Security and compliance
We handle protected health information for a living, so this page is plain and specific. Ask for our policies, the BAA, or the certificate of insurance and we will send them.
HIPAA program
MARR Partners operates as a business associate under HIPAA. We maintain written privacy and security policies, an annual risk assessment, workforce training on hire and annually, and a designated privacy and security officer.
Business Associate Agreement
A BAA is executed with every practice and every billing-company partner before any claim-level data is exchanged. Our BAA covers permitted uses, safeguards, subcontractor flow-down, breach notification within the statutory window, and return or destruction of data at termination.
Encrypted transfer
Aging reports are received only through single-use upload links that expire after 72 hours and deliver files over TLS directly into a restricted, versioned storage bucket. Email attachments are never accepted for files containing patient data.
Encryption at rest
All stored files and records are encrypted at rest with provider-managed keys. Customer-managed keys are available on request for practices that require them.
Access control and MFA
Every person with access to practice data authenticates with multi-factor authentication. Access to each engagement is granted per person and removed the day the engagement ends or the person leaves.
Minimum necessary
We request only the claims, payers, and documentation needed to work the identified balances. Read-only system access is preferred over exports. Nothing containing patient identifiers is displayed on this website or in the client portal.
Audit logging
Every access to a report and every upload link issued is recorded with the person, time, and record touched. Logs are retained for six years.
Retention and destruction
Audit files for practices that do not engage us are deleted 90 days after upload. Engagement records are retained for the term required by the agreement and then destroyed, with certification on request.
Subcontractors
Cloud infrastructure is hosted on Google Cloud under a Business Associate Agreement with Google, using only services covered by that agreement. We use no offshore labor and no subcontractors with access to patient data.
Insurance
Cyber liability and errors-and-omissions coverage are maintained continuously. Certificates of insurance are provided with the agreement.
Incident response
A written incident-response plan covers detection, containment, assessment, and notification. Affected practices are notified without unreasonable delay and within the timeframe required by the BAA.
What this website does and does not collect
Collected
- Business contact information you type into a form: practice name, specialty, provider count, an estimated A/R figure, your name, work email, and phone.
- Server logs with the requesting network address, used only for rate limiting and abuse prevention.
Not collected
- No files. The website cannot receive an upload. Upload links are issued only after a BAA is executed and deliver files to a separate system.
- No cookies and no analytics. The site sets no tracking cookies and makes no third-party requests.
- No patient information in the client portal. Reports show aggregate figures only.