Home / Privacy & HIPAA

Privacy & HIPAA practices

Last updated: September 30, 2026

Information from this website

When you fill in the contact form or email us, we receive the details you choose to send: your name, email, practice name, phone, specialty, software and message. We use them only to reply to you and discuss our services. We do not sell or rent this information. Please do not send patient information (PHI) through the website form or email.

Form submissions are delivered to our inbox through a third-party form service (Web3Forms). The site is hosted on Cloudflare, which may log basic technical data such as IP address for security.

Protected health information (PHI)

  • We sign a Business Associate Agreement (BAA) with every client before accessing any PHI.
  • We work inside the client's own practice management / EHR systems using individual user accounts; we do not copy PHI into our own systems.
  • PHI is never stored on personal devices, shared outside the assigned team, or used for any purpose other than the client's billing.
  • Access is removed as soon as an engagement ends or a team member no longer needs it.
  • Any suspected security incident is reported to the client promptly, as required by the BAA.

Your choices

You can ask us at any time to delete the contact details you sent through this website by emailing [email protected].

Contact

TrueCycle RCM · [email protected]