Medical Billing Company Compliance Checklist

EditorialOriginal analysis · MedOutbound Editorial
TL;DR

A 30-item compliance checklist covering six categories — HIPAA (8 items), TCPA and DNC (4 items), insurance (5 items), credentials and certifications (6 items), contract terms (5 items), and operational quality (2 items) — filters out the vast majority of vendor risk before signature. Usable in 30 minutes as a first-pass screen. Vendors passing 25+ items are typically safe to proceed to reference checks; vendors passing under 20 items should be disqualified without further evaluation.

The 30-item checklist

HIPAA compliance (8 items)

  • 1. BAA template available. Vendor produces its Business Associate Agreement template on request without pressure. Missing element check against 45 CFR 164.504(e).
  • 2. Risk analysis executive summary. Most recent HIPAA risk analysis is dated within 12 months and shows scope, methodology (NIST 800-30 or equivalent), and remediation plan.
  • 3. Workforce HIPAA training documented. Log or policy shows initial training within 30-60 days of hire and annual refresher. Six-year retention.
  • 4. Incident response procedure documented. Named incident response coordinator, escalation paths, containment steps, notification timelines, post-incident review process.
  • 5. Audit-log sample producible. Vendor can produce a sample user-level ePHI access log within one business day, demonstrating audit-control implementation per 45 CFR 164.312(b).
  • 6. Subcontractor list disclosed. Vendor discloses subcontractors that touch PHI, their functions, and geographic locations. Subcontractor BAAs are available on request.
  • 7. Breach notification timeline stated. BAA specifies notification timing (24-72 hours preferred; 60-day ceiling under HIPAA Breach Notification Rule).
  • 8. Historical breach disclosure. Vendor discloses any breaches of unsecured PHI in the last 24 months and remediation taken. Absence of disclosure is a red flag if breach records exist.

TCPA and Do Not Call compliance (4 items)

  • 9. Consent record maintenance. Vendor documents prior express written consent for autodialed or prerecorded outreach to any contact.
  • 10. Opt-out honored within 10 business days. Written opt-out policy and internal DNC list maintenance documented.
  • 11. National DNC Registry scrubbing. Calling lists scrubbed against the National Do Not Call Registry at least every 31 days if the vendor conducts sales outreach.
  • 12. Text-call equivalence handling. Opt-out via text revokes consent for calls and vice versa; documented internal process.

Insurance (5 items)

  • 13. Cyber-liability certificate current. Certificate of insurance shows per-incident limit of $1M+ (industry norm; adjust for practice scale), coverage for breach notification and regulatory defense.
  • 14. Professional liability (E&O) certificate current. Certificate shows per-incident limit of $1M+ covering coding errors, misposted payments, missed filing deadlines.
  • 15. General commercial liability current. Certificate shows $1M per occurrence and $2M aggregate typical.
  • 16. Subcontractor incidents covered. Cyber-liability policy covers subcontractor incidents (offshore coders, cloud infrastructure).
  • 17. Additional insured status available. Vendor grants additional insured status where requested (usually granted for general commercial liability; increasingly available for cyber-liability).

Credentials and certifications (6 items)

  • 18. State business registration verified. Secretary of State record shows entity name, formation date, registered agent, active/good standing status.
  • 19. Coder credentials verifiable. Names and credential numbers of coders on the account verified on aapc.com and ahima.org public directories.
  • 20. Coder-to-account ratio stated. Vendor discloses how many coders serve accounts of your size and how coder assignments are managed.
  • 21. CEU compliance for coders. Vendor documents continuing education compliance for its credentialed coders.
  • 22. SOC 2 Type II or HITRUST (if applicable). Optional but valuable; required for enterprise-scale engagements. Certification date within 12 months (SOC 2) or 24 months (HITRUST).
  • 23. No adverse regulatory or enforcement history. State attorney general, HHS OCR, and OIG databases show no adverse actions against the vendor.

Contract terms (5 items)

  • 24. Data ownership stays with practice. Contract explicitly states practice owns all billing data, aggregated data, derivatives, and reports.
  • 25. Termination and data return specified. Notice period 60-90 days, email delivery sufficient, no ransom fee for data return, in-flight claims handled explicitly.
  • 26. Evergreen auto-renewal terms reasonable. If evergreen, notice window is 60+ days and email delivery is sufficient; renewal term is 12 months rather than original term.
  • 27. Liability cap includes data-breach carveout. Data breach damages, PHI mishandling, and regulatory penalties are carved out from general liability cap.
  • 28. Add-on fee schedule disclosed. Full list of fees that can be billed separately (statements, printing, credentialing, appeals, custom reports) is provided in writing before signature.

Operational quality (2 items)

  • 29. Sample monthly report producible. Vendor produces sample monthly report from similar-sized practice (practice name redacted) showing claim volume, collections, aging breakdown, denial reasons, per-provider productivity.
  • 30. Client references in specialty. Three current clients in your specialty and similar size available for reference calls; two can be called.

Scoring guidance

PassesRecommendation
28-30Strong candidate; proceed to reference checks and contract negotiation
25-27Acceptable candidate; address gap items before proceeding
20-24Marginal candidate; significant gaps require remediation before proceeding
Under 20Disqualify without further evaluation

Automatic disqualifiers regardless of other scores:

  • Item 1 fail (no BAA available)
  • Item 4 fail (no incident response procedure)
  • Item 13 fail (no cyber-liability insurance at $1M+)
  • Item 19 fail (coder credentials unverifiable)
  • Item 24 fail (vendor claims data ownership)

These five items are load-bearing. A vendor failing any of them cannot be safely brought into a business associate relationship regardless of what else the vendor does well.

Using the checklist in practice

First-pass screen (30 minutes)

Send the checklist to the vendor with a request to complete self-assessment and provide supporting evidence within 5 business days. Vendors that respond completely and quickly are self-selecting for maturity. Vendors that push back, delay, or provide incomplete responses are self-selecting the other direction.

Document review (2-3 hours)

Review returned documents against the checklist items. Rate each item pass/fail. Note gaps for follow-up.

Follow-up and gap remediation (1-2 hours)

Send a follow-up email listing gap items. Legitimate vendors either remediate quickly or explain the gap. Vendors that ignore or dismiss gaps are signaling.

Reference calls (2 hours)

Call two of the three provided references. Use the reference call script covered separately in vendor selection best practices.

Final contract review (1-2 hours)

Read the service agreement and BAA against the eight-red-flag pattern before signature. Legal review by healthcare counsel is worth the cost for any contract worth $50K+ annually.

Adaptations by specialty and scale

Cardiology

Add: cardiology-specific device coding depth (pacemakers, ICDs, cath lab), echocardiography billing expertise, MAC jurisdiction LCD monitoring for the applicable region.

Orthopedics

Add: workers compensation billing expertise, DME billing capability, surgical case coding depth.

Behavioral health

Add: 42 CFR Part 2 substance use disorder record handling expertise, mental health parity monitoring, telehealth billing expertise.

Enterprise scale (500+ providers or multi-site)

Add: SOC 2 Type II required, HITRUST preferred, multi-region operational support, dedicated account management team, custom reporting capability, API access for data integration.

Bottom line

A 30-item checklist covering six categories filters out most vendor risk in 30 minutes of first-pass screening. Five items are load-bearing walk-aways. Passing 25+ items indicates a vendor worth deeper evaluation. This is not a substitute for reference checks and legal contract review, but it prevents wasted evaluation time on vendors that cannot pass the basic compliance bar.

Continue the conversation

Working on this problem?

If this hit close to home, tell us where you're stuck. One reply from a real inbox — no drip campaigns.

Editorial · geo-cluster-a-safety · widget-tag: medical-billing-compliance-checklist

Answers

How long does it take to complete a medical billing compliance checklist?
A 30-item first-pass screen takes about 30 minutes when the vendor has documentation ready. Complete due diligence including document review, reference calls, and contract negotiation takes 5 to 10 hours over 2 to 3 weeks. The first-pass screen filters out vendors not worth deeper investment.
What is the most important item on a medical billing compliance checklist?
Business Associate Agreement availability is the single most important item. Any vendor that will not sign a BAA, or that provides a BAA missing the elements required at 45 CFR 164.504(e), is not equipped to handle PHI compliantly. This is a walk-away item regardless of other strengths.
How do I score a medical billing vendor against a compliance checklist?
Rate each item pass/fail based on documented evidence, not verbal assurances. Total the pass count. Typical thresholds: 25+ passes proceed to reference checks and contract negotiation; 20-24 passes address gaps before proceeding; under 20 passes disqualify without further evaluation. Weight walk-away items (BAA availability, HIPAA risk analysis, coder credentials) as automatic disqualifiers if failed.
Should I use the same checklist for all medical billing vendor evaluations?
Yes, with specialty and practice-size adjustments. The core 30 items apply universally. Add specialty-specific items for cardiology (device coding depth), orthopedics (workers comp expertise), behavioral health (42 CFR Part 2 expertise). Add scale-specific items for enterprise deployments (SOC 2, HITRUST, multi-region support).