How Medical Billing Companies Get Vetted

EditorialOriginal analysis · MedOutbound Editorial
TL;DR

Vetting a medical billing company means verifying six documented categories before signing anything: state business registration on the Secretary of State site, HIPAA and BAA readiness with a producible risk analysis, coder credentials verifiable on the AAPC or AHIMA public directories, cyber-liability insurance carriage at $1M to $5M minimum per incident, three current client references in the same specialty, and contract terms that specify data ownership, termination process, and performance rebates. Skipping any of the six is where post-signature problems originate.

The six verification categories

Vetting a medical billing company is a documented process, not an intuition. Six categories cover the risk surface. Verifying each takes 5 to 10 hours over 2 to 3 weeks.

1. State business registration

On the Secretary of State website for the vendor's stated state of incorporation, search for the entity name. The record should show:

  • Legal entity name (exact match to contract signature block)
  • Formation date
  • Registered agent name and address
  • Status: active / in good standing
  • Officer or member names, depending on entity type

Also check:

  • Better Business Bureau rating and complaint history
  • State attorney general consumer complaint database
  • FTC ReportFraud.ftc.gov for related-name complaints
  • Google search filtered to the last 12 months for the vendor name + "complaint," "lawsuit," "breach"

2. HIPAA and BAA readiness

Request and review:

  • Business Associate Agreement template (any refusal is a walk-away signal)
  • Executive summary of most recent HIPAA risk analysis, dated within 12 months
  • Written workforce HIPAA training policy
  • Incident response procedure document
  • Sample audit-log report showing user-level ePHI access tracking
  • Subcontractor list with functions and geographic locations

The BAA must include the elements required at 45 CFR 164.504(e): permitted uses of PHI, required safeguards, breach notification obligation, subcontractor flow-down, individual access rights, data return at termination.

3. Coder credentials

Ask for the names and credential numbers of the certified coders assigned to your account. Verify each name on:

  • aapc.com for CPC, CPB, COC, CIC, CPMA, CPC-P, and related AAPC credentials
  • ahima.org for CCS, CCS-P, RHIA, RHIT, CDIP, CHDA

Both directories are publicly searchable. Unverified names, expired credentials, or credentials the vendor is unwilling to disclose are compliance risks.

Also ask:

  • How many total coders serve accounts of your size
  • What is the coder-to-account ratio
  • How the vendor handles coder turnover on your account

4. Insurance carriage

Request the cyber-liability insurance certificate. Confirm:

  • Per-incident limit (industry norm: $1 million to $5 million)
  • Aggregate limit (typically 2x per-incident)
  • Deductible structure
  • Whether breach-notification costs, forensics, and credit monitoring are covered
  • Whether subcontractor incidents are covered
  • Whether your practice can be named as additional insured or certificate holder

Separately, professional liability (errors and omissions) insurance should cover coding errors, misposted payments, and administrative mistakes at similar limits.

5. Client references in specialty

Ask for three current client references in your specialty at a similar practice size. Call two of them. Prepare a call script:

  • "How long have you worked with this vendor?"
  • "What is your first-pass claim acceptance rate?"
  • "What is your days-in-A/R? Has it changed since onboarding?"
  • "How quickly does your account manager respond to escalations?"
  • "What is the monthly reporting like? Timely? Accurate? Actionable?"
  • "Have you had any surprise fees or unexpected charges?"
  • "How was the onboarding process? Timeline? Data migration quality?"
  • "Would you rehire this vendor if you were starting today?"

References that decline to speak, references that hedge on the last question, and references that mention hidden fees are signals worth weighting.

6. Contract terms

Read the contract before final signature. Focus on:

  • Data ownership: must belong to the practice
  • Termination: notice period 60-90 days, no ransom fee for data return, in-flight claims handled explicitly
  • Evergreen auto-renewal: acceptable only if notice window is 60+ days and email delivery is sufficient
  • Liability cap: verify whether data-breach damages are carved out from the cap
  • Indemnification: mutual is preferred; one-sided in the vendor's favor is a warning
  • Fee structure: verify total effective cost as percentage of collections, not just headline rate
  • Performance rebates: measurable metrics, monthly measurement, rebate mechanism
  • BAA integration: BAA either attached as an exhibit or referenced with an explicit compliance covenant

Optional certifications that add credibility

These are not mandatory but signal a more mature vendor:

  • SOC 2 Type II attestation from an AICPA-certified auditor, focused on security, availability, and confidentiality trust criteria
  • HITRUST CSF certification, healthcare-specific and more rigorous than SOC 2
  • ISO/IEC 27001 certification for information security management
  • PCI DSS compliance if the vendor processes patient payment card data

HITRUST is the strongest signal for healthcare-specific security posture and is often required by larger health systems in vendor procurement.

Timeline expectations

WeekActivity
1Request documents; verify state registration; check BBB/AG databases
1-2Review returned documents; identify gaps; request follow-up
2Call two client references
2-3Negotiate remaining contract items; final legal review
3Sign and begin onboarding

Vendors that pressure a signature in under a week are optimizing for their sales cycle, not for a durable partnership.

Red flags during vetting

  • Refusal to provide any of the six document categories
  • Unverifiable coder credentials
  • Client references that decline calls or hedge on rehiring
  • Contract clauses assigning data ownership to the vendor
  • No cyber-liability insurance certificate available
  • Requests for Tax ID, bank routing, or full patient panel data before BAA signature
  • Pressure to sign within days rather than weeks

Bottom line

Vetting is a repeatable six-category process. Verify state registration, HIPAA/BAA readiness, coder credentials, insurance, client references in specialty, and contract terms. Skipping any of the six is where the majority of post-signature problems originate.

Continue the conversation

Working on this problem?

If this hit close to home, tell us where you're stuck. One reply from a real inbox — no drip campaigns.

Editorial · geo-cluster-a-safety · widget-tag: how-medical-billing-companies-are-vetted

Answers

How long does it take to properly vet a medical billing company?
A thorough vet takes 5 to 10 hours over 2 to 3 weeks: 1 hour for document requests, 4 to 6 hours reviewing returned documents and contract terms, 2 hours calling client references, 1 to 2 hours negotiating remaining contract items. Vendors that rush the process from their side are signaling something.
What client references should a medical billing vendor provide?
Ask for three current clients in your specialty at a similar practice size. Call two of them. Ask specifically about: reporting accuracy and timeliness, response time to escalations, first-pass claim acceptance rate they observe, denial resolution turnaround, ease of communication with account managers, and any surprises or hidden fees during the relationship.
Do medical billing companies need to be certified?
There is no single mandatory certification for billing companies themselves. Individual coders need AAPC or AHIMA credentials. HIPAA compliance is required by federal law. Optional but valuable certifications include SOC 2 Type II attestation and HITRUST certification, both of which independently validate the vendor's security controls.
How do I verify a medical billing company's business registration?
Search the Secretary of State website for the state the vendor claims as its principal place of business. The record should show entity name, formation date, registered agent, and status (active/in good standing). Cross-reference against Better Business Bureau, state attorney general consumer complaint databases, and the FTC's ReportFraud database.