Contingency only. No recovery, no fee.Start an auditClient login

Security and compliance

We handle protected health information for a living, so this page is plain and specific. Ask for our policies, the BAA, or the certificate of insurance and we will send them.

HIPAA program

MARR Partners operates as a business associate under HIPAA. We maintain written privacy and security policies, an annual risk assessment, workforce training on hire and annually, and a designated privacy and security officer.

Business Associate Agreement

A BAA is executed with every practice and every billing-company partner before any claim-level data is exchanged. Our BAA covers permitted uses, safeguards, subcontractor flow-down, breach notification within the statutory window, and return or destruction of data at termination.

Encrypted transfer

Aging reports are received only through single-use upload links that expire after 72 hours and deliver files over TLS directly into a restricted, versioned storage bucket. Email attachments are never accepted for files containing patient data.

Encryption at rest

All stored files and records are encrypted at rest with provider-managed keys. Customer-managed keys are available on request for practices that require them.

Access control and MFA

Every person with access to practice data authenticates with multi-factor authentication. Access to each engagement is granted per person and removed the day the engagement ends or the person leaves.

Minimum necessary

We request only the claims, payers, and documentation needed to work the identified balances. Read-only system access is preferred over exports. Nothing containing patient identifiers is displayed on this website or in the client portal.

Audit logging

Every access to a report and every upload link issued is recorded with the person, time, and record touched. Logs are retained for six years.

Retention and destruction

Audit files for practices that do not engage us are deleted 90 days after upload. Engagement records are retained for the term required by the agreement and then destroyed, with certification on request.

Subcontractors

Cloud infrastructure is hosted on Google Cloud under a Business Associate Agreement with Google, using only services covered by that agreement. We use no offshore labor and no subcontractors with access to patient data.

Insurance

Cyber liability and errors-and-omissions coverage are maintained continuously. Certificates of insurance are provided with the agreement.

Incident response

A written incident-response plan covers detection, containment, assessment, and notification. Affected practices are notified without unreasonable delay and within the timeframe required by the BAA.

What this website does and does not collect

Collected

  • Business contact information you type into a form: practice name, specialty, provider count, an estimated A/R figure, your name, work email, and phone.
  • Server logs with the requesting network address, used only for rate limiting and abuse prevention.

Not collected

  • No files. The website cannot receive an upload. Upload links are issued only after a BAA is executed and deliver files to a separate system.
  • No cookies and no analytics. The site sets no tracking cookies and makes no third-party requests.
  • No patient information in the client portal. Reports show aggregate figures only.
HIPAA-compliant systemsBusiness Associate AgreementEncrypted file transferMFA and access controlsCyber liability and E&O insured
Find out what's still recoverable.Send your aging report. The Recovery opportunity report comes back within 5 business days, with no obligation to have us work the claims.