Compliance & security
SecureRCM handles protected health information (PHI) as a business associate for U.S. physical therapy practices. Serving independent outpatient PT practices in the United States. Below is an honest checklist of how we approach compliance — not a marketing badge wall.
Business Associate Agreement (BAA)
We execute a signed BAA before accessing PHI or billing systems. No PHI work starts without it.
Where PHI lives and how it moves
- PHI is accessed for billing work through systems you authorize (EHR, clearinghouse, payer portals).
- We use encrypted connections in transit (TLS) for web access.
- Data at rest is protected with encryption where our systems store it (AES-256 where applicable).
- We do not use client PHI to train public AI models or for marketing.
Access controls
- Role-based access: only staff who need PHI for assigned work get it
- Unique user accounts (no shared logins for PHI systems)
- MFA on email and key systems where available
- Access reviewed when people join, change roles, or leave
Workforce training
Billing staff are trained on HIPAA basics, minimum necessary use, phishing awareness, and incident reporting. Training is refreshed periodically.
Breach notification
If we discover a breach of unsecured PHI, we will notify the covered entity without unreasonable delay and within the timelines required by HIPAA (and our BAA), and cooperate on required notices.
SOC 2 / HITRUST status (honest)
SecureRCM does not currently hold a SOC 2 Type II report or HITRUST certification. We are an early-stage team building operational controls first. We will not claim certifications we do not have. Ask us what is in place today if you need detail for your risk review.
Questions
Email info@securercm.com. No phone published on this site.