviews may evaluate:

Access to be withdrawn when no longer needed.

  • Active users
  • Privileges
  • Role assignments
  • Client access
  • Administrative accounts
  • Inactive accounts.

42Privileged Access

Only authorized personnel should have administrative/privileged access.

In general, privileged accounts should:

  • Use individual credentials
  • Require stronger authentication
  • Be monitored
  • Be constructive, practical, and aware of the options
  • Be reviewed periodically.

43Password Security

Staff should adhere to ZechionMed's authentication criteria and create robust passwords.

Passwords should not be:

For systems with sensitive data, multi-factor authentication might be necessary.

  • Shared
  • Written in areas where it is visible to others
  • Used in unauthorized systems
  • Sent via insecure channels of communication.

44Remote Work

Authorized remote work with sensitive information should adhere to the security requirements of ZechionMed.

Personnel should:

  • Use authorized devices
  • Use secure connections
  • Protect workstations
  • When possible, do not use public or unsecured networks
  • Ensure that information is not accessible to those not authorised to view it
  • Adhere to access control requirements as appropriate.

45Physical Documents

If PHI or other confidential information is in paper form, employees should:

  • Latch papers when left in the room
  • Restrict access
  • Avoid unnecessary copying
  • Use secure disposal
  • Don't let unauthorized photography or duplication happen.

46The correctness and completeness of data

ZechionMed attempts to ensure proper control of its information to prevent unauthorized modification.

Before, personnel should check information, where appropriate:

  • Submitting claims
  • Updating records
  • Posting payments
  • Processing coding information
  • Modifying Client data.

47Privacy Requests

Requests of privacy with regard to personal information shall be addressed to:

Generally, requests for PHI should be made to the appropriate healthcare provider or Covered Entity in which ZechionMed is merely a Business Associate.

ZechionMed will help Clients in compliance with any privacy requests as applicable under the BAA and under applicable law.

  • Privacy Contact: [Enter Privacy email]

48Individual Privacy Rights

Under the law and situation, there may be rights for the person about his/her personal information.

These may include:

There can be exceptions and other rules governing HIPAA information.

  • Access
  • Correction
  • Deletion
  • Restriction
  • Objection
  • Data portability
  • Other rights which are legally relevant.

49State Privacy Laws

ZechionMed acknowledges the possibility of other privacy and data-security rules being enforced in the U.S. by other states.

If applicable, ZechionMed will assess its liabilities under applicable state legislation.

Requirements for a state may vary based on:

  • Type of information
  • Position of the person
  • Business activity
  • Size of organization
  • Applicable exemptions
  • HIPAA status.

50International Privacy

ZechionMed's primary clientele are U.S. healthcare and business organizations.

Extra privacy needs may exist for information processed outside the United States or for individuals in other jurisdictions.

ZechiomMed will consider and put in place suitable contractual and legal protections when applicable.

51Employee Privacy

ZechionMed may have the right to receive data concerning the workforces for valid employment and business reasons.

This information can be:

Information about the workforce will be processed as per relevant legislation and Company policy.

  • Identification information
  • Contact information
  • Employment information
  • Payroll information
  • Access credentials
  • Training records
  • Security records.

52Acceptable Use

ZechionMed systems and information are permitted to be used only for authorised business use.

Users must not:

  • Access information without permission
  • Share credentials
  • Copy PHI unnecessarily
  • Download unauthorized information
  • Use unauthorized applications
  • Circumvent security controls
  • Make unauthorized access attempts to the system
  • Disclose confidential information.

53Security Awareness

ZechionMed occasionally issues information and communications about security awareness on the following topics:

  • Phishing
  • Password security
  • Social engineering
  • Privacy
  • HIPAA
  • Malware
  • Data protection
  • Secure communications.

54Security Testing

Where appropriate, ZechionMed may perform security testing, assessment or review.

Testing may include:

Testing should be conducted in a controlled way that will reduce the impact of the testing on the operations.

  • Vulnerability assessments
  • Security reviews
  • Configuration reviews
  • Access reviews
  • Incident-response exercises
  • Other appropriate assessments.

55Policy Violations

Any breaches of this Policy may lead to appropriate action.

In situations as described above, following actions may occur:

  • Additional training
  • Access restriction
  • Access termination
  • Disciplinary action
  • Contractual remedies
  • Legal action.

56Exceptions

Exceptions to this Policy should be recorded and authorized by ZechionMed management.

Exceptions which include PHI should also take into account:

  • HIPAA requirements
  • Client contractual requirements
  • Security risks
  • Applicable law.

57Policy Review

ZechionMed reserves the right to review this Policy from time-to-time for any changes in:

The Company may update this Policy when necessary.

  • Business operations
  • Technology
  • Cybersecurity threats
  • HIPAA requirements
  • Privacy laws
  • Client requirements
  • Industry practices.

58Relationship with Other documents

This Policy should be read in conjunction with ZechionMed's:

If a signed agreement has more specific requirements the relationship will be governed by the signed agreement. Documenting the relationship among the various documents.

  • Privacy Policy
  • HIPAA Privacy & Information
  • Business Associate Agreement
  • Terms & Conditions
  • Service Level Agreement
  • Refund & Cancellation Policy
  • Accessibility Statement
  • Incident Response Procedures
  • Internal Security Policies

59Security Contact

Any questions or concerns about ZechionMed's data security practices should be directed to:

  • ZechionMed
  • Medical Billing & Coding Services
  • Wilmington, Delaware, USA
  • Data Security Contact: (Insert Security email)
  • HIPAA Privacy Contact: [Insert HIPAA Email Address]
  • General Email: [Insert Official Email]
  • Call: (Insert Official Phone Number)

60Important Security Notice

Never post patient PHI, medical records, social security numbers, insurance identification numbers, payment information, or other sensitive healthcare information on a public website form, unless ZechionMed has explicitly stated that it is a form or communication method that has been approved to provide this kind of information.

62Contact and Updates

Any queries about this Policy should be addressed to ZechionMed, as detailed above.

Last Updated: August 16, 2026

Questions about this policy?

Our team can walk you through anything in this document.