
A medical billing company that handles claims submission, payment posting, or coding on your behalf must meet the same medical billing company HIPAA compliance requirements as any other HIPAA business associate, not as a covered entity. Under 45 CFR 160.103, a business associate is any person or entity that creates, receives, maintains, or transmits protected health information (PHI), individually identifiable health data such as diagnosis codes, claim details, and insurance information, on behalf of a covered entity. Medical billing companies meet that definition every time they process a claim.
That status means the vendor must sign a Business Associate Agreement (BAA) with your practice and implement HIPAA Security Rule safeguards. If a billing vendor cannot produce a signed BAA, a written security policy, and evidence of workforce training, your practice, the covered entity, carries the compliance and breach notification exposure, not just the vendor.
Quick Answer
A medical billing company is a HIPAA business associate, not a covered entity, so it must sign a Business Associate Agreement (BAA) with each practice it serves and implement the HIPAA Security Rule's administrative, physical, and technical safeguards. It must also report security incidents and breaches involving PHI and limit PHI use to the services the BAA defines. Outsourcing billing does not transfer your practice's compliance obligation. Your practice remains responsible for confirming a HIPAA compliant billing company actually meets these requirements, not just that it signed a contract.
Why the BAA Is Non-Negotiable
The BAA is the contract that makes a billing vendor's obligations enforceable under the HIPAA Security Rule, codified at 45 CFR Part 164, Subpart C. It spells out how the vendor may use and disclose PHI, what safeguards it must maintain, and how quickly it must notify you if something goes wrong. Without a signed BAA, you have no documented commitment that the vendor will protect patient data or return or destroy PHI when the relationship ends. Specific contract language, including subcontractor obligations and indemnification terms, is a legal matter your attorney should review before you sign.
The Three Required HIPAA Safeguard Categories
Administrative safeguards
Written security policies, a designated security official, documented workforce HIPAA training, and a risk analysis covering every system that touches billing data.
Physical safeguards
Controlled access to offices and data centers, workstation security rules, and documented procedures for disposing of devices or paper records containing PHI.
Technical safeguards
Access controls tied to individual user accounts, audit logging, encryption for PHI at rest and in transit, and multi-factor authentication on any system that touches claims data.
What Your Practice Must Verify Before Outsourcing Billing
A signed BAA is the starting point, not the finish line. The HIPAA Security Rule expects covered entities to exercise reasonable diligence over the business associates they choose, which means reviewing how the billing company secures its own systems rather than accepting a signature on a contract. Practices across specialties, including urgent care clinics, outsource billing and take on this same oversight obligation, whether they run a single office or multiple locations.
This is the same vendor-vetting exercise practices go through with other business associates. A chiropractic office outsourcing billing runs through a comparable checklist to the one covered in HIPAA compliance for chiropractors, and a practice adopting telehealth tools faces a similar decision when vetting HIPAA compliant video conferencing platforms. In both cases, the underlying question comes back to the security fundamentals the Security Rule's technical safeguards are built around, confidentiality, integrity, and availability of PHI, summarized in the CIA triad.
If the billing company sends claim status updates or patient statements by email, confirm those messages use encrypted email built for healthcare rather than standard, unencrypted email, a common and easily overlooked gap.
Vendor Due Diligence Checklist
- Get a signed BAA before any PHI is transmitted to the billing company
- Request the vendor's most recent HIPAA risk analysis or security assessment summary
- Confirm PHI is encrypted in transit and at rest on the vendor's systems
- Ask how the vendor authenticates staff access (individual logins, MFA, role-based permissions)
- Confirm workforce HIPAA training is documented and refreshed annually
- Get the vendor's breach notification timeline and process in writing
- Confirm data return or destruction procedures for when the contract ends
Breach Responsibility Doesn't Disappear
If your billing company has a security incident involving your patients' PHI, HIPAA still requires notification to affected individuals and, in many cases, to HHS. Your practice's name is what patients associate with the incident, regardless of whose systems were affected. A strong BAA should specify how quickly the vendor must notify you so you can meet your own notification deadlines.
Questions to Ask Before You Sign
A short set of direct questions during vendor evaluation tells you how seriously a billing company treats security. Ask how it handles a lost or stolen employee laptop, whether it subcontracts any billing functions to a fourth party (which would require its own BAA), and how it would walk you through its incident response process if something went wrong. A vendor with a mature security program answers these specifically; one that responds with vague reassurance is worth a second look before you hand over patient data. The NIST SP 800-66 guide for implementing the HIPAA Security Rule gives smaller billing companies a practical framework for building these controls, and it's a fair benchmark to ask a vendor whether it follows.
The HIPAA rules for medical billing apply regardless of a vendor's size. A small, local billing company has to implement the same safeguard categories as a large national one. It can scale how it implements controls, but it cannot skip a required category.
Schedule Your HIPAA Endpoint Review
See where your practice's own endpoint, access, and email controls stand before you extend that same scrutiny to a billing vendor or any other business associate.
Frequently Asked Questions
No. A BAA is a contractual commitment, not proof of compliance. The billing company still has to implement the required administrative, physical, and technical safeguards; the BAA documents that it agreed to.
Both parties can face liability. HHS Office for Civil Rights can investigate the business associate directly, but your practice, as the covered entity, is still expected to show it exercised reasonable oversight in choosing and managing that vendor. This is a legal determination that depends on the facts, so consult counsel if a breach occurs.
Yes. HIPAA Security Rule requirements apply based on whether an entity handles PHI, not its size. Smaller billing companies can scale how they implement controls, but they cannot skip required safeguard categories.
At minimum, permitted uses of PHI, required safeguards, breach notification timelines, subcontractor obligations, and data return or destruction terms at contract end. Specific language should be reviewed by your attorney.
From requirement to defensible practice
Turn HIPAA requirements into safeguards that fit patient care
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring HIPAA security
Connect HIPAA requirements to the safeguards, assessments, and everyday decisions a healthcare practice can actually implement.
- Common question: HIPAA cybersecurity requirementsUse the plain-language HIPAA guideUnderstand administrative, physical, and technical safeguards without sorting through legal language.
- Common question: HIPAA security risk assessmentPrepare for a HIPAA risk assessmentIdentify vulnerabilities, document risk, and prioritize the gaps that matter most.
- Common question: HIPAA Security Rule explainedReview the HIPAA Security RuleSee how the standards and implementation specifications fit together.
- Common question: healthcare ransomware protectionReduce healthcare ransomware riskProtect patient data and keep clinical operations recoverable after an attack.
- Common question: HIPAA endpoint securityProtect practice workstations and devicesApply managed endpoint detection to the devices that access protected health information.



