1.Our Role
MRi Health provides healthcare operations, administrative, documentation, coding, billing, and related support services to healthcare organizations. Depending on the services performed and the information accessed, MRi Health may function as a Business Associate under HIPAA when it creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a Covered Entity or another Business Associate.
2.Business Associate Agreements
Where HIPAA requires a Business Associate Agreement, MRi Health will enter into an appropriate written BAA with the applicable client. The BAA will define permitted uses and disclosures of PHI and the parties’ respective responsibilities. Where a subcontractor will create, receive, maintain, or transmit PHI on behalf of MRi Health, MRi Health will require appropriate written protections, including a downstream BAA where required.
3.Use and Disclosure of PHI
MRi Health will use and disclose PHI only as permitted or required by the applicable service agreement, BAA, HIPAA, and other applicable law. MRi Health will not use PHI for unrelated purposes or sell PHI.
4.Safeguards
MRi Health maintains administrative, technical, and physical safeguards appropriate to the nature of the information and services involved. These may include access controls, workforce confidentiality requirements, secure systems and communications, security awareness measures, and incident-response procedures. For electronic PHI, applicable HIPAA Security Rule obligations will be addressed through the actual systems, controls, contracts, and practices used for the client engagement.
5.Minimum Necessary Access
Access to PHI should be limited to information reasonably necessary for authorized job responsibilities and the contracted services. Access may be role-based and subject to client and system permissions.
6.Workforce Confidentiality
Personnel who are authorized to access client information are expected to follow applicable confidentiality, security, and privacy requirements and to access information only for authorized business purposes.
7.Security Incidents and Breaches
MRi Health will maintain procedures for identifying, investigating, documenting, and responding to suspected security incidents and unauthorized uses or disclosures. Where applicable, notification and cooperation obligations will be handled in accordance with the applicable BAA, HIPAA, and law.
8.Return or Destruction of PHI
At the termination of a client relationship, MRi Health will return or securely destroy PHI as required by the applicable BAA and law, subject to any legally permitted retention requirements.
9.Website Limitation
The MRi Health public website is not intended to be a secure portal for exchanging patient records. Please do not submit PHI through ordinary website inquiry forms. Clients should use approved secure channels for transferring PHI.
10.Important Notice
This page describes MRi Health’s privacy and security framework and does not represent a government certification or independent HIPAA certification. HIPAA obligations depend on the actual services, systems, contracts, safeguards, workforce practices, and applicable law. Specific HIPAA compliance representations should be made only when supported by the controls and agreements actually in place.
11.Contact
MRi HealthEmail: compliance@mrihealthva.com