How we handle protected health information and protect the data our clients trust us with. Stated plainly, and only where we can stand behind it.
1. Our role under HIPAA
Mindlox AI handles protected health information (PHI) as a business associate of the healthcare organizations we serve. We execute a Business Associate Agreement with each covered entity before PHI is handled, and our obligations under HIPAA and that agreement govern everything below.
2. HIPAA-conscious workflows
Every stage of the revenue cycle is designed around the minimum-necessary standard: people see only the information their task requires.
- Documented policies and procedures for handling PHI across registration, coding, claims, posting, denials, A/R, and patient billing.
- Workforce HIPAA training at onboarding and on a recurring basis, with role-specific guidance.
- A defined incident response process, including client notification as required by HIPAA and our agreements.
3. Access control
Access to client systems and data is granted by role, reviewed on a defined cadence, and removed promptly when a role changes or ends.
- Role-based permissions scoped to the accounts and functions each team member works.
- Multi-factor authentication on the systems that support it.
- Periodic access reviews and same-day offboarding.
4. Audit logging
Claim actions taken by our team are recorded and visible to the client through their dashboard, so every status change has a who, what, and when. Logs are retained for the period set out in the client agreement.
5. Data protection
Data is encrypted in transit and at rest on the systems we operate. Claims, remittances, and eligibility transactions are exchanged with clearinghouses and payers over established secure channels. We do not send PHI by unencrypted email, and this website is not designed to receive it.
6. Working inside your systems
Wherever possible we work within the EHR and practice management systems a client already uses, under the client's own access controls, rather than exporting data into separate tools. Specific connectivity is agreed during discovery and documented in the engagement.
7. Security documentation and assessments
Our security policies, and any third-party assessments we hold, are available to prospective and current clients on request under a confidentiality agreement. We do not publish claims about certifications or attestations on this website; ask us and we will share what is current.
8. Reporting a security concern
If you believe you have found a security issue involving Mindlox AI, email info@mindlox.ai or call 817-256-4378. We acknowledge reports promptly, investigate, and keep you informed. We ask that you give us a reasonable opportunity to address an issue before sharing it publicly, and that you do not access or retain data that is not yours.
Let's identify where your practice is losing revenue — and build a plan to recover it.
