PRIVACY POLICY
Effective Date: June 1, 2026 | Website: navirabilling.com
Navira Medical Billing (“Navira,” “we,” “us,” or “our”) provides medical billing, claims submission, coding support, and related revenue-cycle services to healthcare providers and their patients. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit navirabilling.com (the “Site”), when you interact with us as a client (a healthcare provider or practice), or when we process information on a client’s behalf as part of our billing services.
1. Two Roles We Play
Navira handles information in two distinct capacities, and different rules apply to each:
- As a data controller: information we collect about visitors to the Site, prospective clients, and our own employees/contractors, which we use for our own business purposes (e.g., responding to inquiries, marketing, Site analytics).
- As a HIPAA Business Associate: Protected Health Information we create, receive, maintain, or transmit on behalf of a covered healthcare provider (“Client”) in order to perform billing, coding, claims submission, payment posting, and related services. This PHI is governed primarily by the Business Associate Agreement (“BAA”) between Navira and the Client and by HIPAA — not by patients’ general expectations under this website Privacy Policy alone.
2. Information We Collect
2.1 Information You Provide to Us
- Contact details (name, company/practice name, email, phone, mailing address) submitted through contact forms, demo requests, or account sign-up.
- Billing and payment information for our own invoicing of Clients (e.g., business bank or card details, tax ID).
- Information submitted in support tickets, emails, or phone calls.
2.2 Protected Health Information (PHI)
When acting as a Business Associate, Navira may receive or create PHI such as patient names, dates of birth, contact information, insurance and eligibility details, diagnosis and procedure codes, treatment dates, claim numbers, and payment/adjudication data. This PHI is used solely to perform billing-related services for the applicable Client, in accordance with HIPAA, the Minimum Necessary standard, and the terms of our BAA with that Client.
2.3 Information Collected Automatically
- IP address, browser type, device identifiers, and operating system.
- Pages viewed, referring/exit pages, and timestamps.
- Cookies and similar technologies (see Section 6).
2.4 Information from Third Parties
- Clearinghouses, payers, and insurance carriers involved in claims processing.
- Practice management or EHR systems integrated with our services.
- Publicly available business information (e.g., NPI registries) for prospective Clients.
3. How We Use Information
- To provide, operate, and improve our billing and revenue-cycle services.
- To submit, track, and follow up on insurance claims and patient statements on a Client’s behalf.
- To communicate with Clients, prospective Clients, and Site visitors about our services.
- To process payments owed to Navira for our services.
- To maintain the security, integrity, and performance of the Site and our systems.
- To comply with legal, regulatory, and contractual obligations, including HIPAA and our BAAs.
- For internal analytics, quality assurance, and staff training (using de-identified or minimum-necessary data where feasible).
We do not sell PHI or personal information. We do not use PHI for marketing purposes except as permitted by HIPAA and authorized in writing by the applicable Client or patient.
4. How We Disclose Information
We disclose information only as necessary to perform our services or as required by law, including to:
- Payers and clearinghouses to submit and adjudicate claims.
- Subcontractors and service providers (e.g., hosting, software, and IT vendors) who perform functions on our behalf and who are bound by written agreements — including subcontractor BAAs where PHI is involved — to protect the information consistent with this Policy and HIPAA.
- The applicable Client (the healthcare provider), who is the primary point of contact for patients regarding their own records.
- Regulators and government authorities when required by law, subpoena, court order, or to protect against fraud.
- Successors in the event of a merger, acquisition, or sale of assets, subject to equivalent confidentiality protections.
We do not disclose PHI to third parties for their own independent marketing or advertising purposes.
5. Data Security
We maintain administrative, technical, and physical safeguards designed to protect information consistent with the HIPAA Security Rule, including access controls, encryption of PHI in transit and (where applicable) at rest, audit logging, employee training, and incident response procedures. No system is completely secure, and we cannot guarantee absolute security. If a breach of unsecured PHI occurs, we will notify affected Clients in accordance with the HIPAA Breach Notification Rule and our BAA obligations.
6. Cookies and Tracking Technologies
The Site may use cookies, pixels, and similar technologies to remember preferences, understand Site usage, and support analytics. You can control cookies through your browser settings; disabling cookies may limit some Site functionality. The Site does not use tracking technologies to collect PHI.
7. Data Retention
We retain PHI in accordance with the retention terms specified in each Client’s BAA and applicable law (which often require multi-year retention of billing and claims records). We retain other personal information only as long as reasonably necessary for the purposes described in this Policy, or as required by law, after which it is securely deleted or de-identified.
8. Your Rights and Choices
8.1 Patients
If you are a patient and have questions about your medical records or billing information, please contact your healthcare provider (our Client) directly, as they control your PHI. Navira will support our Client in responding to verified patient requests for access, amendment, or accounting of disclosures as required by HIPAA.
8.2 Site Visitors and Prospective Clients
- You may request access to, correction of, or deletion of the personal information you submitted to us via the Site.
- You may opt out of marketing communications at any time using the unsubscribe link or by contacting us.
8.3 State Privacy Rights
Depending on your state of residence, you may have additional rights (e.g., under the CCPA/CPRA or other state privacy laws) regarding access, deletion, correction, and opt-out of certain data practices.
9. Children’s Privacy
The Site is intended for business use by healthcare providers and administrative staff and is not directed to children under 13. We do not knowingly collect personal information from children through the Site.
10. Third-Party Links
The Site may link to third-party websites (e.g., payer portals, clearinghouses). We are not responsible for the privacy practices of those third parties, and we encourage you to review their policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “Effective Date” above indicates when it was last revised. Material changes affecting PHI handling will also be addressed, as required, through updates to applicable BAAs.
12. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact:
Navira Medical Billing — [Attn: Privacy Officer]
2544 S W Temple St, Salt Lake City, UT 84115
Email: [privacy@navirabilling.com] | Phone: 801-513-1368