A medical billing company that handles patient claims, payment posting, or coding on your behalf must comply with HIPAA as a business associate, not as a covered entity. That means it needs a signed Business Associate Agreement (BAA) with your practice and must implement the same administrative, physical, and technical safeguards required under the HIPAA Security Rule. If a billing vendor cannot produce a BAA, a written security policy, and evidence of workforce training, your practice, the covered entity, carries the compliance and breach-notification exposure, not just the vendor.
Under HHS regulations at 45 CFR 160.103, a business associate is any person or entity that creates, receives, maintains, or transmits protected health information (PHI), individually identifiable health data such as claim details, diagnosis codes, and insurance information, on behalf of a covered entity. Medical billing companies fall squarely into that definition because they process PHI for claims submission and payment processing every day.
Quick Answer
A medical billing company is a HIPAA business associate and must sign a Business Associate Agreement with each covered entity it serves, implement HIPAA Security Rule safeguards (administrative, physical, and technical), report security incidents and breaches involving PHI, and limit PHI use to the services specified in the BAA. If you outsource billing, your practice remains legally responsible for confirming the vendor meets these requirements, the obligation does not transfer away simply because you signed a contract.
Why the BAA is non-negotiable
The Business Associate Agreement is the contract that makes a billing vendor's HIPAA obligations enforceable and spells out how it may use, disclose, and safeguard PHI. Without one, you have no documented commitment that the vendor will protect patient data, notify you of a breach, or return or destroy PHI when the relationship ends. Practices should use a business associate agreement template for healthcare vendors as a starting point and confirm the vendor's counsel has reviewed the final version, since specific contract language is a legal matter for your attorney.
The Security Rule at 45 CFR Part 164, Subpart C requires business associates to implement three categories of safeguards, and a billing company that can't describe its approach to all three is not compliance-ready.
The Three Required Safeguard Categories
Administrative safeguards
Written security policies, a designated security official, workforce HIPAA training, and a documented risk analysis covering the billing systems handling PHI.
Physical safeguards
Controlled access to offices and data centers, workstation security policies, and procedures for disposing of devices or paper records containing PHI.
Technical safeguards
Access controls tied to individual user accounts, audit logging, encryption for PHI at rest and in transit, and multi-factor authentication on systems that touch claims data.
What you're responsible for verifying
Signing a BAA is the starting point, not the finish line. Under the HIPAA Security Rule's requirements for third-party risk, covered entities are expected to exercise reasonable diligence over the business associates they choose. That means reviewing how the billing company secures its own systems, not just accepting a signature on a contract. This overlaps directly with how practices should approach electronic health records security and broader information security in healthcare, since billing platforms often integrate with or pull data from the same EHR.
If the billing company sends you claim status updates, remittance details, or patient statements by email, confirm those communications use HIPAA compliant email for healthcare providers rather than standard, unencrypted email, a common and easily overlooked gap. The same scrutiny applies to specialty practices; medical spas and aesthetics clinics evaluating outsourced billing should review the HIPAA compliance requirements for cosmetic medical spas and Botox/filler practices for a comparable vendor-vetting approach.
Vendor Due Diligence Checklist
- Get a signed BAA before any PHI is transmitted to the billing company
- Request the vendor's most recent HIPAA risk analysis or security assessment summary
- Confirm PHI is encrypted in transit and at rest on the vendor's systems
- Ask how the vendor authenticates staff access (individual logins, MFA, role-based permissions)
- Confirm workforce HIPAA training is documented and refreshed annually
- Get the vendor's breach notification timeline and process in writing
- Confirm data return or destruction procedures for when the contract ends
Breach responsibility doesn't disappear
If your billing company experiences a breach involving your patients' PHI, HIPAA still requires notification to affected individuals and, in many cases, to HHS, and your practice's name is the one patients will associate with the incident, regardless of whose systems failed. A strong BAA should specify how quickly the vendor must notify you so you can meet your own notification deadlines.
Questions to ask before you sign
Beyond the checklist, a short set of direct questions during vendor evaluation tells you a lot about how seriously a billing company treats security. Ask how they handle a lost or stolen employee laptop, whether they subcontract any billing functions to a fourth party (which would require its own BAA), and how they'd walk you through their incident response process if something went wrong. A vendor with a mature security program will answer these specifically; one that responds with vague reassurance is a warning sign worth taking seriously before you hand over patient data.
Following the NIST SP 800-66 guide for implementing the HIPAA Security Rule gives smaller billing companies a practical framework for building these controls even without a large compliance staff, and it's a fair benchmark to ask vendors whether they use.
Vetting a Medical Billing Vendor?
We help accounting, tax, and healthcare practices review business associate contracts and vendor security posture before they sign, and monitor endpoint and email security for practices that keep billing in-house.
Frequently Asked Questions
No. A BAA is a contractual commitment, not proof of compliance. The billing company still has to actually implement the required administrative, physical, and technical safeguards, the BAA just documents that it agreed to.
Both parties can face liability. HHS Office for Civil Rights can investigate the business associate directly, but your practice, as the covered entity, is still responsible for having exercised reasonable oversight in choosing and managing that vendor. This is a legal determination that depends on the facts, so consult counsel if a breach occurs.
Yes. HIPAA's Security Rule requirements apply based on whether an entity handles PHI, not its size. Smaller billing companies can scale how they implement controls, but they can't skip required safeguard categories.
At minimum, permitted uses of PHI, required safeguards, breach notification timelines, subcontractor obligations, and data return or destruction terms at contract end. Specific language should be reviewed by your attorney.
From requirement to defensible practice
Turn HIPAA requirements into safeguards that fit patient care
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring HIPAA security
Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.
- Common question: HIPAA cybersecurity requirementsUse the plain-language HIPAA guideUnderstand administrative, physical, and technical safeguards without sorting through legal language.
- Common question: HIPAA security risk assessmentPrepare for a HIPAA risk assessmentIdentify vulnerabilities, document risk, and prioritize the gaps that matter most.
- Common question: HIPAA Security Rule explainedReview the HIPAA Security RuleSee how the standards and implementation specifications fit together.
- Common question: healthcare ransomware protectionReduce healthcare ransomware riskProtect patient data and keep clinical operations recoverable after an attack.
- Common question: HIPAA endpoint securityProtect practice workstations and devicesApply managed endpoint detection to the devices that access protected health information.



