Last updated: 2025-11-01
Important: This notice describes how Protected Health Information (PHI) about patients may be used and disclosed by Reformiqs in its capacity as a HIPAA Business Associate, and how you can get access to this information. Please review it carefully.
Reformiqs operates as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the HIPAA Privacy Rule (45 CFR Part 164) and the HIPAA Security Rule. As a Business Associate, we handle Protected Health Information (PHI) on behalf of Covered Entities (healthcare providers) solely to provide contracted medical scribing and documentation services.
We do not act as a Covered Entity and do not have a direct treatment relationship with patients. All PHI we receive is provided to us by the healthcare provider client for the sole purpose of producing clinical documentation.
Before handling any PHI, Reformiqs executes a Business Associate Agreement (BAA) with each Covered Entity client. The BAA governs the permitted uses and disclosures of PHI, our obligations to safeguard PHI, and the procedures for reporting breaches. No PHI is accepted from a client without a signed BAA in place.
Protected Health Information includes any individually identifiable health information transmitted or maintained in any form, including:
Reformiqs uses and discloses PHI only as permitted under our BAA and applicable law:
We do not use PHI for marketing, sell PHI to third parties, or use PHI for any purpose beyond what is necessary to perform our contracted services.
Reformiqs implements the following safeguards to protect PHI:
If Reformiqs engages any subcontractors who will have access to PHI, we require those subcontractors to execute a Business Associate Agreement and comply with the same HIPAA obligations that apply to Reformiqs. We remain responsible for ensuring our subcontractors protect PHI appropriately.
In the event of a breach of unsecured PHI, Reformiqs will notify the affected Covered Entity without unreasonable delay and no later than 60 calendar days after discovery of the breach, as required by the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). Notification will include the information required by 45 CFR §164.410.
Reformiqs applies the minimum necessary standard when using or disclosing PHI — we access, use, and disclose only the minimum amount of PHI necessary to accomplish the intended purpose of the use or disclosure.
PHI is retained for the period specified in the applicable BAA or, in the absence of a specific term, for a minimum of six years from the date of creation or the date it was last in effect, whichever is later. Upon termination of the service relationship, PHI will be returned to the Covered Entity or destroyed in a secure manner, as specified in the BAA.
As a Business Associate, Reformiqs does not have a direct relationship with patients. Patients wishing to exercise their HIPAA rights (access, amendment, accounting of disclosures, etc.) should contact their healthcare provider directly. We will cooperate with Covered Entities to facilitate the exercise of patient rights as required by our BAA.
We reserve the right to change this notice and to make the revised notice effective for PHI we already hold. We will update the "Last updated" date when changes are made. Material changes will be communicated to active Covered Entity clients.
If you believe your privacy rights have been violated, you may file a complaint with:
We will not retaliate against you for filing a complaint.
For questions about this notice or our HIPAA compliance practices:
Reformiqs — Privacy Contact
Email: [email protected]
Phone (USA): +1 754 325 1628
Phone (India): +91 88487 43396