Information Security
Protecting our clients’ data is fundamental to how we operate. As a revenue cycle management partner, ClariMed RCM LLC handles sensitive healthcare and financial information every day, and we treat safeguarding that information as a core responsibility : not an afterthought. We maintain a comprehensive information security program built to align with internationally recognized security and privacy assurance frameworks, and kept audit-ready for independent, third-party review. The same standards and safeguards apply consistently across our U.S. operations and our offshore delivery centers.
Our program is designed to protect the confidentiality, integrity, and availability of every piece of information we handle : including Protected Health Information (PHI) : throughout its lifecycle. Key elements include:
- Controlled access : every user has a unique account, access is granted on a least-privilege, need-to-know basis, and multi-factor authentication is required for remote and administrative access. Access rights are reviewed regularly and removed promptly when no longer needed.
- Strong encryption : sensitive data is encrypted in transit using current protocols (TLS 1.2 or higher) and at rest using strong algorithms (AES-256 or equivalent), with keys managed securely.
- Hardened, monitored systems : we use network segmentation, endpoint protection, secure configuration baselines, timely patching, vulnerability management, and periodic penetration testing to reduce risk and detect threats early.
- Security-minded people : we screen personnel in sensitive roles where permitted by law, require confidentiality and acceptable-use agreements, and provide security and privacy training at onboarding and at least annually.
- Accountable partners : any third party that handles data on our behalf, including our offshore delivery affiliate, is bound to safeguards at least as strict as our own and, where applicable, to a Business Associate Agreement.
- Continuous monitoring and response : security activity is logged and monitored, and a documented incident response plan governs how we detect, contain, and recover from events, including breach notification consistent with HIPAA and applicable law.
- Resilience : we maintain protected backups and business continuity and disaster recovery plans that are tested periodically so we can keep serving clients through disruption.
A Living Program
Security is never “finished.” We assess risks on an ongoing basis, measure how well our controls are working, and improve them in response to new threats, audit findings, and changes in law and regulation : including HIPAA and the data protection requirements of the jurisdictions in which we operate. Our controls are owned by a dedicated Information Security Officer, sponsored by executive management, and reviewed at least annually.
Have questions about our security practices? We’re happy to share more with clients and prospective clients - contact us at compliance@clarimedrcm.com