Millin Medical Compliance

Committed to safeguarding the privacy and security of protected health information through rigorous compliance, continuous monitoring, and transparent governance.

Incident Reporting

Suspected data breaches or security concerns must be reported immediately.

Report a Security Concern

Contact: JBarrett@millinmedical.com

What to expect once reported:

  • Immediate acknowledgment of receipt
  • Formal documentation in our tracking system
  • Regular updates on the status throughout the incident lifecycle
  • Data Incident Closure Template

System Use

Terms governing access to the MillinPro+ information system.

  • The MillinPro+ information system is used to support Federal, State, and Local Government, and may only be accessed and used for official Government business by authorized personnel only.
  • Unauthorized access, actions, use, modification, or disclosure of the data contained herein or in transit to/from this system constitutes a violation of the Computer Fraud and Abuse Act, Pub. L. No. 99-474, codified at 18 U.S.C. §1030, state criminal and civil laws, and may subject violators to criminal, civil, and/or administrative action and penalties.
  • All authorized use of this system must comply with Executive Orders, directives, policies, regulations, standards, and guidance. Any unauthorized use or actions will be investigated, and if required, prosecuted.
  • All data contained within this information system may be monitored and recorded and disclosed in any manner by authorized personnel. By proceeding to access the information system, the user acknowledges that there is no right to privacy in this system.
  • System personnel may provide law enforcement officials, for investigation and prosecution purposes, any potential evidence of crime found within this information system.
  • The use of this system by any user, authorized or unauthorized, constitutes consent to monitoring, recording and disclosure.

PHI (Protected Health Information)

Any information in a medical context that can identify an individual and relates to their past, present, or future physical or mental health condition, healthcare provided, or payment for healthcare. It is a subset of PII but specifically pertains to health data and is protected under HIPAA. Examples include medical records, insurance information, or details of doctor visits tied to a person.

PII (Personally Identifiable Information)

Any data that can identify an individual, either directly (like a name, Social Security number, or email address) or indirectly (like combining a ZIP code and birth date to identify someone). PII is a broader category that encompasses any personal information, not just healthcare-related information.

Privacy Impact Assessment Policy Statement

Millin Associates recognizes its responsibility to safeguard the privacy of personally identifiable information (PII) and protected health information (PHI) entrusted to us by our clients and their patients. In alignment with NIST SP 800-53 Revision 5, control RA-8, the organization maintains a Privacy Impact Assessment (PIA) process as a living activity that is:

  • Ongoing: PIAs are conducted not only during system acquisition and deployment but also updated whenever technology, practices, or regulatory requirements change.
  • Comprehensive: PIAs address the full set of applicable NIST privacy controls, identifying risks and recommending mitigations.
  • Vendor-inclusive: Vendor assessments include structured evaluation of privacy controls, not limited to breach notification or policy presence.
  • Integrated with Change Management: All system changes, updates, and maintenance activities require a documented privacy risk classification (Low/Moderate/High/Not Applicable).

This ensures that privacy considerations are embedded into system lifecycle management, vendor oversight, and day-to-day operations, thereby reducing the risk of inappropriate disclosure or misuse of PII/PHI.

Millin Business Model

Millin Medical operates strictly as a B2B (Business-to-Business) entity, processing medical claims on behalf of healthcare providers for submission to payers. We do not offer consumer-facing services, nor do we interact directly with individuals regarding their personally identifiable information (PII). All HIPAA and PII data remain securely contained within our Azure cloud environment, and data is disclosed only to the extent necessary for claims processing and payment purposes, in compliance with legal and contractual requirements. Therefore, mechanisms for individual access and review of PII are not applicable to our business model.

Compliance

Our commitment to regulatory standards and best practices.

  • Millin Medical is committed to maintaining compliance with all applicable laws and regulations governing the privacy and security of PII and PHI.
  • Regular audits and assessments are conducted to ensure adherence to HIPAA, HITECH, and other relevant standards.
  • Staff training programs are implemented to promote awareness and understanding of compliance requirements.
  • Policies and procedures are regularly reviewed and updated to reflect changes in regulations and best practices.

View Compliance Details →

Vendor Certifications

Current certifications and regulatory approvals.

New York State Vendor Responsibility Questionnaire

Millin Associates LLC is certified through the NYS Office of the State Comptroller VendRep System.

Certified by: James Barrett, CTO
Certification Date: March 5, 2026

View Certification →

Technical Leadership

Leadership roles responsible for security, compliance, and technology strategy.

CTO / ISSO
James Barrett
Overarching responsibility for technology strategy, security, system architecture, and information system security oversight.
JBarrett@millinmedical.com
Virtual CISO
Ken Clegg, CISSP, Associate C|CISO, CEH
Provides independent security oversight, advisory services, and review of ISSO activities to ensure separation of duties.
security@millinmedical.com
CCO
James Barrett, CTO
Ensures the organization complies with legal and regulatory requirements, including HIPAA and OHIP standards.
JBarrett@millinmedical.com
COO / Business Operations Manager
Martina Malvoni
Manages day-to-day operations, business processes, partnerships with EMR systems, and operational workflows.
mmalvoni@millinmedical.com
Human Resources Manager
Jenna Lawrence
Manages employee onboarding, training records, background screening, and HR compliance including security awareness training programs.
jenna.lawrence@medsuite.com

Technical Roles

IT Manager / Systems Administrator
Casey M. Napoli
Responsible for maintaining internal systems, network security, and user access controls.
cnapoli@millinmedical.com
Software Development Manager
Chris Beard
Oversees development teams, manages lifecycle management of proprietary and partner-integrated systems.
CBeard@millinmedical.com
Data Architect
Chris Beard
Designs and maintains secure data storage solutions, especially for patient and billing data.
CBeard@millinmedical.com
DevOps Engineer
Chris Beard
Implements secure deployment pipelines, manages cloud resources, and enforces CI/CD practices.
CBeard@millinmedical.com
Cybersecurity Analyst
James Barrett, CTO
Monitors for threats, performs vulnerability assessments, and ensures adherence to security best practices. Supported by Atmosera and Quzara (Cyber Torch).
JBarrett@millinmedical.com
Database Administrator (DBA)
James Barrett, CTO
Manages databases, optimizes performance, and ensures data integrity and compliance with OHIP standards.
JBarrett@millinmedical.com
Cloud Security Specialist
Jon Knight
Focuses on security measures for cloud-hosted environments and ensures alignment with compliance standards. Supported by Atmosera.
JKnight@millinmedical.com
Data Privacy Officer
James Barrett, CTO
Ensures patient and billing data privacy regulations are followed.
JBarrett@millinmedical.com
Risk Officer
James Barrett, CTO
Identifies, assesses, and mitigates risks across IT and business operations. Develops risk management frameworks, oversees audits, and collaborates with leadership to implement risk mitigation strategies.
jbarrett@millinmedical.com