Medical billing privacy and service boundaries
US healthcare clients
HQL provides medical billing services for US clients, including medical billing, coding, payment posting and appointment scheduling within the agreed service scope. This is administrative support, not clinical advice or a public patient portal.
Patient and insurance information
The service involves access to patient records and insurance details by staff based in Morocco and India. Billing software and server locations depend on the client arrangement and have not yet been identified in HQL’s central service inventory. Each engagement must record its approved software, access route, locations, personnel and permitted data categories.
BAA and client instructions
Management confirms that Business Associate Agreement terms are included in the billing contract or signed separately. A services contract is not treated as sufficient solely because it is called a medical billing contract: its BAA provisions must cover the relevant HIPAA obligations and actual workflow. Use and disclosure, subcontractors, incident reporting, assistance, return/deletion and termination must follow the executed agreement and applicable law. This website does not certify HIPAA compliance.
Cross-border access
Morocco and India staff access should be expressly recorded and assessed in the client’s authorised operating arrangements and security risk review. HIPAA does not impose a universal US-only storage rule, but overseas processing can introduce additional risks. Applicable client, payer, programme, contractual and local restrictions must be checked; this notice does not authorise access that the client has not approved.
Separation from marketing
Patient and insurance information is outside the ordinary B2B lead-generation brief. Medical billing instructions must not be interpreted as permission to use patient records for lead generation, unrelated enrichment or advertising. Any additional purpose requires its own lawful authority and agreed scope.
Patient requests, incidents and retention
Patients should contact their healthcare provider for record access, amendments and other requests. HQL assists the provider according to the BAA and applicable requirements. Suspected incidents must be escalated under the agreed client incident procedure. Retention, return, deletion and backup treatment follow client instructions and applicable requirements; the website enquiry five-year period does not apply automatically to patient records.
Business enquiries only
Use the HQL website enquiry form to discuss practice requirements. Never submit patient names, medical records, insurance identifiers or other protected information through Tally or this public enquiry route. Patient-data exchange requires the separately approved client system and process.
Legal policies