Privacy Policy

Effective Date: April 10, 2026 Last Updated: July 4, 2026

Med Aura Medical Billing (“Med Aura,” “we,” “us,” or “our”), operated by Med Aura Billing Services LLC, a New Jersey limited liability company, is committed to protecting the privacy, confidentiality, and security of the personal and sensitive information we collect, use, and maintain in the course of providing medical billing, medical coding, credentialing, revenue cycle management (RCM), and related healthcare administrative services.

This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information through our website, https://medauramedicalbilling.com (the “Website”), and through our services, in compliance with applicable federal and state laws, including the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and its implementing regulations.

By accessing or using our Website or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Website or services.


1. Who We Are

Med Aura Medical Billing is a U.S.-based medical billing and revenue cycle management company headquartered in Woodbridge Township, New Jersey. We serve as a business associate to healthcare providers, practices, and facilities, handling billing, claims submission, coding, credentialing, prior authorization, denial management, and related services on their behalf.

When we process Protected Health Information (PHI) on behalf of our healthcare provider clients, we do so under Business Associate Agreements (BAAs) as required by HIPAA. Your healthcare provider maintains its own privacy practices; we encourage you to review your provider’s Notice of Privacy Practices for information about how they handle your health information.

2. Information We Collect

2.1 Personal Information

Depending on how you interact with us, we may collect:

  • Contact and identity information — names, mailing addresses, phone numbers, email addresses, and job titles of healthcare providers, practice staff, and patients.
  • Practice and business information — practice name, organization details, NPI numbers, tax identification numbers, and payer enrollment information.
  • Insurance information — policy numbers, insurance carrier names, coverage details, and claims data.
  • Financial and billing information — payment records, invoicing details, and banking information necessary to process transactions.
  • Website and device information — IP address, browser type, device type, operating system, referring URLs, pages visited, and general geolocation (city/state level) derived from your IP address.
  • Communications data — records of your correspondence with us, including form submissions, emails, phone calls, and SMS messages (where you have consented to receive them).

2.2 Protected Health Information (PHI)

In the course of providing medical billing and related services to our healthcare provider clients, we may receive and process PHI, including medical records, diagnosis codes, treatment and procedure information, dates of service, and other health data necessary for billing, coding, claims processing, and reimbursement purposes. All PHI is handled strictly in accordance with HIPAA, our Business Associate Agreements, and this Privacy Policy.

2.3 How We Collect Information

  • Directly from you, when you fill out forms on our Website (such as our “Contact Us” or consultation request forms), request a demo or quote, subscribe to communications, call us, or otherwise correspond with us.
  • From our healthcare provider clients, when they engage us to perform billing, coding, credentialing, or RCM services.
  • From insurance payers and clearinghouses, in connection with claims processing, eligibility verification, and remittance.
  • Automatically, through cookies and similar technologies when you browse our Website (see Section 8).

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Preparing, submitting, and following up on insurance claims on behalf of our healthcare provider clients.
  • Medical coding, charge entry, payment posting, and accounts receivable management.
  • Provider credentialing, payer enrollment, and contract management.
  • Prior authorization and eligibility verification.
  • Denial management, appeals, and claims resolution.
  • Communicating with providers, payers, and patients regarding billing, claims, and account matters.
  • Responding to your inquiries, consultation requests, and support needs.
  • Improving our Website, services, and user experience.
  • Maintaining the security and integrity of our systems.
  • Complying with legal, regulatory, and contractual obligations, including HIPAA.

We may use aggregated, anonymized, or de-identified data (which cannot reasonably be used to identify you) for analytics, service improvement, and other lawful business purposes.

4. How We Protect and Manage Your Data

We maintain a comprehensive, multi-layered data protection program designed to safeguard your information:

4.1 Data Security Measures

  • Encryption: All sensitive information, including PHI, is encrypted in transit and at rest using industry-standard encryption protocols.
  • Access Controls: Access to sensitive data is restricted to authorized personnel on a strict need-to-know basis. Role-based access controls and multi-factor authentication minimize data exposure.
  • Secure Infrastructure: Our systems are hosted in secure, HIPAA-compliant environments protected by firewalls, intrusion detection and prevention systems, and continuous monitoring.
  • Data Backups: We maintain regular, encrypted backups of critical data to ensure recoverability in the event of hardware failure, cyber incidents, or other emergencies.
  • Incident Response: We maintain documented incident response procedures. In the event of a breach affecting PHI, we will provide notifications as required by the HIPAA Breach Notification Rule and applicable state laws.

4.2 Workforce Training

All employees and contractors undergo privacy and security training upon hire and regularly, including HIPAA compliance, phishing awareness, and secure data handling practices. Workforce members are bound by confidentiality obligations.

4.3 Data Retention

We retain personal information and PHI only as long as necessary to fulfill the purposes described in this Privacy Policy, to satisfy our contractual obligations to clients, or as required by applicable law and record-retention requirements. When information is no longer needed, it is securely deleted, destroyed, or de-identified.

4.4 Vendor and Third-Party Oversight

We conduct due diligence on third-party service providers and require them, by contract (including BAAs where PHI is involved), to maintain safeguards consistent with our security and privacy standards. We periodically review and monitor vendor compliance.

While we implement robust safeguards, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

5. Information Sharing and Disclosure

Your privacy is of the utmost importance to us. We do not sell, rent, or trade your personal information. We do not share personal information — including phone numbers or SMS opt-in consent — with third parties or affiliates for marketing or promotional purposes under any circumstances.

We may disclose information only in the following limited circumstances:

5.1 Claims Processing and Payer Communications

We disclose necessary information to insurance companies, clearinghouses, and government payers (such as Medicare and Medicaid) to submit claims, verify coverage, obtain authorizations, and secure reimbursement for the services our clients deliver.

5.2 Authorized Service Providers

We may engage trusted third-party providers — such as clearinghouses, payment processors, IT and hosting providers, and practice management software vendors — to support our operations. These providers are contractually bound to protect your information, use it only to perform their designated functions, and, where PHI is involved, comply with HIPAA under a Business Associate Agreement.

5.3 Legal and Regulatory Compliance

We may disclose information to regulatory authorities, courts, or government agencies when required by law, regulation, subpoena, court order, or other legal process, or when necessary to protect our legal rights, prevent fraud, or ensure the safety of any person.

5.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of our business, information may be transferred to the successor entity, subject to the commitments made in this Privacy Policy and applicable law.

6. SMS/Text Messaging Privacy

If you opt in to receive SMS communications from Med Aura Medical Billing:

  • No third-party sharing: SMS opt-in consent and phone numbers collected for SMS purposes will not be shared with, sold to, or disclosed to any third party or affiliate for marketing or promotional purposes.
  • Purpose limitation: SMS messages are used solely for service-related communications, such as billing updates, account notifications, appointment or meeting reminders, and support responses.
  • Opt-out anytime: You may opt out at any time by replying STOP to any message. Reply HELP for assistance, or contact us at 862-445-6962 Ext. 101.
  • Message and data rates may apply. Message frequency may vary.

Full SMS terms are described in our Terms and Conditions at https://medauramedicalbilling.com/terms-and-conditions/.

7. Your Privacy Rights

7.1 Rights Related to Your Information

Depending on your relationship with us and applicable law, you may have the right to:

  • Access — request a copy of the personal or billing information we hold about you.
  • Correction — request that we correct inaccurate or incomplete information.
  • Deletion — request deletion of your personal information, subject to legal and contractual retention requirements.
  • Restriction — request limits on how we use or disclose your information.
  • Opt-out — opt out of non-essential communications at any time.

To exercise any of these rights, contact us at 862-445-6962 Ext. 101 or 862-445-6754, or write to us at the address in Section 12. We may need to verify your identity before fulfilling your request, and we will respond within the timeframe required by applicable law.

7.2 HIPAA Rights

If you are a patient, your rights with respect to your PHI (including rights of access, amendment, and accounting of disclosures) are generally exercised through your healthcare provider, who is the covered entity. We will cooperate with our provider clients to support the fulfillment of these rights as required under our Business Associate Agreements.

7.3 State Privacy Rights

Residents of states with applicable consumer privacy laws (including New Jersey under the New Jersey Data Privacy Act) may have additional rights, such as the right to know, access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, sale of personal data, or certain profiling. We do not sell personal data. To exercise applicable state rights, contact us using the details in Section 12. If we decline a request, you may have the right to appeal, and we will provide instructions for doing so.

8. Cookies and Tracking Technologies

Our Website may use cookies and similar technologies (such as analytics scripts and pixels) to operate the site, analyze traffic, understand visitor behavior, and improve functionality and user experience. Cookies are small text files stored on your device.

You can manage or disable cookies through your browser settings. Please note that disabling certain cookies may affect Website functionality. Where required by law, we will request your consent before placing non-essential cookies.

9. Children’s Privacy

Our Website and services are intended for adults aged 18 and over and are directed at healthcare professionals and businesses. We do not knowingly collect personal information from children under 13 through our Website. If you believe a child has provided us personal information, please contact us and we will delete it in accordance with applicable law, including COPPA. (Note: PHI relating to minor patients that we process on behalf of healthcare providers is handled under HIPAA and our Business Associate Agreements, not through this Website.)

10. Third-Party Links

Our Website may contain links to third-party websites, platforms, or services that we do not control. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party sites you visit.

11. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. Updated versions will be posted on this page with a revised effective date. Your continued use of our Website or services after changes are posted constitutes your acceptance of the updated Policy. We encourage you to review this page periodically.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Med Aura Medical Billing Med Aura Billing Services LLC

Address: 55 Burnet Street, Woodbridge Township, NJ 07001, United States Phone (Main): +1 862-445-6962 Ext. 101 Phone (Primary): +1 862-445-6754 Email: info@medauramedicalbilling.com Website: https://medauramedicalbilling.com