HIPAA Privacy & Compliance Notice

Effective Date: September 10, 2026

Universal Practice Solutions LLC (“UPS”) provides medical billing, revenue cycle management, coding, credentialing, contracting, and related administrative services to healthcare providers and organizations.

Because some of the services we provide may involve access to Protected Health Information (“PHI”) on behalf of our healthcare clients, UPS recognizes the importance of maintaining the confidentiality, integrity, and security of such information.

1. Our Role as a Business Associate

When UPS performs services for a healthcare provider or other covered entity that involve the use or disclosure of PHI, UPS may act as a Business Associate as defined under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and applicable regulations.

Our responsibilities relating to PHI are governed by applicable HIPAA requirements and the terms of the applicable Business Associate Agreement (“BAA”) with our healthcare clients.

HIPAA requires covered entities and business associates to maintain appropriate safeguards for electronic protected health information.

2. Permitted Use and Disclosure of PHI

UPS uses and discloses PHI only as permitted by applicable law, our contractual obligations, and applicable Business Associate Agreements.

Depending on the services provided, this may include activities necessary to:

  • Process and manage healthcare claims
  • Perform revenue cycle management
  • Support medical billing operations
  • Perform coding-related services
  • Conduct accounts receivable activities
  • Support credentialing and payer enrollment
  • Perform authorized audits
  • Support healthcare administrative operations
  • Carry out other services authorized by our healthcare clients

UPS does not use or disclose PHI for purposes outside the scope permitted by applicable law and our contractual obligations.

3. Minimum Necessary Access

UPS uses role-based access controls designed to limit workforce access to information based on job responsibilities and business need.

Workforce members are provided access to information appropriate to their assigned responsibilities.

Where HIPAA’s minimum necessary requirements apply, UPS seeks to limit uses and disclosures of PHI to the minimum necessary for the applicable purpose.

4. Workforce Training

UPS provides applicable workforce members with privacy and HIPAA-related training appropriate to their responsibilities.

Employees and other workforce members who may handle protected or confidential information are expected to follow applicable privacy, security, confidentiality, and information-handling requirements.

5. Multi-Factor Authentication

UPS uses multi-factor authentication (“MFA”) as part of its security practices to help protect access to applicable systems and information.

MFA provides an additional layer of authentication beyond a username and password.

6. Administrative, Technical, and Physical Safeguards

UPS maintains safeguards designed to protect PHI and other confidential information against unauthorized access, use, disclosure, alteration, or loss.

Depending on the applicable system, information, and circumstances, safeguards may include:

  • Role-based access controls
  • Multi-factor authentication
  • HIPAA and privacy training
  • Access management
  • Workforce confidentiality requirements
  • Security policies and procedures
  • Administrative controls
  • Technical safeguards
  • Physical safeguards

Security measures may be updated periodically as technology, risks, regulatory requirements, and business operations change.

7. Business Associate Agreements

Where HIPAA requires a Business Associate Agreement, UPS enters into an appropriate BAA with the applicable covered entity or business associate.

The BAA establishes the permitted uses and disclosures of PHI and the applicable responsibilities of the parties.

HIPAA’s Security Rule also establishes requirements applicable to business associates that handle electronic PHI.

8. Subcontractors and Service Providers

Where UPS uses subcontractors or service providers that may create, receive, maintain, or transmit PHI on behalf of UPS in connection with services to a covered entity, UPS will take appropriate steps to ensure applicable contractual and HIPAA requirements are addressed.

The specific systems and vendors used by UPS may change as our operations develop.

9. Security Incidents and Breaches

UPS maintains procedures designed to identify, respond to, and address security incidents involving information within its responsibility.

If UPS determines that a reportable breach of unsecured PHI has occurred, UPS will provide notifications to the applicable covered entity or other responsible party as required by applicable law and the applicable Business Associate Agreement.

10. Website and PHI

The public UPS website is designed for general business and informational purposes.

UPS does not intentionally collect PHI through its general website contact form.

Website visitors should not submit:

  • Patient names
  • Dates of birth
  • Medical records
  • Diagnoses
  • Treatment information
  • Insurance information
  • Social Security numbers
  • Patient account information
  • Claims containing PHI
  • Other protected health information

through the general website contact form.

Existing clients should use the secure systems and communication methods designated by UPS when transmitting PHI.

11. Patient Privacy Rights

UPS recognizes that HIPAA provides certain privacy rights to individuals with respect to their PHI.

As a Business Associate, UPS’s obligations concerning individual rights are generally governed by applicable HIPAA requirements, the covered entity’s responsibilities, and the applicable Business Associate Agreement.

HHS explains that the HIPAA Privacy Rule primarily regulates covered entities, while Business Associates have specific direct obligations under HIPAA and their agreements with covered entities.

If you are a patient seeking access to, correction of, or information about your medical records, you should generally contact your healthcare provider or other applicable covered entity directly.

12. HIPAA Complaints

If you believe that UPS has improperly handled PHI in connection with services provided to a healthcare client, you may contact us using the information below.

We will review privacy and security concerns in accordance with applicable requirements and our contractual obligations.

You may also have the right to submit a complaint to the U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”).

UPS prohibits retaliation against individuals for raising a good-faith privacy or security concern.

13. No Patient Notice of Privacy Practices

This document is intended to describe UPS’s general HIPAA privacy and compliance practices as a healthcare services Business Associate.

This document is not intended to replace or serve as a healthcare provider’s Notice of Privacy Practices.

Healthcare providers and other covered entities are responsible for providing their own applicable Notice of Privacy Practices to their patients as required by HIPAA.

14. Changes to This Notice

UPS may update this HIPAA Privacy & Compliance Notice periodically to reflect changes in our services, security practices, technology, legal requirements, or regulatory guidance.

The updated version will be posted on our website with a revised Effective Date.

15. Contact Us

For privacy, HIPAA, or security-related questions or concerns, contact:

Universal Practice Solutions LLC
7901 4th St N, Suite 34167
St. Petersburg, Florida 33702
United States

Email: info@universalpracticesolutions.com

Website: www.universalpracticesolutions.com