AC Billing Solutions
Website: get.acbillingsolutions.com
Privacy Officer: HIPAA Privacy Officer, AC Billing Solutions
Telephone Number: (845) 520-9395
Email: info@acbillingsolutions.com
Effective Date: 09/23/2026
get.acbillingsolutions.com is owned and operated by AC Billing Solutions.
1. Our Role Under HIPAA
AC Billing Solutions provides revenue cycle management and medical billing services to behavioral health treatment providers. In performing these services we receive, maintain, and transmit protected health information (PHI) on behalf of those providers.
Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), 45 C.F.R. Parts 160 and 164, we act as a business associate of the covered entities we serve. We are not a covered entity, we do not provide treatment, and we do not have a direct treatment relationship with any patient.
This means:
- We do not issue a Notice of Privacy Practices. That notice is provided to you by the treatment provider that furnished your care.
- Requests to access, amend, or restrict your health information should be directed to the treatment provider that created the record, not to us. Where a provider asks us to assist with such a request, we support the provider in responding.
- We use and disclose PHI only as permitted by our business associate agreement with the provider and as required or permitted by law.
This statement describes how we protect protected health information entrusted to us. It is not a Notice of Privacy Practices and does not replace one.
2. Business Associate Agreements
We execute a written business associate agreement with every covered entity before receiving protected health information. Each agreement obligates us to:
- Use and disclose PHI only as permitted by the agreement or required by law
- Apply appropriate safeguards to prevent unauthorized use or disclosure
- Report any use or disclosure not provided for by the agreement, including security incidents and breaches
- Ensure that any subcontractor who handles PHI on our behalf agrees to the same restrictions and conditions
- Make PHI available to support the covered entity's obligations regarding individual access, amendment, and accounting of disclosures
- Return or destroy PHI at the end of the engagement where feasible
3. Permitted Uses and Disclosures
We use and disclose protected health information only to perform the services our client organizations have engaged us to provide, including:
- Claim preparation, submission, correction, and resubmission
- Eligibility and benefit verification
- Utilization review and authorization support
- Payment posting, reconciliation, and accounts receivable follow-up
- Denial management and appeals
- Reporting to the covered entity on the status of its revenue cycle
We also use and disclose PHI as required by law, and for our own proper management and administration as permitted by 45 C.F.R. § 164.504(e)(4).
We do not sell protected health information. We do not use or disclose protected health information for marketing, and we do not use it for advertising measurement or audience targeting of any kind.
4. Minimum Necessary
We limit requests for, uses of, and disclosures of protected health information to the minimum necessary to accomplish the intended purpose, consistent with 45 C.F.R. § 164.502(b). Access within our organization is restricted to workforce members whose role requires it.
5. Substance Use Disorder Records — 42 CFR Part 2
Many of the organizations we serve are federally assisted substance use disorder treatment programs whose records are protected by 42 C.F.R. Part 2 (the Alcohol and Other Drug Confidentiality Law) in addition to HIPAA.
Where we receive Part 2 records, we act as a qualified service organization to the program and are bound by Part 2's restrictions on use and redisclosure.
Substance use disorder treatment records are protected under 42 CFR Part 2. These records may not be used or disclosed in any civil, criminal, administrative, or legislative proceeding against the individual without written consent or a court order. Penalties for violations align with HIPAA civil and criminal enforcement.
We do not redisclose Part 2 records except as permitted by the program's consent, by a qualifying court order, or as otherwise authorized by Part 2.
6. Safeguards
We maintain administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of electronic protected health information, consistent with the HIPAA Security Rule:
Administrative. Designated privacy and security responsibility, workforce HIPAA training at onboarding and periodically thereafter, role-based access authorization and prompt revocation on separation, risk analysis and risk management, and written policies and procedures.
Physical. Controlled access to facilities and work areas where PHI is handled, workstation use and security policies, and secure handling and disposal of media containing PHI.
Technical. Unique user identification, access controls, encryption of PHI in transit and at rest, audit logging and review, automatic logoff, and integrity controls.
7. Breach Notification
If we discover a breach of unsecured protected health information, we notify the affected covered entity without unreasonable delay and no later than the period required by our business associate agreement and 45 C.F.R. § 164.410. Our notification includes the identification of affected individuals and the information reasonably available to us that the covered entity needs to meet its own notification obligations.
Because we are a business associate, notification to affected individuals is made by the covered entity, not by us.
8. Subcontractors
Where we engage a subcontractor that creates, receives, maintains, or transmits protected health information on our behalf, we execute a written business associate agreement with that subcontractor imposing the same obligations that apply to us, as required by 45 C.F.R. § 164.308(b) and § 164.502(e)(2).
9. Complaints and Questions
If you are a patient with a question about your health information, please contact the treatment provider that furnished your care. That provider holds your record and issues its Notice of Privacy Practices.
If you are a client organization, or if you believe we have handled protected health information improperly, contact our HIPAA Privacy Officer:
AC Billing Solutions
Attn: HIPAA Privacy Officer, AC Billing Solutions
1 Hillcrest Center Drive, Suite 230, Spring Valley, NY 10977
Phone: (845) 520-9395
Email: info@acbillingsolutions.com
You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate against anyone for filing a complaint.
10. Related Policies
For information about how we handle information collected through this website, see our Privacy Policy. For the terms governing your use of this website, see our Terms of Use.
11. Changes to This Statement
AC Billing Solutions reserves the right to change the terms of this statement at any time. We will post the current version on our website with an effective date.