Compliance
Quadax acknowledges its responsibility to provide compliant revenue cycle solutions and ensure the security and privacy of client data. We invest in infrastructure and proactive measures designed to continuously enhance security, confidentiality, availability, and data integrity.
Business Continuity & Disaster Recovery
Quadax maintains a formal Business Continuity and Disaster Recovery (BC/DR) program designed to ensure the resilience, availability, and recoverability of our systems and services. Our infrastructure leverages geographically diverse environments across colocation facilities and cloud platforms, supporting high availability and fault tolerance. Quadax manages its server and application infrastructure within these environments, which incorporate redundancy across critical components such as compute, storage, and network connectivity. Colocation providers maintain the physical data center facilities and associated environmental and physical security controls.
Quadax defines and maintains recovery strategies, including recovery time and recovery point objectives, to support the timely restoration of operations in the event of a disruption. BC/DR plans are reviewed and tested on a regular basis to validate their effectiveness. Test results are analyzed, and identified improvements are tracked through to resolution as part of our continuous improvement process
Quadax Compliance Statement
Quadax considers compliance to be a process rather than a task that can be marked completed. We work on compliance every day, monitoring new regulatory requirements, establishing internal policies, educating our employees, enforcing standards, and implementing enhancements to our software systems. Compliance takes the focus and commitment of the entire organization and is ingrained in our culture. Our compliance plan encourages the prevention, detection, and resolution of any conduct that is in violation of state or federal regulations.
The Quadax Corporate Compliance Officer is responsible for planning, development, and oversight of HIPAA-mandated and OIG- recommended compliance guidelines.
The Compliance function has a program that is reasonably designed to mitigate compliance issues and regulatory risks. This function provides timely and practical guidance on various matters related to healthcare compliance issues. Training sessions are provided to staff members to keep them apprised of regulatory and compliance matters as well as related policies and procedures. Overall, the department assists in promoting a culture of compliance that includes fostering an environment of open communication.
The Compliance Officer at Quadax reports directly to the President and oversees the compliance program, monitors regulatory requirements, establishes applicable internal policies, and educates and trains employees.
Quadax is required to maintain compliance with all applicable state and Federal regulations. The corporate compliance program is structured based on the Office of Inspector General’s Compliance Program for Third-Party Medical Billing Companies and specifically addresses the Federal Sentencing Guidelines. This program includes a compliance reporting hotline for employees.
HIPAA and HITECH Compliance
The Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) established national standards for electronic healthcare transactions and for the security and privacy of healthcare data. It also required national identifiers for providers, health plans, and employers. The goal was to reduce costs and improve the efficiency of the healthcare system by standardizing and encouraging the electronic exchange of data. The initial compliance deadlines for most of the provisions in HIPAA have passed. The Health Information Technology for Economic and Clinical Health (HITECH) Act imposed new healthcare compliance obligations relative to privacy and security, and breach notification.
As a business entrusted with protected health information and required to distribute that information electronically to other business partners, we understand our obligations under the HIPAA statute. We have made every effort to conform to those rules and regulations by modifying business procedures and computer systems to incorporate compliance requirements by the specified deadlines for Transaction Standards and Code Sets, Privacy Standards, Identifiers, and Security.
The Quadax HIPAA Security Official is Gene Calai. Quadax has implemented measures to prevent unauthorized access to protected health information, including these:
- Administrative Safeguards
Quadax maintains comprehensive administrative safeguards to support the protection of healthcare data. These safeguards include the development and enforcement of security policies and procedures, workforce training, risk assessment and management processes, and governance practices designed to promote compliance with applicable regulatory requirements. - Physical Safeguards
Quadax implements physical safeguards designed to protect systems and facilities involved in the processing of healthcare data. These measures include controlled access to facilities, environmental protections, and device security practices within Quadax-managed locations. For cloud-hosted systems, Quadax utilizes leading cloud service providers, including Microsoft Azure and Snowflake, which maintain independently audited physical security controls over their data center environments, such as restricted access, monitoring, and environmental safeguards. - Technical Safeguards
Quadax employs layered technical safeguards designed to protect the confidentiality, integrity, and availability of healthcare data. Our platforms incorporate strong authentication mechanisms, including multi-factor authentication, along with role-based access controls and least-privilege enforcement. We deploy advanced network security technologies, including next-generation firewalls, and maintain continuous monitoring capabilities to detect and respond to potential threats. System activity is captured through comprehensive audit logging to support security monitoring and compliance obligations. Data transmitted through the Quadax website and applications is protected using industry-standard encryption protocols (TLS).
Quadax has established internal guidelines and procedures to ensure that no individual protected health information is disclosed except to authorized parties. Formal policies govern the conduct of employees regarding the confidentiality of patient information and specify penalties associated with breaches of such conduct.
Optum Tested and Approved Data Handling
Quadax is fully HIPAA compliant, adhering to required electronic data interchange (EDI) standards, including ANSI ASC X12 5010 transaction formats for secure and standardized healthcare data exchange.
Quadax supports ICD-10 coding standards, in accordance with federally mandated HIPAA requirements, ensuring accurate and compliant claims processing.
Quadax solutions have been rigorously tested and validated using Optum transaction validation and testing services, confirming compliance with industry standards and payer requirements for data accuracy and integrity.
Billing Compliance
Quadax is fully committed to maintaining compliance with all state and federal regulations, and we have established systems and practices to accomplish that goal. Our A/R Management platform and services incorporate these and other compliance strategies:
- Editing for duplicate claims for Medicare Part A
- Editing claims according to the Correct Coding Initiative for pairs of services that should not be billed on the same claim because they are mutually exclusive or comprehensive/ component (Column 1/ Column 2) services
- Ensuring that valid diagnosis codes, CPT © Codes, and HCPCS are provided by the billing source for each test and are included on all claims.
- Checking procedure/diagnosis code combinations on claims for medical necessity according to LCD/NCD policies and supporting Advanced Beneficiary Notifications (ABNs)
- Enforcing the Medicare three-day payment window rule before a claim gets into the system. For A/R platform users, reports are generated so that these charges can be posted to the patient’s inpatient account in the hospital billing system.
- Reviewing Medicare communications to identify all policy, procedure, and system changes that are required to conform to CMS billing standards and mandates. An insurance committee meets monthly to conduct the review.
SOC Reporting
As a trusted steward of client data, Quadax engages an independent public accounting firm to evaluate the design and effectiveness of our internal controls. System and Organization Controls (SOC) reporting is a recognized framework through which independent practitioners assess and report on controls at both the system level for service organizations and broader entity-level controls.
SOC 1® reports support our clients’ external auditors in evaluating financial reporting controls.
SOC 2® reports evaluate our controls across key trust service criteria—security, availability, confidentiality, and processing integrity. These reports are used by clients and their auditors to assess the reliability and security of our systems and data handling practices.
Access to current SOC 1 and SOC 2 reports is available to customers under a nondisclosure agreement. Please contact your Quadax sales or account representative for details.
For more information on SOC reporting, visit the American Institute of Certified Public Accountants (AICPA) website.
Quadax Code of Business Conduct
The Quadax Inc. Compliance Program is intended to demonstrate the absolute commitment of the organization to the highest standards of ethics and compliance. That commitment permeates all levels of the organization. Quadax Inc. upholds and requests its employees, clients, and vendors to use and promote ethical business practices in the pursuit of excellence.
Quadax Inc., to the best of our ability, strives for compliance with all laws, regulations, and rules that apply to our business, and is committed to prepare and submit accurate claims consistent with such requirements. It is our intention that all employees understand how to do their jobs properly within applicable legal, regulatory, and ethical standards. We all share the responsibility of diligently seeking to prevent, detect, and report any unethical, illegal, or other inappropriate conduct.
Quadax Inc. is committed to treating all persons with respect, dignity, and fairness. We intend to display good judgment and high ethical standards in our business decision making and to conduct business with honesty, fairness, and integrity.
The Code of Business conduct (the “Code) applies to all employees. New employees receive a copy of the Code when they begin working for Quadax. A new employee is required to read the Code and sign an acknowledgement that they understand the Code and will comply with it. The Code provides a framework for employees to make good decisions when faced with ethical questions. While not intended to be comprehensive, the Code covers a broad range of topics. Key areas of the Code cover personal responsibility and accountability, including honesty and compliance with laws, rules and regulations. Other major areas in the Code address conflicts of interest, gifts, discrimination and harassment, privacy and confidentiality, and the use of Company assets. Annually, existing employees are asked to re-read the Code annually to acknowledge that they understand and comply with the Code.