1. Scope
This Policy covers information processed by MBS as a service provider to contracted agencies. Protected Health Information (PHI) is separately governed by the Business Associate Agreement (BAA) between MBS and your agency; see the BAA Notice.
2. Information We Collect
- Account information: name, work email, role, agency affiliation.
- Agency operational data: billing, denials, appeals, credentialing, compliance, and reporting records your agency or MBS staff upload or generate.
- Usage data: log-in events, feature usage, audit trail, and diagnostic logs used for security and reliability.
- Support communications: messages, notes, and files you send to MBS.
3. How We Use Information
- To provide contracted revenue cycle, credentialing, and compliance services.
- To operate, secure, monitor, and improve the Portal.
- To meet legal, regulatory, and contractual obligations.
- To communicate about your account, invitations, notifications, and support.
4. Legal Basis and Roles
For PHI, MBS acts as a Business Associate to your agency (the Covered Entity) under HIPAA. For non-PHI account and usage data, MBS acts as the data controller for security, billing, and product operation purposes.
5. Sharing
MBS does not sell personal information. We share information only:
- Within your agency's own tenant, subject to role-based access.
- With vetted subprocessors that support hosting, email, error monitoring, and analytics under written data-protection terms.
- When required by law, subpoena, or to protect rights, safety, and system integrity.
6. Subprocessors
A current list of subprocessors is available on request to privacy@martinbillingsolutions.com. Material changes to subprocessors that handle PHI are communicated to agency administrators.
7. Security
MBS implements administrative, technical, and physical safeguards designed to protect information, including strict multi-tenant isolation, role-based access controls, encrypted transport, audit logging, invitation-only account provisioning, session timeouts, and least-privilege database policies. No system is perfectly secure; report suspected incidents immediately (see Section 11).
8. Retention
MBS retains records for the period required by your service agreement, applicable law, and regulatory recordkeeping requirements. Historical financial ledger entries are preserved on an append-only basis. Deleted records enter a Trash / Recycle Bin subject to agency retention settings before permanent removal.
9. Your Choices
- Manage notification preferences in-app.
- Request access to, correction of, or deletion of information through your agency administrator, who will coordinate with MBS as permitted by law and the underlying agreement.
10. Children
The Portal is a business tool and is not directed to individuals under 18. Records pertaining to minor patients are handled as PHI under the BAA, not as consumer data.
11. Contact and Incident Reporting
Privacy questions: privacy@martinbillingsolutions.com. Suspected security incidents: security@martinbillingsolutions.com.
12. Changes
We will update this Policy as our practices evolve. Material changes will be communicated to agency administrators before taking effect.