HIPAA for Medical Billing Companies: What You Must Do
A three-provider orthopedic group emails a claims scrubbing file to its billing contractor every Tuesday at 4 p.m. The file contains 900 patient names, dates of birth, diagnosis codes, and the last four of each insurance ID. There is no signed Business Associate Agreement on file, and nobody at the practice has ever asked the billing company where that data lands. That is the single most common failure pattern in HIPAA for medical billing companies — not hacking, not ransomware, just an undocumented data flow that has been running for four years.
This article is for the person on either side of that relationship: the practice administrator who signs the vendor contract, and the billing company owner who is now, under the HIPAA Rules, directly liable to OCR. Below: exactly which obligations attach, who performs each one, on what clock, and what the documented evidence looks like when a regulator asks.
Does a Medical Billing Company Have to Comply With HIPAA?
Yes. A medical billing company that creates, receives, maintains, or transmits protected health information on behalf of a covered entity is a business associate under 45 CFR 160.103. Since the 2013 Omnibus Rule, business associates are directly liable for the HIPAA Security Rule in full, for the Breach Notification Rule, and for the Privacy Rule provisions that apply to them — including impermissible uses and disclosures. That liability exists whether or not a Business Associate Agreement was ever signed. The missing BAA is a separate violation, not a shield.
A billing company must therefore: execute BAAs upstream with each client practice and downstream with each subcontractor, conduct and document a security risk analysis, implement administrative, physical, and technical safeguards, train its workforce, and report breaches to its covered entity clients within 60 days of discovery.
Where the Liability Actually Sits in the Chain
Practices routinely assume that outsourcing billing outsources the risk. It does not. The covered entity remains responsible for its own choices — including whether it did anything at all to verify the vendor. OCR has settled with physician practices whose PHI ended up publicly exposed after being handed to a billing contractor without an agreement in place. The practice paid. The billing company was investigated separately.
Run the chain out loud for your own operation:
- Covered entity — the practice. Owns the patient relationship, the Notice of Privacy Practices, the right-of-access clock, and the ultimate individual notification duty after a breach.
- Business associate — the billing company. Owns the Security Rule in full, minimum necessary in its own workflows, and notification to the practice.
- Subcontractor — the offshore coding team, the clearinghouse the billing company chose, the cloud storage tenant, the fax-to-email service, the AR call center. Each one that touches PHI is itself a business associate and needs its own downstream BAA.
If your billing company sends charts to a coding vendor in another country, that is a subcontractor relationship. HIPAA does not prohibit offshoring, but it does require the same contractual chain and the same safeguards, and several state laws and payer contracts impose additional conditions. Document where the data physically rests.
The Question That Breaks Most Vendor Reviews
Ask your billing company: "List every third party that can view or store our patients' PHI, and send me the executed BAA for each." If the answer takes more than five business days, you have found your risk. A competent billing operation keeps that list current because it needs the list for its own risk analysis.
HIPAA for Medical Billing Companies: The BAA Terms That Matter
A BAA is not boilerplate you scan and sign. HHS publishes sample business associate agreement provisions, and those provisions are the floor, not the ceiling. Read for these specifics:
- Breach reporting window. The regulatory outer limit is 60 days from discovery. That is far too slow for a covered entity that then has its own 60-day clock to individuals. Negotiate 5 business days for a suspected incident and 10 for a confirmed one. Put it in writing.
- Subcontractor consent. Require notice — ideally written approval — before the billing company routes PHI to a new downstream vendor.
- Return or destruction at termination. Specify format and deadline. "Infeasible to return" is the escape hatch every vendor uses; make them justify it in writing and extend protections indefinitely if they keep the data.
- Cooperation with access and amendment requests. If billing data sits only in the vendor's system, the practice cannot meet its 30-day access obligation without vendor cooperation. Say so in the contract.
- Audit and evidence rights. The right to request the vendor's most recent risk analysis date, training completion records, and a summary of security incidents in the prior 12 months.
If you are papering a new billing relationship — or discovering that half your vendor folder is empty — you can produce a signature-ready agreement with the six-step Business Associate Agreement builder, which exports to PDF and DOCX for one flat purchase. Get the document signed before the first claims file moves, not after.
The Security Rule Obligations a Billing Company Cannot Delegate
Billing companies concentrate risk in a way individual practices do not. One firm may hold ePHI for forty clinics. A single credential compromise becomes a forty-practice breach. OCR's public breach reporting portal is full of business-associate incidents where the affected-individual counts run into six and seven figures for exactly this reason.
Risk Analysis — Annual, Documented, Asset-Specific
An accurate and thorough risk analysis under 45 CFR 164.308(a)(1)(ii)(A) is the most frequently cited deficiency in OCR settlements. For a billing company it must enumerate every system holding ePHI: the practice management platform, SFTP drop folders, clearinghouse portals, the shared mailbox that receives EOBs, laptops used by remote AR staff, and any spreadsheet exports. NIST SP 800-66 Revision 2 is the practical implementation guide; it maps Security Rule requirements to concrete controls and is the reference OCR investigators recognize.
Access Controls and the Remote Coder Problem
Unique user IDs are required, not optional. Shared logins to a payer portal are an audit finding waiting to happen. Enforce multi-factor authentication on every remote entry point, terminate access the same day an employee leaves, and run a quarterly access review that a named person signs. If coders work from home, address personal device use, screen visibility, and printing in a written policy that staff acknowledge.
Encryption
Encryption is an addressable specification, which means you implement it or document why an equivalent alternative is reasonable. For a billing company handling bulk claims files, there is no defensible alternative. Encrypt at rest and in transit. Kill unencrypted email attachments containing PHI — use a secure portal or SFTP with per-client credentials.
What Changed in 2025
In January 2025, HHS published a Notice of Proposed Rulemaking that would substantially tighten the Security Rule — removing much of the addressable/required distinction, mandating encryption and MFA more explicitly, requiring asset inventories and network maps, and imposing tighter compliance verification on business associates. The comment period closed in March 2025 and the rule is not final as of this writing. Do not wait for the final rule to build an asset inventory. Every proposed requirement is already a defensible best practice, and the inventory is the input your risk analysis needs anyway.
The Breach Clock, Stated Plainly
Discovery starts the clock. A breach is discovered on the first day it is known, or reasonably should have been known, to any workforce member other than the person who caused it.
- Billing company to practice: without unreasonable delay, no later than 60 calendar days from discovery. Your BAA should shorten this.
- Practice to individuals: no later than 60 calendar days from discovery of the breach by the business associate — not from the day the practice was told. A vendor that sits on the news for 55 days has burned nearly the entire window.
- Practice to HHS, 500+ individuals: within 60 days, plus prominent media notice in the affected state or jurisdiction.
- Practice to HHS, fewer than 500: log it, and submit within 60 days after the end of the calendar year.
The full mechanics are on the HHS Breach Notification Rule page. Note the presumption: any impermissible use or disclosure is a breach unless you document a four-factor risk assessment concluding low probability of compromise. "We decided it wasn't a breach" without that written assessment is not a position you can defend.
Minimum Necessary in a Claims Workflow
Billing needs diagnosis codes, procedure codes, dates of service, and demographics. It rarely needs full clinical notes, imaging, or behavioral health narratives. Yet practices routinely dump entire chart PDFs into an appeal packet because it is faster than curating.
Define, in writing, the standard data set your billing partner receives. Then define the exception path for appeals and audits that genuinely require clinical documentation, with a named approver. Substance use disorder records covered by 42 CFR Part 2 carry separate consent requirements that most billing workflows handle badly — flag those accounts explicitly.
Your Evidence File: What OCR Actually Asks For
When a complaint lands, the data request is predictable. Assemble this now and keep it for six years from creation or last effective date, whichever is later:
- Executed BAAs, upstream and downstream, with signature dates
- The current risk analysis, with a dated revision history
- The risk management plan showing which findings were remediated, by whom, on what date
- Written policies and procedures — security, sanctions, incident response, device and media controls
- Workforce training records with names, dates, and content covered
- Access review logs and termination checklists
- The incident log, including incidents determined not to be breaches, with the four-factor analysis attached
- Contingency plan and the date it was last tested
Note that no vendor, course, or product confers HIPAA "certification." HHS does not certify or endorse compliance tools. What protects you is the documentation, dated and consistent with what your staff actually do.
A 90-Day Sequence for Practices Who Just Realized They Have a Gap
Days 1–15: Inventory every vendor that touches PHI. Billing, clearinghouse, collections agency, transcription, statement printing, answering service, shredding. Mark which have signed BAAs.
Days 16–30: Send agreements to the vendors missing one. Set a hard deadline; PHI transmission stops if the agreement is not returned. Assign one owner — usually the privacy officer — with a calendar reminder for renewals.
Days 31–60: Request each billing partner's risk analysis date, subcontractor list, and breach history. Document what you received and what you did not.
Days 61–90: Update your own risk analysis to reflect the vendor data flows, and rehearse the notification chain — who calls whom, at what hour, on a Saturday. If your policy set and risk analysis need rebuilding from scratch, automated risk analysis and policy generation will get you a defensible baseline faster than a blank template will.
Start With the Agreement You Are Missing
Every element of HIPAA for medical billing companies traces back to a contract that either exists or does not. The BAA defines the breach window, the subcontractor rules, and the data-return terms you will need on your worst day. If a signed agreement is missing for even one billing relationship, close that gap first — generate a signature-ready BAA, send it, and file the executed copy where your successor can find it.