Privacy Policy


Effective Date: May 13th, 2025

Privacy Policy

SCOPE AND PURPOSE

This Privacy Policy (“Policy”) outlines how LUCA Billing and its affiliated companies, subsidiaries, and parent companies (referred to as “LUCA Billing,” “we,” “us,” “our,” or “LB”) collect, use, and disclose information obtained from you through our websites and applications, including www.lucabilling.com (collectively, the “Sites”). This Policy also governs information collected offline—such as at physical offices, LUCA Billing events, or any situation where this Policy is presented to you.

This Policy does not apply to LUCA Billing product offerings with separate privacy policies, or to third-party websites we may link to. We are not responsible for the privacy practices of third-party sites and encourage you to review their privacy policies independently.

LUCA Billing processes data on behalf of healthcare providers according to agreements that may include Business Associate Agreements under the Health Insurance Portability and Accountability Act (“HIPAA”). Please consult your healthcare provider’s privacy practices, as we are not responsible for how they handle your data.


WHAT SERVICES ARE PROVIDED BY LUCA BILLING?

LUCA Billing, based in the United States, delivers network-enabled, cloud-based solutions to healthcare, hospital, and ambulatory care providers nationwide. Our offerings include electronic health records, revenue cycle management (RCM), medical coding, provider credentialing, and patient engagement tools.

For additional details, visit the “About” section on www.lucabilling.com.


LUCA Billing Communications Policy

We ensure that our communication practices uphold transparency, compliance, and client respect.

➜ Communication Channels

Text Messages (SMS):

We use SMS only for:

  • Work-related communication with contracted clients
  • Internal communication among staff

Examples:

  • “Dear Dr. Patel, your billing update for February is now in the portal. – LUCA Billing Team”
  • “Team meeting reminder: Tomorrow at 10 AM – credentialing process updates.”

We do not send marketing or promotional SMS messages.

RingCentral:

Used for secure work-related communication with:

  • Contracted healthcare clients
  • Internal staff
  • Potential clients who request callbacks via our forms

Example Messages:

  • “Hi Dr. Lopez, we’ve processed your claim batch from yesterday.”
  • “The updated billing guideline is now available in your team folder.”

Important: We never send SMS to providers who just submit a contact form. Initial communication is always via phone call.


CLIENT COMMUNICATION

Once a provider becomes a client, we use RingCentral and/or SMS to communicate about:

  • Billing updates
  • Credentialing or RCM-related queries
  • Technical support

Examples:

  • “Hi Dr. Williams, your coding issue has been resolved. – LUCA Billing Team”
  • “Reminder: Your quarterly review is scheduled for Friday.”

📴 Clients may opt out of SMS communication by replying STOP to any message.


CONSENT & OPT-OUT OPTIONS

We obtain explicit SMS consent for:

  • Work-related service updates
  • Reports, meetings, compliance reminders

Examples:

  • “Hello Dr. Moore, your monthly billing summary is ready.”
  • “Reminder: Call scheduled tomorrow for your billing questions.”

Clients can:

  • Reply STOP to opt out
  • Reply HELP for support

📵 Once a client’s contract ends, we cease all communications unless the client initiates further contact.

🚫 We never share SMS consent or phone numbers with third parties.


COMMITMENT TO PRIVACY AND SECURITY

1. HIPAA Compliance

  • Encryption: Emails, calls, and SMS are encrypted in transit and at rest.
  • Access Controls: Only authorized personnel access Protected Health Information (PHI).
  • BAAs: All vendors, including RingCentral, comply with HIPAA.
  • Training & Audits: Regular internal audits and annual HIPAA training for staff.

2. Data Protection

  • Secure Servers: HIPAA-compliant storage with multi-factor authentication.
  • Confidentiality: Client data is never sold or rented.
  • Retention: Data is retained only as legally required.
  • No Spam: We do not send unsolicited marketing communications.

PERSONAL DATA WE COLLECT

Depending on your interaction with us, we may collect:

  • Identifiers: Name, email, IP address
  • Contact Info: Address, phone number
  • Commercial Data: Products/services purchased
  • Device/Usage Info: Browser/device type, activity on our Sites
  • Professional Data: Title, employer
  • Geolocation: City/state from IP, or GPS with consent

HOW WE COLLECT DATA

  • Directly from you: Contact forms, surveys, event registration
  • Automatically: Cookies, session replays, analytics tools
  • Third Parties: Lead generation partners, social networks

HOW WE USE PERSONAL DATA

We use your data to:

  • Fulfill your requests
  • Improve our services and websites
  • Communicate updates, confirmations, and support
  • Ensure security and legal compliance
  • Develop new products based on survey feedback
  • Send important service announcements (not promotions)

We may also use aggregated or anonymized data for lawful purposes.


DATA SECURITY AND RETENTION

  • Encryption and access controls protect your data.
  • Retention periods vary by purpose and legal requirements.
  • In cases where deletion isn’t feasible, we take steps to prevent further processing.

COOKIES & AUTOMATED TECHNOLOGIES

Our websites use:

  • Cookies
  • Pixels
  • Ad tags
  • JavaScript
  • Session replay tools

These help enhance user experience, track website performance, and deliver targeted content. You can manage cookie preferences via the “Cookie Preferences” link at the bottom of our website.


STATE-SPECIFIC PRIVACY RIGHTS

Depending on your state, you may have the right to:

  • Know what personal data we collect
  • Access or correct your data
  • Request deletion of your data
  • Opt out of data sharing or targeted advertising

To exercise your rights, contact us via:

📞 402-741-3200
📧 [email protected]
📝 Contact Form

We may verify your identity before processing your request. If denied, you may have the right to appeal.


FOR USERS UNDER 18

Our Sites are intended for users 18 years or older. We do not knowingly collect data from children under 13. If you believe we have done so in error, contact us immediately for removal.


INTERNATIONAL USERS

By using our website outside the U.S., you acknowledge that your data will be processed in accordance with U.S. laws. Your country may have different data protection rules.


CHANGES TO THIS POLICY

We may revise this Policy at any time. Updates will be posted at www.lucabilling.com and become effective immediately upon posting. Continued use of our Sites signifies your agreement to these changes.


CONTACT US

If you have any questions or wish to exercise your rights:

LUCA Billing
📍 3710 W Plum St, Lincoln, NE 68522
📞 402-741-3200
📧 [email protected]
🌐 www.lucabilling.com


Scroll to Top