MedfirstRCM
Legal

Privacy Policy

This policy explains how MedfirstRCM handles personal information and protected health information (PHI) in connection with our services.

Last updated: July 1, 2026

Scope

This Privacy Policy applies to visitors of our website and to clients who engage MedfirstRCM for revenue cycle management and related services.

When we act as a business associate to a covered entity, our handling of PHI is also governed by a Business Associate Agreement (BAA) and applicable HIPAA rules.

Information we collect

We may collect contact details you submit via forms (name, email, phone, practice or lab name), technical data such as IP address and browser type, and — when providing services — billing, claims, and clinical documentation necessary to perform RCM.

We do not sell personal information.

How we use information

We use information to respond to inquiries, deliver contracted services, improve our operations, meet legal obligations, and communicate about audits, reports, and service updates.

Marketing emails are opt-in; you may unsubscribe at any time.

Sharing

We share information with subprocessors needed to deliver services (for example, secure hosting or clearinghouse partners), under contractual privacy and security obligations.

We may disclose information if required by law or to protect rights, safety, and security.

Security

We maintain administrative, technical, and physical safeguards designed to protect information, including access controls, encryption in transit, and workforce training.

No method of transmission or storage is 100% secure; we continuously improve our controls.

Contact

For privacy questions, contact billing@medfirstrcm.com or write to us at 212 N. 2nd St. STE 100, Richmond, KY 40475.