HIPAA & Business Associate Notice
How Medical Billing Wyoming protects and handles Protected Health Information when providing healthcare business and technology services.
Effective Date: August 31, 2026Medical Billing Wyoming (“MBW,” “we,” “us,” or “our”) provides medical billing, revenue cycle management, credentialing, transcription, and healthcare technology services to healthcare organizations.
Some of these services may involve MBW creating, receiving, maintaining, or transmitting Protected Health Information (“PHI”) on behalf of a healthcare organization. When applicable, MBW acts as a Business Associate under the Health Insurance Portability and Accountability Act (“HIPAA”).
This notice describes MBW’s general approach to protecting and handling PHI in its role as a Business Associate.
MBW’s Role as a Business Associate
MBW may perform services for healthcare providers and organizations that require access to PHI.
Where HIPAA applies, MBW will act as a Business Associate in accordance with the applicable Business Associate Agreement (“BAA”) and applicable HIPAA requirements.
MBW does not operate as the healthcare provider responsible for a patient’s treatment or as the entity responsible for issuing the healthcare provider’s Notice of Privacy Practices.
Protected Health Information
PHI may include individually identifiable health information that MBW creates, receives, maintains, or transmits while performing services for a healthcare client.
The types of PHI MBW may handle depend on the services provided and may include information contained in claims, billing records, eligibility information, medical documentation, transcription records, or related healthcare business records.
Permitted Uses & Disclosures
MBW may use or disclose PHI as permitted or required by the applicable BAA, HIPAA, or other applicable law.
Depending on the services provided, permitted activities may include:
- Medical billing and revenue cycle management
- Claims processing and payment-related activities
- Medical coding and documentation support
- Provider credentialing and payer-related activities
- Eligibility and benefits verification
- Accounts receivable and denial management
- Medical transcription and dictation support
- Healthcare technology and workflow services
- Other activities specifically authorized by the applicable client agreement or BAA
Minimum Necessary Use
MBW applies the HIPAA minimum necessary principle where applicable and takes reasonable steps to limit access, use, and disclosure of PHI to what is necessary to perform authorized functions and services.
Access to PHI is limited according to job responsibilities, authorized services, system permissions, and applicable contractual requirements.
Security Safeguards
MBW maintains administrative, physical, and technical safeguards designed to protect electronic Protected Health Information (“ePHI”) against unauthorized access, use, disclosure, alteration, or destruction.
Safeguards may include appropriate access controls, authentication, authorization, system protections, monitoring, workforce procedures, and other security measures appropriate to the systems and information involved.
PracticeOS™
PracticeOS™ may be used to support EHR, practice management, workflow, and related healthcare business functions.
Where PracticeOS™ processes PHI on behalf of a healthcare organization, the applicable use and handling of PHI will be governed by the applicable BAA, service agreement, and HIPAA requirements.
Access to PracticeOS™ is limited to authorized users and is subject to applicable account, security, and acceptable-use requirements.
DictaFlow™
DictaFlow™ supports medical dictation and transcription workflows and may process clinical audio, transcribed documentation, or related information.
Where information processed through DictaFlow™ constitutes PHI, it will be handled in accordance with the applicable BAA, service agreement, and HIPAA requirements.
Access to DictaFlow™ is restricted to authorized users and personnel based on applicable roles and permissions.
Business Associate Agreements
Where required by HIPAA, MBW enters into appropriate Business Associate Agreements with covered entities or other business associates before handling PHI on their behalf.
BAAs establish permitted and required uses and disclosures of PHI and address applicable safeguards, reporting obligations, subcontractors, and other HIPAA requirements.
Where these provisions conflict with a valid BAA regarding PHI, the applicable BAA will control.
Subcontractors & Service Providers
MBW may use authorized subcontractors and service providers to support its operations and provide contracted services.
Where a subcontractor creates, receives, maintains, or transmits PHI on behalf of MBW in a manner subject to HIPAA, MBW will require appropriate contractual protections consistent with applicable HIPAA requirements.
Security Incidents
MBW maintains processes designed to identify, investigate, respond to, and document security incidents involving information systems.
MBW will handle reportable security incidents involving PHI in accordance with applicable HIPAA requirements and the applicable BAA.
Breach Notification
If MBW discovers a breach of unsecured PHI for which HIPAA breach notification requirements apply, MBW will notify the applicable covered entity or business associate in accordance with HIPAA and the applicable BAA.
MBW will provide required notifications without unreasonable delay and within the timeframes required by applicable law and the applicable BAA.
The applicable covered entity generally remains responsible for notifications to affected individuals, the Secretary of HHS, and the media when required, although responsibilities may be delegated to a business associate under the applicable arrangement.
Individual Rights & Requests
MBW supports applicable client obligations relating to individuals’ HIPAA rights as required by the applicable BAA and law.
Because MBW generally acts as a Business Associate rather than the individual’s healthcare provider, requests concerning an individual’s medical records, Notice of Privacy Practices, treatment, or other patient rights should generally be directed to the applicable healthcare provider or covered entity.
Where MBW is required to assist a covered entity with an individual request, MBW will provide such assistance as required by the applicable BAA and HIPAA.
Confidentiality
MBW treats PHI and other confidential client information as confidential and uses appropriate controls to limit access to authorized personnel and service providers.
Workforce members and other authorized individuals may be subject to confidentiality obligations appropriate to their responsibilities.
Data Retention & Disposal
PHI and other information may be retained for the period necessary to perform contracted services, satisfy contractual obligations, comply with applicable legal requirements, maintain appropriate business records, and fulfill other legitimate operational requirements.
Return or destruction of PHI following termination of a Business Associate relationship will be handled in accordance with the applicable BAA and applicable law.
No Sale of PHI
MBW does not sell PHI received from healthcare clients for independent commercial purposes.
Uses and disclosures of PHI remain subject to the applicable BAA, HIPAA requirements, and applicable law.
Patient Notice of Privacy Practices
MBW generally acts as a Business Associate and is not the healthcare provider responsible for a patient’s Notice of Privacy Practices.
MBW does not provide or replace the Notice of Privacy Practices of a healthcare provider or health plan.
Patients seeking information about how their healthcare provider uses or discloses their PHI should contact the applicable healthcare provider or covered entity.
Changes to This Notice
MBW may update this notice periodically to reflect changes in our services, technology, security practices, contractual requirements, or applicable law.
Updated versions will be posted on this page with a revised effective date.
Contact Us
Questions regarding MBW’s handling of PHI, HIPAA-related practices, or this notice may be directed to:
