🎉 Limited Offer: Free Practice Audit + Free EHR Setup for New Clients — Claim Now →
🔒 HIPAA Compliant · info@zenomedix.com · Mon–Fri 8am–8pm ET

HIPAA Compliance Statement

Last Updated: September 13, 2026

Business Associate Agreement

ZenoMedix RCM signs a Business Associate Agreement (BAA) with every client before accessing any Protected Health Information (PHI). We are a HIPAA-covered Business Associate.

Our HIPAA Compliance Program

ZenoMedix RCM maintains a comprehensive HIPAA compliance program that meets and exceeds the requirements of the Health Insurance Portability and Accountability Act of 1996 and the HITECH Act of 2009.

Administrative Safeguards

  • Designated Privacy Officer and Security Officer
  • Annual HIPAA training for all employees and contractors
  • Workforce access controls — employees only access PHI required for their job function
  • HIPAA policies and procedures reviewed and updated annually
  • Business Associate Agreements executed with all sub-contractors handling PHI
  • Incident response procedures for potential breaches

Physical Safeguards

  • Physical access controls at all facilities where PHI is processed
  • Secure workstation use policies — screen locks, clean desk requirements
  • Device and media controls for any hardware containing PHI
  • Secure disposal of any physical media containing PHI

Technical Safeguards

  • All PHI transmission encrypted using TLS 1.3 minimum
  • PHI at rest encrypted using AES-256
  • Multi-factor authentication required for all systems containing PHI
  • Audit logging of all PHI access with regular review
  • Automatic session timeouts on all PHI-processing systems
  • Regular vulnerability assessments and penetration testing

Breach Notification

In the unlikely event of a PHI breach, ZenoMedix RCM follows all required breach notification procedures under the HIPAA Breach Notification Rule: notification to affected covered entities within 60 days of discovery, and support for required notifications to affected individuals and HHS.

Sub-Contractor Management

All sub-contractors or business associates who may access PHI in the course of providing services to ZenoMedix RCM are required to sign Business Associate Agreements and demonstrate equivalent HIPAA compliance standards.

Questions About Our HIPAA Compliance

To request a copy of our BAA template, ask compliance questions, or report a privacy concern:

Email: info@zenomedix.com
Phone: 1-800-XXX-XXXX

Stop Losing Revenue to Billing Errors & Denials

Join 1,500+ healthcare providers who increased collections by up to 30%.