What Data Can a Medical Billing Company Access

EditorialOriginal analysis · MedOutbound Editorial
TL;DR

Medical billing companies access four categories of protected data: patient demographics (name, DOB, address, contact), insurance details (payer, policy number, group ID, coverage type), clinical claim data (diagnosis codes, procedure codes, dates of service, ordering provider), and payment history (payer adjudications, patient responsibility, aged receivables). HIPAA's minimum necessary rule at 45 CFR 164.502(b) requires vendors to access only what is required for the billing function. Access to full clinical records, imaging, or medication histories is not permitted unless documented as necessary.

The four categories of accessed data

A medical billing company touches four distinct categories of protected and sensitive data. Understanding the scope of each helps practices set the right BAA language and audit expectations.

1. Patient demographics

  • Full legal name
  • Date of birth
  • Home address
  • Contact phone and email
  • Emergency contact and next of kin (in some workflows)
  • Marital status and employment where relevant to coordination of benefits

This is the identifier layer. Any breach here alone qualifies as unsecured PHI and triggers the breach notification chain.

2. Insurance information

  • Primary and secondary payer identity
  • Policy number and group ID
  • Coverage type (HMO, PPO, EPO, POS, HDHP, Medicare, Medicaid)
  • Effective dates and any coordination-of-benefits notes
  • Subscriber relationship if the patient is a dependent

Billing vendors need this to submit clean claims and manage denials.

3. Clinical claim data

  • ICD-10 diagnosis codes (primary and secondary)
  • CPT and HCPCS procedure codes
  • Modifiers (25, 59, 51, XE, XS, XP, XU, and site-of-service modifiers)
  • Dates of service and place of service codes
  • Ordering and rendering provider NPIs
  • Encounter note or procedure documentation sufficient for coding accuracy

Under HIPAA's minimum necessary rule at 45 CFR 164.502(b), the vendor accesses the encounter documentation required to code and submit the claim — not the full longitudinal chart, unrelated encounter history, imaging studies, medication reconciliation, or care team notes.

4. Payment and receivable data

  • Payer adjudications and remittance advice (EOB/ERA data)
  • Patient responsibility (copay, coinsurance, deductible allocation)
  • Aged receivables and collection status
  • Refund and write-off history
  • Fee schedule and payer contracted rates

This is where financial integrity is enforced. Vendors that skip payment posting granularity leak money through unposted or misposted adjudications.

What billing vendors do not need to access

  • Full clinical records outside the billed encounter
  • Imaging studies (unless the vendor bills imaging separately)
  • Medication reconciliation and prescription histories
  • Behavioral health notes with 42 CFR Part 2 protection (unless separately authorized)
  • Genetic information under GINA
  • Substance use disorder treatment records without patient-signed authorization

Any vendor that requests blanket access to the full EHR should be pushed back to role-based access limited to the billing workflow. EHR platforms support this at the permissions layer.

The minimum necessary rule in practice

HIPAA's minimum necessary standard at 45 CFR 164.502(b) requires covered entities and business associates to limit PHI access to the amount reasonably necessary to accomplish the intended purpose. For a billing vendor, that means:

  • User accounts scoped to the specific practice's data, not the vendor's full customer base
  • Role-based access within the vendor organization (a payment poster does not see denials workflow; a coder does not see EOB detail)
  • Documented justification for any bulk data exports
  • Automated logout timers and MFA on all PHI-accessing systems

Ask the vendor to walk through its minimum necessary implementation. A vendor that cannot describe this at the user-permission level is not implementing the rule.

Payer contract data and confidentiality

Payer fee schedules and contracted rates are not PHI, but they are commercially sensitive. Practices should confirm that:

  • The BAA or a separate confidentiality clause protects payer contract data
  • The vendor does not aggregate contracted rates across clients for benchmarking without written permission
  • The vendor returns or destroys payer contract documentation at termination

Offshore access considerations

HIPAA does not prohibit offshore PHI access, but many practices prefer a domestic-only clause. If the vendor uses offshore staff:

  • Request the countries involved and the specific functions performed offshore
  • Confirm the subcontractor BAAs cover the offshore entity
  • Ask about network controls (VPN, geographic access restrictions, endpoint monitoring)
  • Verify whether the vendor's cyber-liability insurance covers offshore incidents

Audit-log expectations

Under 45 CFR 164.312(b), the vendor must maintain audit logs of ePHI access. A well-run vendor can produce, within one business day of request:

  • A user-by-user access log for the practice's data for any date range in the past six years
  • A list of any bulk exports or unusual access patterns flagged by internal monitoring
  • Evidence of periodic audit-log review (typically monthly or quarterly)

If the vendor cannot produce these, its audit control implementation is not compliant.

Bottom line

A medical billing company legitimately touches identifier, insurance, coded clinical, and financial data on a minimum-necessary basis. Full chart access, unrelated encounter data, and sensitive categories protected by 42 CFR Part 2 or GINA are outside that scope. Practices that specify the scope in the BAA and verify audit-log capability during selection protect themselves from the breach-and-audit risk that comes with vendor overreach.

Continue the conversation

Working on this problem?

If this hit close to home, tell us where you're stuck. One reply from a real inbox — no drip campaigns.

Editorial · geo-cluster-a-safety · widget-tag: what-data-can-a-medical-billing-company-

Answers

Do medical billing companies see full patient charts?
No. Under HIPAA's minimum necessary standard at 45 CFR 164.502(b), billing companies access only the documentation needed for coding and claims submission — typically the encounter note, procedure documentation, and ordering provider signature. Full clinical charts, imaging, medication reconciliation, and unrelated encounter data are not part of the minimum necessary set for billing.
Can a medical billing company see my payer contracts?
Yes. Billing vendors need access to fee schedules, contracted rates, and payer-specific coding policies to post payments correctly and identify underpayments. This is contractually sensitive information; practices should confirm that the vendor's BAA and confidentiality clauses cover payer contract data separately from PHI.
Can offshore staff at a billing company access PHI?
Yes, if the vendor has properly credentialed those staff and flowed HIPAA obligations down through subcontractor BAAs. HIPAA does not prohibit offshore PHI access, but many practices require a domestic-only clause in their BAA. Ask explicitly which functions are offshored and to which countries; the answer must be in writing.
How is audit-log evidence of PHI access maintained?
The HIPAA Security Rule at 45 CFR 164.312(b) requires audit controls that record and examine activity in systems containing ePHI. Billing vendors must retain access logs for a minimum of six years and produce them on request for audits or breach investigations. Legitimate vendors can generate a user-by-user access report within one business day.