For medical billing & coding companies
HIPAA compliance for medical billing companies
Nobody has to tell a billing company it’s a business associate — claims, remittances, eligibility checks, and patient demographics are the job. The open question at most billing companies isn’t whether HIPAA applies. It’s whether anything is written down when a client, an insurer, or a regulator asks to see it.
What settlements against billing companies keep citing
When OCR — the federal HIPAA enforcer — has settled with medical billing companies, the cited failure has been strikingly consistent. Comstar, a billing company, reached a $75,000 settlement with OCR after a breach investigation, and state attorneys general added $515,000 more; the core finding was a missing risk analysis. iHealth Solutions, another billing vendor, also settled with OCR for $75,000 — same gap.
The dollar figures aren’t the story — these are settlements, and OCR settles for what a business can actually pay. The story is that the cases keep turning on the same missing document: a written, dated risk analysis of where patient data lives in the business and what could go wrong with it. That document is cheap to produce and expensive to not have.
Change Healthcare changed the questions
The biggest healthcare data breach on record happened at a business associate — and every practice that couldn’t bill for weeks remembers it. Practices and their insurers now ask harder questions of the billing vendors they trust with patient data. A signed BAA answers “did you promise?” A documented security program answers “can you show me?” — and that’s the question that wins and keeps contracts.
What to have on file
- A documented risk analysis — the artifact every case above was missing, and the first thing requested in an investigation.
- A safeguards inventory: encryption on every laptop and phone that touches claims data, multi-factor authentication, backups, and who has access to which client’s records.
- Written policies and training records — proof your team knows the rules, dated.
- A breach plan that runs upstream: business associates must notify affected healthcare clients without unreasonable delay — 60 days at the outside (45 CFR §164.410). Your clients’ own notification clocks start after yours.
If you run a small or home-based billing operation: HIPAA has no small-business exemption, but its safeguards scale to your size. A two-person company doesn’t need enterprise software — it needs the same questions answered, in writing.
The clock worth knowing about
The proposed update to the HIPAA Security Rule would require business associates to give their healthcare clients an annual written verification of deployed safeguards. It’s proposed, not final — currently expected around July 2027 — so nothing new is required today. But when clients start collecting those verifications, their billing company will be on the list. The vendors who documented early will be sending a PDF; the rest will be starting from zero. More on what’s changing for business associates →
Where HIPAAPath fits — and an honest note
HIPAAPath walks you through a HIPAA Security Rule risk assessment in plain English, one question at a time, and ends in a documented risk analysis and a security manual you keep. It’s free to complete, and your answers stay in your browser — they never touch our servers. (For a billing company, that last part matters: nothing about your clients ever lands on ours.)
The honest note: HIPAAPath was built first for small healthcare practices, so today’s walkthrough says “your patient records” where you’d say “your clients’ claims data.” The safeguards it documents are the same ones the Security Rule requires of you as a business associate. A billing-company edition that speaks your language is on our roadmap — want it sooner? Tell us: hello@hipaapath.com.
Free — no account needed to start, and your answers never leave your browser. Not legal advice: for questions about your specific obligations, talk to a healthcare attorney.