Privacy Policy
How Edge RCM collects, uses, protects and shares information through this website and in the course of providing our services.
1. Who we are
Edge RCM ("Edge RCM", "we", "us" or "our") is a healthcare support company based in Reisterstown, Maryland. We provide medical billing and revenue cycle management, provider credentialing and payer enrollment, state medical licensing support, and healthcare IT services to healthcare organizations across the United States.
This policy explains how we handle information collected through edgercm.com and information you provide when enquiring about or using our services.
2. Scope of this policy
This policy covers information we collect as a business, for example, when a practice administrator submits our contact form or emails us about billing services. It does not govern protected health information that we process on behalf of a client under a business associate agreement; that information is governed by the agreement itself and by HIPAA, as described in section 5.
If you are a patient of a practice we support, this policy does not apply to your health information. Please contact your healthcare provider directly, as they control that information and their notice of privacy practices governs it.
3. Information we collect
3.1 Information you give us
- Contact form submissions: your name, practice name, email address, phone number, state, the service you are interested in, and the content of your message.
- Direct communications: anything you send by email, telephone, video call or post, including documents you share during a consultation or audit.
- Client onboarding information: if you engage us, business details required to deliver services: practice information, provider rosters, credentialing documents, system access details and billing configuration.
3.2 Information collected automatically
- Technical data: IP address, browser type and version, operating system, device type, screen size and referring page.
- Usage data: pages viewed, time on page, navigation paths and interactions such as clicks on call or email links.
- Security data: server logs recording requests to the site, retained to detect and investigate abuse.
3.3 Information we do not want
Please do not submit protected health information, patient names, dates of birth, medical record numbers, insurance ID numbers or clinical details through our website forms or by unsecured email. Our website contact form is not a secure channel for patient data. If you send us such information unsolicited, we will handle it confidentially and delete it as soon as reasonably practicable.
4. How we use information
We use the information described above to:
- respond to your enquiry and arrange a consultation;
- prepare proposals, scopes of work, audits and quotations;
- deliver the services you have engaged us to provide;
- communicate about your account, including service updates and reporting;
- improve our website, services and customer experience;
- maintain the security and integrity of our systems and detect fraud or abuse;
- comply with legal, regulatory, tax and accounting obligations; and
- send occasional business updates where you have asked to receive them.
We do not sell your personal information, and we do not share it with third parties for their own marketing purposes.
5. Protected health information and HIPAA
When we provide billing, credentialing or technology services that involve access to protected health information, we act as a business associate under the Health Insurance Portability and Accountability Act (HIPAA). In that role:
- we execute a written business associate agreement with the covered entity before any protected health information is exchanged;
- we use and disclose protected health information only as permitted by that agreement and by law;
- we apply administrative, physical and technical safeguards designed to protect the confidentiality, integrity and availability of that information;
- we limit access to workforce members who require it to perform the engagement, on a least-privilege basis;
- we maintain audit logging of access to client systems and data; and
- we report security incidents and breaches of unsecured protected health information to the covered entity in accordance with the agreement and applicable law.
Protected health information processed on behalf of a client remains that client's information. We do not use it for our own purposes, we do not sell it, and we return or securely destroy it at the end of the engagement as directed by the agreement.
6. When we share information
We share information only in the following circumstances:
- Service providers. Vendors who support our operations, such as hosting, email delivery, clearinghouses, secure file transfer and practice management platforms, and only to the extent needed to perform their function. Where these vendors may access protected health information, they are bound by written agreements including business associate agreements where required.
- At your direction. Payers, hospitals, state boards, credentialing bodies and other organizations to which you have asked us to submit applications or information on your behalf.
- Legal requirements. Where disclosure is required by law, subpoena, court order or a government or regulatory authority with jurisdiction.
- Protection of rights. Where necessary to investigate, prevent or act on suspected fraud, security incidents, violations of our terms, or threats to the safety of any person.
- Business transfer. In connection with a merger, acquisition or sale of assets, subject to the recipient honoring commitments materially equivalent to those in this policy.
7. Cookies and analytics
This website is deliberately built to be lightweight. It does not load third-party advertising networks, social media tracking pixels or cross-site behavioral advertising trackers, and it does not set advertising cookies.
Where we use analytics to understand how the site is used, we configure it to minimize the personal data collected, and we do not place analytics or marketing tags on pages that handle patient information. Your browser also gives you controls: you can block or delete cookies through your browser settings, and you can enable "Do Not Track" or global privacy control signals, which we respect where technically supported.
If you engage us to build a website, we will advise you on tracking configuration that avoids inadvertently transmitting patient information to advertising platforms, a common and serious exposure on healthcare websites.
8. How we protect information
We maintain a security program that includes:
- encryption of data in transit using current TLS standards, and encryption at rest where supported by the systems involved;
- role-based access control and least-privilege permissions, reviewed when staff join, change role or leave;
- multi-factor authentication on systems that support it;
- workforce confidentiality agreements and periodic privacy and security training;
- logging and monitoring of access to client systems;
- patch and vulnerability management on infrastructure we control; and
- documented incident response and breach notification procedures.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your information, we will notify you as required by the applicable agreement and by law.
9. How long we keep information
We keep enquiry information for as long as needed to respond and for a reasonable period afterwards to maintain a record of business communications, typically no longer than 24 months for enquiries that do not become engagements. Client records are retained for the duration of the engagement and afterwards for the period required by our agreement with you, applicable law and professional record-keeping obligations. Protected health information is returned or destroyed as directed by the business associate agreement. Server and security logs are retained for a short period appropriate to their purpose.
10. Your privacy rights
Depending on where you live, you may have rights to:
- request access to the personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion of information, subject to legal and contractual retention requirements;
- object to or restrict certain processing;
- request a copy of your information in a portable format;
- opt out of marketing communications at any time; and
- not be discriminated against for exercising any of these rights.
Residents of Maryland, California and other states with comprehensive privacy laws may have additional rights under those laws. To exercise a right, email [email protected] with the subject line "Privacy Request". We will verify your identity before acting and will respond within the timeframe required by applicable law. Requests concerning protected health information held on behalf of a covered entity are directed to that covered entity, which is the appropriate party to respond.
11. Children's privacy
Our website and services are directed to healthcare businesses and professionals, not to children. We do not knowingly collect personal information from anyone under 18 through this website. If you believe a child has provided us with information through our website, contact us and we will delete it.
12. Third party links
This website links to third-party sites, including social media platforms and, in client work, external systems and portals. We are not responsible for the privacy practices or content of those sites. We encourage you to read the privacy policy of any site you visit.
13. Changes to this policy
We may update this policy from time to time to reflect changes to our practices, technology, legal requirements or services. The "last updated" date at the top of this page always shows the current version. Material changes will be highlighted on this page, and if you are an active client we will notify you directly where the change affects our handling of your information.
14. How to contact us
Questions, requests or concerns about this policy or our handling of information can be directed to:
- Email: [email protected]
- Phone: +1 (855) 307-4535, Monday to Friday, 8:00 AM to 6:00 PM Eastern Time
- Address: Edge RCM, Reisterstown, MD 21136, United States
See also our Terms & Conditions.
Questions about how we handle your data?
Our team will walk you through our safeguards, business associate agreement and access controls before you share anything sensitive.