BAA for Billing Company: What Your Practice Must Sign
Your billing company sees more protected health information than most of your clinical staff. Diagnosis codes, dates of service, member IDs, guarantor addresses, and frequently the full encounter note that substantiates the claim. If you do not have a signed BAA for billing company services on file — executed before the vendor touched the first chart — you have an unauthorized disclosure of PHI on your hands, and it belongs to your practice, not to them. This article covers what that agreement must contain under 45 CFR 164.504(e), which clauses to negotiate, and what documented evidence looks like when a regulator asks for it.
Does a Medical Billing Company Need a BAA? The Short Answer
Yes. A medical billing company creates, receives, maintains, or transmits PHI on your behalf to perform a function regulated by HIPAA — claims processing and billing are named explicitly in the definition of business associate at 45 CFR 160.103. The agreement must be signed before the vendor receives any PHI. It applies whether the billing company is offshore, a two-person shop, or a national revenue cycle firm, and whether you pay per claim or a percentage of collections.
There is no exception for "they only see claims data." Claims data is PHI. There is no exception for a verbal understanding, an NDA, or a confidentiality clause buried in the master services agreement. HHS is direct on this point in its business associate guidance.
What a BAA for Billing Company Services Must Contain
The Privacy Rule lists the required provisions. A contract missing any of them is not a compliant BAA, even if it is titled one. Pull your current agreement and check for all eleven items below.
- A description of the permitted and required uses and disclosures of PHI by the billing company.
- A statement that the vendor will not use or further disclose PHI other than as permitted by the contract or required by law.
- An obligation to use appropriate safeguards and to comply with the Security Rule with respect to electronic PHI.
- An obligation to report to you any use or disclosure not provided for by the contract, including breaches of unsecured PHI and security incidents.
- A requirement that subcontractors who receive PHI agree to the same restrictions through written agreement.
- An obligation to make PHI available for patient access under 164.524.
- An obligation to make PHI available for amendment under 164.526.
- An obligation to provide an accounting of disclosures under 164.528.
- To the extent the vendor carries out one of your Privacy Rule obligations, a requirement that it comply with the rules applicable to you.
- An obligation to make internal practices, books, and records available to HHS.
- Return or destruction of PHI at termination, and your right to terminate for material breach.
HHS publishes sample business associate agreement provisions. Treat that document as a floor, not a finished contract — it deliberately leaves the operational terms blank.
The Blanks the Sample Language Leaves You
The sample provisions do not tell you how fast the vendor must notify you of a breach, whether they may de-identify your data and keep it, whether they can offshore the work, who pays for patient notification letters, or how PHI comes back to you when the relationship ends. Those are the clauses that matter at 2 a.m. on the day something goes wrong. Fill them in deliberately.
The $500,000 Reminder: Advanced Care Hospitalists
In December 2018, OCR announced a $500,000 settlement with Advanced Care Hospitalists, a Florida physician group that had engaged an individual representing himself as a medical billing service. Patient names, dates of birth, and Social Security numbers ended up viewable on a website. OCR's findings included that the practice had no business associate agreement in place with the billing vendor and had not conducted a risk analysis.
The instructive part is not the dollar figure. It is that the practice was penalized for the paperwork gap independently of the exposure itself. A missing BAA is a standalone violation. You do not need a breach to be cited for it.
Browse the OCR breach portal and filter by business associate involvement. Billing and revenue cycle vendors appear regularly, and a single vendor incident often shows up as a dozen separate covered entity entries — one for each practice on their client list.
Subcontractors: Your Billing Company's Vendors Are In Scope Too
Since the 2013 Omnibus Rule, a subcontractor that handles PHI on behalf of a business associate is itself a business associate, with direct liability. Your billing company must have written agreements downstream. You are not required to sign those agreements, but you are entitled to know they exist.
Ask your billing vendor for a list of every subcontractor that touches your PHI. In practice this usually surfaces: the clearinghouse, the cloud hosting provider, an offshore data entry or coding team, a statement print-and-mail house, a patient payment portal, and sometimes a collections agency. Each is a link in the chain.
Offshore Work Deserves an Explicit Clause
HIPAA does not prohibit offshoring PHI. Some state laws and many payer contracts do restrict it, and Medicaid managed care agreements in several states include location requirements. Write the clause you actually want: either prohibit offshore processing outright, or require written notice and your prior approval before any PHI leaves the country. Silence in the contract means the vendor decides.
Negotiate the Breach Notification Clock Down to 5 Days
Under 45 CFR 164.410, a business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 calendar days from discovery. That is the regulatory ceiling. If your vendor uses all 60 days, you may have only days left inside your own 60-day patient notification window under the Breach Notification Rule.
Negotiate for notice within five business days of discovery for confirmed breaches, and immediate notice — same or next business day — for any incident involving ransomware, unauthorized access to your practice's records, or law enforcement involvement. Also specify what the notice must include: affected individuals, data elements, dates of discovery and occurrence, and remediation status.
Add a cost allocation clause. Someone has to pay for the mailing, the credit monitoring, the call center, and the media notice if the count exceeds 500 residents of a state. Decide that now, in writing, rather than during the incident.
A 30-Day Workflow to Get Every Billing Vendor Under Agreement
If you are staring at an incomplete vendor file, work this sequence. Assign each step to a named person, not a department.
- Days 1–3 — Build the list. Your practice administrator pulls every vendor paid from the AP ledger in the last 24 months and flags anyone who could plausibly see PHI. Add the ones who never invoice you, like a percentage-of-collections biller netting their fee.
- Days 4–7 — Match against the signed file. Your privacy officer checks each flagged vendor for an executed BAA with a countersignature and a date. "We sent it to them" is not an executed agreement.
- Days 8–14 — Issue agreements to the gaps. Send a current, complete BAA to every vendor without one. This is where a template with the eleven required provisions already drafted saves you two weeks of legal back-and-forth — you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX the same afternoon, with a one-time purchase rather than a subscription.
- Days 15–21 — Chase signatures. Two follow-ups, then escalate to the account executive. A billing company that will not sign a BAA is telling you something important about its compliance posture.
- Days 22–30 — File and calendar. Store executed agreements in one location with a review date. Set a recurring annual reminder to re-verify subcontractor lists and confirm the vendor is still operating under the terms.
If a vendor refuses to sign, document the refusal, stop sending PHI, and begin transition planning. Continuing to disclose PHI to a non-signing vendor is a knowing violation, and the penalty tiers reflect that.
What Documented Evidence Looks Like When OCR Asks
An investigator responding to a complaint about your billing operation will typically request a specific set of documents. Have these ready:
- The executed BAA for billing company services, with both signatures and dates, plus any amendments.
- The date the vendor relationship began, so the BAA date can be compared against it.
- Your security risk analysis, showing the billing vendor's data flow was considered. NIST SP 800-66 Revision 2 is the practical reference for scoping that analysis.
- Evidence of vendor due diligence — a completed security questionnaire, a SOC 2 report, or an attestation regarding safeguards.
- Your record of any breach reports received from the vendor and what you did with them.
- Termination records for former billing vendors, including confirmation of PHI return or destruction.
Retention is six years from creation or last effective date, whichever is later, under 45 CFR 164.530(j). That means the BAA for a billing company you fired in 2021 still needs to be in your file today.
Watch the Proposed Security Rule Changes
OCR published a notice of proposed rulemaking in January 2025 that would substantially revise the HIPAA Security Rule, including proposals requiring business associates to verify their technical safeguards annually through written analysis and certification, and to notify covered entities within 24 hours of activating contingency plans. The rule is not final as of December 2025. Do not rewrite your BAAs around it yet, but when you draft new agreements, leaving room for a shorter notification clock costs you nothing.
Three Clauses Worth the Fight, One That Usually Isn't
Worth it: audit rights. Reserve the right to request evidence of safeguards annually. Most billing companies will accept a documentation-based right even if they resist an on-site audit.
Worth it: data return format. Specify that PHI returned at termination arrives in a usable, documented format within 30 days. Practices lose years of AR detail because the contract said "return or destroy" and nothing more.
Worth it: no secondary use. Prohibit de-identification, aggregation, or benchmarking use of your data unless you explicitly agree. Some revenue cycle firms build analytics products on client data.
Usually not worth it: unlimited indemnification. A small billing company will not accept it, and pushing hard costs you leverage on the clauses that actually reduce risk. Ask for a reasonable liability cap tied to fees paid, plus cyber insurance evidence.
Get the Paperwork Done This Week
The BAA is the cheapest compliance control you own. It takes an afternoon and it is the first document anyone asks for. If your vendor file has gaps, close them: generate a compliant BAA for billing company relationships in a few minutes, send it for signature, and file the countersigned copy with a review date attached. For the broader documentation set — risk analysis, policies, and workforce procedures that OCR requests alongside your agreements — automated HIPAA compliance documentation covers the same ground without a consulting engagement.