This Privacy Policy ("Policy") describes how Servixa, LLC ("Servixa," "we," "us," or "our") collects, uses, discloses, and protects information in connection with our cloud-based Practice Management and Revenue Cycle Management platform (the "Platform") and our website at www.rightvitals.com (the "Site"). This Policy applies to our Subscribers ("Clients"), their authorized users, and visitors to our Site.
This Policy does not govern the collection or processing of patient data by our Clients in their capacity as covered entities under HIPAA. Clients' use of patient Protected Health Information ("PHI") through the Platform is governed by the Business Associate Agreement and Data Processing Addendum between Servixa and each Client. Patients seeking information about how their PHI is handled should contact their healthcare provider directly.
Information We Collect
1.1 Information Provided by Clients and Users
We collect information that Clients and their Authorized Users provide to us, including:
- Practice Information: Practice name, legal entity name, DBA name, NPI number(s), Tax ID (EIN), state of licensure, specialty, physical and billing addresses, and insurance credentialing information
- Provider Information: Names, credentials, NPI numbers, DEA numbers (where applicable), specialty codes, and other professional identification information
- Account and Contact Information: Names, email addresses, phone numbers, job titles, and login credentials of authorized users
- Payment and Billing Information: Bank account information (for ACH), credit card information (processed through PCI-DSS compliant third-party payment processors), billing address, and payment history
- Patient Information (PHI): Demographics, insurance information, appointment history, medical records, diagnosis and procedure codes, billing data, and electronic remittance information — collected and processed solely in our capacity as a Business Associate on behalf of Clients as Covered Entities
- Communications: Support tickets, emails, chat logs, and other communications you send to us
1.2 Information Collected Automatically
When you access the Platform or Site, we automatically collect:
- Log Data: IP addresses, browser type and version, operating system, referring URLs, pages visited, date and time of access, and session duration
- Device Information: Device type, operating system, unique device identifiers, and mobile network information
- Usage Data: Features accessed, actions taken within the Platform, workflow patterns, and performance metrics
- Cookies and Tracking Technologies: We use cookies, web beacons, pixels, and similar technologies as described in Section 7 below
- Voice Data: Where you use voice-enabled features, we collect voice recordings and transcribed text, which may contain PHI and are processed in accordance with the Business Associate Agreement
1.3 Information from Third Parties
We may receive information about Clients and users from third parties, including:
- Electronic clearinghouses and payers in connection with claim submission, ERA processing, and eligibility verification
- Credit reporting agencies and background check services in connection with account verification
- Integration partners and API providers that connect with the Platform
How We Use Your Information
2.1 To Provide and Improve the Platform
We use information collected to:
- Provide, operate, maintain, and secure the Platform
- Process and transmit healthcare claims, ERA/EOBs, and eligibility verification requests on behalf of Clients
- Provide customer support, training, and implementation services
- Diagnose technical problems and improve Platform performance
- Develop, train, and improve AI Features, subject to HIPAA requirements and using de-identified or aggregated data where required
- Send administrative communications, including account notifications, billing statements, and product updates
- Enforce our Terms of Service and other agreements
- Comply with applicable laws and regulatory requirements
2.2 Aggregate and De-Identified Data
We may create aggregate, statistical, or de-identified data from Client Data (in compliance with HIPAA's de-identification standards at 45 C.F.R. § 164.514) for product development, benchmarking, analytics, and other lawful purposes. De-identified data is not subject to this Policy and may be used and shared without restriction.
2.3 AI Feature Improvement
We may use Platform usage data and de-identified or aggregated data derived from Client use to train, improve, and validate our AI Features. We will not use identifiable PHI to train AI models except as permitted under the applicable Business Associate Agreement and in compliance with HIPAA.
2.4 We Do Not Sell Your Data
How We Disclose Your Information
3.1 Service Providers and Business Associates
We share information with vetted third-party service providers and subcontractors who perform services on our behalf, including cloud hosting and infrastructure providers, electronic clearinghouses, payment processors, cybersecurity vendors, customer support platforms, and analytics providers. All such third parties are required to maintain confidentiality and implement commercially reasonable security measures and, where applicable, to execute Business Associate Agreements with us.
3.2 Electronic Clearinghouses and Payers
In the ordinary course of providing the Platform, we transmit PHI-containing claims data to clearinghouses, payers, and other covered entities as directed by Clients, consistent with our role as a Business Associate and the applicable Business Associate Agreement.
3.3 Legal Requirements
We may disclose information if we believe disclosure is required by applicable law, regulation, legal process, or governmental request, including to comply with a court order, subpoena, or legal obligation. We will make commercially reasonable efforts to notify Clients of such requests unless prohibited by law, impractical under the circumstances, or where we reasonably determine that notification could jeopardize an investigation or create a risk of harm.
3.4 Business Transfers
If Servixa is involved in a merger, acquisition, reorganization, or sale of assets, Client Data and other information may be transferred as part of such transaction. We will provide reasonable notice of such transfer and ensure that the successor entity is bound by terms no less protective than this Policy with respect to information previously collected.
3.5 Protection of Rights
We may disclose information where we believe disclosure is necessary to: (a) protect the rights, property, or safety of Servixa, our Clients, users, or others; (b) detect or prevent fraud or security incidents; or (c) enforce our Terms of Service.
3.6 With Consent
We may disclose information for any other purpose with the applicable party's prior written consent.
HIPAA & Protected Health Information
4.1 Business Associate Role
Servixa acts as a Business Associate under HIPAA with respect to PHI that we receive, process, or maintain on behalf of our Clients as Covered Entities. Our use and disclosure of PHI is governed by the Business Associate Agreement executed with each Client.
4.2 HIPAA Safeguards
We implement the administrative, physical, and technical safeguards required under the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C), including:
- Risk analysis and risk management programs
- Workforce training on HIPAA policies and procedures
- Role-based access controls and multi-factor authentication
- Encryption of ePHI in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent)
- Audit logging and monitoring of access to ePHI
- Incident response procedures and Breach notification protocols
- Business Associate Agreements with all Subcontractors that access PHI
4.3 Patient Rights
Patients seeking to exercise their rights under HIPAA (including rights of access, amendment, accounting of disclosures, or restriction) should contact their healthcare provider directly. Servixa will cooperate with Client to facilitate the exercise of patient rights as required by our Business Associate Agreement.
Data Security
We implement and maintain a comprehensive information security program designed to protect the confidentiality, integrity, and availability of Client Data and PHI, including:
- 256-bit AES encryption at rest and TLS 1.2+ encryption in transit
- Role-based access control (RBAC) and principle of least privilege
- Multi-factor authentication (MFA) for all administrative access
- Regular penetration testing and vulnerability assessments
- Compliance with SOC 2 Type II audit standards (or equivalent framework), or active pursuit thereof
- Continuous security monitoring and intrusion detection
- Documented incident response and disaster recovery plans
- Annual workforce security training
- Physical security controls at all data processing facilities
No security system is completely impenetrable. In the event of a data breach involving PHI, we will notify affected Clients in accordance with our Business Associate Agreement and applicable law.
Data Retention
We retain Client Data and PHI for as long as the applicable Client account is active, or as necessary to provide the Platform, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods:
- PHI: Retained in accordance with the Business Associate Agreement and applicable HIPAA requirements. Upon termination of the applicable agreement, PHI will be returned or destroyed in accordance with the Business Associate Agreement
- Account Information: Retained for the duration of the Client relationship and for up to seven (7) years thereafter for legal and compliance purposes
- Billing and Financial Records: Retained for a minimum of seven (7) years as required by applicable tax and healthcare regulations
- Log and Usage Data: Retained for up to two (2) years, or longer if required for legal or security purposes
- Voice Recordings: Retained for up to ninety (90) days unless incorporated into PHI records, in which case HIPAA-applicable retention periods apply
Clients may request deletion of their account and associated data upon termination of the applicable agreement, subject to the retention requirements described above. Servixa will use commercially reasonable efforts to complete such deletion within ninety (90) days of a verified request, provided that Servixa may retain de-identified or aggregated data derived from Client Data.
Cookies & Tracking Technologies
7.1 Types of Cookies
We use the following types of cookies and similar technologies:
- Strictly Necessary Cookies: Required for the operation of the Platform, including authentication, session management, and security features. These cannot be disabled
- Functional Cookies: Enable enhanced functionality and personalization, such as remembering user preferences and login information
- Performance and Analytics Cookies: Help us understand how users interact with the Platform, identify areas for improvement, and optimize performance. We use aggregated, anonymized data for this purpose
- Security Cookies: Used to detect and prevent fraud, unauthorized access, and other security threats
7.2 Cookie Management
You may adjust your browser settings to refuse cookies; however, disabling certain cookies may impair the functionality of the Platform. We do not use tracking cookies for cross-site advertising or behavioral marketing purposes.
Children's Privacy
The Platform is designed for use by healthcare professionals and is not intended for use by or directed to individuals under the age of eighteen (18). We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected personal information from a minor, we will take steps to delete such information promptly.
State Privacy Rights
9.1 Texas Residents
Texas residents may have additional privacy rights under the Texas Data Privacy and Security Act (TDPSA) and other applicable Texas law, to the extent their personal data is not exempt under such laws (including exemptions for data governed by HIPAA). Texas residents may have the right to:
- Access personal data we hold about them
- Correct inaccurate personal data
- Delete personal data, subject to legal retention requirements
- Obtain a copy of personal data in a portable format
- Opt out of certain processing activities
To exercise these rights, contact us at privacy@rightvitals.com.
9.2 Other States
If you are located in a state with applicable consumer privacy laws (including California, Virginia, Colorado, Connecticut, Utah, or other states), you may have additional rights with respect to your personal data, to the extent such data is not exempt under applicable law (including HIPAA exemptions). Please contact us at privacy@rightvitals.com to inquire about your rights under applicable state law.
International Data Transfers
The Platform is hosted and operated in the United States. If you are accessing the Platform from outside the United States, please be aware that your information may be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Platform, you consent to such transfer, storage, and processing.
Third-Party Links & Services
The Platform and Site may contain links to or integrations with third-party websites, services, and clearinghouses. This Policy does not apply to third-party websites or services. We encourage you to review the privacy policies of any third-party services before providing your personal information.
Changes to This Policy
We may update this Privacy Policy from time to time. We will provide notice of material changes by:
- Posting the updated Policy on our website and/or within the Platform with an updated effective date
- Sending notice to the primary contact email address of record for each Client at least thirty (30) days prior to the effective date of material changes
Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Policy.
Contact Us
For questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us at:
If you are a patient seeking information about how your healthcare provider handles your medical records or PHI, please contact your provider directly.