Skip to content

Policies

Health Information Privacy

Your medical bill is health information, and it is protected. This page explains what Patient Payments does with it, what it does not do with it, and why questions about your rights go to your healthcare provider rather than to us.

Effective

This is not your provider's Notice of Privacy Practices

Your healthcare provider issues the Notice of Privacy Practices that covers your care. This page is not that notice and does not replace it. Ask your provider for theirs, or look for it on their website or in the paperwork from your visit.

Under HIPAA, the notice is something a healthcare provider or health plan gives you. Patient Payments is neither. We are a business associate — a company your provider hired to do one job on their behalf, and bound by a written agreement about how we handle your information while we do it.

Who we are in this

Reclaimly, Inc. operates Patient Payments. Healthcare providers use it to show patients what they owe and to take payment.

Before any patient information reaches us, we sign a business associate agreement with the provider. That agreement is what limits us: it sets out what we may do with the information, requires us to safeguard it, requires the same of anyone we use to help, and requires us to return or destroy it when the relationship ends.

We do not decide what you owe, we do not hold your medical record, and we do not treat you. Your provider does all three.

What health information appears here

Depending on what your provider sends us and which screen you open, the pages can show:

  • Your name and date of birth.
  • An account or bill reference from your provider.
  • The balance you owe, and payments already made against it.
  • Dates of service, and the name of the provider or facility.
  • Itemised charges — what was billed, what insurance paid, what was written off, and what is left for you. This is only shown after you confirm your identity, and only if you ask for it.

We never ask for, and never hold, your Social Security number or your bank sign-in.

How the link in your message works

There is no account here and no password. The five-character code at the end of your link is what opens your bill, which means the link itself is the key — anyone holding it can see your balance.

Two things follow from that, and both are deliberate:

  1. Treat the link like a key. Do not forward it, post it, or read the code out to someone who called you.
  2. The itemised breakdown needs more than the link. To see the charges line by line, you have to enter the patient's last name and date of birth — which may not be yours, because the person paying a medical bill often is not the patient. That second step exists so that a forwarded link on its own does not open the details of someone's care.

Links are personal and time-limited, and stop working after a while. If yours has expired, your provider can send a new one.

How we may use and disclose it

Only to run the payment service for your provider, and only as our agreement with them and HIPAA permit. In practice that means showing you your bill, taking your payment, setting up and running a payment plan, telling you when something needs your attention, and answering your questions about the payment.

We also disclose information where the law requires it — for example, in response to a valid court order.

What we do not do

  • We do not sell your information. Not any of it, to anyone, ever.
  • We do not use it for marketing, and we do not let anyone else do so.
  • We do not use it for our own purposes, such as building products or training models.
  • We do not share your mobile number, your email address or your postal address for marketing or promotion. See the Text Message Terms.

Who else handles it

Your provider
They send us the bill and they receive the payment. They hold your medical record.
The payment processor
Stripe. Your card details go straight to them over an encrypted connection — we never receive or store your full card number.
Hosting and infrastructure
The providers that run the servers this site is served from, under written terms that hold them to the same safeguards.
Getting in touch with you
The services that deliver a text message, an email or — where your provider still posts paper — a printed statement. Each one receives the address it needs to reach you and the message itself, and nothing beyond that.
Analytics and error reporting
Two tools that tell us how the payment pages are performing. They receive counts of named actions and the details of anything that breaks, with the code from the web address and any name, date of birth or contact detail removed before it is sent. They never receive your bill, and they never record what is on your screen.

Everyone in that list is bound by a written agreement covering how they may handle your information. Nobody in it is permitted to use it for their own purposes.

Your rights, and where to exercise them

HIPAA gives you rights over your health information — to see it, to get a copy, to ask for a correction, to ask for an accounting of disclosures, and to ask for restrictions on how it is used.

Those requests go to your healthcare provider, not to us. They hold your record and they are the ones HIPAA gives the duty to answer. We cannot grant these requests on their behalf, and it would not be honest to pretend otherwise.

If you send us a request of this kind anyway, we will forward it to your provider and tell you that we have. Write to info@reclaimly.com.

If you want to complain

You can complain to your provider, to us at info@reclaimly.com, or directly to the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr/complaints. Nobody may retaliate against you for filing a complaint.

How we protect it

  • Everything is served over an encrypted connection, and information is encrypted where it is stored.
  • Access is limited to the people who need it to do their job, and access is logged.
  • Card numbers never reach our systems. They go directly from your browser to the payment processor.
  • The pages that carry your information tell search engines not to index them, and are not listed anywhere public.
  • Anyone we use to help run the service is bound by a written agreement with the same obligations.

There is no such thing as a HIPAA certification, and we do not claim one. What we can tell you is what we actually do, which is the list above.

If something goes wrong

If health information we hold is exposed, we notify your healthcare provider without unreasonable delay, as our agreement with them and HIPAA require. Your provider is the one who notifies you — they hold the relationship, and HIPAA gives them the duty.

If you think something has gone wrong — a bill that is not yours, a message meant for someone else, a link that showed you the wrong information — tell us straight away and we will act on it.

Contact us

Privacy questions
info@reclaimly.com
Everything else
info@reclaimly.com
Who we are
Reclaimly, Inc., a Delaware corporation.

For anything about your care, your medical record, or what you were charged for, contact your healthcare provider directly.

Questions about this page? Email info@reclaimly.com . Effective 1 July 2026.