Compliance

ZenoMed Privacy Policy & Data Protection Practices

Your privacy is important to us. This policy explains how we collect, use and protect your information.

Last updated: January 2025

Information We Collect

We collect personal information you provide directly to us when you interact with our services. The types of personal information we may collect include:

  • Contact information: name, email address, phone number, mailing address
  • Practice information: practice name, medical specialty, location, NPI numbers
  • Professional information: medical credentials, licensing information, certifications
  • Billing and payment information: payment details, billing addresses, financial account information
  • Communication data: records of communications with our support team, feedback and inquiries
  • Technical information: IP address, browser type and device information when you visit our website
  • SMS/text messaging: phone numbers for appointment reminders and practice communications (with your consent)

Protected Health Information (PHI)

As a HIPAA-compliant business associate, ZenoMed may also handle Protected Health Information on behalf of healthcare providers. All PHI is handled in strict accordance with HIPAA regulations and stored on secure 256-bit encrypted servers.

Cookies and Tracking Technologies

We use cookies and similar technologies to understand how visitors use our website and to measure the effectiveness of our marketing.

  • Google Analytics (GA4): collects anonymised usage data such as pages visited, time on site and general traffic patterns.
  • Google Ads conversion tracking: records when a visitor completes an action we consider a lead, such as submitting our contact form.

These tools may set cookies or use similar identifiers in your browser. We do not use this data to identify individual patients or to process PHI — PHI is never used for analytics or advertising purposes. You can control or disable cookies through your browser settings, and you can opt out of Google Analytics using Google's browser add-on. Disabling cookies may affect how parts of our website function.

How We Use Your Information

  • Service delivery: provide, maintain and improve our medical billing and RCM services
  • Transaction processing: process payments, billing and send related financial information
  • Communication: send service updates, technical notices, support messages and respond to inquiries
  • Practice management: assist with credentialing, insurance verification and administrative tasks
  • SMS communications: send appointment reminders, billing notifications and practice updates with your explicit consent
  • Compliance: meet legal obligations, maintain HIPAA compliance and protect our rights and your data
  • Quality improvement: analyse service performance and improve our processes

Lawful Basis for Processing

We process your personal information based on (1) your consent, (2) performance of our contract with you, (3) our legitimate business interests, and (4) compliance with legal obligations.

SMS Communications and Privacy

When you opt in to receive SMS messages from ZenoMed, we collect your phone number and optionally your name or other contact details via our secure web form or lead form. You have given explicit consent to receive these messages, for example by checking an opt-in box or replying "Yes".

Types of SMS messages we send

  • Account notifications and service updates
  • Customer support communications
  • Delivery and credentialing status updates
  • Occasional informational or educational updates about billing and compliance

Your SMS rights and controls

  • Opt-out: reply STOP at any time to unsubscribe from SMS messages
  • Help: reply HELP for assistance or contact us directly
  • Rates: message and data rates may apply based on your mobile plan
  • Data access: you may request access, correction or deletion of your SMS-related data

SMS data protection

SMS consent is not shared with third parties or affiliates. We may share your information with trusted service providers who assist with message delivery, subject to confidentiality safeguards. SMS data is stored on encrypted servers and accessed only by authorised personnel.

Information Sharing

We do not sell, trade or rent your personal information to third parties. We may share your personal information only in the following limited circumstances:

  • Service providers: trusted vendors who help us operate our business, such as cloud hosting and payment processing, under strict confidentiality agreements
  • Healthcare providers: with your practice as necessary to provide our services
  • Legal requirements: when required by law, court order, or to protect our rights and safety
  • Business transfers: in connection with a merger, acquisition or sale of assets, with continued privacy protection
  • With your consent: when you explicitly authorise us to share your information

HIPAA-protected information

Protected Health Information is shared only as permitted under our Business Associate Agreement and HIPAA regulations. We never use or disclose PHI for marketing purposes or share it with unauthorised parties.

Data Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure or destruction. All PHI is stored on secure 256-bit encrypted servers running on HIPAA-compliant infrastructure.

Your Rights

  • Access: request access to the personal information we hold about you
  • Correction: request correction of inaccurate or incomplete personal information
  • Deletion: request deletion of your personal information, subject to legal requirements
  • Portability: request a copy of your data in a portable format
  • Opt-out: unsubscribe from marketing communications and SMS messages at any time
  • Restrict processing: request limitation of how we process your personal information
  • Complaint: file a complaint with regulatory authorities if you believe your privacy rights have been violated

State-specific privacy rights

California residents have additional rights under the CCPA, as amended by the CPRA, including the right to know what personal information we collect, the right to delete it, and the right to opt out of its sale or sharing (we do not sell or share personal information). Virginia residents have similar rights under the VCDPA.

To exercise any of these rights, contact us using the details below. We will respond to your request within 30 days. To stop receiving SMS messages, reply STOP to any text message or contact us directly.

Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including:

  • For the duration of our service relationship with you
  • As required by applicable laws and regulations
  • To resolve disputes and enforce our agreements
  • For legitimate business purposes such as fraud prevention

PHI is retained in accordance with HIPAA requirements and your healthcare provider's record retention policies.

Contact ZenoMed

Questions about this page, your data or your rights? Our compliance team responds within one business day.