OBPO Managed Svcs Inc.Effective Date: 14 September 2026Version 1.0
This organisation operates as a HIPAA-compliant Business Associate. HIPAA Compliant PCI DSS ISO 27001

1Who We Are

OBPO Managed Svcs Inc., operating as OneBPO ("we," "us," or "our"), is a Business Process Outsourcing (BPO) company headquartered in Iloilo City, Philippines. We provide call-center, healthcare BPO, data management, and customer support services to businesses worldwide.

This Privacy Policy governs how we collect, use, store, and protect information obtained through our website (onebpo.com) and through the provision of our services. It applies to all visitors, prospective clients, and individuals who contact us through our website.

Business Associate Status: In connection with our healthcare BPO services — including medical billing, medical transcription, healthcare claims processing, medical data processing, and medical inquiries — OneBPO acts as a Business Associate as defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Any Protected Health Information (PHI) handled in the course of providing these services is governed by separate Business Associate Agreements (BAAs) with our covered-entity clients, and is subject to the full requirements of HIPAA and the HITECH Act.

2Information We Collect

2.1 Information You Provide Directly

When you interact with our website, you may provide the following personal information:

  • Contact inquiries: Name, email address, phone number, company name, and message content submitted via our contact form or quote request form.
  • Newsletter subscription: Email address provided when subscribing to our newsletter.
  • Communications: Any information you include in emails or other correspondence directed to us.

2.2 Information Collected Automatically

When you visit our website, certain technical information is automatically collected by our systems and third-party tools:

  • IP address and approximate geographic location
  • Browser type and version
  • Device type and operating system
  • Pages visited, time spent on pages, and referring URL
  • Date and time of visits

This information is collected through cookies and similar tracking technologies. Please see Section 5 (Cookies & Tracking) for full details.

2.3 Information We Do Not Collect Through This Website

We do not collect, process, or store any Protected Health Information (PHI) — including patient records, medical histories, diagnoses, or insurance information — through this website. PHI is handled exclusively through our secure, client-managed operational systems, governed by executed BAAs with our covered-entity clients.

3How We Use Your Information

We use the personal information collected through this website solely for the following purposes:

  • Responding to inquiries: To respond to contact form submissions, quote requests, and general questions.
  • Business communications: To send relevant information about our services, proposals, and follow-up communications you have requested.
  • Newsletter delivery: To send our newsletter to subscribers who have opted in. You may unsubscribe at any time using the link included in every email.
  • Website improvement: To analyse how visitors use our website so we can improve content, navigation, and user experience.
  • Legal compliance: To comply with applicable laws, regulations, and legal obligations.
  • Security: To detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activities.

We do not sell, rent, or trade your personal information to any third party for marketing purposes.

4HIPAA & Protected Health Information

4.1 Our Role as a Business Associate

OneBPO provides services — including medical billing, medical transcription, healthcare claims processing, medical data processing, medical appointment scheduling, and medical inquiries handling — that involve access to Protected Health Information (PHI) on behalf of our covered-entity clients (healthcare providers, health plans, and healthcare clearinghouses).

In this capacity, OneBPO operates as a Business Associate under HIPAA (45 CFR Parts 160 and 164). We are contractually required to:

  • Use and disclose PHI only as permitted by the applicable Business Associate Agreement and HIPAA regulations.
  • Implement appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI (ePHI).
  • Report any breach of unsecured PHI to the relevant covered-entity client without unreasonable delay and within 60 calendar days of discovery.
  • Ensure that any sub-contractors who access PHI on our behalf are bound by equivalent obligations through sub-Business Associate Agreements.
  • Return or destroy all PHI upon termination of the service agreement, where feasible.

4.2 Safeguards in Place

OneBPO maintains the following safeguards to protect PHI across all healthcare BPO operations:

  • Administrative: Mandatory HIPAA training for all agents upon onboarding and annually thereafter; documented privacy and security policies; HIPAA-specific workforce sanctions policy; background verification for all staff prior to engagement.
  • Physical: Supervised call-center facility with electronic access control; CCTV surveillance of all operational areas; clear-desk policy for agents; no personal mobile devices permitted on the call floor.
  • Technical: USB and removable media ports disabled on all agent workstations; access to client systems provided exclusively through client-managed credentials and secure portals; no PHI stored on OneBPO-owned infrastructure.

4.3 BAA Requirement

OneBPO will not commence any healthcare BPO service involving PHI without a fully executed Business Associate Agreement in place with the covered-entity client. To request a BAA or to enquire about our HIPAA compliance posture, please contact our Privacy Officer using the details in Section 12.

Note to Patients: OneBPO is not a healthcare provider and does not maintain patient records. If you are an individual seeking access to your own health information, please contact your healthcare provider directly. Requests directed to OneBPO relating to individual PHI rights will be referred to the applicable covered-entity client in accordance with HIPAA.

5Cookies & Tracking

5.1 What Are Cookies

Cookies are small text files placed on your device when you visit a website. They allow the website to recognise your browser and remember certain information across pages and sessions.

5.2 Cookies We Use

  • Strictly necessary cookies: Required for the website to function. These cannot be disabled. They include session management and security cookies.
  • Functional cookies: Enable enhanced features such as remembering your preferences across visits.
  • Analytics cookies: We use analytics tools to understand how visitors use our website (pages visited, time on site, referral sources). This data is aggregated and anonymised. No personally identifiable information is linked to analytics data.
  • Third-party plugin cookies: Our website uses WordPress plugins (including Slider Revolution) that may set their own cookies for functionality and performance purposes.

5.3 Managing Cookies

You may control or disable cookies through your browser settings. Note that disabling certain cookies may affect the functionality of this website. For more information on managing cookies, visit www.allaboutcookies.org.

6Sharing of Information

We do not sell or rent your personal information. We may share your information only in the following limited circumstances:

  • Service providers: Third-party vendors who assist us in operating our website or conducting our business (e.g., email delivery, website hosting), who are contractually bound to protect your information and use it only as directed by us.
  • Legal obligation: Where we are required to disclose information by law, regulation, court order, or governmental authority.
  • Protection of rights: Where disclosure is necessary to enforce our terms, protect our rights, property, or safety, or that of our clients or the public.
  • Business transfer: In the event of a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction. We will notify you via a prominent notice on our website of any such change in ownership.

Any PHI handled under a BAA is shared only as permitted by that agreement and applicable HIPAA regulations — never for any other purpose.

7Data Retention

We retain personal information collected through this website for as long as is necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law. Specifically:

  • Contact form submissions: Retained for up to 2 years from the date of submission, or for the duration of the client relationship, whichever is longer.
  • Newsletter subscriber data: Retained until you unsubscribe, after which your email address is removed from active mailing lists within 30 days.
  • Website analytics data: Retained in aggregated, anonymised form for up to 2 years.
  • PHI handled under BAAs: Retained or destroyed in accordance with the applicable BAA and HIPAA requirements. HIPAA-related documentation is retained for a minimum of 6 years from the date of creation or last effective date, whichever is later.

8Data Security

OneBPO implements appropriate technical and organisational measures to protect personal information against unauthorised access, loss, destruction, or disclosure. Our security programme includes:

  • Access controls and authentication requirements for all internal systems
  • Supervised and physically secured operational facilities
  • Endpoint security controls on all agent workstations
  • Regular security awareness training for all staff
  • Periodic vulnerability assessments and internal audits
  • Incident response procedures for detecting, reporting, and containing security events

Notwithstanding our security measures, no method of transmission over the internet or method of electronic storage is 100% secure. If you believe your information has been compromised, please contact us immediately using the details in Section 12.

9Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

  • Access: The right to request a copy of the personal information we hold about you.
  • Correction: The right to request correction of inaccurate or incomplete information.
  • Deletion: The right to request deletion of your personal information, subject to our legal obligations and legitimate business interests.
  • Objection / Restriction: The right to object to or request restriction of certain processing activities.
  • Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format.
  • Withdraw Consent: Where processing is based on consent (e.g., newsletter subscription), the right to withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact our Privacy Officer using the details in Section 12. We will respond within 30 days of receiving your request. We may need to verify your identity before processing your request.

HIPAA Patient Rights: If you are a patient whose PHI was handled by OneBPO on behalf of a covered-entity client, your HIPAA rights (access, amendment, accounting of disclosures, restriction) must be exercised directly with your healthcare provider. OneBPO will support the covered entity in fulfilling any such requests as required under the applicable BAA.

10Children's Privacy

Our website and services are directed to business clients and are not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will take prompt steps to delete it.

11Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or operational requirements. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify clients directly.

We encourage you to review this policy periodically. Continued use of our website following the posting of changes constitutes your acceptance of the updated policy.

12Contact Us

For any questions, concerns, or requests relating to this Privacy Policy, your personal information, or our HIPAA compliance programme — including BAA requests — please contact our Privacy Officer:

Privacy Officer – OneBPO

OrganisationOBPO Managed Svcs Inc. (OneBPO)
Websiteonebpo.com
AddressIloilo City 5000, Philippines

If you are not satisfied with our response to your privacy concern, you may have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. For US residents whose PHI has been affected, you may also contact the HHS Office for Civil Rights (OCR) at www.hhs.gov/hipaa.