ZemMedX LLC (“ZemMedX,” “we,” “us,” or “our”) provides medical billing and revenue cycle management services to healthcare practices in the United States. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our website at zemmedx.com and our business communications, including email and text messaging.
By using our website or providing us with your information, you agree to the practices described in this policy.
1. Scope: two different kinds of information
It is important to understand the distinction between the two categories of information we handle, because they are governed by different rules.
Business and website information — covered by this policy
This includes information about practice owners, office managers, providers, staff, vendors, job applicants, and website visitors who contact us, request a quote, subscribe to updates, or browse our site. This Privacy Policy applies to that information.
Protected Health Information (PHI) — not covered by this policy
When we perform billing and revenue cycle services for a healthcare practice, we act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). Patient PHI that we access, receive, or process in that role is governed by HIPAA, by the Business Associate Agreement (BAA) we sign with each client practice, and by that practice’s own Notice of Privacy Practices — not by this Privacy Policy.
If you are a patient: we do not have a direct relationship with you. To exercise your HIPAA rights — to request access to your records, request an amendment, request an accounting of disclosures, or file a complaint — please contact your healthcare provider directly. We will support your provider in responding to your request as required by our agreement with them.
2. Information we collect
Information you give us
- Name, job title, and practice or organization name
- Email address, mailing address, and telephone or mobile number
- Practice details such as specialty, number of providers, EHR/EMR system, states of operation, and current billing arrangement
- The content of messages you send us through web forms, email, text message, or phone
- Resume and application details, if you apply for a role with us
Information we collect automatically
- IP address, approximate location derived from it, browser type, device type, and operating system
- Pages viewed, referring URL, links clicked, and time spent on the site
- Cookies and similar technologies, as described in Section 6
Information from other sources
- Referrals from existing clients or business partners
- Publicly available professional and provider directory information
- Analytics and advertising platforms we use to measure the performance of our marketing
3. How we use information
- To respond to inquiries, prepare quotes, and schedule consultations
- To deliver, support, and improve our billing and revenue cycle services
- To send service, account, and operational communications, including by text message where you have consented
- To send marketing communications you have asked to receive, and to measure their effectiveness
- To maintain the security, integrity, and availability of our systems
- To evaluate job applications
- To meet our legal, regulatory, tax, and contractual obligations
4. Text messaging (SMS) and mobile information
If you provide your mobile number and opt in, we may send you text messages relating to your inquiry, your account, service updates, appointment or meeting confirmations, and support. Consent to receive text messages is never a condition of purchasing any product or service from us.
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties
Program details
- Message frequency: message frequency varies based on your interaction with us.
- Cost: message and data rates may apply. Contact your wireless provider for details of your plan.
- Opt out: reply STOP to any message to stop receiving text messages from us. You will receive a confirmation message and no further texts unless you opt in again.
- Help: reply HELP for assistance, or contact us using the details in Section 15.
- Carriers: wireless carriers are not liable for delayed or undelivered messages.
- Supported carriers: carrier support may vary and is subject to change without notice.
We use messaging service providers to deliver these messages on our behalf. Those providers are permitted to use mobile information only to transmit our messages to you, and are prohibited from using it for their own marketing or promotional purposes or from disclosing it to any other party.
5. How we share information
We do not sell your personal information, and we do not share it with third parties or affiliates for their own marketing or promotional purposes.
We share information only in the following circumstances:
- Service providers. Vendors who perform functions on our behalf — hosting, clearinghouse and claims transmission, email and messaging delivery, analytics, customer relationship management, and IT security. They are bound by contract to use the information only to provide services to us, and, where PHI is involved, by a Business Associate Agreement.
- Client practices and payers. In the course of performing billing services, we exchange claim and remittance information with payers, clearinghouses, and the practice that engaged us, as authorized by our agreement with that practice.
- Legal and regulatory. Where required by law, subpoena, court order, or government or regulatory request, or to establish, exercise, or defend legal claims.
- Safety and integrity. To investigate suspected fraud, security incidents, or violations of our terms.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to the protections in this policy.
Mobile numbers and text messaging opt-in data are excluded from all of the sharing categories described above, as stated in Section 4.
6. Cookies and analytics
We use cookies and similar technologies to keep the site working correctly, remember your preferences, and understand how the site is used. Some are strictly necessary; others support analytics and marketing measurement.
You can control cookies through your browser settings. Blocking cookies may affect how parts of the site function. Where required by law, we present a cookie notice that lets you manage non-essential cookies.
We do not respond to browser Do Not Track signals at this time. Where required, we honor Global Privacy Control (GPC) signals as an opt-out of sharing for cross-context behavioral advertising.
7. HIPAA and protected health information
Where we act as a Business Associate, we handle PHI in accordance with HIPAA, the HITECH Act, and our BAA with the client practice. Our commitments include:
- Using and disclosing PHI only as permitted by the BAA and applicable law
- Applying the HIPAA minimum necessary standard to all access
- Maintaining administrative, physical, and technical safeguards
- Requiring HIPAA training for all personnel with access to PHI
- Executing agreements with any subcontractor that may access PHI
- Reporting security incidents and breaches to the client practice as required
8. Our workforce and international access
ZemMedX operates a hybrid delivery model. Some members of our workforce, including administrative and support personnel, are located outside the United States and may access client systems and data as part of their duties. All such personnel are our own workforce members, are HIPAA trained, are bound by confidentiality and HIPAA obligations, and operate under the minimum necessary standard and the terms of the applicable Business Associate Agreement.
Client practices whose contracts or internal policies require that data be accessed only from within the United States may request a US-only staffing configuration.
9. Data security
We maintain reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and loss. These include access controls, role-based permissions, encryption in transit, audit logging, and workforce training. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Please do not send PHI, Social Security numbers, or other sensitive information to us through unsecured email, text message, or website forms.
10. Data retention
We retain information for as long as needed to provide our services, meet our legal, tax, and regulatory obligations, resolve disputes, and enforce our agreements. PHI is retained and returned or destroyed in accordance with the applicable Business Associate Agreement. Marketing contact information is retained until you opt out or ask us to delete it.
11. Your privacy choices
- Email: use the unsubscribe link in any marketing email, or contact us.
- Text messages: reply STOP to any message.
- Access, correction, and deletion: contact us using the details in Section 15 and we will respond as required by applicable law.
State privacy rights
Depending on where you live, you may have the right to know what personal information we collect and how we use it, to request a copy of it, to request correction or deletion, to opt out of sale or sharing for targeted advertising, and to be free from discrimination for exercising these rights.
California residents: under the CCPA/CPRA, we confirm that we have not sold personal information and do not share it for cross-context behavioral advertising. You may exercise your rights by contacting us, and you may designate an authorized agent to make a request on your behalf. We will verify your identity before responding.
Residents of other states with comprehensive privacy laws have comparable rights and may exercise them the same way. If we deny a request, you may appeal by replying to our response.
12. Children’s privacy
Our website and services are directed to businesses and are not intended for children under 16. We do not knowingly collect personal information from children through our website. If you believe a child has provided us with information, please contact us and we will delete it.
13. Third-party links
Our site may link to third-party websites, including payer portals, EHR vendors, and social media. We are not responsible for the privacy practices of those sites. Review their privacy policies before providing information.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes will be communicated to affected clients as required by contract or law. Continued use of our website or services after an update constitutes acceptance of the revised policy.
15. Contact us
Questions, requests, or complaints about this Privacy Policy or our handling of information:
ZemMedX LLC
Email: admin@zemmedx.com
Phone: +1-888-499-7169
Mailing address: 1225 Amsterdam Ave, NYC, NY, 10027.