MedLink RCM Privacy Policy

Effective date: May 6, 2026    |    Last updated: May 6, 2026

This Privacy Policy explains how Global Link LLC, a California limited liability company doing business as MedLink RCM (“MedLink RCM”, “we”, “us”, or “our”) collects, uses, stores, shares, retains, and disposes of personal information when you visit https://www.medlinkrcm.com (the “Site”), contact us, use our revenue cycle management, medical billing, and dental billing services (the “Services”), or agree to receive text messages from us.

Please read this Policy carefully. By using the Site or the Services, or by opting in to our text messaging program, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Site or opt in to text messages.

1. Who We Are and Who This Policy Covers

MedLink RCM provides outsourced revenue cycle management services to healthcare providers, including patient access and registration support, medical coding, charge capture and billing, claims submission, denial management, accounts receivable follow-up, payment posting, credentialing, and reporting. Our office is located at 3333 Michelson Drive, Suite 210, Irvine, CA 92612.

This Policy applies to:

  • Visitors to the Site and anyone who submits a form, email, call, or text message to us;
  • Prospective and current clients (medical practices, dental practices, home health and hospice agencies, hospitals, and other healthcare organizations) and their owners, staff, and authorized contacts;
  • Individuals who opt in to receive text messages from us; and
  • Job applicants and business contacts, to the extent described below.

This Policy does not replace any Business Associate Agreement, Master Services Agreement, or other written contract between us and a client. If this Policy conflicts with a written contract, the contract controls for the data covered by that contract.

2. Protected Health Information (HIPAA Notice)

When we perform Services for a healthcare provider, we act as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”). Any Protected Health Information (“PHI”) we receive, create, maintain, or transmit on behalf of a provider is governed by HIPAA and by the Business Associate Agreement (“BAA”) we sign with that provider, not by this Policy.

  • We use and disclose PHI only as permitted by the applicable BAA and HIPAA, and only to the minimum extent necessary to perform the Services.
  • We do not sell PHI, and we do not use PHI for marketing or advertising.
  • We maintain a written HIPAA privacy and security compliance program, designate a Privacy and Security Officer, train our workforce, perform periodic risk analyses, and follow the safeguards described in Section 8.
  • Patients: your rights to access, amend, or receive an accounting of your health information are exercised through your healthcare provider under that provider’s Notice of Privacy Practices. If you contact us directly about your health information, we will forward your request to your provider promptly and assist the provider in responding.
  • If we ever send text messages to a patient on behalf of a provider (for example, a billing statement notice), we do so only under written instructions from that provider and only to a number the patient has provided for that purpose.

3. Information We Collect

Information you give us directly

  • Contact and inquiry information: name, email address, telephone number, subject, and the content of your message when you use our contact form, request a consultation, call, email, or text us.
  • Text messaging consent: your mobile number, the date and time of your opt-in, the method of opt-in, and your opt-out requests.
  • Client onboarding and account information: practice or organization name, address, tax identification number, National Provider Identifier (NPI), payer and clearinghouse enrollment details, bank information for payment of our fees, user names for portals we access on your behalf, and the names and contact details of your authorized staff.
  • Job applicant information: resume, work history, and contact details if you apply for a position with us.
  • Any other information you choose to provide to us.

Information we collect automatically

  • Device and usage data when you visit the Site: IP address, browser type, operating system, device identifiers, referring pages, pages viewed, time spent, and links clicked.
  • Cookies and similar technologies, as described in Section 7.

Information we receive from other sources

  • Business contact information from referral partners, industry directories, publicly available provider databases (such as NPPES), and professional networking sites.
  • Information from our service providers, such as message delivery status from our text messaging platform.

4. How We Use Information

We use personal information to:

  • Respond to your inquiries and requests and provide quotes and consultations;
  • Set up, provide, support, and improve the Services and manage our client relationships;
  • Send service, account, security, and administrative communications by email, phone, or text message;
  • Send marketing communications about our Services where you have given the required consent, and honor your opt-out choices;
  • Verify identity, prevent fraud, and protect the security of the Site, our systems, and our clients’ data;
  • Comply with legal, regulatory, contractual, and audit obligations, including HIPAA, tax, and record-keeping requirements;
  • Evaluate job applications; and
  • Analyze Site usage to maintain and improve the Site.

We do not use personal information for automated decision-making that produces legal or similarly significant effects about you.

5. Text Messaging (SMS/MMS) Program

MedLink RCM offers a text messaging program so that we can respond to your inquiries and keep you informed about your account and the Services. This section, together with our SMS Terms and Conditions available at https://www.medlinkrcm.com/sms-terms, governs that program.

Types of messages. Depending on the consent you give, we may send: (a) conversational and informational messages, such as replies to your inquiry, meeting and call confirmations, document requests, onboarding steps, account and service notices, and security alerts; and (b) only if you separately agree, occasional marketing or promotional messages about our Services. Consent to receive marketing messages is never required as a condition of purchasing any goods or services.

How you opt in. You may consent to receive text messages by (i) checking the SMS consent box on a form on the Site and submitting your mobile number, (ii) providing your mobile number and agreeing to receive texts in a written agreement, onboarding form, or email, (iii) texting a keyword to our number, or (iv) giving verbal consent to a member of our team, which we document. Sample opt-in language used on the Site: “I agree to receive SMS messages from MedLink RCM regarding my inquiry, account, or services. Message frequency may vary. Message and data rates may apply. Reply STOP to opt out, HELP for help.”

Message frequency and cost. Message frequency varies based on your interactions with us. Message and data rates may apply according to your mobile carrier plan. Carriers are not liable for delayed or undelivered messages.

How to opt out. You may withdraw your consent at any time and by any reasonable means. Reply STOP, QUIT, END, CANCEL, UNSUBSCRIBE, or a similar message to any text from us, or contact us using the details in Section 14. After you opt out we will send one final message confirming your opt-out and will not send further texts unless you opt in again. We process opt-out requests promptly and in all cases within 10 business days as required by law.

Help. Reply HELP to any message, call +1 (888) 426-1280, or email info@medlinkrcm.com for assistance.

How we protect your mobile information. We treat your mobile number and your opt-in and opt-out records as confidential. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All categories of sharing described in Section 6 exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. Our text messaging service provider processes messages solely on our behalf, under contract, and may not use your number or consent data for its own purposes.

Records. We keep a record of your consent (number, date, time, source, and the consent language shown to you) and of any opt-out request so that we can prove compliance and honor your choices. See Section 9 for retention periods.

Timing and scope. We send messages only between 8:00 a.m. and 9:00 p.m. in your local time zone unless you have started a conversation with us or a message is required for security or fraud prevention. We follow the Telephone Consumer Protection Act (TCPA), the CTIA Messaging Principles and Best Practices, and applicable state telemarketing and text messaging laws.

6. How We Share Information

We do not sell personal information, and we do not share personal information with third parties for cross-context behavioral advertising. We share personal information only in the following circumstances:

  • Service providers. We use carefully selected vendors that act on our behalf and under written contracts that restrict their use of your information to providing services to us. These include cloud hosting and data storage, practice management and billing software, clearinghouses, secure email and document exchange, customer relationship management, text messaging and telephony platforms, website hosting and analytics, payment processing, and professional advisors such as attorneys, accountants, and auditors.
  • Subcontractor. Certain back-office production work (such as claim preparation, coding support, payment posting, and accounts receivable follow-up) is performed by MedLink RCM Private Limited, an independent contractor located in India, under a written Subcontractor Business Associate Agreement and security addendum that impose the same HIPAA obligations we owe to our clients. See Section 10 for the safeguards that apply to that arrangement.
  • Payers, clearinghouses, and government programs. In performing the Services we transmit claims, eligibility inquiries, and related information to insurance companies, Medicare, Medicaid, and other payers as directed by our clients. Electronic transactions with government payers are submitted from the United States.
  • Our clients. If you are a patient or a staff member of a client, we share information with that client as part of the Services.
  • Legal and safety. We may disclose information when required by law, subpoena, court order, or governmental request; to enforce our agreements; or to protect the rights, property, or safety of MedLink RCM, our clients, or others.
  • Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy and applicable law, and PHI will be transferred only as permitted by the applicable BAA.
  • With your consent. We may share information for any other purpose you authorize.

For clarity, none of the sharing described above includes your text messaging opt-in data or consent, which is never shared with third parties or affiliates.

7. Cookies, Analytics, and Do Not Track

The Site uses cookies and similar technologies that are strictly necessary for the Site to function and, where used, analytics cookies that help us understand how visitors use the Site. Analytics data is aggregated or pseudonymized and is not combined with PHI. You can control cookies through your browser settings; disabling cookies may affect some Site features. We honor Global Privacy Control signals as a request to opt out of any sale or sharing of personal information. Because there is no common industry standard, we do not currently respond to browser “Do Not Track” signals. We do not use third-party advertising cookies or social media tracking pixels on the Site.

8. How We Protect Information

We maintain a written information security program with administrative, physical, and technical safeguards designed to meet the HIPAA Security Rule and aligned with the NIST Cybersecurity Framework. Our safeguards include:

  • Encryption of data in transit using TLS 1.2 or higher and encryption of data at rest using AES-256 or equivalent;
  • Multi-factor authentication for all systems that store or access personal information or PHI;
  • Role-based, least-privilege access controls, unique user IDs, automatic session timeouts, and prompt removal of access when a workforce member leaves or changes roles;
  • Centralized logging and monitoring of access to systems containing PHI, with audit logs reviewed for unusual activity;
  • Vulnerability management, timely security patching, endpoint protection, and secure configuration standards;
  • Encrypted, access-controlled, and regularly tested backups;
  • An annual enterprise-wide security risk analysis and risk management plan;
  • Workforce screening, confidentiality agreements, and HIPAA privacy and security training at hire and at least annually;
  • Written vendor due diligence and contracts, including Business Associate Agreements, for every vendor that handles PHI;
  • Physical safeguards for our offices, including controlled access, clean-desk rules, and locked storage for any paper records;
  • A documented incident response and breach notification plan, tested at least annually; and
  • Periodic independent third-party security assessments.

Breach notification. If we discover a breach of unsecured PHI, we notify the affected client without unreasonable delay and within the time required by the applicable BAA and HIPAA so that the client can notify affected individuals and regulators. If a security incident affects other personal information, we notify affected individuals and authorities as required by the California Civil Code section 1798.82 and other applicable state breach notification laws.

No system is completely secure. We cannot guarantee absolute security, and you are responsible for keeping any passwords or credentials you use with us confidential.

9. How Long We Keep Information

We keep personal information only as long as needed for the purposes described in this Policy, to meet legal, regulatory, contractual, and audit requirements, and to resolve disputes. Our standard retention periods are:

Category of informationRetention periodBasis
Website inquiries and contact form submissions24 months after our last contact with you, unless you become a clientBusiness need
Text messaging consent recordsFor as long as you are opted in, plus 5 yearsTCPA statute of limitations and carrier audit requirements
Text messaging opt-out (STOP) recordsRetained indefinitely on our do-not-text list so that we never text you again by mistakeTCPA and CTIA requirements
Client contracts, invoices, and business records7 years after the relationship endsFederal and state tax and contract requirements
PHI processed on behalf of a clientFor the term of the BAA; at termination we return or destroy the PHI as the client directs. If return or destruction is not feasible, we extend the protections of the BAA for as long as we hold the information45 CFR 164.504(e)(2)(ii)(J) and the applicable BAA
Claims and billing support recordsAs instructed by the client, which is typically at least 7 years and 10 years for Medicare Advantage recordsCMS and payer record-retention rules
HIPAA compliance documentation (policies, training records, risk analyses, incident records)6 years from creation or the date last in effect, whichever is later45 CFR 164.316(b)(2) and 164.530(j)
System access and audit logsAt least 1 year online and 6 years in archiveHIPAA Security Rule and industry practice
BackupsRetained on a rolling 90-day cycle and then overwritten; information deleted from live systems is purged from backups at the end of that cycleBusiness continuity
Website analytics data14 monthsAnalytics platform retention setting
Job applicant records3 years after the decisionFederal and California employment record rules

When a retention period ends, or when you validly request deletion and no legal obligation requires us to keep the information, we delete or de-identify the information using the disposal methods described in Section 11. Where a legal hold, investigation, or audit requires us to keep information longer, we do so only for as long as that requirement lasts.

10. International Processing and Offshore Safeguards

We are based in the United States and store personal information and PHI on servers located in the United States. As described in Section 6, part of our back-office production work is performed in India by an independent subcontractor. That arrangement is subject to the following safeguards:

  • A written Subcontractor Business Associate Agreement and security addendum that flow down every HIPAA obligation we owe to our clients, including breach reporting to us within 24 hours;
  • Work is performed only inside a US-hosted virtual desktop environment. No PHI or personal information is downloaded to, stored on, or printed from devices located outside the United States, and encryption keys remain under our control in the United States;
  • Offshore staff receive the same HIPAA training, background screening, and confidentiality obligations as our US workforce, and their access is limited to the minimum data needed for their assigned tasks;
  • Data belonging to Medicaid programs in states that prohibit offshore processing, and any other data a client instructs us to keep onshore, is not accessed from outside the United States;
  • Where a client serves Medicare Advantage or Part D members, we complete the required offshore subcontractor attestation; and
  • Electronic transactions with Medicare, Medicaid, and other government payers are submitted and received in the United States.

Any client may opt out of offshore processing for its data by written notice, subject to the terms of its service agreement.

11. How We Dispose of Information

We dispose of personal information and PHI in a way that makes it unreadable, indecipherable, and unable to be reconstructed, following the U.S. Department of Health and Human Services guidance on disposal of PHI and the National Institute of Standards and Technology Special Publication 800-88 Revision 1, Guidelines for Media Sanitization. Specifically:

  • Electronic records in cloud systems are securely deleted, and where the storage is encrypted the associated encryption keys are destroyed (cryptographic erase), so the data cannot be recovered. We obtain deletion confirmation from our service providers where available.
  • Retired hard drives, solid-state drives, removable media, and mobile devices are purged using NIST 800-88 approved methods or physically destroyed (shredded, crushed, or degaussed as appropriate to the media) before disposal or reuse. Devices are never donated, sold, or recycled with data on them.
  • Paper records containing personal information or PHI are placed in locked collection containers and cross-cut shredded to DIN 66399 security level P-4 or higher, either on site or by a NAID AAA certified destruction vendor that provides a certificate of destruction.
  • Electronic waste is handled only by recyclers certified to the R2 or e-Stewards standards.
  • Because our offshore subcontractor works exclusively inside our US-hosted virtual desktop environment with no local storage, no disposal step is required outside the United States.
  • Disposal activities are logged, and certificates of destruction are kept for 6 years.

12. Your Rights and Choices

Subject to applicable law, you may:

  • Access the personal information we hold about you and request a copy in a portable format;
  • Ask us to correct inaccurate personal information;
  • Ask us to delete your personal information, unless we are required by law or contract to keep it;
  • Opt out of marketing emails by using the unsubscribe link in any email or by contacting us;
  • Opt out of text messages at any time by replying STOP or by contacting us in any reasonable manner (see Section 5);
  • Control cookies through your browser settings; and
  • Designate an authorized agent to make a request on your behalf, provided the agent gives us proof of authorization.

To exercise these rights, contact us at privacy@medlinkrcm.com or +1 (888) 426-1280. We will verify your identity before acting on a request, typically by matching the information you provide against the information we hold, and we will respond within 45 days, which may be extended by a further 45 days where permitted by law. We will not discriminate against you for exercising any of your rights.

California residents. To the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), applies to us, California residents have the rights to know, delete, correct, and receive a portable copy of their personal information; to opt out of any sale or sharing of personal information (we do not sell or share personal information as those terms are defined in the CCPA); to limit the use of sensitive personal information; and to be free from discrimination. In the preceding 12 months we have collected the categories of personal information listed in Section 3 for the purposes listed in Section 4 and disclosed them to the categories of recipients listed in Section 6. PHI covered by HIPAA and information covered by the California Confidentiality of Medical Information Act are exempt from the CCPA. California Civil Code section 1798.83 (“Shine the Light”) permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes; we do not make such disclosures.

Other states. Residents of states with comprehensive privacy laws (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) may have similar rights and may appeal our decision on a request by contacting us at the address in Section 14. To the extent those laws apply to us, we honor them.

Patients. Your rights concerning your health information are exercised through your healthcare provider (see Section 2).

13. Children

The Site and the Services are intended for businesses and adults. We do not knowingly collect personal information from anyone under 18 years of age through the Site, and we do not knowingly sell or share the personal information of consumers under 16. If you believe a child has provided us personal information, contact us and we will delete it.

14. Third-Party Websites

The Site may contain links to websites or services we do not operate, such as payer portals or software vendors. This Policy does not apply to those sites, and we encourage you to read their privacy policies.

15. Changes to This Policy

We may update this Policy from time to time. When we do, we will post the revised Policy on the Site and update the effective date at the top. If we make material changes to how we use personal information, we will provide additional notice, such as by email or a notice on the Site, before the change takes effect. Your continued use of the Site or the Services after the effective date means you accept the revised Policy.

16. How to Contact Us

Questions, requests, or complaints about this Policy or our privacy practices may be directed to our Privacy and Security Officer:

  • MedLink RCM (Global Link LLC), Attention: Privacy and Security Officer
  • 3333 Michelson Drive, Suite 210, Irvine, CA 92612
  • Email: privacy@medlinkrcm.com (privacy requests) or info@medlinkrcm.com (general)
  • Phone: +1 (888) 426-1280
  • Hours: Monday to Friday, 8:00 a.m. to 7:00 p.m. Central Time; Saturday, 9:00 a.m. to 2:00 p.m. Central Time

We prohibit retaliation against anyone who raises a privacy concern in good faith. If you believe your HIPAA rights have been violated you may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at www.hhs.gov/ocr. California residents may contact the California Privacy Protection Agency or the California Attorney General.

MedLink RCM SMS Terms and Conditions

Effective date: September 3, 2026

These SMS Terms and Conditions govern the text messaging program operated by Global Link LLC, a California limited liability company doing business as MedLink RCM (“MedLink RCM”, “we”, or “us”). By opting in you agree to these terms and to our Privacy Policy at https://www.medlinkrcm.com/privacy-policy.

Program description

MedLink RCM sends text messages (SMS and MMS) to people who have opted in, for the purpose of responding to inquiries, confirming calls and meetings, requesting documents, and sending account, service, onboarding, and security notices related to our revenue cycle management and medical and dental billing services. Marketing or promotional messages are sent only to people who have separately agreed to receive them.

How to opt in

You can opt in by checking the SMS consent box and entering your mobile number on a form on our website, by agreeing to receive texts in a written agreement or onboarding form, by texting a keyword to our number, or by giving verbal consent to a member of our team. Consent to receive marketing texts is not a condition of purchasing any goods or services.

Message frequency

Message frequency varies depending on your interactions with us.

Cost

Message and data rates may apply. Check with your mobile carrier for details. Carriers are not liable for delayed or undelivered messages.

How to opt out

Reply STOP to any message to cancel at any time. You may also reply QUIT, END, CANCEL, or UNSUBSCRIBE, or contact us at +1 (888) 426-1280 or info@medlinkrcm.com. After you opt out you will receive one final message confirming that you have been unsubscribed. You may opt back in at any time by replying START or by opting in again through one of the methods above.

Help and support

Reply HELP to any message, call +1 (888) 426-1280, or email info@medlinkrcm.com.

Privacy

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. See our Privacy Policy for details on how we collect, use, protect, retain, and dispose of your information.

Sample messages

  • MedLink RCM: Thanks for your inquiry. A member of our team will call you within one business day. Reply STOP to opt out, HELP for help.
  • MedLink RCM: Your onboarding call is confirmed for Tue 10:00 AM CT. Reply STOP to opt out, HELP for help.

Eligibility and changes

You must be 18 or older and the account holder or authorized user of the mobile number you provide. We may change or end the program at any time, and we will post any changes to these terms on our website.

Contact

MedLink RCM (Global Link LLC), 3333 Michelson Drive, Suite 210, Irvine, CA 92612. Phone +1 (888) 426-1280. Email info@medlinkrcm.com.