Privacy Policy
VeriMedix LLC – Medical Billing & Revenue Cycle Management Services
Website: VeriMedix.com
Last updated: February 21, 2026
Introduction
VeriMedix LLC (“we,” “our,” or “us”) operates VeriMedix.com and provides medical billing and revenue cycle management (RCM) services to healthcare providers, practices, clinics, and facilities throughout the United States.
This Privacy Policy explains how we collect, use, disclose, store, and protect information, including Protected Health Information (PHI), when healthcare providers engage our Services.
By using our website or engaging our Services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of information as described herein, in accordance with HIPAA, applicable state privacy laws, and other relevant regulations.
Note: This Privacy Policy applies only to VeriMedix.com and our medical billing/RCM services for healthcare providers. For privacy practices related to clinical and psychological assessment services for patients (ESA letters, behavioral health assessments, etc.), please refer to the separate Privacy Policy at www.PetESALetter.com.
1. Information We Collect
1.1 Healthcare Provider Information
Practice name and business information
Provider names, credentials, and NPI (National Provider Identifier) numbers
Tax identification numbers (TIN/EIN)
Contact information (email, phone, mailing address)
Licensing and credentialing information
Bank account information for payment remittance
1.2 Protected Health Information (PHI)
As part of providing billing and RCM services, we access, use, and disclose PHI on behalf of healthcare provider clients, including:
Patient demographic information (names, dates of birth, addresses, contact information)
Insurance information (policy numbers, group numbers, subscriber information)
Clinical information necessary for billing and coding (diagnoses, procedure codes, dates of service, treating providers)
Medical record documentation to support claims and appeals
Payment and claims history
This information is considered PHI under HIPAA and is subject to strict confidentiality and security requirements.
1.3 Technical and Usage Information
When you visit VeriMedix.com, we may automatically collect:
IP address
Browser type and version
Device type and operating system
Pages visited and links clicked
Date and time of visits
Referring website or source
Cookies and similar tracking technologies (see Section 7)
2. How We Use Information
2.1 To Provide Medical Billing and RCM Services
Submit claims to payers (insurance companies, Medicare, Medicaid, patients)
Process and post payments
Follow up on accounts receivable and denied claims
Prepare and submit appeals and reconsiderations
Provide reporting and analytics to healthcare provider clients
Conduct provider enrollment and credentialing with payers
Verify patient insurance eligibility and benefits
2.2 To Communicate With Healthcare Provider Clients
Respond to inquiries, questions, and support requests
Send service updates, reports, and notifications
Provide training and onboarding support
Discuss billing issues, denials, and claim status
2.3 To Improve Our Services
Analyze service performance and identify areas for improvement (in aggregated or de-identified form where possible)
Conduct internal quality assurance and compliance audits
Develop new features and service offerings
2.4 To Comply With Legal and Regulatory Obligations
Comply with federal, state, and local laws, regulations, and professional standards
Respond to subpoenas, court orders, and government requests
Maintain records as required by law, HIPAA, and payer contracts
Report suspected fraud, waste, or abuse as required by law
3. Legal Basis for Processing (Where Applicable)
Where required by applicable law, we process information based on one or more of the following legal bases:
Contract Performance: Processing is necessary to provide the Services contracted by the healthcare provider
Legal Obligation: Processing is required to comply with applicable laws, regulations, or legal process
Legitimate Interests: Processing is necessary for our legitimate business interests (such as improving Services, preventing fraud, and ensuring security), balanced against privacy rights
4. How We Share Information
VeriMedix LLC does not sell, rent, or trade PHI or other confidential information to third parties. We may share information only in the following limited circumstances:
4.1 With Healthcare Provider Clients
We share billing, payment, and claims information with the healthcare provider clients who engage our Services.
4.2 With Payers (Insurance Companies, Medicare, Medicaid)
We submit claims and communicate with payers on behalf of our healthcare provider clients, including sharing PHI necessary for claims adjudication, payment processing, and coordination of benefits.
4.3 With Service Providers and Business Associates
We may share information with trusted third-party service providers who perform functions on our behalf, including:
Practice management and billing software vendors
Clearinghouses (for electronic claims submission)
Payment processors and banking institutions
Cloud storage and data hosting providers
IT security and technical support providers
All service providers are required to maintain confidentiality and security of information and are permitted to use information only as necessary to perform services for us, in compliance with HIPAA Business Associate Agreement requirements.
4.4 As Required by Law
We may disclose information when required by law, regulation, court order, subpoena, legal process, or government authority, including:
Responding to lawful requests from public authorities (CMS, OIG, state Medicaid agencies, law enforcement, courts)
Complying with mandatory reporting requirements (fraud, waste, abuse)
Cooperating with audits and investigations
4.5 Business Transfers
In the event of a merger, acquisition, sale of assets, bankruptcy, or other business transaction, information (including PHI) may be transferred to the successor entity, subject to continued protection under this Privacy Policy, HIPAA, and applicable law.
5. HIPAA and Protected Health Information (PHI)
5.1 Business Associate Relationship
VeriMedix LLC acts as a Business Associate under HIPAA when handling PHI on behalf of healthcare provider clients (who are “Covered Entities”).
We execute a Business Associate Agreement (BAA) with each healthcare provider client, which outlines our obligations to:
Use and disclose PHI only as permitted by the BAA and HIPAA
Implement appropriate safeguards to protect PHI
Report breaches of unsecured PHI
Make PHI available to individuals upon request (as directed by the Covered Entity)
Return or destroy PHI upon termination of services
5.2 Healthcare Provider Responsibilities
Healthcare providers (“Covered Entities”) remain responsible for:
Ensuring patients are provided with Notice of Privacy Practices
Obtaining patient authorizations when required
Responding to patient requests for access to PHI
Handling patient complaints related to privacy
VeriMedix LLC supports these obligations but does not have a direct relationship with patients.
6. Patient Rights Under HIPAA
Patients have rights under HIPAA regarding their PHI, including:
Right to Access: Request and receive a copy of their PHI
Right to Request Corrections: Request amendments to their PHI
Right to an Accounting of Disclosures: Receive a list of certain disclosures of PHI
Patients should direct all requests related to their PHI to their healthcare provider (the Covered Entity). If VeriMedix LLC receives a patient request directly, we forward it to the appropriate healthcare provider client.
7. Cookies and Tracking Technologies
Our website may use cookies, web beacons, pixels, and similar tracking technologies to:
Remember preferences and settings
Authenticate sessions and keep users logged in
Analyze website traffic and usage patterns (in aggregate form)
Improve website functionality and user experience
7.1 Types of Cookies We Use
Essential Cookies: Necessary for website function (e.g., session management, security)
Analytics Cookies: Help understand visitor usage (e.g., Google Analytics, aggregated/anonymized data)
Preference Cookies: Remember settings and preferences for future visits
7.2 Managing Cookies
You can control cookies through your web browser settings. Blocking or deleting cookies may affect website functionality.
Learn more at www.allaboutcookies.org.
8. Data Security
We implement reasonable safeguards to protect information, including:
Encryption: SSL/TLS for data transmission; PHI encryption at rest
Access Controls: Role-based access; unique user IDs; multi-factor authentication
Audit Controls: Logging and monitoring system access and activity
Secure Infrastructure: Firewalls, intrusion detection, secure data centers
Staff Training: Regular privacy and security training
HIPAA Compliance: Policies in line with HIPAA Security Rule
No method is 100% secure; we cannot guarantee absolute security.
9. Data Retention
We retain information as long as necessary to:
Provide services to healthcare provider clients
Comply with legal and regulatory obligations
Resolve disputes, enforce agreements, and defend legal claims
Retention periods vary depending on information type, legal requirements, and audit/compliance needs. Upon expiration, we return, destroy, or de-identify PHI per BAA and law.
10. Healthcare Provider Rights
Healthcare providers engaging our Services have the right to:
Request access to information we hold on their behalf
Request corrections or updates
Request an accounting of disclosures of PHI
Request restrictions on certain uses or disclosures (subject to HIPAA)
Terminate the Business Associate relationship in accordance with the Service Agreement
Contact us to exercise these rights.
11. International Users and Data Transfers
VeriMedix LLC is based in the U.S., and our Services are for U.S. healthcare providers. Information is stored and processed in the U.S. in compliance with HIPAA.
12. Third-Party Links
Our website may link to third-party websites or services. We are not responsible for their privacy practices. Review their privacy policies when visiting.
13. Changes to This Privacy Policy
VeriMedix LLC may update this Privacy Policy at any time. The “Last updated” date reflects the latest revision.
Active healthcare provider clients will be notified of material changes via email or Client portal. Continued use constitutes acceptance of the updated Privacy Policy.
14. Contact Information
VeriMedix LLC
Medical Billing & Revenue Cycle Management
Privacy Officer
Phone: +1 (470) 887-9106
Email: [email protected]
Address: Conover, North Carolina, United States
Website: www.verimedix.com
For privacy practices related to clinical and psychological assessment services (ESA letters, behavioral health assessments, etc.), please visit www.PetESALetter.com.
