A medical billing company touches four distinct categories of protected and sensitive data. Understanding the scope of each helps practices set the right BAA language and audit expectations.
1. Patient demographics
- Full legal name
- Date of birth
- Home address
- Contact phone and email
- Emergency contact and next of kin (in some workflows)
- Marital status and employment where relevant to coordination of benefits
This is the identifier layer. Any breach here alone qualifies as unsecured PHI and triggers the breach notification chain.
2. Insurance information
- Primary and secondary payer identity
- Policy number and group ID
- Coverage type (HMO, PPO, EPO, POS, HDHP, Medicare, Medicaid)
- Effective dates and any coordination-of-benefits notes
- Subscriber relationship if the patient is a dependent
Billing vendors need this to submit clean claims and manage denials.
3. Clinical claim data
- ICD-10 diagnosis codes (primary and secondary)
- CPT and HCPCS procedure codes
- Modifiers (25, 59, 51, XE, XS, XP, XU, and site-of-service modifiers)
- Dates of service and place of service codes
- Ordering and rendering provider NPIs
- Encounter note or procedure documentation sufficient for coding accuracy
Under HIPAA's minimum necessary rule at 45 CFR 164.502(b), the vendor accesses the encounter documentation required to code and submit the claim — not the full longitudinal chart, unrelated encounter history, imaging studies, medication reconciliation, or care team notes.
4. Payment and receivable data
- Payer adjudications and remittance advice (EOB/ERA data)
- Patient responsibility (copay, coinsurance, deductible allocation)
- Aged receivables and collection status
- Refund and write-off history
- Fee schedule and payer contracted rates
This is where financial integrity is enforced. Vendors that skip payment posting granularity leak money through unposted or misposted adjudications.
What billing vendors do not need to access
- Full clinical records outside the billed encounter
- Imaging studies (unless the vendor bills imaging separately)
- Medication reconciliation and prescription histories
- Behavioral health notes with 42 CFR Part 2 protection (unless separately authorized)
- Genetic information under GINA
- Substance use disorder treatment records without patient-signed authorization
Any vendor that requests blanket access to the full EHR should be pushed back to role-based access limited to the billing workflow. EHR platforms support this at the permissions layer.
The minimum necessary rule in practice
HIPAA's minimum necessary standard at 45 CFR 164.502(b) requires covered entities and business associates to limit PHI access to the amount reasonably necessary to accomplish the intended purpose. For a billing vendor, that means:
- User accounts scoped to the specific practice's data, not the vendor's full customer base
- Role-based access within the vendor organization (a payment poster does not see denials workflow; a coder does not see EOB detail)
- Documented justification for any bulk data exports
- Automated logout timers and MFA on all PHI-accessing systems
Ask the vendor to walk through its minimum necessary implementation. A vendor that cannot describe this at the user-permission level is not implementing the rule.
Payer contract data and confidentiality
Payer fee schedules and contracted rates are not PHI, but they are commercially sensitive. Practices should confirm that:
- The BAA or a separate confidentiality clause protects payer contract data
- The vendor does not aggregate contracted rates across clients for benchmarking without written permission
- The vendor returns or destroys payer contract documentation at termination
Offshore access considerations
HIPAA does not prohibit offshore PHI access, but many practices prefer a domestic-only clause. If the vendor uses offshore staff:
- Request the countries involved and the specific functions performed offshore
- Confirm the subcontractor BAAs cover the offshore entity
- Ask about network controls (VPN, geographic access restrictions, endpoint monitoring)
- Verify whether the vendor's cyber-liability insurance covers offshore incidents
Audit-log expectations
Under 45 CFR 164.312(b), the vendor must maintain audit logs of ePHI access. A well-run vendor can produce, within one business day of request:
- A user-by-user access log for the practice's data for any date range in the past six years
- A list of any bulk exports or unusual access patterns flagged by internal monitoring
- Evidence of periodic audit-log review (typically monthly or quarterly)
If the vendor cannot produce these, its audit control implementation is not compliant.
Bottom line
A medical billing company legitimately touches identifier, insurance, coded clinical, and financial data on a minimum-necessary basis. Full chart access, unrelated encounter data, and sensitive categories protected by 42 CFR Part 2 or GINA are outside that scope. Practices that specify the scope in the BAA and verify audit-log capability during selection protect themselves from the breach-and-audit risk that comes with vendor overreach.