Key takeaways
- A billing company that handles PHI is a business associate and must sign a BAA before any PHI is shared.
- Apply the minimum necessary standard: each person sees only what their role requires.
- Treat MFA and encryption as mandatory, even where the Security Rule labels them “addressable.”
- Keep audit logs and review them — access you cannot see, you cannot defend.
- Breach notification has hard deadlines; rehearse the response before you need it.
Which HIPAA rules apply to medical billing?
| Rule | What it requires in billing |
|---|---|
| Privacy Rule | Limits how PHI may be used and disclosed. Payment activities are permitted uses, but the minimum necessary standard applies. |
| Security Rule | Administrative, physical, and technical safeguards for electronic PHI, starting with a documented risk analysis. |
| Breach Notification Rule | Notice to affected individuals, HHS, and in some cases the media after a breach of unsecured PHI. |
Submitting claims, posting remittances, following up on AR, and sending statements are payment activities, so they do not need separate patient authorization. That permission does not relax the obligation to protect the data.
Does a medical billing company need a Business Associate Agreement?
Yes. A billing company, coding vendor, statement vendor, or patient-calling vendor that creates, receives, maintains, or transmits PHI on a provider’s behalf is a business associate. HIPAA requires a written Business Associate Agreement (BAA) that limits how the vendor may use PHI, requires safeguards, and requires breach reporting. Subcontractors that handle PHI for the business associate need their own BAAs.
A vendor that hesitates to sign a BAA before receiving PHI is a vendor to avoid. LRx Healthcare signs a BAA before any PHI is exchanged.
The day-to-day controls that matter most
| Control | What good looks like |
|---|---|
| Minimum necessary access | Role-based access so each person sees only the patients and fields their job requires |
| Multi-factor authentication | Required on every system that stores or displays PHI, including email and remote access |
| Encryption | TLS 1.2 or higher in transit; encryption at rest for databases, laptops, and backups |
| Audit logging | Who accessed what and when — retained and actually reviewed |
| Secure transmission | No PHI in unencrypted email or text; secure portals or SFTP for files |
| Endpoint security | Managed devices, disk encryption, patching, and anti-malware |
| Workforce training | At onboarding and at least annually, including phishing and social engineering |
| Offboarding | Same-day access removal when someone leaves |
The Security Rule currently labels some safeguards, including encryption, as “addressable.” Addressable does not mean optional — you must implement the safeguard or document why an equivalent alternative is reasonable. HHS has also proposed Security Rule updates that would make encryption and multi-factor authentication explicit requirements. The practical answer is to treat both as mandatory now.
Where billing workflows leak PHI most often
- Statements mailed to outdated addresses or to the wrong guarantor
- Patient calls and voicemails that disclose balance details before identity is verified
- AR or denial spreadsheets emailed around or saved to personal devices
- Shared payer-portal logins that make access impossible to attribute
- Screenshots and exports kept long after they are needed
- Phishing that compromises a billing mailbox full of remittances and EOBs
What are the HIPAA breach notification deadlines?
After a breach of unsecured PHI, covered entities must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more individuals must also be reported to HHS within that window, and breaches affecting more than 500 residents of a state or jurisdiction require notice to prominent media outlets. Smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year.
Business associates must notify the covered entity without unreasonable delay and no later than 60 days after discovering a breach — and the BAA can set a shorter deadline.
Questions to ask a billing vendor about HIPAA
- Will you sign a BAA before receiving any PHI?
- Do subcontractors or offshore staff access our PHI? Are they covered by BAAs?
- Is MFA enforced on every system that holds our data?
- Where is our data stored and processed?
- How is access logged, reviewed, and removed when staff leave?
- When did you last complete a security risk analysis?
- What is your incident response process and your breach notification timeline to us?
- Are your security claims third-party audited, or internally aligned to a framework such as SOC 2?
LRx Healthcare publishes its posture openly: HIPAA-focused workflows, signed BAAs before PHI exchange, TLS 1.2 and 1.3, encryption at rest, MFA, role-based access, audit logging, U.S.-based infrastructure, and controls aligned to SOC 2 and SOC 3 Trust Services Criteria. See Compliance & Security and the Security Statement.
This guide is general information about healthcare billing operations, not legal, tax, or compliance advice. Payer rules and regulations change — confirm current requirements with the payer or a qualified advisor.
