Last Updated: January 14, 2026
Health Quest Billing LLC (“HQB,” “we,” “our,” or “us”) is committed to protecting the privacy and security of Protected Health Information (“PHI”) in accordance with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and all applicable federal privacy and security regulations.
This HIPAA Compliance Statement explains how HQB safeguards PHI when providing revenue cycle management, medical billing, credentialing, payer enrollment, denial management, and related administrative services to healthcare providers.
HQB performs services that require access to PHI on behalf of covered entities (healthcare providers).
As a Business Associate, HQB enters into a legally binding Business Associate Agreement (“BAA”) with every client requiring PHI access.
The BAA outlines:
HQB does not use PHI for marketing, data mining, or any activity unrelated to contracted operations. HQB maintains a signed and current BAA with each client before accessing or processing PHI.
HQB maintains internal policies, controls, and workforce procedures that limit PHI access and protect data confidentiality:
Only authorized personnel with documented job roles may access PHI.
HQB employs secure technical infrastructure to prevent unauthorized access, tampering, or disclosure of PHI:
Offshore personnel (if utilized) access systems only through secure Virtual Desktop Infrastructure (VDI) with:
HQB conducts periodic reviews and performs penetration testing of its technical systems.
To prevent unauthorized physical access to data:
HQB may engage subcontractors solely for operational support.
If a subcontractor requires access to PHI:
HQB does not sell, rent, exchange, or distribute PHI to any third party for marketing purposes.
HQB follows HIPAA and HITECH breach notification requirements.
If unsecured PHI is accessed, acquired, used, or disclosed in a manner not permitted by the BAA or law:
HQB uses PHI only for authorized billing and administrative operations, including:
PHI is not used for training unrelated to client operations, product development, sales, or marketing.
Upon termination of services, HQB will return or securely destroy PHI in accordance with:
Secure destruction includes wiping encrypted servers and removing backups after contractual retention periods expire. Destruction is logged and, upon request, certification of destruction can be provided.
HQB monitors regulatory updates and adjusts policies and procedures as needed to remain compliant with:
Internal compliance reviews are performed to maintain ongoing adherence.
For HIPAA-related requests, security questions, or breach reporting:
Health Quest Billing LLC – Compliance & Security
Address: 611 S Dupont Hwy Ste 102, Dover, Delaware 19901.
Email: legal@healthquestbilling.com
Phone: (415) 508-6537
Website: www.healthquestbilling.com