Privacy Policy

Last Updated: December 12, 2025

MyMedicalBillAudit ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational medical bill review service. We implement security measures aligned with healthcare privacy best practices, though we do not claim formal HIPAA certification or compliance.

Privacy Commitment

MyMedicalBillAudit implements security measures aligned with healthcare privacy best practices. We take reasonable steps to protect your data, including encryption during transmission and, when possible, removal of obvious personal identifiers prior to analysis. We do not claim formal HIPAA certification or compliance.

Information We Collect

Protected Health Information (PHI)

When you upload medical bills or billing documents to our service, we may collect PHI including but not limited to:

  • Patient names, addresses, and dates of birth
  • Medical record numbers and account numbers
  • Diagnosis codes (ICD-10) and procedure codes (CPT, HCPCS)
  • Healthcare provider information and facility names
  • Service dates and billing amounts
  • Insurance information and claim details

Account Information

When you create an account, we collect:

  • Name and email address
  • Account credentials (encrypted passwords)
  • Profile information you choose to provide

Usage Information

We automatically collect certain information about your use of our service:

  • IP addresses and device information
  • Browser type and operating system
  • Pages visited and features used
  • Date and time of access
  • Referring website addresses

How We Use Your Information

Primary Purposes

We use your information for the following purposes:

  • Medical Bill Review: To review your medical bills, identify potential inconsistencies, and generate summary reports for educational purposes
  • Privacy Processing: When possible, we attempt to remove or mask obvious personal identifiers prior to analysis
  • Service Delivery: To provide, maintain, and improve our medical bill auditing service
  • Account Management: To create and manage your account, authenticate users, and provide customer support
  • Communication: To send you service-related notifications, updates, and responses to your inquiries
  • Security: To detect, prevent, and respond to fraud, security incidents, and other harmful activities
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes

Data Minimization

We limit the use and disclosure of your information to what is reasonably necessary to accomplish the intended purpose. Our systems are designed to access only the information required for medical bill review and report generation.

Privacy Processing

When possible, we attempt to remove or mask obvious personal identifiers from your medical billing documents, such as:

  • Names
  • Addresses
  • Dates of birth
  • Telephone numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Account numbers
  • Insurance ID numbers

Note: This process may not be 100% effective. Please do not include SSNs or full credit card numbers in your uploads. This privacy processing is intended to reduce unnecessary exposure but is not guaranteed to remove all identifying information.

Data Security Measures

We implement comprehensive security measures to protect your information:

Technical Safeguards

  • Encryption: 256-bit AES encryption for data at rest and TLS 1.3 encryption for data in transit
  • Access Controls: Role-based access controls (RBAC) and multi-factor authentication
  • Audit Logging: Comprehensive logging of all data access and system activities
  • Vulnerability Management: Regular security assessments and penetration testing
  • Secure Infrastructure: SOC 2 certified cloud infrastructure with redundant systems

Administrative Measures

  • Security Awareness: Security awareness practices for personnel
  • Risk Management: Periodic security reviews
  • Incident Response: Procedures for security incident detection and response

Physical Safeguards

  • Secure Facilities: Restricted physical access to servers and data centers
  • Disaster Recovery: Redundant backup systems and disaster recovery procedures
  • Device Security: Encrypted devices and secure disposal of hardware

Data Sharing and Disclosure

We Do NOT Sell Your Information

We do not sell, rent, or trade your PHI or personal information to third parties for marketing purposes.

Limited Disclosures

We may disclose your information only in the following limited circumstances:

  • With Your Consent: When you explicitly authorize us to share your information
  • Service Providers: To trusted third-party service providers who assist in operating our service (e.g., cloud hosting, AI processing) under appropriate confidentiality terms
  • Legal Requirements: When required by law, court order, or government regulation
  • Protection of Rights: To protect our legal rights, prevent fraud, or ensure the safety of users
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

Your Rights

You have the following rights regarding your information:

Right to Access

You have the right to access and obtain a copy of your information that we maintain. You can view and download your medical bill review reports and uploaded documents at any time through your account dashboard.

Right to Amend

You have the right to request amendments to your information if you believe it is incorrect or incomplete. Contact us using the information below to request an amendment.

Right to an Accounting of Disclosures

You have the right to receive an accounting of certain disclosures of your information that we have made. Contact us to request an accounting.

Right to Request Restrictions

You have the right to request restrictions on how we use or disclose your information. We will consider your request but are not required to agree to all restrictions.

Right to Confidential Communications

You have the right to request that we communicate with you about your information in a specific way or at a specific location.

Right to Deletion

You have the right to request deletion of your information and account data. You can delete your account and all associated data through your account settings, or contact us for assistance.

Right to Data Portability

You have the right to receive your information in a structured, commonly used, and machine-readable format. You can export your data through your account dashboard.

Data Retention and Deletion

Retention Periods

We retain your information for the following periods:

  • Medical Bills and Reports: Retained for the duration of your account plus a reasonable period after account closure
  • Account Information: Retained for the duration of your account plus a reasonable period after account closure
  • Usage Logs: Retained for a reasonable period for security and service improvement purposes
  • Anonymized Data: May be retained indefinitely for research, quality improvement, and service enhancement purposes

Secure Deletion

When data is deleted (either at your request or at the end of the retention period), we use secure deletion methods to ensure the data cannot be recovered. This includes overwriting data on storage media and destroying backup copies according to industry best practices.

Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Maintain your login session and authenticate your account
  • Remember your preferences and settings
  • Analyze usage patterns and improve our service
  • Prevent fraud and enhance security

You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of our service. We do not use third-party advertising cookies or track you across other websites.

Children's Privacy

Our service is not intended for children under 18 years of age. We do not knowingly collect PHI or personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately so we can delete it.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  • Posting the updated Privacy Policy on our website with a new "Last Updated" date
  • Sending you an email notification to the address associated with your account
  • Displaying a prominent notice on our service

Your continued use of our service after the effective date of the updated Privacy Policy constitutes your acceptance of the changes. If you do not agree with the updated Privacy Policy, you should discontinue use of our service and delete your account.

Breach Notification

In the event of a breach of unsecured PHI, we will notify affected individuals without unreasonable delay and no later than 60 days after discovery of the breach, as required by HIPAA. We will also notify the U.S. Department of Health and Human Services and, if applicable, prominent media outlets.

Our breach notification will include:

  • A description of what happened and when the breach occurred
  • The types of PHI involved in the breach
  • Steps you should take to protect yourself
  • What we are doing to investigate, mitigate, and prevent future breaches
  • Contact information for questions and assistance

Contact Us

If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a privacy concern, please contact us:

Privacy Officer

MyMedicalBillAudit

Email: [email protected]

For general inquiries or customer support, please visit our About page.

Filing a Complaint

If you believe your privacy rights have been violated, you have the right to file a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against you for filing a complaint.

U.S. Department of Health and Human Services
Office for Civil Rights
Website: www.hhs.gov/ocr/privacy/hipaa/complaints/
Phone: 1-877-696-6775

This Privacy Policy is effective as of December 12, 2025, and applies to all information collected by MyMedicalBillAudit.

My Medical Bill Audit is an assumed business name of RB Imports LLC, an Indiana limited liability company.

10769 Broadway, #132, Crown Point, IN 46307, USA