Accumedic Compliance

Committed to safeguarding the privacy and security of protected health information through rigorous compliance, continuous monitoring, and transparent governance.

Incident Reporting

Suspected data breaches or security concerns must be reported immediately.

Report a Security Concern

Contact: security@accumedic.com

This is a monitored mailbox reviewed by the Compliance & Security team, not an individual inbox.

What to expect once reported:

  • Immediate acknowledgment of receipt
  • Formal documentation in our tracking system
  • Regular updates on the status throughout the incident lifecycle
  • Data Incident Closure Template

HR Hotline

Accumedic Computer Systems, LLC provides a confidential HR hotline for reporting workplace concerns including harassment, discrimination, ethics violations, or any other matter requiring human resources attention.

Contact: James Barrett, Compliance Officer

Phone: 865-384-7865

Email: james.barrett@medsuite.com

  • All reports are treated as confidential to the extent permitted by law
  • Retaliation against anyone who makes a good-faith report is strictly prohibited
  • Reports may be made anonymously if preferred
  • Matters will be investigated promptly and fairly

System Use

Terms governing access to the AccuMed Behavioral Health EHR information system.

  • The AccuMed Behavioral Health EHR information system is used to support Federal, State, and Local Government, and may only be accessed and used for official Government business by authorized personnel only.
  • Unauthorized access, actions, use, modification, or disclosure of the data contained herein or in transit to/from this system constitutes a violation of the Computer Fraud and Abuse Act, Pub. L. No. 99-474, codified at 18 U.S.C. §1030, state criminal and civil laws, and may subject violators to criminal, civil, and/or administrative action and penalties.
  • All authorized use of this system must comply with Executive Orders, directives, policies, regulations, standards, and guidance. Any unauthorized use or actions will be investigated, and if required, prosecuted.
  • All data contained within this information system may be monitored and recorded and disclosed in any manner by authorized personnel. By proceeding to access the information system, the user acknowledges that there is no right to privacy in this system.
  • System personnel may provide law enforcement officials, for investigation and prosecution purposes, any potential evidence of crime found within this information system.
  • The use of this system by any user, authorized or unauthorized, constitutes consent to monitoring, recording and disclosure.

PHI (Protected Health Information)

Any information in a medical context that can identify an individual and relates to their past, present, or future physical or mental health condition, healthcare provided, or payment for healthcare. It is a subset of PII but specifically pertains to health data and is protected under HIPAA. Examples include medical records, insurance information, or details of doctor visits tied to a person.

PII (Personally Identifiable Information)

Any data that can identify an individual, either directly (like a name, Social Security number, or email address) or indirectly (like combining a ZIP code and birth date to identify someone). PII is a broader category that encompasses any personal information, not just healthcare-related information.

Privacy Impact Assessment Policy Statement

Accumedic Computer Systems, LLC recognizes its responsibility to safeguard the privacy of personally identifiable information (PII) and protected health information (PHI) entrusted to us by our clients and their patients. In alignment with NIST SP 800-53 Revision 5, control RA-8, the organization maintains a Privacy Impact Assessment (PIA) process as a living activity that is:

  • Ongoing: PIAs are conducted not only during system acquisition and deployment but also updated whenever technology, practices, or regulatory requirements change.
  • Comprehensive: PIAs address the full set of applicable NIST privacy controls, identifying risks and recommending mitigations.
  • Vendor-inclusive: Vendor assessments include structured evaluation of privacy controls, not limited to breach notification or policy presence.
  • Integrated with Change Management: All system changes, updates, and maintenance activities require a documented privacy risk classification (Low/Moderate/High/Not Applicable).

This ensures that privacy considerations are embedded into system lifecycle management, vendor oversight, and day-to-day operations, thereby reducing the risk of inappropriate disclosure or misuse of PII/PHI.

Accumedic Business Model

Accumedic operates strictly as a B2B (Business-to-Business) entity, processing medical claims on behalf of healthcare providers for submission to payers. We do not offer consumer-facing services, nor do we interact directly with individuals regarding their personally identifiable information (PII). All HIPAA and PII data remain securely contained within our Azure cloud environment, and data is disclosed only to the extent necessary for claims processing and payment purposes, in compliance with legal and contractual requirements. Therefore, mechanisms for individual access and review of PII are not applicable to our business model.

Routine Uses and Required Disclosures

While Accumedic operates as a Business Associate and does not interact directly with individuals, we make limited disclosures of PII/PHI as authorized by our Business Associate Agreements and applicable law. Such disclosures fall into the following enumerated categories:

  • Disclosure to the Customer (Covered Entity): primary purpose, governed by BAA.
  • Disclosure to payers and clearinghouses: for the submission, adjudication, and reconciliation of medical claims, on behalf of and at the direction of the Customer.
  • Disclosure to authorized subcontractors and third-party service providers: including cloud infrastructure (Microsoft Azure), security operations (SOC), and audit and compliance vendors — under signed BAAs that bind subcontractors to equivalent privacy and security obligations.
  • Disclosure pursuant to court order, subpoena, or other legal process: only when legally compelled, with notice to the affected Customer and, where applicable, qualified protective orders, in accordance with 45 CFR §164.512(e) and (f).
  • Disclosure to the U.S. Department of Health and Human Services (HHS): for compliance investigations and enforcement actions, in accordance with 45 CFR §160.310.
  • Disclosure for required breach notification: to the Customer (Covered Entity), and, where required, to affected individuals, regulators, and the public, in accordance with 45 CFR §164.410.
  • Disclosure to authorized auditors: for SOC 2, OHIP, FedRAMP, and similar third-party audit programs, under non-disclosure agreements.

Accumedic does not sell, rent, or share PII/PHI with any party for marketing or commercial purposes outside the scope of the Business Associate relationship.

Compliance

Our commitment to regulatory standards and best practices.

  • Accumedic is committed to maintaining compliance with all applicable laws and regulations governing the privacy and security of PII and PHI.
  • Regular audits and assessments are conducted to ensure adherence to HIPAA, HITECH, and other relevant standards.
  • Staff training programs are implemented to promote awareness and understanding of compliance requirements.
  • Policies and procedures are regularly reviewed and updated to reflect changes in regulations and best practices.

Certifications & Assessments

Current certifications and independent assessments.

ONC Health IT Certification

AccuMed Behavioral Health EHR holds an active ONC Health IT certification, issued by Drummond Group. The listing is published on the ONC Certified Health IT Product List (CHPL).

Assurance Documentation

Customers, auditors and insurers requiring assurance documentation should contact the security office. Requests are reviewed and responded to individually.

Requests: security@accumedic.com

Leadership & Designations

Roles responsible for security, privacy, compliance and technology.

Security Officer / ISSO
James Barrett
Information system security oversight, security program ownership, and primary point of contact for external auditors and assessors.
james.barrett@medsuite.com
Virtual CISO
Designation pending
Provides independent security oversight, advisory services, and review of Security Officer activities to ensure separation of duties.
security@accumedic.com
Compliance Officer
James Barrett
Ensures the organization complies with applicable legal and regulatory requirements, including HIPAA and New York State obligations.
james.barrett@medsuite.com
Privacy Officer
James Barrett
Responsible for privacy program oversight under 45 CFR §164.530(a)(1), including uses and disclosures of protected health information.
james.barrett@medsuite.com
Chief Technology Officer
Eddie Frederick
Technology strategy and engineering oversight across the MedSuite group.
eddie.frederick@medsuite.com
VP of Engineering
Rick Laymance
Product engineering leadership for AccuMed Behavioral Health EHR and the practice management application.
rick.laymance@medsuite.com
Director of Operations
Rosana Hiralal-Darr
Day-to-day operations, business processes and operational workflows.
rosana.hiralal-darr@accumedic.com
Chief Financial Officer & Human Resources
Jason Vandenbogaard
Financial oversight, and workforce administration including onboarding, training records and background screening.
jason.vandenbogaard@medsuite.com
Information Technology
Brady Hooper
Endpoint provisioning, workstation management and IT support.
brady.hooper@medsuite.com
IT Cloud Engineering
Jim Deblaey
Cloud infrastructure, network engineering and hosting environment administration.
jim.deblaey@medsuite.com
Risk Officer
James Barrett
Risk assessment, risk management activities and maintenance of the plan of action and milestones.
james.barrett@medsuite.com