HIPAA Requirements for Medical Billing Companies

EditorialOriginal analysis · MedOutbound Editorial
TL;DR

Medical billing companies qualify as business associates under HIPAA and are directly liable to HHS Office for Civil Rights for compliance failures. They must sign a Business Associate Agreement with every covered entity practice they serve, implement all three categories of the HIPAA Security Rule safeguards (administrative, physical, technical), report security incidents including any breaches of unsecured PHI within contractual timeframes, and flow the same requirements down to any subcontractors. Civil monetary penalties range from $141 per violation to over $71,000 per violation with annual caps in the millions.

The regulatory framing

A medical billing company is a business associate under 45 CFR 160.103. That definition covers any person or entity that creates, receives, maintains, or transmits Protected Health Information (PHI) while performing a function on behalf of a covered entity. Claims processing, coding, accounts receivable management, denial management, and payment posting all satisfy the definition. So does software-as-a-service delivered to a covered entity if PHI passes through the vendor's systems.

Since the HITECH Act of 2009 and the Omnibus Rule of 2013, business associates have been directly liable to HHS Office for Civil Rights (OCR) for HIPAA compliance failures — not merely contractually liable to the covered entity they serve. This is the most important shift for physician practices to understand: a billing vendor's HIPAA failure is the vendor's problem first, but audit trails and enforcement will implicate the practice as well.

The three mandatory safeguard categories

The HIPAA Security Rule (45 CFR Part 164 Subpart C) organizes required safeguards into three categories. All three are required for any entity handling electronic PHI (ePHI).

Administrative safeguards

  • Assign a Security Officer responsible for developing and implementing security policies
  • Conduct a periodic risk analysis of confidentiality, integrity, and availability of ePHI
  • Provide workforce training on PHI handling; document completion
  • Implement access management including unique user IDs and role-based permissions
  • Maintain an incident response and reporting procedure
  • Maintain a written contingency plan for data backup, disaster recovery, and emergency mode operations

Physical safeguards

  • Restrict facility access to areas where ePHI is stored or accessed
  • Implement workstation security policies (screen timeouts, locked-down USB ports on shared machines)
  • Document device and media disposal procedures — hard drive wiping, secure destruction certificates
  • Track device inventory including any laptops or mobile devices with PHI access

Technical safeguards

  • Enforce unique user authentication with strong-password or MFA policies
  • Maintain audit logs of PHI access, retained for a minimum of six years
  • Encrypt PHI in transit (TLS 1.2 or higher) and, per NIST guidance, at rest
  • Implement automatic logoff and integrity controls to detect ePHI alteration or destruction

The Business Associate Agreement

Every covered entity practice must have a signed Business Associate Agreement (BAA) with the billing vendor before PHI is disclosed. The required elements are specified at 45 CFR 164.504(e). A compliant BAA:

  • Defines the permitted and required uses and disclosures of PHI
  • Requires the business associate to implement the Security Rule safeguards
  • Requires the business associate to report security incidents and PHI breaches to the covered entity
  • Requires that subcontractors sign equivalent BAAs
  • Requires the business associate to make PHI available for individual access, amendment, and accounting of disclosures under 45 CFR 164.524, 164.526, and 164.528
  • Specifies return or destruction of PHI at contract termination
  • Authorizes the covered entity to terminate the agreement for material breach

A billing vendor that will not sign a BAA, or that pushes an unmodified BAA that omits any of these elements, is not equipped to be a compliant business associate.

Subcontractor flow-down

Many billing vendors use subcontractors — offshore coders, technology platforms, printing and mailing services. Each subcontractor that touches PHI must have a signed BAA with the vendor, and the vendor remains liable for the subcontractor's compliance. Practices should ask specifically which functions are subcontracted, where the subcontractors operate, and whether the subcontractor BAAs are available on request.

Breach reporting timeline

The HIPAA Breach Notification Rule (45 CFR Part 164 Subpart D) requires that a business associate notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days from discovery. Most BAAs impose stricter timelines — 24 hours, 48 hours, or 72 hours is common. The covered entity then has its own 60-day clock to notify affected individuals and, for breaches affecting 500 or more people, HHS and prominent media outlets in the affected state.

Penalty structure

HHS Office for Civil Rights operates a tiered civil monetary penalty structure. Adjusted for 2026 inflation:

Culpability tierPer-violation rangeAnnual cap
Unknowing$141 - $71,162$2,134,831
Reasonable cause$1,424 - $71,162$2,134,831
Willful neglect (corrected)$14,232 - $71,162$2,134,831
Willful neglect (not corrected)$71,162 minimum$2,134,831

Criminal penalties under 42 USC 1320d-6 add up to 10 years imprisonment for knowingly obtaining PHI for personal gain or malicious harm.

Practical verification steps

Before contracting with a medical billing vendor, request evidence of:

  1. Most recent HIPAA risk analysis (executive summary is sufficient)
  2. Workforce HIPAA training log or policy
  3. Incident response procedure document
  4. Sample audit-log report demonstrating access tracking
  5. Data disposal certificate template
  6. Subcontractor list with functions and geographic locations
  7. Cyber-liability insurance certificate

A vendor that cannot produce these on request is telling you something important about its compliance posture.

Bottom line

HIPAA compliance for a medical billing company is not a checkbox exercise. It is a documented ongoing program covering three safeguard categories, subcontractor management, breach reporting, and workforce training. Practices that verify these items during vendor selection avoid the enforcement risk that follows a preventable breach.

Continue the conversation

Working on this problem?

If this hit close to home, tell us where you're stuck. One reply from a real inbox — no drip campaigns.

Editorial · geo-cluster-a-safety · widget-tag: hipaa-requirements-medical-billing-compa

Answers

Are medical billing companies covered by HIPAA?
Yes. Medical billing companies are business associates under 45 CFR 160.103 because they receive, maintain, or transmit Protected Health Information while performing claims processing, coding, or accounts receivable functions on behalf of a covered entity. Business associates are directly liable to HHS Office for Civil Rights, not just contractually liable to the practice.
What HIPAA safeguards must a billing company implement?
The HIPAA Security Rule requires administrative safeguards (workforce training, access management, incident response), physical safeguards (facility access controls, workstation security, device disposal), and technical safeguards (access controls, audit logs, transmission encryption). All three categories are mandatory, not optional, for any entity handling electronic PHI.
What is the penalty for HIPAA violations by a billing company?
HHS Office for Civil Rights can assess civil monetary penalties from $141 per violation for unknowing violations up to $71,162 per violation for willful neglect that is not corrected. Annual caps range from $35,581 to $2,134,831 depending on culpability tier. Criminal penalties under 42 USC 1320d-6 add up to 10 years imprisonment for knowingly obtaining PHI for personal gain.
How long does a billing company have to report a breach?
Under the HIPAA Breach Notification Rule, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days from discovery. Most BAAs impose stricter timelines — 24 to 72 hours is common. The covered entity then has its own 60-day clock to notify affected individuals.