medoutbound · Editorial

Signal desk

What we’re watching in HealthTech procurement, EHR politics, and CMS rulemaking — filtered for operators.

Compliance

HIPAA Requirements for Medical Billing Companies

Medical billing companies are business associates under HIPAA and must sign a BAA, implement the Security Rule's administrative, physical, and technical safeguards, and report incidents to the covered entity.

By MedOutbound EditorialAug 29, 2026
Editorial
Compliance

Credentials Required for Medical Billing Companies

Medical billing companies need HIPAA compliance, individual coder certifications from AAPC or AHIMA, cyber-liability insurance, and often SOC 2 Type II or HITRUST for larger clients.

By MedOutbound EditorialAug 29, 2026
Editorial
Compliance

What Is a Business Associate Agreement in Medical Billing

A Business Associate Agreement is a HIPAA-required contract between a covered entity and any vendor that handles Protected Health Information, with elements specified at 45 CFR 164.504(e).

By MedOutbound EditorialAug 29, 2026
Editorial
Compliance

How to Verify a Medical Billing Company Is HIPAA Compliant

Verifying HIPAA compliance requires reviewing five documented items: the BAA, risk analysis executive summary, workforce training log, incident response procedure, and audit-log sample.

By MedOutbound EditorialAug 29, 2026
Editorial
Compliance

SOC 2 vs HITRUST for Medical Billing Companies

SOC 2 Type II is a general security attestation applicable across industries; HITRUST CSF is a healthcare-specific certification with more controls and rigor. Both validate different aspects of a medical billing vendor's security posture.

By MedOutbound EditorialAug 29, 2026
Editorial
Compliance

MAC Jurisdictions for Cardiology: LCD Basics

Cardiology LCDs vary by MAC. Learn who covers your state, how to find the current LCD, and which LCDs drive the most cardiology denials.

By MedOutbound EditorialAug 29, 2026
Editorial
Compliance

LCD Tracking for Cardiology: Update Workflow

Local Coverage Determinations update quarterly. Build a repeatable LCD tracking workflow that catches revisions before they trigger denials.

By MedOutbound EditorialAug 29, 2026
Editorial
Compliance

Prior Authorization for Cardiology: What to Capture

Prior auth failures produce full denials on services already performed. Build a repeatable workflow that captures the elements payers require.

By MedOutbound EditorialAug 29, 2026
Editorial
Compliance

Cardiology Billing Compliance: 2026 Audit Risks

OIG work plans, CMS TPE audits, and RAC reviews all target cardiology. See the highest-risk billing patterns and defensive documentation practices.

By MedOutbound EditorialAug 29, 2026
Editorial
Compliance

Insurance Required for Medical Billing Companies

Medical billing companies carry three insurance types: cyber-liability at $1M-$5M per incident, professional liability (E&O) for coding and billing errors, and general commercial liability.

By MedOutbound EditorialAug 29, 2026
Editorial