Privacy Policy
2280 Ance Street, Strasburg, CO 80136
admin@brightspectrumbillingconsultants.com • (720) 662-4508
This Privacy Policy explains what information Bright Spectrum Billing Consultants LLC collects, how we use it, who we share it with, how we share it, and how we protect it. It covers our website, our client and employee portals, and our medical billing, coding, and credentialing services.
1. Who We Are
Bright Spectrum Billing Consultants LLC (“BSBC,” “we,” “us,” or “our”) is a Colorado limited liability company providing medical billing, coding, credentialing, and revenue cycle management services to healthcare providers and clinics. We are the controller of the business information described in this policy.
2. Two Categories of Information
We handle two distinct categories of information, and they are governed differently. Please read this section first, because it determines which rules apply.
- Business information — information about our clients, prospective clients, website visitors, and portal users. This Privacy Policy governs that information.
- Protected Health Information (PHI) — patient information we process on behalf of our healthcare provider clients. We act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). Our handling of PHI is governed by HIPAA, the HITECH Act, and the Business Associate Agreement executed with each client — not by this policy. We do not use PHI for our own purposes, and we never sell it.
3. Information We Collect
3.1 Information you give us
- Contact and inquiry information — name, business name, email address, phone number, and the contents of messages you send us through our website, by email, or by phone.
- Client account information — practice or clinic name, business address, Tax ID / EIN, National Provider Identifier (NPI), provider license and credentialing details, payer enrollment information, and authorized contact names and roles.
- Billing and payment information — billing contact, billing address, and payment records. Card and bank account numbers are collected and stored by our payment processor, not by us. See Section 5.
- Portal account information — username, email address, hashed password, role and permission assignments, and multi-factor authentication settings.
3.2 Information we collect automatically
- Technical and usage data — IP address, browser type and version, device and operating system, referring page, pages viewed, and timestamps.
- Security and audit logs — authentication events, access records, and actions taken within our portals. These logs are required for HIPAA compliance and fraud prevention.
- Cookies — we use strictly necessary cookies to keep you signed in and to maintain session security. We do not use advertising cookies and we do not sell advertising.
3.3 Information we do not collect
We do not knowingly collect information from children under 13 through our website. Our services are sold to businesses, not to consumers. We do not purchase marketing lists containing personal information.
4. How We Use Information
We use the information described above only for the following purposes:
- To provide, maintain, and support our billing, coding, and credentialing services
- To create and administer client and portal user accounts
- To invoice clients and process payments for our services
- To respond to inquiries, service requests, and support questions
- To secure our systems — including authentication, access control, audit logging, fraud prevention, and investigating suspected misuse
- To meet legal, regulatory, tax, and contractual obligations, including HIPAA obligations owed to our clients
- To send service and administrative communications about your account, our services, or changes to our terms
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use client business information or PHI to train publicly available artificial intelligence models.
5. Who We Disclose Information To, and How
We disclose information only in the circumstances below. In every case, disclosure is made over encrypted connections (TLS 1.2 or higher) through authenticated interfaces — our vendors’ APIs, secure web portals, encrypted file transfer, or HIPAA-compliant clearinghouse transmission. We do not disclose personal information by unencrypted email, and we do not post it publicly.
| Recipient | What is disclosed | Why, and how |
|---|---|---|
| Payment processor (Stripe, Inc.) | Billing contact, invoice amounts, payment details | To process invoices and payments. Card and bank details go directly to Stripe over an encrypted connection and are stored by Stripe under its own privacy policy — BSBC never receives or stores full card or account numbers. |
| Insurance payers and clearinghouses | Claims data, including PHI, on behalf of our clients | To submit claims, check eligibility, obtain authorizations, and pursue appeals. Transmitted through HIPAA-compliant electronic data interchange. |
| Infrastructure and hosting vendors | Account data and application data at rest and in transit | To host our applications and databases. These vendors act as subprocessors under written agreements, including Business Associate Agreements where PHI is involved. |
| Artificial intelligence service providers | Business and workflow data only | To power assistant features in our portals. PHI is not transmitted to any AI provider unless a Business Associate Agreement is in force with that provider. |
| Professional advisors | Business records as needed | To obtain legal, accounting, and tax services, under professional duties of confidentiality. |
| Government and legal authorities | Only what is legally required | To comply with law, subpoenas, audits, or valid legal process, or to protect our rights and the safety of others. |
| A successor entity | Records associated with the business | In connection with a merger, acquisition, or sale of assets. Any successor remains bound by this policy and by existing Business Associate Agreements. |
We require every vendor with access to personal information to be bound by a written contract limiting its use of that information to the services it performs for us. Where a vendor may encounter PHI, we execute a Business Associate Agreement before any PHI is shared.
6. How We Protect Information
We maintain administrative, physical, and technical safeguards designed to meet the HIPAA Security Rule. These include:
- Encryption — data encrypted in transit using TLS 1.2 or higher, and encrypted at rest in our databases and backups
- Access control — unique individual accounts, no shared logins, role-based permissions, and access granted on a minimum-necessary basis
- Multi-factor authentication — required for administrative and portal accounts
- Row-level database security — enforced so that each client can access only its own records
- Audit logging — authentication and access events are logged and retained for review
- Credential management — secrets and client portal credentials stored encrypted, never in plain text
- Workforce training — HIPAA privacy and security training for all personnel with access to PHI, plus signed confidentiality agreements
- Vendor diligence — written agreements and, where applicable, Business Associate Agreements with every subprocessor
- Incident response — documented procedures for investigating suspected breaches and issuing notifications within the timeframes HIPAA requires
No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.
7. How Long We Keep Information
We retain business records for as long as your account is active and afterward as needed to meet legal, tax, and contractual obligations. HIPAA-related documentation is retained for at least six years. PHI is retained, returned, or destroyed according to the terms of the applicable Business Associate Agreement. Security and audit logs are retained for at least six years.
8. Your Choices and Rights
You may:
- Request access to the business information we hold about you
- Ask us to correct information that is inaccurate
- Request deletion, subject to the retention obligations described in Section 7
- Opt out of non-essential email at any time by using the unsubscribe link
Patients: if you are a patient seeking access to, or correction of, your medical records, please contact your healthcare provider directly. As a Business Associate, we process PHI only under our provider clients’ instructions and must direct patient requests to them.
To make a request, email admin@brightspectrumbillingconsultants.com. We will respond within 30 days.
9. Where Information Is Processed
We operate in the United States, and all information is processed and stored in the United States.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the “Last updated” date at the top of this page, and for material changes we will notify affected clients by email or through the portal.
11. Contact Us
Questions, requests, or complaints about this policy or our privacy practices can be directed to our Privacy Officer:
Bright Spectrum Billing Consultants LLC
Attn: Privacy Officer
2280 Ance Street, Strasburg, CO 80136
admin@brightspectrumbillingconsultants.com
(720) 662-4508
You also have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate against you for filing a complaint.
