Home / HIPPA Notice and Business Associate Practices
HIPAA Notice and Business Associate Practices
How EPMN handles protected health information on behalf of the practices it serves.
LAST UPDATED: AUGUST 4, 2026
Our Role Under HIPAA
El Paso Medical Network is not a healthcare provider and does not deliver patient care. In its work for member practices, EPMN generally acts as a business associate, as that term is defined by the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, including the HITECH Act and the Omnibus Rule.
This means our obligations flow from the Business Associate Agreement executed with each member practice, and from the provisions of HIPAA that apply directly to business associates. Your practice remains the covered entity responsible for its own Notice of Privacy Practices to patients.
What Information We Handle
Most information EPMN handles is provider information rather than patient information: licenses, board certifications, NPIs, malpractice coverage, and contract documents. In limited circumstances our work involves protected health information (PHI), for example when resolving claim denials, reimbursement disputes, or plan participation issues on your behalf.
Permitted Uses and Disclosures
EPMN uses and discloses PHI only as permitted by the applicable Business Associate Agreement, as required by law, or as necessary to:
- Perform credentialing, re-credentialing, and primary source verification
- Submit and support enrollment applications with health plans, Medicare, and Medicaid
- Negotiate, administer, and maintain managed care contracts
- Assist with claim denials, appeals, and reimbursement issues at your request
- Carry out our own proper management and administration and meet our legal responsibilities
Business Associate Agreements
EPMN executes a Business Associate Agreement with each member practice before performing services that may involve PHI. The Participating Practice Agreement and Business Associate Agreement are included in the EPMN Initial Credentialing Packet available on our Join and Downloads pages.
Minimum Necessary Standard
We request, use, and disclose only the minimum amount of information necessary to accomplish the purpose of a request. Staff access is limited by role, and credentialing files are accessible only to personnel whose work requires them.
Safeguards We Maintain
EPMN maintains administrative, physical, and technical safeguards appropriate to the information in our custody, including:
- Written privacy and security policies, reviewed periodically
- Workforce training on HIPAA privacy and security obligations at hire and annually
- Role-based access controls and unique user credentials
- Encryption of sensitive information in transit and at rest where applicable
- Secure destruction of paper and electronic records at the end of the retention period
- Physical security controls at our administrative offices
Subcontractors
Where EPMN engages a subcontractor that may create, receive, maintain, or transmit PHI on our behalf, we require that subcontractor to agree in writing to restrictions and conditions at least as protective as those that apply to EPMN.
Breach Notification
If EPMN discovers a breach of unsecured PHI, we will notify the affected covered entity without unreasonable delay and no later than the period required by the applicable Business Associate Agreement and by law. Our notice will include the information required under 45 CFR 164.410 so the covered entity can meet its own notification obligations.
Rights of Member Practices
As a covered entity, your practice may:
- Request access to PHI maintained by EPMN in a designated record set
- Request amendment of PHI in our custody
- Request an accounting of disclosures made by EPMN
- Request restrictions on certain uses and disclosures
- Request the return or destruction of PHI upon termination of services, where feasible
Reporting a Privacy Concern
To report a privacy or security concern, or to ask a question about these practices, contact the EPMN Privacy Officer c/o Cypress Healthcare Consultants at EPMNCred@cypresshcc.com or (972) 424-1360. You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights. EPMN will not retaliate against anyone for filing a complaint.
Note for review: designate the named Privacy Officer and confirm the effective date before publishing this notice.