1-888-912-2594 Info@codesurercm.com
Legal

Privacy Policy

CodeSure (“CodeSure,” “we,” “us,” or “our”) provides medical billing, coding, credentialing, and Revenue Cycle Management services to physicians, clinics, and healthcare organizations across the United States and Canada. This Policy explains how information is handled on our public website and inside the secure client Portal used by our clinic and provider clients.

HIPAA-Aligned Safeguards256-Bit Encryption, In Transit & At RestNPI Registry-Verified ProvidersPHIPA & PIPEDA Aligned (Canada)We Never Sell Your Data
Effective date September 3, 2026
Applies to codesurercm.com & the Client Portal
01Who we are

Who we are

CodeSure ("CodeSure," "we," "us," or "our") provides medical billing, coding, credentialing, and Revenue Cycle Management services to physicians, clinics, and healthcare organizations across the United States and Canada. Our website at www.codesurercm.com (the "Site") describes our services and lets prospective clients request a consultation. Our client Portal (the "Portal") is a secured, login-based application where clinic and provider clients review claims, invoices, billing fees, and reporting.

Because we perform billing and claims functions on behalf of healthcare providers, we may create, receive, maintain, or transmit Protected Health Information ("PHI") as a Business Associate under the Health Insurance Portability and Accountability Act ("HIPAA"). Section 4 explains that role in detail.

02Scope of this policy

Scope of this policy

This Policy covers visitors to the Site, prospective clients who submit a consultation or booking request, and Portal users at our clinic and provider clients. It does not apply to the internal systems of the healthcare practices we serve.

Relationship to your BAA

Where CodeSure handles PHI on behalf of a covered entity, that relationship is governed by a signed Business Associate Agreement ("BAA"). This Policy explains our general practices and does not replace, limit, or amend the terms of any BAA. If your engagement requires a BAA and one is not yet in place, contact us using Section 16.

03Information we collect

Information we collect

  • Site visitors. IP address, browser and device type, pages viewed, and referring page, collected automatically to keep the Site secure and understand how it's used.
  • Consultation requests. When you request a Revenue Cycle Assessment or booking, we collect your name, email, phone number, practice name, country, and any message you include.
  • Portal accounts. For each Portal user: name, role, username, email address, and a securely hashed password. We never store passwords in plain text and cannot read them ourselves.
  • Clinic & billing data. Clinic name, region, and fee schedule; claim records (date of service, payer, specialty, billed and paid amounts, A/R days, status, and denial reason); invoices; and payment method details limited to card brand and the last four digits — full card numbers are handled exclusively by our PCI-compliant payment processor and never reach our servers.
  • Notification preferences. The alert settings you choose in the Portal, such as denial alerts, invoice reminders, and weekly summaries.
  • Provider verification data. Publicly available identifiers we reference from the NPI Registry to confirm the providers we bill for — see Section 6.
04HIPAA & PHI

HIPAA & protected health information

Where CodeSure processes PHI to submit claims, post payments, and manage denials for a covered entity, we act as its Business Associate and apply the following safeguards:

  • Minimum necessary. Access to PHI is limited to what is needed to perform billing, coding, and credentialing tasks for the specific clinic engagement.
  • Administrative safeguards. Workforce members are trained on HIPAA obligations before handling client data, and access is granted on a role and engagement basis.
  • Technical & physical safeguards. Encryption, access logging, and restricted infrastructure access, described further in Section 5.
  • Breach notification. If a breach of unsecured PHI occurs, we will notify affected covered entities without unreasonable delay, consistent with the HIPAA Breach Notification Rule and, for Canadian clients, applicable PHIPA requirements.
05Security

Encryption & data security

Data moving between your browser and the Portal is protected end-to-end with TLS (HTTPS). Data at rest — claims, invoices, provider records, and account information — is encrypted using 256-bit encryption standards.

  • Portal sign-in is protected by a signed, HTTP-only session cookie that cannot be read by page scripts and expires automatically after 7 days or immediately on sign-out.
  • Passwords are stored only as salted cryptographic hashes.
  • Role-based access control keeps each Portal user scoped to their own clinic's records.
  • Backups are encrypted, and infrastructure access is limited and logged.
06NPI Registry

NPI Registry & provider verification

To support accurate claim submission and credentialing, we reference the NPI Registry (the National Plan and Provider Enumeration System, or NPPES) maintained by the U.S. Centers for Medicare & Medicaid Services. We use it to verify a provider's National Provider Identifier (NPI), specialty, and practice-location information before that provider is billed on our Portal.

  • NPI Registry records are public federal directory data — we don't alter or expand their public status by using them.
  • Any NPI data we retain for a client is stored in the same encrypted, access-controlled environment as the rest of that clinic's Portal data, described in Section 5.
  • We use this data solely to verify identity and support billing and credentialing accuracy — never to build marketing profiles or resell provider information.
07Cookies

Cookies & the Portal session

The Portal uses one essential, encrypted session cookie to keep you signed in. It carries no readable personal data, cannot be accessed by page scripts, and expires automatically after 7 days or when you sign out. We do not use it for advertising or cross-site tracking.

The Site may use functional or analytics cookies to understand aggregate visit patterns, such as which pages are most useful, so we can improve it. You can block or delete cookies in your browser at any time; doing so will prevent the Portal from keeping you signed in.

08Use of information

How we use information

  • Operate and secure the Portal, and deliver billing, coding, denial management, and credentialing services.
  • Respond to consultation and booking requests.
  • Process payments through our PCI-compliant payment processor.
  • Send the notifications you've opted into, such as denial alerts or invoice reminders.
  • Detect and prevent fraud, and meet our legal and regulatory obligations.
  • Maintain and improve the Site and Portal.
  • We do not use PHI or client billing data for marketing purposes.
09Sharing

Who we share data with

  • Payment processing. Card payments are handled by our PCI-compliant payment processor (currently Stripe, Inc.), which receives only what's necessary to process the transaction.
  • Hosting & infrastructure. We use reputable cloud hosting and database providers to run the Site and Portal, bound by confidentiality and security obligations.
  • The NPI Registry. We query CMS's public NPI Registry to verify provider information; this is a lookup against public federal data, not a disclosure of your personal information to CMS.
  • Legal & safety. We may disclose information when required by law, regulation, or valid legal process.
  • Business transfers. If CodeSure is involved in a merger or acquisition, client data would remain subject to protections at least as strong as this Policy.
Marketing & mobile data

We do not sell personal information. No mobile information is shared with third parties or affiliates for marketing or promotional purposes. All other data categories exclude text-messaging originator opt-in data and consent — that information is not shared with any third party.

10Retention

Data retention

  • Consultation and booking inquiries are kept as long as needed to respond and for legitimate business records, then deleted.
  • Portal, billing, and claims data are retained for the duration of the client engagement and afterward as required by HIPAA recordkeeping rules and applicable state or provincial law, then securely deleted or de-identified.
  • Session cookies expire automatically after 7 days regardless of activity.
11Your rights

Your rights & choices

  • Site visitors. You may request a copy of, or ask us to delete, the personal information we hold about you, subject to legal or administrative retention obligations.
  • Portal users. You can view and update your profile and notification preferences anytime in Settings, or contact us for anything not self-service.
  • Patients of our clinic clients. Where we process PHI as a Business Associate, HIPAA access, amendment, and accounting-of-disclosures requests are handled through your provider. Contact your provider directly, or contact us and we'll coordinate with them.
  • Canadian clients. You have access and correction rights under PHIPA (Ontario) and PIPEDA at the federal level.
  • California residents. We don't sell personal information; you may have rights under the CCPA/CPRA to know, delete, or correct your information.
12Children

Children's privacy

The Site and Portal are intended for healthcare professionals and business contacts, not children. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will remove it.

13SMS & mobile

Text messaging & mobile information

If you opt in to receive text messages from CodeSure, your mobile opt-in information and consent are used only to send you the messages you've requested. No mobile information is shared with third parties or affiliates for marketing or promotional purposes, and text-messaging originator opt-in data and consent are never shared with any third party.

14Cross-border

Cross-border data

CodeSure serves clients in both the United States and Canada. Data may be processed and stored on infrastructure located in the United States. By using the Site or Portal, you acknowledge this processing, to the extent permitted by applicable law.

15Updates

Changes to this policy

We may update this Policy as our services, technology, or legal obligations change. Updates will be posted here with a revised effective date. Any change materially affecting how we handle PHI will be reflected in the relevant BAA as well.

16Contact

Contact us

Questions about this Policy, or requests regarding your data, can be directed to:

CodeSure RCM
1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801
Email: Info@codesurercm.com
Phone: 1-888-912-2594

Let’s Improve Your Revenue Cycle Together
Schedule a free consultation and see how CodeSureRCM can help your practice grow.