Legal · Healthcare Compliance

HIPAA Notice of Privacy Practices

Last updated: 2025-11-01

Important: This notice describes how Protected Health Information (PHI) about patients may be used and disclosed by Reformiqs in its capacity as a HIPAA Business Associate, and how you can get access to this information. Please review it carefully.

1. Our Role Under HIPAA

Reformiqs operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the HIPAA Privacy Rule (45 CFR Part 164) and the HIPAA Security Rule. As a Business Associate, we handle Protected Health Information (PHI) on behalf of Covered Entities (healthcare providers) solely to provide contracted medical scribing and documentation services.

We do not act as a Covered Entity and do not have a direct treatment relationship with patients. All PHI we receive is provided to us by the healthcare provider client for the sole purpose of producing clinical documentation.

2. Business Associate Agreement

Before handling any PHI, Reformiqs executes a Business Associate Agreement (BAA) with each Covered Entity client. The BAA governs the permitted uses and disclosures of PHI, our obligations to safeguard PHI, and the procedures for reporting breaches. No PHI is accepted from a client without a signed BAA in place.

3. What Constitutes PHI

Protected Health Information includes any individually identifiable health information transmitted or maintained in any form, including:

  • Patient names, dates of birth, addresses, and contact information
  • Medical record numbers and account numbers
  • Clinical notes, diagnoses, treatment plans, and medication information
  • Audio recordings of patient encounters submitted for transcription
  • Any other information that could identify a patient and relates to their health condition or care

4. Permitted Uses and Disclosures of PHI

Reformiqs uses and discloses PHI only as permitted under our BAA and applicable law:

  • Service delivery: To produce clinical documentation (scribing, transcription, pre-charting) as contracted
  • Quality assurance: Internal review of completed notes by quality specialists to ensure accuracy
  • Legal compliance: As required by law, including responses to valid legal process
  • Breach notification: To notify the Covered Entity and, where required, relevant authorities of any breach of unsecured PHI

We do not use PHI for marketing, sell PHI to third parties, or use PHI for any purpose beyond what is necessary to perform our contracted services.

5. Safeguards for PHI

Reformiqs implements the following safeguards to protect PHI:

  • Administrative safeguards: HIPAA training for all staff who handle PHI; access controls limiting PHI access to authorised personnel only; documented policies and procedures for PHI handling
  • Physical safeguards: Secure workstations; screen lock policies; restricted physical access to systems containing PHI
  • Technical safeguards: Encryption of PHI in transit and at rest; unique user authentication; audit logs of PHI access; secure communication channels for PHI transmission

6. Subcontractors

If Reformiqs engages any subcontractors who will have access to PHI, we require those subcontractors to execute a Business Associate Agreement and comply with the same HIPAA obligations that apply to Reformiqs. We remain responsible for ensuring our subcontractors protect PHI appropriately.

7. Breach Notification

In the event of a breach of unsecured PHI, Reformiqs will notify the affected Covered Entity without unreasonable delay and no later than 60 calendar days after discovery of the breach, as required by the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). Notification will include the information required by 45 CFR §164.410.

8. Minimum Necessary Standard

Reformiqs applies the minimum necessary standard when using or disclosing PHI — we access, use, and disclose only the minimum amount of PHI necessary to accomplish the intended purpose of the use or disclosure.

9. Retention and Destruction of PHI

PHI is retained for the period specified in the applicable BAA or, in the absence of a specific term, for a minimum of six years from the date of creation or the date it was last in effect, whichever is later. Upon termination of the service relationship, PHI will be returned to the Covered Entity or destroyed in a secure manner, as specified in the BAA.

10. Patient Rights

As a Business Associate, Reformiqs does not have a direct relationship with patients. Patients wishing to exercise their HIPAA rights (access, amendment, accounting of disclosures, etc.) should contact their healthcare provider directly. We will cooperate with Covered Entities to facilitate the exercise of patient rights as required by our BAA.

11. Changes to This Notice

We reserve the right to change this notice and to make the revised notice effective for PHI we already hold. We will update the "Last updated" date when changes are made. Material changes will be communicated to active Covered Entity clients.

12. Complaints

If you believe your privacy rights have been violated, you may file a complaint with:

We will not retaliate against you for filing a complaint.

13. Contact Our Privacy Officer

For questions about this notice or our HIPAA compliance practices:

Reformiqs — Privacy Contact

Email: [email protected]

Phone (USA): +1 754 325 1628

Phone (India): +91 88487 43396