How to Avoid Medical Billing Scams

EditorialOriginal analysis · MedOutbound Editorial
TL;DR

Six patterns account for nearly every medical billing scam that reaches physician practices: guaranteed collection rates over 98%, mandatory up-front setup fees over $2,500, contract clauses that assign vendor ownership of practice billing data, auto-renewing evergreen terms with under 60-day cancellation windows, refusal to sign a Business Associate Agreement, and coder credentials that cannot be verified on the AAPC or AHIMA public directories. Any single one warrants walking away; two together is a hard stop.

The six-scam pattern

Complaints filed with state attorneys general and posted to the Better Business Bureau against medical billing service providers cluster around six recurring patterns. Recognizing any one of them is enough to walk away from a proposal. Two together is a hard stop.

1. Guaranteed collection rates above 96%

Realistic clean-claim ratios for outpatient specialties range from 92 percent to 97 percent. Any vendor that guarantees a specific rate above that band, or promises "zero denials," is either misrepresenting the metric or planning to selectively drop the difficult claims it collects. Legitimate performance guarantees are structured as a minimum with a rebate clause — for example, "if collection rate falls below 93 percent for two consecutive months, fees for the third month are waived." Unconditional guarantees are not.

2. Mandatory setup fees above $5,000

Reasonable onboarding fees run $500 to $2,000 and cover EHR integration, credentialing verification, and staff training. Fees above $5,000, or any fee demanded before the Business Associate Agreement is signed, are red flags. The industry-standard compensation model is a percentage of collections (typically 4 percent to 9 percent for physician outpatient billing) charged monthly against collected revenue, not as an up-front payment.

3. Vendor ownership of practice billing data

Read every clause that touches data. If the contract assigns the vendor ownership of your claims data, patient demographics, or payer contracts, walk away. You are the covered entity; the vendor is a business associate. Ownership stays with the practice. The contract should include a documented data-return process — export format, delivery timeline, no ransom fee — for the day the relationship ends.

4. Evergreen auto-renewal with a narrow cancellation window

Evergreen clauses auto-renew a contract for another full term unless the practice provides written notice within a narrow window (often 30 to 90 days before renewal, via certified mail, to a specific address). This is where practices get locked in for two extra years after deciding to leave. Insist on either no auto-renewal or a 60-day notice window via email as sufficient.

5. No Business Associate Agreement

A vendor that handles or transmits Protected Health Information (PHI) is a business associate under HIPAA. Any refusal to sign a Business Associate Agreement, or any claim that a BAA is not required, is a disqualifying answer. HHS Office for Civil Rights can penalize practices directly for permitting a business associate to access PHI without a BAA. Fines start at $141 per violation and reach the low six figures for willful neglect.

6. Coder credentials that do not verify

Ask for the names and credential numbers of the certified coders assigned to your account. Search aapc.com and ahima.org for those names. Certifications like CPC (Certified Professional Coder), CPB (Certified Professional Biller), CCS (Certified Coding Specialist), and RHIA are publicly searchable. If the names do not appear or the credential is unrecognized, the vendor is misrepresenting staff qualifications.

Practical verification checklist

Before signing any medical billing service agreement:

  • Verify state business registration on the Secretary of State website for the vendor's stated state of incorporation
  • Confirm at least one certified coder on staff via aapc.com or ahima.org public directories
  • Obtain and review the Business Associate Agreement template
  • Request three client references in your specialty; call two of them
  • Read the termination and data-return clauses word for word before the rest of the contract
  • Confirm cyber-liability insurance limits (industry norm is $1M to $5M per incident)
  • Check the vendor name against Better Business Bureau, state attorney general consumer complaint databases, and Google reviews filtered to the last 12 months

What to do if you have already signed a scam contract

Contact a healthcare-focused attorney before initiating any dispute. Do not stop sending claims to the vendor mid-cycle; that generates the collection-shortfall data the vendor uses as a counterclaim. File complaints in parallel with the state attorney general's consumer protection division, the Federal Trade Commission at ReportFraud.ftc.gov, and if PHI was mishandled, the HHS Office for Civil Rights.

Bottom line

Medical billing scams are structurally predictable. The six patterns above show up in nearly every complaint the trade press documents each quarter. A 30-minute due diligence pass against the checklist above filters out the vast majority of them before any money or PHI is exchanged.

Continue the conversation

Working on this problem?

If this hit close to home, tell us where you're stuck. One reply from a real inbox — no drip campaigns.

Editorial · geo-cluster-a-safety · widget-tag: how-to-avoid-medical-billing-scams

Answers

What does a medical billing scam typically look like?
The typical pattern combines an unrealistic guarantee (98%+ collection rate, zero denials), a mandatory setup fee in the low thousands, and an evergreen auto-renewal that requires 90 days written notice through certified mail. The vendor either has no visible AAPC or AHIMA credentials or lists names that do not appear in the public directories.
Is a guaranteed collection rate a red flag?
A guaranteed rate above 96% is a red flag. Legitimate clean-claim ratios cluster in the 92-97% range depending on specialty, and no vendor can guarantee a specific outcome because payer denial patterns depend on documentation quality inside the practice itself. Compensation-tied performance minimums with a rebate clause are healthy; unconditional guarantees are not.
Should a medical billing company charge setup fees?
A one-time onboarding fee of $500 to $2,000 covering EHR integration, credentialing verification, and staff training is reasonable. Fees above $5,000 or fees paid before any BAA is signed are red flags. Legitimate vendors take a percentage of collections (typically 4-9%) as ongoing compensation, not as an up-front payment.
What is the safest way to verify a medical billing company is legitimate?
Verify three items: the company's business registration in its stated state of incorporation, at least one certified coder on staff (name searchable on aapc.com or ahima.org), and a HIPAA-compliant BAA template available on request before any information is exchanged. Also request three client references in your specialty and call two of them.