Privacy Policy & HIPAA Compliance

Image 001

Last Updated: August 2026

At Flower City Billing, we understand that handling revenue cycle management for speech-language pathology (SLP) and therapy practices requires the absolute highest standard of data privacy and security. We are fully committed to protecting the privacy of our practice partners and their patients in compliance with the Health Insurance Portability and Accountability Act (HIPAA), the HITECH Act, and all applicable state and federal privacy laws.

1. Business Associate Agreement (BAA)

As a dedicated billing partner for healthcare providers, Flower City Billing acts as a Business Associate under HIPAA regulations. Prior to onboarding or accessing any Protected Health Information (PHI), we enter into a formal Business Associate Agreement (BAA) with every practice partner. This legally binding agreement ensures that patient data is handled, processed, and safeguarded according to strict federal privacy guidelines.

2. Information We Collect

We collect information across two distinct categories:

  • Website Visitor Data: Standard non-personally identifiable information (such as browser type, pages visited, and contact form submissions) used strictly to respond to inquiries and schedule billing audits.
  • Practice & Billing Data (PHI): Protected Health Information provided securely by practice partners solely for the purpose of claim generation, payer submission, denial resolution, credentialing, and revenue cycle management.

3. Data Security & Technical Safeguards

To safeguard Protected Health Information and practice records, Flower City Billing enforces strict technical and administrative safeguards:

  • End-to-End Encryption: All data transmitted to and from our systems is encrypted in transit using standard SSL/TLS protocols and encrypted at rest using AES 256-bit encryption.
  • Direct EHR Integration: We work directly inside your existing EHR system (SimplePractice, WebPT, Therabill, etc.), minimizing unnecessary data exports or external file transfers.
  • Access Controls: Staff access to practice files is strictly restricted based on role-based permissions and multi-factor authentication.
  • No Commercialization: Flower City Billing will never sell, rent, trade, or commercialize your practice information or patient data under any circumstances.

4. Contact Us Regarding Compliance

If you have questions regarding our HIPAA safeguards, Business Associate Agreements, or privacy practices, please contact our compliance team:

  • Business Name: Flower City Billing
  • Website: flowercitybilling.com
  • Compliance Email: privacy@flowercitybilling.com