A medical billing company is a business associate under 45 CFR 160.103. That definition covers any person or entity that creates, receives, maintains, or transmits Protected Health Information (PHI) while performing a function on behalf of a covered entity. Claims processing, coding, accounts receivable management, denial management, and payment posting all satisfy the definition. So does software-as-a-service delivered to a covered entity if PHI passes through the vendor's systems.
Since the HITECH Act of 2009 and the Omnibus Rule of 2013, business associates have been directly liable to HHS Office for Civil Rights (OCR) for HIPAA compliance failures — not merely contractually liable to the covered entity they serve. This is the most important shift for physician practices to understand: a billing vendor's HIPAA failure is the vendor's problem first, but audit trails and enforcement will implicate the practice as well.
The three mandatory safeguard categories
The HIPAA Security Rule (45 CFR Part 164 Subpart C) organizes required safeguards into three categories. All three are required for any entity handling electronic PHI (ePHI).
Administrative safeguards
- Assign a Security Officer responsible for developing and implementing security policies
- Conduct a periodic risk analysis of confidentiality, integrity, and availability of ePHI
- Provide workforce training on PHI handling; document completion
- Implement access management including unique user IDs and role-based permissions
- Maintain an incident response and reporting procedure
- Maintain a written contingency plan for data backup, disaster recovery, and emergency mode operations
Physical safeguards
- Restrict facility access to areas where ePHI is stored or accessed
- Implement workstation security policies (screen timeouts, locked-down USB ports on shared machines)
- Document device and media disposal procedures — hard drive wiping, secure destruction certificates
- Track device inventory including any laptops or mobile devices with PHI access
Technical safeguards
- Enforce unique user authentication with strong-password or MFA policies
- Maintain audit logs of PHI access, retained for a minimum of six years
- Encrypt PHI in transit (TLS 1.2 or higher) and, per NIST guidance, at rest
- Implement automatic logoff and integrity controls to detect ePHI alteration or destruction
The Business Associate Agreement
Every covered entity practice must have a signed Business Associate Agreement (BAA) with the billing vendor before PHI is disclosed. The required elements are specified at 45 CFR 164.504(e). A compliant BAA:
- Defines the permitted and required uses and disclosures of PHI
- Requires the business associate to implement the Security Rule safeguards
- Requires the business associate to report security incidents and PHI breaches to the covered entity
- Requires that subcontractors sign equivalent BAAs
- Requires the business associate to make PHI available for individual access, amendment, and accounting of disclosures under 45 CFR 164.524, 164.526, and 164.528
- Specifies return or destruction of PHI at contract termination
- Authorizes the covered entity to terminate the agreement for material breach
A billing vendor that will not sign a BAA, or that pushes an unmodified BAA that omits any of these elements, is not equipped to be a compliant business associate.
Subcontractor flow-down
Many billing vendors use subcontractors — offshore coders, technology platforms, printing and mailing services. Each subcontractor that touches PHI must have a signed BAA with the vendor, and the vendor remains liable for the subcontractor's compliance. Practices should ask specifically which functions are subcontracted, where the subcontractors operate, and whether the subcontractor BAAs are available on request.
Breach reporting timeline
The HIPAA Breach Notification Rule (45 CFR Part 164 Subpart D) requires that a business associate notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days from discovery. Most BAAs impose stricter timelines — 24 hours, 48 hours, or 72 hours is common. The covered entity then has its own 60-day clock to notify affected individuals and, for breaches affecting 500 or more people, HHS and prominent media outlets in the affected state.
Penalty structure
HHS Office for Civil Rights operates a tiered civil monetary penalty structure. Adjusted for 2026 inflation:
| Culpability tier | Per-violation range | Annual cap |
|---|
| Unknowing | $141 - $71,162 | $2,134,831 |
| Reasonable cause | $1,424 - $71,162 | $2,134,831 |
| Willful neglect (corrected) | $14,232 - $71,162 | $2,134,831 |
| Willful neglect (not corrected) | $71,162 minimum | $2,134,831 |
Criminal penalties under 42 USC 1320d-6 add up to 10 years imprisonment for knowingly obtaining PHI for personal gain or malicious harm.
Practical verification steps
Before contracting with a medical billing vendor, request evidence of:
- Most recent HIPAA risk analysis (executive summary is sufficient)
- Workforce HIPAA training log or policy
- Incident response procedure document
- Sample audit-log report demonstrating access tracking
- Data disposal certificate template
- Subcontractor list with functions and geographic locations
- Cyber-liability insurance certificate
A vendor that cannot produce these on request is telling you something important about its compliance posture.
Bottom line
HIPAA compliance for a medical billing company is not a checkbox exercise. It is a documented ongoing program covering three safeguard categories, subcontractor management, breach reporting, and workforce training. Practices that verify these items during vendor selection avoid the enforcement risk that follows a preventable breach.