CompyMax

HIPAA compliant billing software and companies

No billing product is compliant on its own, and no government body certifies one — no such designation exists. What you are actually buying is a vendor that will sign an agreement covering the specific service you use, and a configuration you remain responsible for. Here is what to require, in both directions: what a practice should demand of a billing company, and what a billing company has to be able to produce.

Last reviewed .

First, establish which side of the line you are on

Most billing companies are business associates: they handle patient information to perform billing on a practice’s behalf. But a health care clearinghouse is a covered entity in its own right under 45 CFR 160.103, and the definition is functional — it turns on processing nonstandard health information into a standard transaction, or the reverse. A billing company doing that conversion can land on the covered-entity side for that activity.

This is not a technicality. It changes which obligations apply to you directly, what your contracts have to say, and who notifies whom when something goes wrong. Settle it in writing before you build the programme on top of the wrong assumption.

Six things to require of billing software

In roughly the order they get skipped. The first two are the ones that decide whether the rest matters.

  • They will sign a business associate agreement

    Not “we are HIPAA compliant” on a marketing page — an executed agreement naming the service you are buying. If a vendor will not sign one, the conversation is over regardless of how good the product is, because disclosing patient data to them without it is your violation.

  • The agreement names the specific product and plan

    The commonest trap in this category. A vendor's agreement frequently covers its core platform and excludes the analytics module, the AI coding assistant, the patient-communication add-on or anything on the free tier. Read what the agreement lists, not what the sales page implies.

  • Access is per-user and revocable by you

    Unique logins for every biller and every one of the vendor's support staff who can reach your data, with a way to remove someone the day they leave. Shared credentials are the failure that turns a personnel change into an incident.

  • It logs who looked at what, and lets you read the log

    45 CFR 164.312(b) requires mechanisms that record and examine activity in systems containing electronic protected health information. A billing system you cannot audit cannot satisfy that for the data inside it.

  • The subprocessor list is published, or available on request

    Your billing vendor's own vendors — hosting, clearinghouse connections, statement printing, payment processing — are in the chain. 45 CFR 164.502(e)(1)(ii) pushes the obligation down it, and you are entitled to know who is on it.

  • Statements, payments and email are covered too

    Patient statements go out by post or email, payment pages take card details next to a patient name, and dunning notices say what the service was. These are frequently run by a different subprocessor under different terms from the billing platform itself.

If you are the practice, ask for these five

You are choosing a business associate, and 45 CFR 164.502(e) requires satisfactory assurances before you hand over anything. That phrase means evidence, not a logo on a website. A billing company running a real programme produces all five in a day.

  1. 01

    The executed business associate agreement, naming the services in scope.

  2. 02

    A dated risk analysis of their environment — not yours, and not a certificate.

  3. 03

    Their subprocessor list, including clearinghouse, statement and payment vendors.

  4. 04

    How they screen staff and contractors against the federal exclusion lists, and when they last did.

  5. 05

    Their breach notification procedure, with the time limit they commit to for telling you.

Invoicing, statements and the money side

A common assumption is that the financial half of the practice sits outside HIPAA. It does not. Protected health information includes information relating to the past, present or future payment for the provision of health care to an individual — so a statement naming a patient, a date of service and a procedure is squarely inside the definition, and so is the dunning letter that follows it.

The practical line is identifiers. General ledger software holding revenue totals and no patient identifiers is a different question from an invoicing tool holding names against services. If your accounting stack has drifted into the second category — and it usually does the first time someone raises an invoice per patient — it needs an agreement like anything else.

Our verdicts on accounting and bookkeeping tools →

Common questions

Is there such a thing as HIPAA compliant billing software?
Not as a property of the software by itself. No product is compliant in isolation, and no government body certifies one — what exists is a vendor that will sign a business associate agreement covering the specific service you use, plus a configuration you are responsible for. Two practices running identical software can be in completely different positions depending on whether the agreement was signed, which modules it names, and how access is managed. Treat vendor claims as a starting point and the executed agreement as the fact.
Is a medical billing company a business associate or a covered entity?
Usually a business associate — it handles protected health information to perform billing on a practice's behalf. But a health care clearinghouse is itself a covered entity under 45 CFR 160.103, and the definition turns on function: an entity that processes nonstandard health information into a standard transaction, or the reverse, is a clearinghouse. Billing companies that do that conversion can fall on the covered-entity side of the line for that activity. It is worth establishing which you are in writing, because the answer changes which obligations apply directly to you.
What should a practice ask a billing company for?
An executed business associate agreement naming the services; evidence of a dated risk analysis; their subprocessor list; how they screen staff and contractors against the federal exclusion lists; their breach notification procedure and how fast it runs; and confirmation that documentation is retained for six years. A billing company that can produce those in a day is running a programme. One that needs three weeks is assembling it for you.
Does HIPAA apply to invoicing and patient statements?
Yes, when they identify a patient in connection with their care or payment for it — which a statement does by definition. Payment information itself is inside the definition of protected health information, not outside it: the Privacy Rule covers information relating to the past, present or future payment for the provision of health care. Generic accounting software holding only totals and no patient identifiers is a different question from an invoicing tool holding names, dates of service and procedure descriptions.
Are billing companies required to screen for exclusions?
Federal health care programmes will not pay for items or services furnished, ordered or prescribed by an excluded individual or entity, and that prohibition reaches employees and contractors. For anyone in the revenue cycle this is not an abstract compliance point — it is a payment risk with your name on it, and the OIG list is published monthly and free to check.

Be the billing company that answers in a day.

Keep the assessment current, the agreements in both directions, the training recorded per person and the exclusion screening running monthly — then produce the whole pack as one dated export when a practice asks. 14 days free, no credit card, no sales call.

The full business associate checklist →

Informational only, based on the published text of 45 CFR Parts 160 and 164 and the exclusion authorities at 42 USC 1320a-7 and 42 CFR Part 1001. This is not legal advice, and whether a particular billing operation meets the clearinghouse definition is a fact-specific question worth putting to counsel. No organization or product can be “HIPAA certified” — no such designation exists. See our editorial standards.