This notice describes our role under HIPAA and the safeguards we maintain when handling Protected Health Information on behalf of our provider clients.
Last updated: August 12, 2026
The Xylo International provides medical billing, coding, and revenue cycle management services to healthcare providers. In performing these services, we typically act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA), operating on behalf of our provider clients (the "Covered Entities") under signed Business Associate Agreements (BAAs).
In the course of billing, coding, and follow-up work, we may access Protected Health Information (PHI) such as patient demographics, insurance details, and treatment/diagnosis codes necessary to process claims. We handle this information solely to perform the services requested by our provider clients, consistent with the applicable BAA and the HIPAA Privacy and Security Rules.
We use and disclose PHI only as permitted under our Business Associate Agreements and applicable law — primarily to submit and follow up on claims, post payments, and support the billing operations of our provider clients. We do not use PHI for marketing purposes and do not sell PHI.
Where we engage subcontractors that may touch PHI in support of our services, we require those subcontractors to agree to protections equivalent to those in our own Business Associate Agreements.
In the event we discover a breach involving unsecured PHI, we will notify the affected Covered Entity without unreasonable delay, consistent with HIPAA's Breach Notification Rule and the terms of the applicable BAA, so the provider can meet their own notification obligations to patients.
Because we act as a Business Associate rather than the treating provider, patients seeking access to, or corrections of, their medical or billing records should contact their healthcare provider directly. We assist our provider clients in fulfilling those requests as required by their policies and HIPAA.
Before beginning work with any new practice, we execute a Business Associate Agreement that sets out the permitted uses and disclosures of PHI, required safeguards, and each party's obligations under HIPAA. A copy is available to clients upon request.
Questions about how we handle PHI, or requests related to our HIPAA compliance program, can be directed to info@thexylo.co or +1 (800) 555-0199.
Reach out any time — we're glad to walk through the details of how we protect your practice's and your patients' information.