1What Is HIPAA?
HIPAA is a U.S. federal law that establishes requirements concerning the privacy and security of certain health information.
The HIPAA Rules include requirements addressing:
Certain administrative and electronic healthcare transactions.
The HIPAA Rules apply to covered entities and business associates within the scope established by federal law. HHS explains that business associates can have direct obligations under certain HIPAA provisions in addition to their contractual responsibilities to covered entities.
- Privacy of Protected Health Information
- Security of electronic Protected Health Information
- Breach notification
2ZechionMed's Role
ZechionMed provides healthcare administrative and revenue cycle services, which may include:
When these activities involve the use or disclosure of PHI on behalf of a covered entity, the relationship may constitute a Business Associate relationship under HIPAA.
HHS identifies payment and healthcare operations activities among the types of functions that may result in a Business Associate relationship when they involve PHI.
- Medical billing
- Medical coding
- Claims processing
- Claims submission
- Denial management
- Accounts receivable management
- Payment posting
- Revenue cycle management
- Eligibility verification
- Provider credentialing support
- Coding audits
- Revenue integrity support
- Healthcare administrative reporting
- Other contracted healthcare administrative services.
3Business Associate Agreements
Where required, ZechionMed enters into a written Business Associate Agreement (BAA) with the applicable covered entity.
The BAA establishes the permitted and required uses and disclosures of PHI and sets out applicable privacy and security responsibilities.
BAA May Address
A BAA may address matters including:
HHS explains that a covered entity's written agreement with a Business Associate must establish appropriate protections for PHI and specify permitted and required uses and disclosures.
The applicable BAA between ZechionMed and a Client governs the parties' specific contractual HIPAA obligations.
- Permitted uses of PHI
- Required safeguards
- Restrictions on use and disclosure
- Reporting of certain security incidents and breaches
- Cooperation with applicable privacy obligations
- Subcontractor requirements
- Return or destruction of PHI
- Regulatory cooperation.
4Protected Health Information
Protected Health Information (PHI) generally refers to individually identifiable health information that is protected under HIPAA.
Depending on the Services provided, ZechionMed may process information such as:
Other information necessary to perform contracted revenue cycle services.
ZechionMed accesses and processes such information only as permitted by the applicable relationship, agreement, Client instructions, and applicable law.
- Patient demographic information
- Insurance information
- Claims information
- Diagnosis and procedure information
- Medical coding information
- Billing information
- Payment information
- Provider information
- Eligibility information
5Permitted Use of PHI
When acting as a Business Associate, ZechionMed may use or disclose PHI as necessary to perform the Services authorized by the applicable Client agreement and BAA.
Depending on the contracted Services, this may include activities such as:
ZechionMed will not use or disclose PHI for purposes outside those permitted by the applicable agreement or law.
HHS states that PHI may be disclosed to a Business Associate to help a covered entity perform its healthcare functions and that the Business Associate must appropriately safeguard the information.
- Medical coding
- Claim preparation
- Claim submission
- Claim status follow-up
- Denial management
- Payment posting
- Accounts receivable management
- Eligibility verification
- Revenue cycle analysis
- Coding quality review
- Reporting
- Healthcare operations support.
6Minimum Necessary Principle
Where applicable, ZechionMed follows the HIPAA principle of limiting uses, disclosures, and requests for PHI to the minimum necessary to accomplish the intended purpose, subject to applicable exceptions and requirements.
Access to healthcare information may therefore be restricted according to:
This approach helps limit unnecessary access to sensitive healthcare information.
HHS provides specific guidance concerning the HIPAA minimum necessary standard and its application to uses and disclosures of PHI.
- Job responsibilities
- Client authorization
- Service requirements
- System permissions
- Business need
- Applicable legal requirements.
7Administrative Safeguards
ZechionMed may implement administrative safeguards designed to protect PHI, including:
Administrative safeguards are part of the HIPAA Security Rule's framework for protecting electronic PHI.
- Privacy and security policies
- Workforce access procedures
- Security awareness practices
- Role-based responsibilities
- Access authorization
- Workforce training
- Incident response procedures
- Vendor and subcontractor controls
- Risk management procedures
- Business continuity practices.
8Physical Safeguards
Where applicable to ZechionMed's operations, physical safeguards may include controls designed to protect facilities, equipment, workstations, and physical media containing sensitive information.
These may include:
The specific safeguards used may vary according to the nature of the Services, systems, and information involved.
- Controlled facility access
- Workstation security
- Secure equipment handling
- Secure disposal procedures
- Restricted access to areas containing sensitive information
- Physical security controls.
9Technical Safeguards
ZechionMed may use technical safeguards designed to protect electronic PHI, including:
The HIPAA Security Rule establishes national standards for appropriate administrative, physical, and technical safeguards protecting electronic PHI.
- User authentication
- Access controls
- Role-based permissions
- Password controls
- Encryption where appropriate
- Secure data transmission
- System logging
- Monitoring
- Endpoint security
- Network security
- Backup controls
- Security monitoring.
10Access Control
Access to systems containing PHI is restricted according to authorized business responsibilities.
Depending on the applicable system, controls may include:
ZechionMed seeks to limit access to authorized personnel who require information to perform their assigned responsibilities.
- Individual user accounts
- Role-based permissions
- Authentication requirements
- Restricted administrative access
- Access reviews
- Account termination procedures
- Monitoring and logging.
11Workforce Privacy and Security
ZechionMed may establish privacy and security requirements for personnel who access confidential or healthcare-related information.
Depending on their responsibilities, personnel may receive training or guidance concerning:
Unauthorized access, use, or disclosure of protected information may result in appropriate corrective or disciplinary action.
- HIPAA requirements
- Privacy practices
- Information security
- Confidentiality
- Secure system use
- PHI handling
- Incident reporting
- Access control
- Appropriate use of Client information.
12Subcontractors and Service Providers
Where ZechionMed uses subcontractors or other service providers that may create, receive, maintain, or transmit PHI on ZechionMed's behalf, applicable HIPAA and contractual requirements will be considered.
Where required, appropriate written agreements and safeguards will be established.
HHS states that Business Associates generally must obtain appropriate assurances from their subcontractors when those subcontractors handle PHI on the Business Associate's behalf.
13Cloud and Electronic Systems
ZechionMed may use cloud-based and electronic systems to support its operations.
Where a cloud service provider creates, receives, maintains, or transmits electronic PHI on behalf of a covered entity or Business Associate, applicable HIPAA requirements and contractual safeguards must be addressed.
HHS states that a cloud service provider handling electronic PHI on behalf of a covered entity or Business Associate generally requires an appropriate Business Associate Agreement and must comply with applicable HIPAA requirements.
14Security Incidents
ZechionMed maintains procedures for identifying, assessing, responding to, and documenting suspected security incidents involving protected information.
Potential incidents may include:
Incidents will be evaluated according to applicable law, contractual requirements, and ZechionMed's internal response procedures.
- Unauthorized access
- Unauthorized disclosure
- Lost or improperly handled information
- Credential compromise
- Malware
- Phishing
- Ransomware
- Unauthorized system activity
- Other security events affecting protected information.
15Breach Notification
If ZechionMed determines that a breach involving PHI has occurred, notification and response obligations will be handled according to applicable HIPAA requirements, the applicable BAA, and other applicable law.
Depending on the circumstances, ZechionMed may be required to notify the affected Client so that the Client can fulfill its obligations under HIPAA.
Applicable breach-notification requirements may differ depending on the nature of the information, the parties involved, and the circumstances of the incident.
16Patient Privacy Rights
ZechionMed recognizes that individuals have important privacy rights concerning their protected health information.
However, when ZechionMed acts solely as a Business Associate, the HIPAA Privacy Rule generally places the primary responsibility for fulfilling individual rights such as access, amendment, and accounting obligations on the applicable covered entity, subject to the Business Associate's contractual obligations to assist the covered entity.
If you are a patient and have questions about:
you should generally contact the healthcare provider or covered entity responsible for your care and records.
ZechionMed may assist its healthcare-provider Clients in responding to applicable requests as required by the BAA and applicable law.
- Access to your medical records
- Correction of your medical information
- Restrictions on certain uses or disclosures
- Accounting of certain disclosures
- Your healthcare provider's Notice of Privacy Practices
17Notice of Privacy Practices
A HIPAA Notice of Privacy Practices (NPP) is generally provided by the applicable covered healthcare provider or health plan, not by a Business Associate acting solely in that capacity.
HHS states that the HIPAA Privacy Rule generally requires covered healthcare providers and health plans to provide individuals with a Notice of Privacy Practices explaining how PHI may be used and disclosed and describing individual privacy rights.
ZechionMed's healthcare-provider Clients are responsible for maintaining and providing their applicable Notice of Privacy Practices where required.
This page is intended as ZechionMed's HIPAA privacy information page and is not intended to replace a healthcare provider's Notice of Privacy Practices.
18Sensitive Information and Website Forms
ZechionMed's public website is primarily intended for business inquiries and service information.
Unless a secure, authorized submission method is specifically provided, visitors should not submit:
If PHI is required for contracted Services, ZechionMed will use appropriate authorized systems and communication channels.
- Patient medical records
- Patient diagnoses
- Clinical notes
- Social Security numbers
- Insurance member identification numbers
- Patient account information
- Payment card information
- Protected Health Information
- Other sensitive healthcare information.
19Email and Electronic Communications
Standard email may not provide the same level of protection as a dedicated secure healthcare communication system.
For this reason, Clients should use ZechionMed's designated secure communication methods when transmitting PHI or other sensitive information.
ZechionMed may provide secure portals or other authorized technology for Client communications where applicable.
20Data Retention and Disposal
ZechionMed may retain PHI and other Client information for the period necessary to:
When information is no longer required, it may be returned, securely destroyed, deleted, or otherwise handled according to the applicable BAA, service agreement, retention requirements, and law.
- Perform contracted Services
- Meet contractual obligations
- Comply with applicable law
- Support audits
- Resolve disputes
- Maintain required business records
- Meet regulatory obligations.
21Data Return Upon Termination
When a Client relationship ends, ZechionMed will handle PHI according to the applicable BAA and service agreement.
Depending on the contractual requirements, this may include:
Retaining limited information where required by law or permitted by the applicable agreement.
- Returning PHI
- Providing access to Client information
- Securely destroying PHI
22AI, Automation, and PHI
ZechionMed may use automation, analytics, and AI-assisted technologies in certain business and revenue cycle workflows.
Where PHI is involved, such technology may only be used in accordance with applicable contractual, privacy, security, and legal requirements.
ZechionMed will evaluate the role of any technology or service provider that may process PHI and implement appropriate contractual and security measures where required.
AI-assisted technology does not replace clinical judgment or independently determine patient treatment.
23Risk Management and Continuous Improvement
ZechionMed may periodically review its privacy and security practices to identify opportunities to strengthen protection of sensitive information.
Reviews may consider:
Security and privacy practices may evolve as risks and regulatory expectations change.
- Technology changes
- Security threats
- Operational changes
- Vendor relationships
- Regulatory developments
- Internal processes
- Client requirements.
24HIPAA Compliance Is a Shared Responsibility
HIPAA compliance is not achieved solely through a billing or coding vendor.
Healthcare-provider Clients remain responsible for their own HIPAA compliance obligations, including obligations relating to:
ZechionMed is responsible for the HIPAA obligations applicable to its role and contractual relationship.
HHS explains that covered entities and Business Associates have distinct responsibilities under the HIPAA Rules, including direct obligations applicable to Business Associates.
- Patient privacy
- Medical records
- Notice of Privacy Practices
- Patient rights
- Workforce practices
- Clinical operations
- Risk management
- Policies and procedures
- Appropriate use and disclosure of PHI.
25HIPAA Does Not Mean Zero Risk
ZechionMed takes reasonable measures to protect PHI and other sensitive information.
However, no information system, network, cloud environment, electronic communication method, or cybersecurity program can guarantee absolute protection against every possible threat.
ZechionMed will maintain appropriate safeguards and respond to identified incidents according to applicable requirements.
26Relationship With Other ZechionMed Policies
This HIPAA Privacy & Information page should be read together with:
Where a Client has executed a BAA or other written agreement with ZechionMed, that agreement governs the parties' specific contractual obligations concerning PHI.
- Privacy Policy
- Terms & Conditions
- Business Associate Agreement (BAA)
- Data Security & Privacy Policy
- Service Level Agreement (SLA)
- Refund & Cancellation Policy
- Accessibility Statement
27Questions About HIPAA and Privacy
For questions concerning ZechionMed's HIPAA-related practices, privacy safeguards, or Business Associate relationships, please contact:
HIPAA / Privacy Contact: [Insert Privacy or HIPAA Email] General Email: [Insert Official Email] Phone: [Insert Official Phone Number] Website: [Insert Official Website URL]
- ZechionMed Medical Billing & Coding Services Wilmington, Delaware, USA
28External HIPAA Resources
For authoritative information about HIPAA requirements, individuals and healthcare organizations may consult the U.S. Department of Health & Human Services Office for Civil Rights.
U.S. Department of Health & Human Services — HIPAA
HHS — Business Associates
HHS — HIPAA Security Rule
HHS — Notice of Privacy Practices
29Important Notice
ZechionMed provides medical billing, medical coding, revenue cycle management, and related healthcare administrative services. Where ZechionMed acts as a Business Associate, PHI is handled according to applicable HIPAA requirements, the applicable Business Associate Agreement, Client instructions, and other applicable legal and contractual requirements. This page provides general information about ZechionMed's HIPAA-related privacy and security practices and is not a substitute for a healthcare provider's legally required Notice of Privacy Practices, a Business Associate Agreement, legal advice, or regulatory guidance.
Last Updated: August 16, 2026
© 2026 ZechionMed. All Rights Reserved.