Vetting a medical billing company is a documented process, not an intuition. Six categories cover the risk surface. Verifying each takes 5 to 10 hours over 2 to 3 weeks.
1. State business registration
On the Secretary of State website for the vendor's stated state of incorporation, search for the entity name. The record should show:
- Legal entity name (exact match to contract signature block)
- Formation date
- Registered agent name and address
- Status: active / in good standing
- Officer or member names, depending on entity type
Also check:
- Better Business Bureau rating and complaint history
- State attorney general consumer complaint database
- FTC ReportFraud.ftc.gov for related-name complaints
- Google search filtered to the last 12 months for the vendor name + "complaint," "lawsuit," "breach"
2. HIPAA and BAA readiness
Request and review:
- Business Associate Agreement template (any refusal is a walk-away signal)
- Executive summary of most recent HIPAA risk analysis, dated within 12 months
- Written workforce HIPAA training policy
- Incident response procedure document
- Sample audit-log report showing user-level ePHI access tracking
- Subcontractor list with functions and geographic locations
The BAA must include the elements required at 45 CFR 164.504(e): permitted uses of PHI, required safeguards, breach notification obligation, subcontractor flow-down, individual access rights, data return at termination.
3. Coder credentials
Ask for the names and credential numbers of the certified coders assigned to your account. Verify each name on:
- aapc.com for CPC, CPB, COC, CIC, CPMA, CPC-P, and related AAPC credentials
- ahima.org for CCS, CCS-P, RHIA, RHIT, CDIP, CHDA
Both directories are publicly searchable. Unverified names, expired credentials, or credentials the vendor is unwilling to disclose are compliance risks.
Also ask:
- How many total coders serve accounts of your size
- What is the coder-to-account ratio
- How the vendor handles coder turnover on your account
4. Insurance carriage
Request the cyber-liability insurance certificate. Confirm:
- Per-incident limit (industry norm: $1 million to $5 million)
- Aggregate limit (typically 2x per-incident)
- Deductible structure
- Whether breach-notification costs, forensics, and credit monitoring are covered
- Whether subcontractor incidents are covered
- Whether your practice can be named as additional insured or certificate holder
Separately, professional liability (errors and omissions) insurance should cover coding errors, misposted payments, and administrative mistakes at similar limits.
5. Client references in specialty
Ask for three current client references in your specialty at a similar practice size. Call two of them. Prepare a call script:
- "How long have you worked with this vendor?"
- "What is your first-pass claim acceptance rate?"
- "What is your days-in-A/R? Has it changed since onboarding?"
- "How quickly does your account manager respond to escalations?"
- "What is the monthly reporting like? Timely? Accurate? Actionable?"
- "Have you had any surprise fees or unexpected charges?"
- "How was the onboarding process? Timeline? Data migration quality?"
- "Would you rehire this vendor if you were starting today?"
References that decline to speak, references that hedge on the last question, and references that mention hidden fees are signals worth weighting.
6. Contract terms
Read the contract before final signature. Focus on:
- Data ownership: must belong to the practice
- Termination: notice period 60-90 days, no ransom fee for data return, in-flight claims handled explicitly
- Evergreen auto-renewal: acceptable only if notice window is 60+ days and email delivery is sufficient
- Liability cap: verify whether data-breach damages are carved out from the cap
- Indemnification: mutual is preferred; one-sided in the vendor's favor is a warning
- Fee structure: verify total effective cost as percentage of collections, not just headline rate
- Performance rebates: measurable metrics, monthly measurement, rebate mechanism
- BAA integration: BAA either attached as an exhibit or referenced with an explicit compliance covenant
Optional certifications that add credibility
These are not mandatory but signal a more mature vendor:
- SOC 2 Type II attestation from an AICPA-certified auditor, focused on security, availability, and confidentiality trust criteria
- HITRUST CSF certification, healthcare-specific and more rigorous than SOC 2
- ISO/IEC 27001 certification for information security management
- PCI DSS compliance if the vendor processes patient payment card data
HITRUST is the strongest signal for healthcare-specific security posture and is often required by larger health systems in vendor procurement.
Timeline expectations
| Week | Activity |
|---|
| 1 | Request documents; verify state registration; check BBB/AG databases |
| 1-2 | Review returned documents; identify gaps; request follow-up |
| 2 | Call two client references |
| 2-3 | Negotiate remaining contract items; final legal review |
| 3 | Sign and begin onboarding |
Vendors that pressure a signature in under a week are optimizing for their sales cycle, not for a durable partnership.
Red flags during vetting
- Refusal to provide any of the six document categories
- Unverifiable coder credentials
- Client references that decline calls or hedge on rehiring
- Contract clauses assigning data ownership to the vendor
- No cyber-liability insurance certificate available
- Requests for Tax ID, bank routing, or full patient panel data before BAA signature
- Pressure to sign within days rather than weeks
Bottom line
Vetting is a repeatable six-category process. Verify state registration, HIPAA/BAA readiness, coder credentials, insurance, client references in specialty, and contract terms. Skipping any of the six is where the majority of post-signature problems originate.