For billing, RCM and coding companies
You are a business associate. Sooner or later someone asks you to prove it.
Handling claims means handling protected health information on behalf of your provider clients, which puts you directly under the HIPAA rules — and makes you the party a practice's auditor, insurer or hospital partner asks about. This gives you the program and the paperwork, without a consultant on retainer.
Last reviewed .
The request arrives mid-contract, and it has a deadline.
A new provider client sends their vendor security packet before signing. An existing client's cyber-insurance renewal asks what their vendors have in place. A hospital system decides to review every downstream billing partner. Each one wants documentation you either have on hand or scramble to assemble over a weekend.
One packet answers most of them
A dated PDF with your risk assessment summary, open and closed remediation items, signed policies, staff training certificates, your own vendor and BAA register, and your incident log. Generated in a click, current as of the moment you send it.
Your subcontractors tracked too
The clearinghouse, the storage provider, the phone system, the offshore coding partner — each one needs its own agreement. The vendor register tracks who has signed, on what date, and when it needs revisiting.
Training records that produce certificates
Record each person's completion — of your own course or a provider you already use — and the platform issues a per-person certificate carrying their name, the completion date and a sequential reference. Renewal intervals are tracked, so lapses surface before a reviewer finds them.
An incident log that knows the deadlines
Record an incident, work through the risk assessment factors, and the log tracks the notification clock and the reporting threshold that applies — so a small event doesn't quietly become a missed obligation.
Priced like software, not consulting
$79 a month for your organization, with a 14-day free trial and no onboarding fee. Compare that to the four-figure setup charges common in this category.
We don't hold your clients' patient data
The platform stores compliance artifacts only — policies, tasks, certificates, registers. Your claims data stays in your billing system where it belongs.
What HIPAA requires of a billing company specifically
Billing, RCM and coding companies are business associates by definition — claims work is the textbook example in the regulation itself. What follows from that is a short list, and each item is something a provider's auditor can ask you to produce.
- Agreements in both directions
- One with every provider client, and one with every subcontractor of yours that touches their data: the clearinghouse, the document storage service, the offshore coding partner, the transcription vendor, the phone system that records calls.
- A documented, organization-wide risk analysis
- Required by 45 CFR 164.308(a)(1)(ii)(A) and the most commonly missing artifact in OCR enforcement. It has to cover your whole operation, be written down, and be revisited — a vulnerability scan is not a substitute.
- The minimum necessary standard, applied to your staff
- A coder working one practice's claims should not be able to pull another practice's records. Role-based access inside your billing system, reviewed periodically, is what this looks like in practice.
- Breach notification to your client, on a clock
- As a business associate, your obligation runs to the covered entity, not to patients — without undue delay and no later than 60 days from discovery, per 45 CFR 164.410. Your contract may well require faster.
- Six-year documentation retention
- Policies, risk analyses, training records, incident determinations, agreements. 45 CFR 164.316(b)(2) sets six years from creation or last effective date, whichever is later — including incidents you assessed and concluded were not reportable.
Remote and offshore staffing deserves specific attention, because it is common in this industry and it is where reviews find problems. Contractors are workforce members for HIPAA purposes: they need training records, unique named accounts, and agreements. An offshore coding partner is a subcontractor requiring its own signed agreement, and a home worker's environment is part of your risk analysis.
Where billing companies actually get caught
These are the recurring findings — not exotic attacks, but the ordinary gaps that turn a routine question into a problem. Each maps to something the platform tracks, which is the point of tracking it.
| The gap | How it usually shows up | What closes it |
|---|---|---|
| No written risk analysis | A client's auditor asks for it and there is a security checklist from years ago, or nothing. | The guided assessment across all 68 Security Rule controls, dated and repeatable annually. |
| Missing downstream agreements | A subcontractor list is requested and two or three vendors have never signed anything. | A vendor register with agreement status, signature dates and renewal reminders. |
| Undocumented training | Staff were trained; nobody can produce records with names and dates. | Per-person completion records with certificates and renewal tracking. |
| Accounts that outlive employment | A departed coder's login is still active in the billing system months later. | An automated check that flags enabled accounts dormant 90+ days, filed as dated evidence. |
| Incidents assessed only verbally | A laptop went missing, it was handled, and no record exists of the determination. | An incident log with the four-factor assessment and the notification clock recorded. |
| Policies never acknowledged | Policies exist as documents nobody signed off on. | Versioned policies with per-person acknowledgement against the exact version read. |
Answering a client's vendor security packet
When a provider client's packet lands, the delay is rarely the answering — it is the assembling, and then the follow-up round created by answers that do not agree with each other.
Read what is actually being asked
A request for “HIPAA certification” is asking for evidence, since no such certification exists. A request for SOC 2 Type II is a different, auditor-driven exercise. Answering the wrong one costs weeks.
Pull the answers from live program data
The questionnaire library covers around fifty recurring questions, filled from your current records rather than from memory — so training percentages and agreement counts match the pack you attach.
Attach the Trust Packet rather than rebuilding a document
Risk assessment summary, remediation status, policy list with acknowledgement dates, training certificates, vendor register and incident summary, stamped with the moment the data was true.
Do not hide the open items
The pack reports overdue tasks and lapsed training deliberately. A reviewer reading a flawless document asks harder questions; open items with owners and due dates read as a programme someone is actually running.
Keep the copy you sent
Every generated pack is archived with its generation date, so months later you can show exactly what you provided and when.
Questions we get
- What are the requirements for HIPAA compliance in medical billing?
- A billing company is a business associate, so the obligations are direct: a signed business associate agreement with every provider client and every subcontractor, a documented security risk analysis, written policies with workforce training, minimum-necessary access to claims data, an incident log with breach notification procedures, and six-year record retention. Signing the client's agreement is the start of the obligation, not the end — this is where you run and document the rest.
- What are the top 5 HIPAA violations?
- From OCR enforcement patterns: no documented risk analysis, missing business associate agreements, impermissible disclosures, lost or stolen unencrypted devices, and failing to give patients timely access to records. For billing companies specifically, the missing-agreement and missing-risk-analysis failures dominate — both are documentation problems, and both apply regardless of headcount.
- What is the 72 hour rule in medical billing?
- It is not a HIPAA rule — it usually refers to Medicare's three-day payment window, which bundles certain outpatient services into the inpatient claim. The HIPAA clock that actually matters in billing is breach notification: without unreasonable delay and no later than 60 days from discovery, with your provider clients notified so they can meet their own deadlines.
Have the answer ready before the next questionnaire lands.
Complete the assessment in an afternoon and export a packet the same day. Free for 14 days, no credit card.
Start free trialWe publish software and researched information, not legal advice, and no product can make an organization “HIPAA certified” — no such designation exists under the HIPAA rules.
Keep reading
- Answering a security questionnaireWhat they are really asking for, and what to send.
- Trust Packet exportOne dated pack answering the whole request.
- For healthcare software vendorsStop rebuilding the same answers for every deal.
- Questionnaire answer starterFill-in-the-blank answers to the twelve questions every form asks.