Legal
HIPAA Compliance
Vertex Medical Billing is fully committed to protecting Protected Health Information (PHI) and complying with the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
Last updated: May 13, 2026
Our Commitment to Privacy and Security
As a Business Associate under HIPAA, Vertex Medical Billing handles Protected Health Information on behalf of covered entities. We understand the critical importance of maintaining the confidentiality, integrity, and availability of PHI, and we have implemented comprehensive safeguards to meet and exceed HIPAA requirements.
Our compliance program is designed to protect patient data throughout its lifecycle - from initial collection through processing, storage, transmission, and eventual secure disposal.
HIPAA Safeguards
Administrative Safeguards
We implement comprehensive security management policies, workforce training programs, and access authorization procedures. All staff complete annual HIPAA training and sign confidentiality agreements.
Physical Safeguards
Our facilities and systems feature controlled access, workstation security, and device and media controls. Physical access to PHI storage areas is restricted to authorized personnel only.
Technical Safeguards
We employ AES-256 encryption for data at rest and TLS 1.3 for data in transit. Multi-factor authentication, automatic logoff, and audit controls protect against unauthorized access.
Workforce Training
All employees receive initial and annual HIPAA training covering privacy rules, security standards, breach notification procedures, and incident response protocols.
Business Associate Agreements
We execute Business Associate Agreements (BAAs) with all covered entities and subcontractors. These agreements ensure all parties maintain HIPAA compliance when handling PHI.
Risk Assessment & Auditing
We conduct annual security risk assessments, quarterly internal audits, and continuous monitoring of our systems. Vulnerability scans and penetration testing are performed by third-party security firms.
Breach Notification Procedures
In the unlikely event of a breach of unsecured PHI, we follow strict breach notification procedures:
- Discovery and documentation of the breach within 24 hours
- Risk assessment to determine breach severity and notification obligations
- Notification to affected covered entities within 60 days of discovery
- Notification to the Secretary of HHS when required (500+ individuals affected)
- Media notification when required (500+ individuals in the same state/jurisdiction)
- Implementation of corrective actions to prevent future breaches
Your Rights
Under HIPAA, patients have rights regarding their PHI. As a Business Associate, we support our covered entity clients in honoring these rights:
- Right to access and obtain copies of PHI
- Right to request corrections to PHI
- Right to request restrictions on uses and disclosures
- Right to receive an accounting of disclosures
- Right to file a complaint with the Office for Civil Rights (OCR)
Contact Our Compliance Officer
If you have questions about our HIPAA compliance program or need to report a privacy or security concern, please contact our Compliance Officer:
Vertex Medical Billing - Compliance Department
28 E Jones Ave
Edgewater Park, NJ 08010
Phone: 732-209-1487
Questions about this policy?
Reach out to our Compliance Officer or our team and we will respond to your privacy or security question.
