How to Verify a Medical Billing Company Is HIPAA Compliant

EditorialOriginal analysis · MedOutbound Editorial
TL;DR

Verifying HIPAA compliance of a medical billing company requires reviewing five documented items and getting written answers to four questions. The five documents: Business Associate Agreement template, executive summary of most recent HIPAA risk analysis (dated within 12 months), workforce training log or policy, written incident response procedure, and sample audit-log report showing user-level ePHI access tracking. The four questions cover subcontractor management, breach notification timing, cyber-liability insurance limits, and data return process at termination.

Why HIPAA compliance verification is documentary

HHS Office for Civil Rights has stated explicitly that there is no HHS-issued HIPAA compliance certification. Compliance is not a certificate; it is a documented ongoing program covering safeguards, workforce practices, incident response, and continuous risk management.

Verifying compliance therefore means reviewing the documents that evidence the program. A billing vendor that cannot produce these documents is telling you the program does not exist in operational form.

The five documents to review

1. Business Associate Agreement template

Request the BAA template the vendor uses with its clients. Review for the eight required elements at 45 CFR 164.504(e):

  • Permitted uses and disclosures of PHI
  • Required Security Rule safeguards
  • Reporting of security incidents and breaches
  • Subcontractor flow-down
  • Individual access, amendment, and accounting rights
  • PHI availability for HHS compliance activity
  • Return or destruction of PHI at termination
  • Covered entity termination rights for material breach

Specifically check the breach notification timing (24-72 hours is preferred; 60 days is the regulatory ceiling but is functionally too slow for most practices).

2. Risk analysis executive summary

The HIPAA Security Rule at 45 CFR 164.308(a)(1)(ii)(A) requires a periodic risk analysis of the confidentiality, integrity, and availability of ePHI. Request the executive summary of the most recent risk analysis. It should show:

  • Date of analysis (within 12 months)
  • Scope (which systems, workflows, data flows were assessed)
  • Methodology (NIST SP 800-30 or equivalent framework)
  • Identified risks categorized by likelihood and impact
  • Remediation plan with timeline and ownership

A risk analysis older than 24 months is a red flag. Operations, technology, and threat landscape all change; the analysis needs to keep up.

3. Workforce training log or policy

HIPAA requires workforce training on PHI handling for all workforce members with PHI access. The training log or policy should show:

  • Employee name and role
  • Date of training
  • Training content or module completed
  • Delivery method (online, in-person, blended)
  • Duration
  • Post-training assessment score if administered

Retention: six years minimum. Cadence: initial training within 30-60 days of hire, refresher training annually, updated training after policy or workflow changes.

4. Incident response procedure

The procedure documents how the vendor detects, contains, investigates, and reports security incidents. A compliant procedure includes:

  • Named incident response coordinator with backup
  • Escalation paths for different incident severities
  • Containment steps (account lockdown, network isolation, forensic preservation)
  • Investigation methodology
  • Covered-entity notification timeline and template
  • Regulator notification obligations (OCR for HIPAA breaches, state AG for state breach laws)
  • Post-incident review and lessons-learned process

Absence of a documented incident response procedure is a common finding in HHS enforcement actions and cited in nearly every enforcement announcement.

5. Sample audit-log report

The HIPAA Security Rule at 45 CFR 164.312(b) requires audit controls that record and examine activity in systems containing ePHI. Request a sample audit-log report showing:

  • User-level access records
  • Timestamps of access events
  • Actions performed (view, edit, export, delete)
  • Client-account scoping (data from one practice not visible to users assigned to a different practice)
  • Retention window (six years minimum)

A vendor that cannot produce a sample audit-log report — even with client data redacted — does not have the audit-control capability the Security Rule requires.

The four verification questions

Beyond the documents, get written answers to:

Q1. What is your subcontractor list and where do they operate?

Ask for the list of subcontractors that touch PHI, the functions they perform, and their geographic locations. Confirm subcontractor BAAs are in place. If offshore access is not acceptable for the practice, insist on a domestic-only clause in the BAA.

Q2. What is your breach notification timeline?

The BAA states the ceiling; the vendor's operational process may be faster. Ask for the internal target (24 hours, 48 hours, 72 hours) and how it is measured. Ask about historical breach frequency in the last 24 months, breach notification performance, and any post-breach remediation.

Q3. What are your cyber-liability insurance limits?

Confirm per-incident limit ($1M-$5M industry norm), aggregate limit (typically 2x per-incident), coverage scope (breach notification, forensics, credit monitoring, regulatory defense), subcontractor incident inclusion, and additional-insured availability.

Q4. What is the data-return process at termination?

Specify format (CSV or SQL dump), delivery timeline (30 days from termination notice), completeness (all patient data, all claim history, all correspondence with payers), and cost (should be zero).

What third-party attestations add

While no HIPAA compliance certificate exists, third-party attestations can validate specific security controls that map to HIPAA requirements:

  • SOC 2 Type II — evaluates security, availability, processing integrity, confidentiality, and privacy trust criteria over 6-12 months. Good for confirming security control maturity.
  • HITRUST CSF Certification — healthcare-specific, more rigorous than SOC 2, considered the gold standard for demonstrating security posture in healthcare.
  • ISO/IEC 27001 — international information security management standard, less common in US healthcare but recognized globally.

Request the attestation report (or the SOC 3 summary if the full SOC 2 is confidential). Verify the attestation date is within 12 months and the scope covers the services your practice uses.

Red flags during compliance verification

  • Vendor refuses to provide any of the five documents
  • Risk analysis is older than 24 months or not available
  • Workforce training log does not exist or covers only new hires
  • No documented incident response procedure
  • Cannot produce a sample audit-log report
  • Subcontractor list is not disclosed
  • Cyber-liability insurance limits below $1M per incident
  • Vendor pushes a template BAA missing required elements
  • Vendor claims HIPAA compliance based on a purchased certificate from a non-HHS third party (there is no such thing as a HIPAA compliance certificate)

What to do if compliance verification fails

Do not sign a service agreement. Do not permit PHI transmission. Notify the vendor of the specific compliance gaps identified. Reputable vendors will remediate; vendors that push back or claim the checks are unreasonable are not equipped to be compliant business associates.

Bottom line

Five documents plus four written answers verify HIPAA compliance in an operational sense. There is no compliance certificate to shortcut this. Vendors that produce the documents easily are the ones running a real program; vendors that resist are the ones the enforcement actions are written about.

Continue the conversation

Working on this problem?

If this hit close to home, tell us where you're stuck. One reply from a real inbox — no drip campaigns.

Editorial · geo-cluster-a-safety · widget-tag: how-to-verify-hipaa-compliance-billing-c

Answers

Is there a HIPAA compliance certificate a billing company can show?
No. HIPAA does not have an official certification issued by HHS. HHS specifically states that no certification demonstrates HIPAA compliance. Third-party assessments (SOC 2, HITRUST) can validate security controls that map to HIPAA requirements, but no single document is a HIPAA compliance certificate. Compliance is demonstrated through a documented ongoing program.
How often should a HIPAA risk analysis be updated?
HIPAA does not specify a fixed cadence but requires the risk analysis be updated 'as needed' — after significant changes in operations, technology, or threat landscape. Industry best practice is annual review with formal reassessment every two to three years. A risk analysis older than 24 months is a red flag; the underlying operations have almost certainly changed.
What should be in a HIPAA workforce training log?
The log should show: employee name, date of training, training content or module completed, delivery method (online, in-person), duration, and any post-training assessment score. Retention should be six years minimum. New employees should receive training within a reasonable period of hire (typically 30 to 60 days). Refresher training should occur annually.
What is a HIPAA incident response procedure and why does it matter?
The incident response procedure documents how the business associate detects, contains, investigates, and reports security incidents including PHI breaches. A compliant procedure names an incident response coordinator, specifies escalation paths, defines containment steps, and specifies covered-entity and regulator notification obligations with timelines. Absence of a documented procedure is a common finding in enforcement actions.