CompyMax

For billing, RCM and coding companies

You are a business associate. Sooner or later someone asks you to prove it.

Handling claims means handling protected health information on behalf of your provider clients, which puts you directly under the HIPAA rules — and makes you the party a practice's auditor, insurer or hospital partner asks about. This gives you the program and the paperwork, without a consultant on retainer.

Last reviewed .

The request arrives mid-contract, and it has a deadline.

A new provider client sends their vendor security packet before signing. An existing client's cyber-insurance renewal asks what their vendors have in place. A hospital system decides to review every downstream billing partner. Each one wants documentation you either have on hand or scramble to assemble over a weekend.

One packet answers most of them

A dated PDF with your risk assessment summary, open and closed remediation items, signed policies, staff training certificates, your own vendor and BAA register, and your incident log. Generated in a click, current as of the moment you send it.

Your subcontractors tracked too

The clearinghouse, the storage provider, the phone system, the offshore coding partner — each one needs its own agreement. The vendor register tracks who has signed, on what date, and when it needs revisiting.

Training records that produce certificates

Record each person's completion — of your own course or a provider you already use — and the platform issues a per-person certificate carrying their name, the completion date and a sequential reference. Renewal intervals are tracked, so lapses surface before a reviewer finds them.

An incident log that knows the deadlines

Record an incident, work through the risk assessment factors, and the log tracks the notification clock and the reporting threshold that applies — so a small event doesn't quietly become a missed obligation.

Priced like software, not consulting

$79 a month for your organization, with a 14-day free trial and no onboarding fee. Compare that to the four-figure setup charges common in this category.

We don't hold your clients' patient data

The platform stores compliance artifacts only — policies, tasks, certificates, registers. Your claims data stays in your billing system where it belongs.

What HIPAA requires of a billing company specifically

Billing, RCM and coding companies are business associates by definition — claims work is the textbook example in the regulation itself. What follows from that is a short list, and each item is something a provider's auditor can ask you to produce.

Agreements in both directions
One with every provider client, and one with every subcontractor of yours that touches their data: the clearinghouse, the document storage service, the offshore coding partner, the transcription vendor, the phone system that records calls.
A documented, organization-wide risk analysis
Required by 45 CFR 164.308(a)(1)(ii)(A) and the most commonly missing artifact in OCR enforcement. It has to cover your whole operation, be written down, and be revisited — a vulnerability scan is not a substitute.
The minimum necessary standard, applied to your staff
A coder working one practice's claims should not be able to pull another practice's records. Role-based access inside your billing system, reviewed periodically, is what this looks like in practice.
Breach notification to your client, on a clock
As a business associate, your obligation runs to the covered entity, not to patients — without undue delay and no later than 60 days from discovery, per 45 CFR 164.410. Your contract may well require faster.
Six-year documentation retention
Policies, risk analyses, training records, incident determinations, agreements. 45 CFR 164.316(b)(2) sets six years from creation or last effective date, whichever is later — including incidents you assessed and concluded were not reportable.

Remote and offshore staffing deserves specific attention, because it is common in this industry and it is where reviews find problems. Contractors are workforce members for HIPAA purposes: they need training records, unique named accounts, and agreements. An offshore coding partner is a subcontractor requiring its own signed agreement, and a home worker's environment is part of your risk analysis.

Where billing companies actually get caught

These are the recurring findings — not exotic attacks, but the ordinary gaps that turn a routine question into a problem. Each maps to something the platform tracks, which is the point of tracking it.

The gapHow it usually shows upWhat closes it
No written risk analysisA client's auditor asks for it and there is a security checklist from years ago, or nothing.The guided assessment across all 68 Security Rule controls, dated and repeatable annually.
Missing downstream agreementsA subcontractor list is requested and two or three vendors have never signed anything.A vendor register with agreement status, signature dates and renewal reminders.
Undocumented trainingStaff were trained; nobody can produce records with names and dates.Per-person completion records with certificates and renewal tracking.
Accounts that outlive employmentA departed coder's login is still active in the billing system months later.An automated check that flags enabled accounts dormant 90+ days, filed as dated evidence.
Incidents assessed only verballyA laptop went missing, it was handled, and no record exists of the determination.An incident log with the four-factor assessment and the notification clock recorded.
Policies never acknowledgedPolicies exist as documents nobody signed off on.Versioned policies with per-person acknowledgement against the exact version read.

Answering a client's vendor security packet

When a provider client's packet lands, the delay is rarely the answering — it is the assembling, and then the follow-up round created by answers that do not agree with each other.

  1. Read what is actually being asked

    A request for “HIPAA certification” is asking for evidence, since no such certification exists. A request for SOC 2 Type II is a different, auditor-driven exercise. Answering the wrong one costs weeks.

  2. Pull the answers from live program data

    The questionnaire library covers around fifty recurring questions, filled from your current records rather than from memory — so training percentages and agreement counts match the pack you attach.

  3. Attach the Trust Packet rather than rebuilding a document

    Risk assessment summary, remediation status, policy list with acknowledgement dates, training certificates, vendor register and incident summary, stamped with the moment the data was true.

  4. Do not hide the open items

    The pack reports overdue tasks and lapsed training deliberately. A reviewer reading a flawless document asks harder questions; open items with owners and due dates read as a programme someone is actually running.

  5. Keep the copy you sent

    Every generated pack is archived with its generation date, so months later you can show exactly what you provided and when.

Questions we get

What are the requirements for HIPAA compliance in medical billing?
A billing company is a business associate, so the obligations are direct: a signed business associate agreement with every provider client and every subcontractor, a documented security risk analysis, written policies with workforce training, minimum-necessary access to claims data, an incident log with breach notification procedures, and six-year record retention. Signing the client's agreement is the start of the obligation, not the end — this is where you run and document the rest.
What are the top 5 HIPAA violations?
From OCR enforcement patterns: no documented risk analysis, missing business associate agreements, impermissible disclosures, lost or stolen unencrypted devices, and failing to give patients timely access to records. For billing companies specifically, the missing-agreement and missing-risk-analysis failures dominate — both are documentation problems, and both apply regardless of headcount.
What is the 72 hour rule in medical billing?
It is not a HIPAA rule — it usually refers to Medicare's three-day payment window, which bundles certain outpatient services into the inpatient claim. The HIPAA clock that actually matters in billing is breach notification: without unreasonable delay and no later than 60 days from discovery, with your provider clients notified so they can meet their own deadlines.

Have the answer ready before the next questionnaire lands.

Complete the assessment in an afternoon and export a packet the same day. Free for 14 days, no credit card.

Start free trial

We publish software and researched information, not legal advice, and no product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules.