CodeSure (“CodeSure,” “we,” “us,” or “our”) provides medical billing, coding, credentialing, and Revenue Cycle Management services to physicians, clinics, and healthcare organizations across the United States and Canada. This Policy explains how information is handled on our public website and inside the secure client Portal used by our clinic and provider clients.
CodeSure ("CodeSure," "we," "us," or "our") provides medical billing, coding, credentialing, and Revenue Cycle Management services to physicians, clinics, and healthcare organizations across the United States and Canada. Our website at www.codesurercm.com (the "Site") describes our services and lets prospective clients request a consultation. Our client Portal (the "Portal") is a secured, login-based application where clinic and provider clients review claims, invoices, billing fees, and reporting.
Because we perform billing and claims functions on behalf of healthcare providers, we may create, receive, maintain, or transmit Protected Health Information ("PHI") as a Business Associate under the Health Insurance Portability and Accountability Act ("HIPAA"). Section 4 explains that role in detail.
This Policy covers visitors to the Site, prospective clients who submit a consultation or booking request, and Portal users at our clinic and provider clients. It does not apply to the internal systems of the healthcare practices we serve.
Where CodeSure handles PHI on behalf of a covered entity, that relationship is governed by a signed Business Associate Agreement ("BAA"). This Policy explains our general practices and does not replace, limit, or amend the terms of any BAA. If your engagement requires a BAA and one is not yet in place, contact us using Section 16.
Where CodeSure processes PHI to submit claims, post payments, and manage denials for a covered entity, we act as its Business Associate and apply the following safeguards:
Data moving between your browser and the Portal is protected end-to-end with TLS (HTTPS). Data at rest — claims, invoices, provider records, and account information — is encrypted using 256-bit encryption standards.
To support accurate claim submission and credentialing, we reference the NPI Registry (the National Plan and Provider Enumeration System, or NPPES) maintained by the U.S. Centers for Medicare & Medicaid Services. We use it to verify a provider's National Provider Identifier (NPI), specialty, and practice-location information before that provider is billed on our Portal.
The Portal uses one essential, encrypted session cookie to keep you signed in. It carries no readable personal data, cannot be accessed by page scripts, and expires automatically after 7 days or when you sign out. We do not use it for advertising or cross-site tracking.
The Site may use functional or analytics cookies to understand aggregate visit patterns, such as which pages are most useful, so we can improve it. You can block or delete cookies in your browser at any time; doing so will prevent the Portal from keeping you signed in.
We do not sell personal information. No mobile information is shared with third parties or affiliates for marketing or promotional purposes. All other data categories exclude text-messaging originator opt-in data and consent — that information is not shared with any third party.
The Site and Portal are intended for healthcare professionals and business contacts, not children. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will remove it.
If you opt in to receive text messages from CodeSure, your mobile opt-in information and consent are used only to send you the messages you've requested. No mobile information is shared with third parties or affiliates for marketing or promotional purposes, and text-messaging originator opt-in data and consent are never shared with any third party.
CodeSure serves clients in both the United States and Canada. Data may be processed and stored on infrastructure located in the United States. By using the Site or Portal, you acknowledge this processing, to the extent permitted by applicable law.
We may update this Policy as our services, technology, or legal obligations change. Updates will be posted here with a revised effective date. Any change materially affecting how we handle PHI will be reflected in the relevant BAA as well.
Questions about this Policy, or requests regarding your data, can be directed to:
CodeSure RCM
1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801
Email: Info@codesurercm.com
Phone: 1-888-912-2594