1. Who we are
EMDE Billing & Transcription Agency ("EMDE", "we", "us") is a medical billing, coding and clinical transcription agency operating from Lahore, Pakistan, serving healthcare providers in the United States, the United Arab Emirates, the Kingdom of Saudi Arabia and Qatar.
For questions about this policy or about how your information is handled, contact info@emdebilling.com.
2. Two different kinds of information
This policy covers two distinct categories, which are governed differently:
- Website information — data you give us directly through this website, such as an enquiry or a cost estimate request. For this, EMDE is the data controller.
- Client patient information — health and billing data belonging to a healthcare provider's patients, which we process on that provider's instructions under a written services agreement. For this, EMDE is a data processor (in United States terms, a business associate). The provider remains the controller and the covered entity.
3. Website information we collect
Information you give us
- Name, email address, and optionally practice name and telephone number, submitted through our enquiry forms or cost estimator.
- The answers you provide to the cost estimator (region, service, practice size, patient volume) and the estimate generated from them.
- The content of any email or message you send us.
Information collected automatically
This website uses Google Analytics 4 (property G-N2CTQ3ND6L) to understand how visitors use the site. Google Analytics sets cookies and collects information including your approximate location, device and browser type, pages visited and time on page. This information is processed by Google LLC. You can prevent this collection by using your browser's cookie controls or Google's opt-out browser add-on.
We do not sell your information, share it with advertising networks, or add you to marketing lists without your agreement.
Why we use it and on what basis
- To respond to your enquiry and provide the information you asked for — because you asked us to.
- To send you a cost breakdown you requested — on the basis of your consent, which you may withdraw at any time.
- To understand website performance — on the basis of our legitimate interest in improving the site.
4. Client patient information
Where we perform billing, coding or transcription work, we handle protected health information belonging to our clients' patients. In every case:
- We process such information only on the documented instructions of the healthcare provider who engaged us.
- We do not use it for any purpose of our own, and we never sell, licence or disclose it to third parties except as instructed by the provider or as required by law.
- We restrict access to personnel who need it to perform the engaged work, each bound by written confidentiality obligations.
- We transfer it only through encrypted channels. We do not accept or send patient information via WhatsApp, consumer messaging apps, or unencrypted email.
- We retain it only for the period set out in the services agreement, and return or securely destroy it at the end of the engagement.
5. Regional frameworks
United States
For clients in the United States, EMDE acts as a business associate under the Health Insurance Portability and Accountability Act (HIPAA). We execute a Business Associate Agreement (BAA) with every US client before any protected health information is exchanged. Our handling of that information is governed by the BAA and by the HIPAA Privacy and Security Rules.
United Arab Emirates
UAE Federal Law No. 2 of 2019 concerning the Use of Information and Communications Technology in Health Fields restricts the storage, processing, generation and transfer of health data relating to health services provided in the UAE outside the UAE. MOHAP Ministerial Resolution No. 51 of 2021 sets out categories of exception that may be granted by the relevant emirate health authority on a case-by-case basis, one of which relates to the administration of insurance claims.
EMDE will not process health data originating from a UAE healthcare provider outside the UAE unless the provider confirms that an applicable authorisation or exception is in place, or an alternative lawful arrangement has been agreed in writing. Prospective UAE clients should raise this with us at the outset so the position can be established before any data is exchanged.
Personal data more generally is subject to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. Providers licensed in Abu Dhabi are additionally subject to the Department of Health's Healthcare Information and Cyber Security Standard (ADHICS).
Saudi Arabia
For clients in the Kingdom, the Personal Data Protection Law and its implementing regulations govern the handling and cross-border transfer of personal data. Arrangements for any transfer of data outside the Kingdom are agreed in writing with the client before processing begins, and we will not proceed without a lawful basis being established.
Qatar
Health services in Qatar are regulated under Law No. 22 of 2021 and its Executive Regulations, administered by the Ministry of Public Health. Data protection is governed by Law No. 13 of 2016 concerning Personal Data Privacy Protection. Arrangements for handling data are agreed in writing with the client before processing begins.
6. Security
We apply access controls, encryption in transit, role-based permissions and written confidentiality obligations for all personnel. Access is limited to the specific engagement each person works on. No system is completely secure, and we do not claim otherwise; we will notify affected clients without undue delay if we become aware of a breach affecting their data, in line with the notification obligations in the relevant services agreement and applicable law.
7. Retention
- Website enquiries: retained for up to 24 months from last contact, then deleted.
- Client patient information: retained only as set out in the services agreement, then returned or securely destroyed.
- Analytics data: retained according to the retention period configured in Google Analytics.
8. Your rights
Depending on where you are located, you may have the right to request access to the personal information we hold about you, to have it corrected or deleted, to object to or restrict its processing, and to withdraw consent you have given.
To exercise any of these, email info@emdebilling.com. We will respond within 30 days. If your request concerns patient information we process for a healthcare provider, we will direct you to that provider, who is responsible for responding.
9. Third parties
We use a small number of service providers to operate this website and our business, including our web host, our email provider, Google Analytics for website measurement, and a form submission service that delivers enquiries to our inbox. These providers process information only as needed to deliver their service to us.
10. Children
This website is directed at healthcare professionals and businesses. We do not knowingly collect personal information from children through this website.
11. Changes
We may update this policy as our services or the applicable regulations change. The date at the top of this page shows when it was last revised. Material changes affecting existing clients will be notified directly.
12. Contact
EMDE Billing & Transcription Agency
Lahore, Pakistan
info@emdebilling.com
www.emdebilling.com