How Ellery Health Partners protects patient information
When Ellery Health Partners performs services for a covered practice that involve protected health information, Ellery Health Partners acts as the practice's HIPAA business associate.
This page explains how access is controlled, where patient information remains, who performs the work, and the safeguards Ellery Health Partners uses when working through practice-approved systems and payer workflows.
Business Associate Agreements, security information, and applicable policy documentation are available to practices during evaluation and onboarding.
At a glance
- Your practice creates, controls, and can revoke the accounts Ellery Health Partners uses.
- Ellery Health Partners works through practice-approved systems and payer workflows and does not maintain a separate patient-record database.
- Named Ellery Health Partners specialists performing work involving protected health information are located in the United States and access PHI only from within the United States.
- A Business Associate Agreement is executed before Ellery Health Partners receives access to protected health information.
- Ellery Health Partners-controlled accounts use multi-factor authentication.
- Ellery Health Partners devices used for client work are encrypted and subject to defined security requirements.
- Patient information is not accepted through the Ellery Health Partners website.
Access your practice controls
Your practice creates the accounts Ellery Health Partners uses, determines the permissions provided, and retains the ability to modify or revoke access.
Accounts are assigned to named individuals. Ellery Health Partners does not use shared credentials for client systems.
Ellery Health Partners requests only the access necessary to perform the services described in your Service Order, which may include work queues, documentation required to perform the contracted payer-administration work, practice-management systems, and payer portals approved by your practice.
Access begins only after the Business Associate Agreement and applicable service agreement have been executed and your practice has provisioned the necessary accounts.
If the specialist assigned to your practice changes, Ellery Health Partners coordinates with your designated contact so that access can be updated appropriately.
When the engagement ends, your practice can revoke Ellery Health Partners's access to its systems.
Work stays within approved systems and payer workflows
Ellery Health Partners performs contracted payer-administration work through the systems and payer workflows your practice authorizes. Depending on the contracted scope, that work may include prior authorization, insurance verification and benefits, claims follow-up, denial and appeal administration, and provider credentialing and payer enrollment. These may include your EHR, practice-management system, payer platforms such as Availity, Carelon, eviCore, payer-specific portals, and authorized payer telephone channels when required.
Ellery Health Partners does not maintain a separate patient-record database and does not download or retain copies of patient records outside the practice-approved systems required to perform the work.
Case documentation, payer reference numbers, statuses, follow-up activity, and outcomes are recorded in the systems designated by your practice. Telephone follow-up activity is documented in the same practice-approved workflow.
Ellery Health Partners does not maintain patient-level case tracking outside practice-approved systems. Case status, payer reference numbers, patient-specific dates, documentation, and outcomes remain within the systems designated by your practice. Ellery Health Partners may maintain aggregate operational information for workload and capacity management that does not identify individual patients.
Patient information should not be submitted through the Ellery Health Partners website, ordinary email, text message, or other unapproved communication channels.
If patient information is inadvertently sent to Ellery Health Partners through an unapproved channel, Ellery Health Partners notifies your practice and deletes the information from Ellery Health Partners-controlled systems in accordance with its documented privacy and incident-response procedures.
Who performs the work
Named Ellery Health Partners specialists are assigned to client work.
Personnel who access protected health information for Ellery Health Partners perform that work from within the United States. Ellery Health Partners does not offshore client PHI access.
Specialists complete required privacy and security training before being granted access to client PHI and receive refresher training in accordance with Ellery Health Partners policy.
Contracted payer-administration work is performed by personnel authorized by Ellery Health Partners and assigned to the practice.
Any person or entity permitted to create, receive, maintain, or transmit PHI on behalf of Ellery Health Partners must satisfy the applicable HIPAA, confidentiality, security, and contractual requirements before access is granted.
How Ellery Health Partners accounts and devices are protected
Ellery Health Partners requires multi-factor authentication on every Ellery Health Partners-controlled account.
Devices authorized for client work use full-disk encryption and are subject to Ellery Health Partners security requirements.
Credentials are assigned to individual users and managed through approved credential-management practices. Credentials may not be shared between personnel.
Ellery Health Partners uses a HIPAA-eligible workspace under a signed Business Associate Agreement with the platform provider for its internal email, documents, and video.
Patient information may not be stored in personal email accounts, on personal mobile devices, or in unauthorized applications.
Access to client systems follows the authentication and security controls established by the practice and the applicable platform.
What Ellery Health Partners does not do
Ellery Health Partners provides payer-administration support for independent medical practices. Ellery Health Partners does not:
- Make clinical decisions.
- Determine medical necessity.
- Select or change diagnosis or procedure codes.
- Conduct peer-to-peer reviews.
- Sign documents on behalf of a treating provider.
- Represent itself as the treating provider.
- Sell patient information.
- Use patient information for purposes outside the services authorized by the practice.
- Use client PHI to train or improve artificial intelligence models.
Clinical decisions and clinical documentation remain the responsibility of the treating practice.
If a security or privacy incident occurs
If Ellery Health Partners becomes aware of a suspected security or privacy incident involving a client's information, Ellery Health Partners follows its documented incident-response process to investigate, contain, document, and address the event.
The affected practice is notified without unreasonable delay and in accordance with the requirements contained in the applicable Business Associate Agreement and law.
Information provided to the practice will include, as applicable, what occurred, the information involved, actions taken in response, and any additional steps required.
Ellery Health Partners designates responsibility for administration of its HIPAA privacy and security program, including risk analysis, workforce training, incident response, and maintenance of its security policies.
Agreements and documentation
Before live client work involving PHI begins, Ellery Health Partners requires appropriate agreements and operational safeguards.
These include:
- A Business Associate Agreement covering the parties' responsibilities under applicable HIPAA requirements.
- A Service Order or service agreement documenting scope, responsibilities, capacity, pricing, and exclusions.
- Written privacy and security policies applicable to Ellery Health Partners personnel.
- A documented security risk analysis and risk-management process.
- Workforce privacy and security training records.
- Defined incident-response procedures.
- Appropriate agreements with subcontractors or service providers that may create, receive, maintain, or transmit PHI on Ellery Health Partners's behalf.
Additional security documentation may be made available to contracted practices or prospective clients during security review.
Where your records remain
Ellery Health Partners's operating model is designed so that patient records remain within the systems your practice has selected and approved.
Ellery Health Partners does not maintain a separate patient-record database and does not retain copies of patient records outside those systems.
Florida law requires certain health care providers using certified electronic health record technology to ensure that patient information stored in an offsite physical or virtual environment is physically maintained in the continental United States, its territories, or Canada.
Ellery Health Partners does not relocate or separately host your patient records.
As an additional Ellery Health Partners operating control, personnel do not access client PHI from outside the United States.
What we ask of your practice
To help maintain appropriate access and information-security controls, we ask each client practice to:
- Provision individual accounts with only the permissions required for the agreed scope of work.
- Keep clinical documentation and patient information within approved practice systems.
- Avoid sending PHI through ordinary email, text messages, the Ellery Health Partners website, or other unapproved channels.
- Notify Ellery Health Partners when payer portals, EHR access, workflows, or designated practice contacts change.
- Promptly revoke access when it is no longer required.
- Notify Ellery Health Partners of suspected security or privacy concerns involving our services.
Security questions and documentation requests
For questions about Ellery Health Partners's Business Associate Agreement, security practices, or available compliance documentation, contact:
info@elleryhealthpartners.com
1-888-601-4040
To report a suspected privacy or security concern involving Ellery Health Partners, use the same contact information and mark the message “Urgent: Privacy/Security.”
Reported concerns are reviewed promptly by the person responsible for Ellery Health Partners's privacy and security program.
Last reviewed: September 2026
