Is VeroRCM HIPAA certified?
There is no official HHS-issued HIPAA certification or government HIPAA seal. When Vero handles PHI for a practice, we do so as a business associate and operate under the applicable Business Associate Agreement.
Medical billing requires us to work with sensitive healthcare information.
When VeroRCM handles protected health information on behalf of a physician practice, we do so as a business associate and use that information for the billing and revenue cycle work we have been asked to perform.
When we work on a practice's billing, we may need access to claims, remittance information, patient information, and other data that is considered protected health information.
We treat that access as part of the responsibility that comes with doing the billing work.
When Vero provides billing and revenue cycle services for a practice, we generally handle PHI as the practice's business associate.
That information may be needed to:
The purpose of having access to that information is to do the work the practice hired us to do.
When our work requires access to PHI, the appropriate Business Associate Agreement is put in place before we begin working with that information.
The BAA sets out how PHI may be used and handled as part of the relationship.
Access to client accounts and healthcare information is limited based on the work someone needs to perform.
Not every person on the Vero team needs access to every client account.
We try to keep access tied to the people actually servicing the practice.
We use technology as part of the billing operation.
It can help identify claims that may need attention, recurring denial patterns, aging accounts, or other areas that deserve review.
Technology assists the billing team.
People remain responsible for reviewing the work and deciding what action should be taken.
Using technology does not change the reason we have access to PHI in the first place: to perform the billing and revenue cycle services authorized by the practice.
If something happens involving PHI that requires us to notify a client practice, we notify the practice as required.
The practice remains the covered entity, and we work with the practice as appropriate when information in our possession is involved.
Patients who want to access their records, request an amendment, or exercise other HIPAA rights should generally contact their physician practice directly.
The practice is the covered entity responsible for the patient's medical record.
If the practice needs information that Vero holds as part of the billing relationship, we assist the practice as appropriate.
Whether a BAA is needed depends on what information we need to review.
If the audit requires access to PHI or a system containing PHI, the appropriate BAA should be in place before that access is provided.
If you are not sure what your audit will require, email team@verorcm.com or use our contact form.
We will walk through what information is needed before you provide access.
There is no official HHS-issued HIPAA certification or government HIPAA seal. When Vero handles PHI for a practice, we do so as a business associate and operate under the applicable Business Associate Agreement.
When our work requires us to access PHI as a business associate, the appropriate BAA is put in place before that work begins.
Access is limited according to the work being performed on the account.
No. PHI received as part of a billing relationship is used for the authorized billing and revenue cycle work, not to market to the practice's patients.
Patients should contact their physician practice or healthcare provider directly.
The information collected through verorcm.com, such as website analytics and contact form submissions, is covered separately by our Privacy Policy.
Our general website forms are not intended for medical records or other patient PHI unless we have specifically instructed you to provide information through an approved process.
Email team@verorcm.com or use our contact form.
For information about the public website, see our Privacy Policy.