Privacy Policy & Cookies Policy
RevGen Billing — Medical Billing Services & Revenue Cycle Management
Website: https://revgenbilling.com
This Privacy Policy and integrated Cookies Policy (collectively, the “Policy”) governs the information practices of RevGen Billing (“RevGen,” “we,” “us,” or “our”) in connection with the website located at https://revgenbilling.com (the “Site”). By accessing or using the Site, you acknowledge that you have read, understood, and agree to be bound by this Policy.
1. Introduction & Scope
RevGen Billing is a provider of medical billing, medical coding, revenue cycle management (RCM), accounts receivable management, credentialing and enrollment, prior authorization, denial management, medical billing audit, MACRA/MIPS reporting, and contract negotiation services to healthcare practices, medical billing companies, and related healthcare entities (collectively, our “Services”). This Policy applies exclusively to information collected through the Site and through direct communications (email, contact forms, telephone, and newsletter subscriptions) initiated through the Site. It does not govern Protected Health Information (“PHI”) that RevGen processes on behalf of its healthcare provider clients pursuant to signed Business Associate Agreements (“BAAs”) under the Health Insurance Portability and Accountability Act (“HIPAA”). PHI received by RevGen in its capacity as a business associate is handled under the terms of the applicable BAA and not under this consumer-facing website Policy.
RevGen is committed to protecting the privacy of all visitors, prospective clients, existing clients, newsletter subscribers, and other individuals who interact with the Site. We adhere to applicable global data protection laws, including, without limitation, the European Union General Data Protection Regulation (“GDPR”), the United Kingdom GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other analogous state, federal, and international privacy legislation.
2. Information Collection Matrix
The following matrix itemizes each category of information collected by or through the Site, the source of such information, the purposes for which it is collected, and the retention period. We collect only the information reasonably necessary to operate, secure, and improve the Site and to deliver the information and Services requested by our visitors.
| Category of Data | Specific Data Points | Source / Collection Method | Primary Purpose | Retention |
|---|---|---|---|---|
| Log Data | IP address; browser type and version; operating system and platform; referring/exit pages; date/time stamp; page views; clickstream data; requested URLs; HTTP status codes; bandwidth usage; ISP; mobile network information (if applicable). | Automatically collected by web servers, Content Delivery Networks (CDN), and security/firewall systems upon each Site visit. | Site availability, troubleshooting, fraud and abuse prevention, bandwidth management, security incident detection, and compliance with legal obligations. | 12 months (server logs); longer if required by law or active security investigation. |
| Device & Analytics Data | Device type (desktop, tablet, mobile); screen resolution; language preference; time zone; hardware model; JavaScript support; anonymized/pseudonymized user identifiers; aggregate interaction metrics (scroll depth, session duration, click events, form interaction events). | Automatically collected via analytics tooling (e.g., Google Analytics or comparable services — see Cookies section), JavaScript beacons, and pixel tags upon consent where required. | Site optimization, usability testing, performance measurement, content relevance improvement, A/B testing, and understanding audience segments in aggregate. | 26 months from collection (or shorter per tool settings); anonymized data retained indefinitely in aggregated form. |
| Cookie Identifiers & Similar Tracking Technologies | First-party and third-party cookie IDs; persistent and session cookie identifiers; local storage objects; pixel/web beacon identifiers; advertising IDs where applicable and consented. | Placed on your browser or device by the Site, our analytics providers, and (where consented) advertising/marketing partners, subject to the cookie consent banner. | Session continuity, preference storage, traffic measurement, performance monitoring, fraud prevention, and (where consented) personalized marketing/retargeting. | Session cookies: deleted on browser close. Persistent cookies: up to 13 months (or longer for strictly necessary cookies). See Cookies section for granular list. |
| Newsletter Signup Data | Full name; email address; practice/organization name (optional); specialty (optional); consent timestamp; IP address at time of signup; email engagement events (opens, clicks, bounces, unsubscribes). | Voluntarily submitted by the user through our newsletter subscription form. Double opt-in confirmation may be used. | Delivery of requested newsletters, industry updates, revenue cycle insights, service announcements, and compliance-related content; measuring newsletter performance. | For the duration of the subscription plus 30 days following unsubscribe; consent records retained for 6 years to demonstrate lawful basis. |
| Contact / Comment / Inquiry Data | Full name; email address; phone number; practice/organization name; specialty; message content; uploaded attachments (if any); consent timestamp; correspondence history. | Voluntarily submitted through contact forms, demo request forms, free Practice Revenue Audit requests, blog comments, or direct email/telephone contact initiated from the Site. | Responding to inquiries, providing requested information about Services, scheduling consultations, delivering the complimentary Practice Revenue Audit, and pre-contractual due diligence. | 36 months from last contact for sales/CRM purposes; longer if a contractual relationship is formed; comment data retained as long as the comment remains published or as required by law. |
| Client / Prospective Client Data (Contractual) | Billing contact name; practice/company name; business address; business phone; business email; tax/billing identifiers as required for invoicing; service preferences. | Submitted by prospective or engaged clients during onboarding, contracting, and service delivery arranged via the Site. | Performance of the Services contract, invoicing, account management, customer support, and legal/regulatory recordkeeping. | Duration of contract plus 7 years (or longer where required by healthcare, tax, or regulatory recordkeeping obligations). |
3. The Mechanics of Data Processing
3.1 How We Use Collected Information
RevGen processes personal data only for specified, explicit, and legitimate purposes. Our processing activities include, but are not limited to, the following:
- Site Operation & Optimization. Log data, device analytics, and performance cookies are processed to maintain the reliability, security, speed, and usability of the Site; diagnose technical issues; prevent unauthorized access, distributed denial-of-service (DDoS) attacks, and other malicious activity; and continuously improve content layout, navigation, and user experience.
- Delivery of Requested Resources. Contact form submissions, newsletter signups, and audit/demo requests are processed to deliver the specific resources, information, communications, and services you expressly request, including industry whitepapers, billing guides, KPI reports, newsletters, and the complimentary Practice Revenue Audit.
- Pre-Contractual & Contractual Performance. Where you express interest in engaging RevGen’s medical billing or RCM services, we process your business contact data to prepare proposals, conduct due diligence, negotiate terms, execute service agreements, onboard your practice, and deliver contracted Services.
- Customer Support & Correspondence. We process communications data to respond to your questions, comments, support requests, or complaints and to maintain records of those interactions.
- Legal Obligations & Regulatory Compliance. We may process personal data where required to do so by applicable law, regulation, court order, subpoena, governmental request, or to establish, exercise, or defend legal claims, including compliance with tax, accounting, healthcare, anti-fraud, and law-enforcement obligations.
- Legitimate Interests. Where not overridden by your data-protection rights, we rely on our legitimate interests in (a) operating and securing the Site; (b) understanding how visitors engage with our content; (c) preventing fraud and abuse; (d) conducting aggregated, de-identified business analytics; and (e) marketing our own Services to existing customers and to individuals who have expressed a clear interest in medical billing services.
- Consent-Based Processing. Where legally required (e.g., for non-essential cookies, email marketing to certain jurisdictions, or certain analytics), processing occurs only on the basis of your freely given, specific, informed, and unambiguous consent, which you may withdraw at any time.
3.2 Lawful Bases Under the GDPR
For EEA/UK data subjects, processing of personal data is grounded in one or more of the following lawful bases under Article 6 of the GDPR: (a) consent (Art. 6(1)(a)); (b) performance of a contract or pre-contractual steps (Art. 6(1)(b)); (c) compliance with a legal obligation (Art. 6(1)(c)); (d) protection of vital interests (Art. 6(1)(d)); (e) performance of a task carried out in the public interest or in the exercise of official authority (Art. 6(1)(e)); and/or (f) our legitimate interests as described above (Art. 6(1)(f)).
3.3 We Do Not Sell Your Personal Information to Third-Party Brokers
RevGen does not, and will not, sell your personal data to third-party data brokers, advertising networks, or information resalers. We do not monetize visitor contact information, newsletter lists, or behavioral profiles. We do not engage in “cross-context behavioral advertising” as that term is understood under California law except to the limited extent, if any, that you provide explicit opt-in consent for marketing cookies (see Section 7). We do not knowingly sell the personal information of minors under 16 years of age. To the extent any sharing of information with service providers occurs — for example, with our email marketing platform, cloud hosting provider, CRM vendor, or analytics provider — such sharing is conducted under written data-processing agreements that limit use to the provision of services to RevGen, incorporate appropriate confidentiality and security obligations, and do not permit those vendors to use your personal data for their own independent commercial purposes.
3.4 Service Providers, Processors & Permitted Disclosures
We may share your information with the following categories of recipients, strictly for the purposes described in this Policy:
- Infrastructure & Hosting Providers — cloud hosting, CDN, DNS, email delivery, and security services required to operate the Site.
- Analytics & Performance Vendors — providers of web analytics, session recording (where lawful), error monitoring, and performance tooling.
- CRM, Email & Marketing Platforms — providers used to manage contact lists, send newsletters, track engagement, and schedule consultations.
- Professional Advisors — attorneys, accountants, auditors, insurers, and compliance consultants bound by professional confidentiality obligations.
- Law Enforcement & Regulators — where disclosure is required by law, subpoena, court order, or governmental authority, or where we reasonably believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Corporate Transaction — in connection with a merger, acquisition, reorganization, financing, asset sale, or bankruptcy, in which case personal data may be transferred as a business asset subject to appropriate confidentiality protections and applicable law.
3.5 Data Security
RevGen implements and maintains commercially reasonable administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, destruction, or misuse. These safeguards include, as appropriate, encryption in transit (TLS 1.2+), encryption at rest, role-based access controls, strong authentication, regular vulnerability assessments, logging and monitoring, employee confidentiality training, and vendor due diligence. However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.
3.6 International Data Transfers
RevGen is headquartered in the United States and processes data on servers located primarily in the United States. If you access the Site from outside the United States (including the EEA, UK, or Switzerland), your information may be transferred to, stored in, and processed in the United States or other jurisdictions where our service providers maintain facilities. Where such transfers involve personal data subject to the GDPR or equivalent regimes, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs), UK International Data Transfer Addenda, adequacy decisions where applicable, or other lawful transfer mechanisms to ensure an adequate level of protection.
3.7 Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, reporting, or evidentiary requirements, and in accordance with the retention periods set forth in the Information Collection Matrix in Section 2. When data is no longer required, we securely delete, anonymize, or aggregate it.
4. Your International Privacy Rights
Depending on your jurisdiction of residence, you may enjoy certain statutory rights regarding your personal data. This section summarizes rights under the CCPA/CPRA (California), the GDPR (EEA/UK), and analogous regimes. Rights requests may be submitted using the contact information in Section 9. We will respond to verifiable requests within the timeframes required by applicable law (generally 45 days under CCPA/CPRA, extendable by an additional 45 days where necessary; one month under GDPR, extendable by two further months where necessary for complex requests).
Right of Access / Right to Know
You may request disclosure of the categories and specific pieces of personal data we have collected about you, the sources of collection, the purposes for processing, the categories of third parties with whom we have shared the data, and (where applicable) the business or commercial purpose for collection or sharing.
Right to Deletion
You may request the deletion of personal data we hold about you, subject to exceptions such as data needed to complete a transaction, detect security incidents, exercise free speech, comply with legal obligations, or engage in scientific/historical research in the public interest.
Right to Opt-Out of Sale / Sharing
Because RevGen does not sell personal data to third parties, there is generally nothing to opt out of in this regard. However, to the extent certain non-essential marketing cookies or advertising identifiers constitute a “sale” or “sharing” under an expansive reading of applicable state laws, you may opt out by rejecting non-essential cookies via our consent banner or by contacting us.
Right to Data Portability
You may request a machine-readable copy (e.g., CSV or structured electronic format) of the personal data you have provided to us, or request transmission of that data directly to another controller where technically feasible, under applicable law.
Right to Rectification
You may request correction of inaccurate or incomplete personal data we hold about you. We will promptly correct such data upon verification.
Right to Restrict Processing
In certain circumstances (e.g., where accuracy is contested, processing is unlawful, or data is no longer needed but you require it for legal claims), you may request restriction of processing of your personal data.
Right to Object
You may object, on grounds relating to your particular situation, to processing based on our legitimate interests, including profiling. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims. You may also object at any time to processing for direct marketing purposes.
Rights Related to Automated Decision-Making
RevGen does not engage in automated decision-making, including profiling, that produces legal or similarly significant effects concerning you. Where such processing occurs in the future, appropriate safeguards will be provided as required by law.
Right to Withdraw Consent
Where processing is based on consent (e.g., non-essential cookies, newsletter subscription), you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent prior to withdrawal.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your privacy rights, including by denying goods or services, charging different prices/rates, or providing a different level or quality of service, except where such difference is reasonably related to the value provided by your data or otherwise permitted by applicable law.
4.1 CCPA/CPRA — California Resident Disclosures
Pursuant to Cal. Civ. Code § 1798.100 et seq., we disclose the following for the preceding twelve (12) months:
- Categories of personal information collected: Identifiers (name, email, IP, device IDs); internet/network activity (browsing history, interaction with Site); commercial information (services requested, engagement history); electronic/online activity; geolocation (IP-derived); professional/employment information (practice affiliation, specialty); inferences drawn to tailor content and offers.
- Categories of sources: Directly from you (forms, emails); automatically from your device/browser; third-party analytics and marketing partners (where consented); publicly available sources where relevant to business development.
- Business/commercial purposes: As described in Section 3 of this Policy.
- Categories of third parties with whom information is shared: As described in Section 3.4.
- Sale/Sharing: RevGen does not sell personal information for monetary consideration. To the extent any sharing of cookie/advertising identifiers for cross-context behavioral advertising is deemed a “sale” or “sharing” under the CPRA, such activity occurs only with your opt-in consent (where required) and can be disabled via our cookie consent manager.
- Sensitive personal information: The Site does not intentionally collect or process “sensitive personal information” as defined under the CPRA, except where voluntarily submitted in free-text messages.
California residents may submit a verifiable consumer request to exercise the rights described above by emailing privacy@revgenbilling.com. We will verify your identity using a two-step process that may include matching two or more data points you have previously provided to us. Authorized agents may submit requests on behalf of California residents provided they can demonstrate written authorization or valid power of attorney.
4.2 GDPR — EEA/UK Data Subject Rights
Data subjects in the European Economic Area or the United Kingdom may exercise their rights of access, rectification, erasure, restriction of processing, data portability, objection, and the right to lodge a complaint with a supervisory authority (e.g., the data protection authority in your Member State of residence or the UK Information Commissioner’s Office) if you are dissatisfied with our handling of your personal data. We encourage you to contact us first so that we may address your concerns before you escalate to a regulator.
4.3 Other U.S. State Privacy Laws
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with comprehensive consumer privacy legislation enjoy analogous rights to access, correct, delete, obtain a copy of, and opt out of targeted advertising, sale, or profiling in furtherance of decisions that produce legal or similarly significant effects. You may exercise these rights using the contact details in Section 9.
5. Children’s Privacy
The Site is a business-to-business website directed to healthcare professionals, practice administrators, and medical billing decision-makers. It is not directed to children under the age of 16, and we do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will take reasonable steps to delete such information promptly. If you believe a child may have provided us with personal data, please contact us using the details in Section 9.
6. Third-Party Links
The Site may contain links to third-party websites, tools, widgets, or resources (including social media platforms, industry resources, and partner websites) that are not owned or operated by RevGen. This Policy applies solely to our Site. We are not responsible for the privacy practices, content, or policies of those third-party sites. We encourage you to review the privacy policy of every website you visit after leaving our Site.
7. The Cookies Directive — Cookie & Tracking Technologies Policy
7.1 What Are Cookies?
Cookies are small alphanumeric text files that are stored on your device (computer, tablet, or smartphone) when you visit certain websites. They allow the website to recognize your device, remember certain information about your visit (such as preferred language and settings), and enable certain features and functionality. Similar technologies, including local shared objects (“Flash cookies”), HTML5 local storage, web beacons (also known as pixel tags or clear GIFs), JavaScript, and software development kits (SDKs), may perform analogous functions.
7.2 Categories of Cookies We Use
We classify the cookies and similar technologies used on the Site into three categories. You may manage your preferences at any time via our cookie consent banner or the cookie settings panel linked in the Site footer.
| Category | Purpose | Examples / Providers | Duration | Consent Required? |
|---|---|---|---|---|
| Essential (Strictly Necessary) Cookies | Required for the basic operation of the Site, security, fraud prevention, session management, load balancing, and compliance with legal obligations. These cannot be turned off. | Session identifiers; CSRF tokens; cookie-consent-preference cookies; load-balancer cookies; security firewall cookies; WordPress/CM core cookies (if applicable). | Session to persistent (up to 12 months for consent preference cookies). | No (required for legitimate operation). |
| Analytical / Performance Cookies | Collect aggregated or pseudonymous information about how visitors use the Site — pages visited, time on site, error rates, traffic sources — to measure and improve performance, diagnose issues, and optimize content. | Google Analytics (e.g., _ga, _gid, _gat); Hotjar or similar session/heatmap tools (where used); WordPress analytics plugins; internal performance monitoring tools. | Typically 24 hours to 26 months (depending on the provider). | Yes (opt-in where required by GDPR, UK GDPR, and ePrivacy rules; opt-out where governed by certain U.S. state laws). |
| Marketing / Advertising / Targeting Cookies | Used (where enabled) to deliver relevant advertising, measure campaign effectiveness, limit ad frequency, and build audience profiles. These may be set by us or by our advertising partners across websites, and may share identifiers with third-party ad networks. | Google Ads conversion/remarketing; Meta Pixel; LinkedIn Insight Tag; YouTube embeds with advertising-enabled cookies; retargeting pixels (where deployed and consented). | Varies by provider; typically 30 days to 13 months, occasionally longer for persistent advertising IDs. | Yes — activated only upon your explicit opt-in consent. Not deployed in “essential” mode. |
7.3 How to Immediately Revoke Cookie Consent or Clear Cookies
You remain in control of cookies at all times. You can change or withdraw your consent at any time using one or more of the following methods:
Method A — On-Site Consent Manager:
- Click the “Cookie Settings” or “Manage Consent” link located in the Site footer (or reopen the floating consent banner by clearing existing consent cookies as described below).
- Toggle the categories (Essential, Analytical, Marketing) on or off according to your preference. Essential cookies cannot be disabled as they are necessary for basic operation.
- Click “Save Preferences” or “Confirm My Choices.” Your choice will be recorded and respected across future visits, subject to the consent cookie’s expiry.
Method B — Browser Settings to Clear or Block Cookies:
Every major web browser allows you to control cookie behavior directly through its settings. The exact steps vary by browser; the following are current general pathways for popular desktop browsers (please consult your browser’s official help documentation for version-specific instructions):
- Google Chrome: Menu (⋮) → Settings → Privacy and security → Clear browsing data (to delete existing cookies) OR Cookies and other site data → Block all third-party cookies / Block all cookies / See all site data and permissions to manage per-site.
- Mozilla Firefox: Menu (☰) → Settings → Privacy & Security → Cookies and Site Data → Clear Data (to delete) OR Manage Exceptions (to block/allow per site); select “Custom” to block all or third-party cookies.
- Microsoft Edge: Menu (…) → Settings → Cookies and site permissions → Manage and delete cookies and site data → toggle “Block third-party cookies” or use “See all cookies and site data” to delete individual entries.
- Safari (macOS): Safari menu → Settings (or Preferences) → Privacy → Manage Website Data (to delete); check “Block all cookies” or use “Prevent cross-site tracking” for additional controls.
- Safari (iOS/iPadOS): Settings app → Safari → Advanced → Website Data (to delete); toggle “Block All Cookies” or “Prevent Cross-Site Tracking.”
- Opera: Menu → Settings → Privacy & security → Cookies and other site data → clear or block per your preferences.
- Brave: Menu → Settings → Shields → Cookies → select blocking preference; use “Clear browsing data” to delete stored cookies.
Method C — Industry Opt-Out Mechanisms (for Targeted Advertising):
- Digital Advertising Alliance (DAA) opt-out: optout.aboutads.info
- Network Advertising Initiative (NAI) opt-out: optout.networkadvertising.org
- European Interactive Digital Advertising Alliance (EDAA): youronlinechoices.eu
- Google Analytics opt-out browser add-on: tools.google.com/dlpage/gaoptout
7.4 “Do Not Track” Signals
Some browsers transmit “Do Not Track” (“DNT”) signals. Because there is no uniform industry or legal consensus on how website operators should respond to DNT signals, RevGen does not currently alter its tracking practices in response to DNT browser signals. However, we honor the consent choices made through our cookie consent manager and respect the opt-out rights described in Section 4.
8. Newsletter, Marketing Communications & Unsubscribe
If you subscribe to our newsletter or request information about our Services, we will use your email address to send you the communications you have requested. We will not send you unsolicited commercial electronic messages in violation of applicable anti-spam laws (such as CAN-SPAM, CASL, PECR, or GDPR). Every marketing email we send will contain a clear and conspicuous “unsubscribe” link that enables you to opt out of future marketing communications with a single click (or by replying “UNSUBSCRIBE”). You may also opt out at any time by emailing privacy@revgenbilling.com. Please note that even after unsubscribing from marketing messages, we may continue to send you non-marketing, transactional, or service-related communications necessary to fulfill ongoing contractual relationships or legal obligations (e.g., responses to inquiries, billing notices, or updates to this Policy).
9. Data Controller & Contact Information
For the purposes of applicable data protection law, the data controller responsible for personal data collected via the Site is:
RevGen BillingPrivacy / Data Protection Officer
Website: https://revgenbilling.com
Email: privacy@revgenbilling.com
General Inquiries: info@revgenbilling.com
Jurisdiction: United States (federal and applicable state law)
If you wish to exercise any of your rights under this Policy, ask questions about our data practices, or lodge a complaint, please contact us at the address above. We will respond within the legally required timeframe after verifying your identity.
10. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. When we do so, we will revise the “Last Revised” date at the top of this page. Where changes are material or where required by law, we will provide additional notice (such as a banner on the Site or an email to subscribers) before the changes become effective. We encourage you to review this Policy periodically. Your continued use of the Site following the posting of an updated Policy constitutes acceptance of the revised Policy to the extent permitted by law.
11. Governing Law & Dispute Resolution
This Policy shall be interpreted under the laws of the United States and, to the extent applicable, the state in which RevGen maintains its principal place of business, without regard to conflict-of-law principles. Any disputes arising out of or related to this Policy or your use of the Site shall be resolved in accordance with the applicable terms of service or, absent such terms, through good-faith negotiation between you and RevGen, and thereafter in the competent courts of the relevant jurisdiction. Nothing in this section limits your mandatory rights as a consumer under the data protection laws of your country of residence, including your right to lodge a complaint with a supervisory authority.
