Legal & Compliance
Privacy Policy, Terms of Service, and HIPAA Business Associate Standards for Ecardius RCM Solutions.
Effective Date: January 1, 2026 | Entity: Ecardius RCM Solutions | Operational Standards: United States Healthcare & HIPAA Compliance
1. Corporate Identity & Overview
These terms, policies, and compliance notices govern your use of the website operated by Ecardius RCM Solutions ("Ecardius", "we", "us", or "our"), a specialized revenue cycle management (RCM) provider serving medical clinics, physician practices, ambulatory surgery centers, and healthcare organizations across the United States.
We provide full-lifecycle medical billing, old accounts receivable (A/R) recovery, claim denial management, provider credentialing, and coding audit services strictly under written service agreements and executed Business Associate Agreements (BAAs).
2. Privacy Policy
Ecardius RCM Solutions is committed to protecting the privacy, confidentiality, and data integrity of healthcare providers, clinical administrators, and the patients they serve. This Privacy Policy details how we collect, process, and safeguard information submitted through our website, appointment schedulers, and inquiry forms.
Information We Collect
- Business Contact Information: Name, professional title, practice or facility name, corporate email address, telephone number, specialty, and estimated practice volume submitted through contact or audit request forms.
- Practice Operational Details: Electronic Health Record (EHR) / Practice Management (PM) platform names, approximate monthly billing volumes, and de-identified aggregate A/R figures provided voluntarily to calculate diagnostic estimates.
- Technical Usage Data: IP address, browser type, device information, operating system, and referral source collected automatically via web server logs and standard analytics.
Strict Prohibition of Protected Health Information (PHI) via Public Forms
Do not submit Protected Health Information (PHI) through website contact forms or appointment notes. Our website forms and schedulers are intended strictly for administrative and commercial communications between practice leadership and Ecardius. Submission of patient names, dates of birth, Social Security numbers, medical record numbers, diagnostic descriptions, or claim identifiers through web forms is strictly prohibited.
Third-Party Processors & Infrastructure
We utilize trusted third-party technology providers to facilitate communications and scheduling:
- HubSpot Inc.: Powers our consultation scheduling and inquiry management. All data in transit is encrypted using modern Transport Layer Security (TLS 1.3/1.2).
- Cloud Infrastructure: Hosted on enterprise cloud hosting infrastructure (including AWS and Google Cloud) utilizing SOC 2 Type II certified data centers and end-to-end encryption for stored records.
Data Usage, Disclosure & Zero-Sale Commitment
We use submitted information solely to evaluate audit requests, respond to inquiries, schedule discovery consultations, and deliver contracted billing advisory services. We do not sell, rent, lease, or monetize contact details or practice data to third parties, data brokers, or advertisers under any circumstances.
Data Retention & Security Safeguards
Inquiry data is retained only as long as necessary to fulfill business purposes or comply with applicable legal obligations. We maintain administrative, technical, and physical safeguards—including role-based access restrictions and encrypted transport protocols—to prevent unauthorized access or disclosure.
Your Rights
Depending on your jurisdiction (including rights under state privacy frameworks such as the CCPA/CPRA), you may request access to, correction of, or deletion of your business contact information by emailing [email protected].
3. Terms of Service
By accessing this website, utilizing our interactive revenue estimators, or submitting a request for a 10-point A/R audit, you agree to these Terms of Service. If you do not agree, please discontinue website use.
Service Model & Engagement Process
- Performance-Based Model: Ecardius operates on a collections-contingent model. Our fees represent an agreed percentage of actual payments collected from payers and deposited directly into your designated organization bank account.
- Non-Binding Diagnostic Audits: Requesting a 10-point A/R and denial audit or scheduling an exploratory strategy call does not create a binding service contract, agency relationship, or fiduciary partnership.
- Prerequisites for Client Onboarding: Formal billing, coding, or recovery work commences only after mutual execution of a formal Master Services Agreement (MSA) and a HIPAA Business Associate Agreement (BAA).
- Financial Estimators & Tools: Revenue calculators and A/R aging slider tools on this site provide mathematical estimates based on user inputs. They are illustrative only and do not constitute a financial guarantee of recovery, as actual collections depend on timely filing limits, payer policies, and clinical documentation.
Intellectual Property & Proprietary Rights
All website content, copy, diagnostic methodologies, calculators, and graphics are the intellectual property of Ecardius RCM Solutions. Third-party electronic health record (EHR) and practice management system names (including athenahealth, eClinicalWorks, Kareo/Tebra, AdvancedMD, DrChrono, and Prompt) are trademarks of their respective owners and are referenced solely to describe system compatibility and workflow experience.
Limitation of Liability
To the maximum extent permitted by applicable law, Ecardius RCM Solutions and its officers, directors, employees, and agents shall not be liable for any indirect, incidental, consequential, or punitive damages arising from the use of this website, informational materials, or reliance on self-service calculators.
Governing Law & Dispute Resolution
These Terms of Service and any informational inquiries arising from the use of this website shall be governed by and construed in accordance with the applicable laws of the United States. In the event of formal client engagements, governing law, jurisdiction, and dispute resolution mechanisms are established directly within the client's mutually executed Master Services Agreement and Business Associate Agreement.
4. HIPAA & HITECH Compliance Statement
Ecardius RCM Solutions operates in strict alignment with the administrative, technical, and physical safeguards mandated under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and the Omnibus Rule of 2013 as an authorized Business Associate to healthcare providers and Covered Entities.
Business Associate Agreement (BAA) Standard
We execute a legally binding Business Associate Agreement with every client practice before receiving, accessing, or processing any Protected Health Information (PHI) or electronic Protected Health Information (ePHI). Our BAA outlines explicit responsibilities regarding data safeguarding, permitted uses, subcontractor compliance, and breach notification standards.
De-Identified Data Standard for Pre-Contract Audits
To perform the complimentary 10-point A/R and denial audit prior to BAA execution, practices are instructed to provide only fully de-identified aggregate A/R reports compliant with the HIPAA Privacy Rule Safe Harbor standard (45 CFR § 164.514(b)(2)). Reports must have all 18 direct patient identifiers removed, containing only payer names, aging buckets, denial codes, and financial totals.
Technical, Administrative & Physical Safeguards
- Direct System Workflow: Wherever feasible, our billing specialists work directly within your existing EHR and practice management clearinghouses, eliminating redundant external exports of clinical records.
- Encryption: All data stored or transmitted in connection with our services is protected by industry-standard AES-256 bit encryption at rest and TLS 1.3/1.2 in transit.
- Minimum Necessary Standard: Access to patient billing files is restricted strictly to authorized billing staff assigned to your specific account, enforcing the Principle of Least Privilege.
- Audit Logging & Access Monitoring: User sessions, claim submissions, and system interactions within billing workflows are continuously logged and monitored.
Breach Notification Protocol
In accordance with 45 CFR § 164.410, Ecardius maintains an Incident Response and Notification Protocol requiring prompt written notice to affected Covered Entities without unreasonable delay, and in no case later than required by applicable federal and state statutes, following the discovery of any confirmed security incident or unauthorized acquisition of unencrypted PHI.
5. Compliance & Legal Inquiries
For questions regarding these legal terms, to request a signed copy of our standard Business Associate Agreement (BAA), or regarding HIPAA compliance and BAA execution, please reach out to:
Ecardius RCM Solutions
Legal & Compliance Department
HIPAA & BAA Desk: [email protected]
General Inquiries: Visit our Contact Us page or email [email protected]