Skip to content
LRx HealthcareLRx Healthcare

Compliance

HIPAA-Compliant Medical Billing: The Controls That Actually Matter

HIPAA-compliant medical billing means protecting patient information across every billing workflow — claims, remittances, statements, calls, and reports — under the HIPAA Privacy, Security, and Breach Notification Rules. The controls that matter most day to day are a signed Business Associate Agreement with every vendor that touches PHI, minimum necessary access, multi-factor authentication, encryption in transit and at rest, audit logging, workforce training, and a tested incident response plan.

By LRx HealthcareUpdated 4 min read

Key takeaways

  • A billing company that handles PHI is a business associate and must sign a BAA before any PHI is shared.
  • Apply the minimum necessary standard: each person sees only what their role requires.
  • Treat MFA and encryption as mandatory, even where the Security Rule labels them “addressable.”
  • Keep audit logs and review them — access you cannot see, you cannot defend.
  • Breach notification has hard deadlines; rehearse the response before you need it.

Which HIPAA rules apply to medical billing?

RuleWhat it requires in billing
Privacy RuleLimits how PHI may be used and disclosed. Payment activities are permitted uses, but the minimum necessary standard applies.
Security RuleAdministrative, physical, and technical safeguards for electronic PHI, starting with a documented risk analysis.
Breach Notification RuleNotice to affected individuals, HHS, and in some cases the media after a breach of unsecured PHI.

Submitting claims, posting remittances, following up on AR, and sending statements are payment activities, so they do not need separate patient authorization. That permission does not relax the obligation to protect the data.

Does a medical billing company need a Business Associate Agreement?

Yes. A billing company, coding vendor, statement vendor, or patient-calling vendor that creates, receives, maintains, or transmits PHI on a provider’s behalf is a business associate. HIPAA requires a written Business Associate Agreement (BAA) that limits how the vendor may use PHI, requires safeguards, and requires breach reporting. Subcontractors that handle PHI for the business associate need their own BAAs.

A vendor that hesitates to sign a BAA before receiving PHI is a vendor to avoid. LRx Healthcare signs a BAA before any PHI is exchanged.

The day-to-day controls that matter most

ControlWhat good looks like
Minimum necessary accessRole-based access so each person sees only the patients and fields their job requires
Multi-factor authenticationRequired on every system that stores or displays PHI, including email and remote access
EncryptionTLS 1.2 or higher in transit; encryption at rest for databases, laptops, and backups
Audit loggingWho accessed what and when — retained and actually reviewed
Secure transmissionNo PHI in unencrypted email or text; secure portals or SFTP for files
Endpoint securityManaged devices, disk encryption, patching, and anti-malware
Workforce trainingAt onboarding and at least annually, including phishing and social engineering
OffboardingSame-day access removal when someone leaves

The Security Rule currently labels some safeguards, including encryption, as “addressable.” Addressable does not mean optional — you must implement the safeguard or document why an equivalent alternative is reasonable. HHS has also proposed Security Rule updates that would make encryption and multi-factor authentication explicit requirements. The practical answer is to treat both as mandatory now.

Where billing workflows leak PHI most often

  • Statements mailed to outdated addresses or to the wrong guarantor
  • Patient calls and voicemails that disclose balance details before identity is verified
  • AR or denial spreadsheets emailed around or saved to personal devices
  • Shared payer-portal logins that make access impossible to attribute
  • Screenshots and exports kept long after they are needed
  • Phishing that compromises a billing mailbox full of remittances and EOBs

What are the HIPAA breach notification deadlines?

After a breach of unsecured PHI, covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more individuals must also be reported to HHS within that window, and breaches affecting more than 500 residents of a state or jurisdiction require notice to prominent media outlets. Smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year.

Business associates must notify the covered entity without unreasonable delay and no later than 60 days after discovering a breach — and the BAA can set a shorter deadline.

Questions to ask a billing vendor about HIPAA

  • Will you sign a BAA before receiving any PHI?
  • Do subcontractors or offshore staff access our PHI? Are they covered by BAAs?
  • Is MFA enforced on every system that holds our data?
  • Where is our data stored and processed?
  • How is access logged, reviewed, and removed when staff leave?
  • When did you last complete a security risk analysis?
  • What is your incident response process and your breach notification timeline to us?
  • Are your security claims third-party audited, or internally aligned to a framework such as SOC 2?

LRx Healthcare publishes its posture openly: HIPAA-focused workflows, signed BAAs before PHI exchange, TLS 1.2 and 1.3, encryption at rest, MFA, role-based access, audit logging, U.S.-based infrastructure, and controls aligned to SOC 2 and SOC 3 Trust Services Criteria. See Compliance & Security and the Security Statement.

This guide is general information about healthcare billing operations, not legal, tax, or compliance advice. Payer rules and regulations change — confirm current requirements with the payer or a qualified advisor.

FAQ

Frequently asked questions.

Direct answers to the questions providers ask most about this topic.

Yes. A billing company that creates, receives, maintains, or transmits PHI on behalf of a provider is a business associate. It must sign a Business Associate Agreement and comply with the applicable HIPAA Security Rule and breach notification requirements.
Only through a secure, encrypted channel with appropriate safeguards. Unencrypted email is a common source of billing-related breaches; use secure portals, encrypted email, or SFTP for PHI.
Encryption is an “addressable” specification under the current Security Rule, which means you must implement it or document an equivalent alternative. HHS has proposed making it an explicit requirement, and in practice it should be treated as mandatory.
HIPAA requires required documentation — policies, procedures, risk analyses — to be retained for six years from creation or the date it was last in effect, whichever is later. Medical record retention periods are set separately by state law.

Let's get started

Turn these fixes into results.

Book a free consultation and we'll walk through where your revenue cycle is leaking — and what to fix first.