HIPAA-compliant medical billing & revenue cycle management
HomeServices SpecialtiesHIPAA & Security AboutTeamContact Free A/R review

HIPAA & Security

How we protect patient information

As a business associate under HIPAA and the HITECH Act, we're directly liable for how we handle your patients' protected health information. Here's exactly what that looks like in practice.

A stethoscope resting on a patient chart

Administrative safeguards

People and process

Business Associate Agreement

A signed BAA is executed before onboarding starts and before any PHI is transmitted. It defines permitted uses, breach-notification timelines, and what happens to your data when the relationship ends.

Workforce training

Everyone with PHI access completes HIPAA privacy and security training at hire and annually after. Training records are retained and available on request.

Minimum necessary

Staff get access only to the records required for their assigned accounts. Access is reviewed when roles change and revoked the day someone leaves.

Subcontractor control

Any vendor that could touch PHI signs a downstream BAA. We don't offshore PHI to a subcontractor without disclosing it to you in writing first.

Incident response

A documented plan covers containment, investigation, and notification. If a breach affects your patients, you hear it from us without undue delay and well inside the statutory window.

Sanctions policy

Policy violations carry defined consequences up to termination. Compliance isn't treated as a suggestion internally.

Technical & physical safeguards

Systems and premises

Encryption

PHI is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. PHI is never sent over unencrypted email or consumer messaging apps — we use secure portals or SFTP.

Access control & MFA

Unique credentials per user, multi-factor authentication on every system that stores or transmits PHI, automatic session timeout, and no shared logins.

Audit logging

System access is logged and retained. If you need to know who opened a record and when, that answer exists.

Endpoint security

Company-managed devices with full-disk encryption, endpoint protection, enforced patching, and remote wipe. No PHI on personal or unmanaged devices.

Physical security

Work areas are access-controlled with clean-desk and locked-storage requirements. Paper with PHI is cross-cut shredded; drives are wiped or destroyed to NIST 800-88 standards.

Backup & continuity

Encrypted backups with tested restoration and a written contingency plan, so a hardware failure never becomes a records-availability problem.

This website

What this site does and doesn't collect

Our contact form is for business inquiries only. It is not a channel for protected health information, and we ask you never to enter patient names, dates of birth, member IDs, diagnoses, or account numbers into it.

Site traffic is served over HTTPS. Once you're a client, all PHI moves through the secure channels defined in your BAA — never through this website and never through ordinary email.

Request our documentation

Practices and payers are welcome to request our BAA template, policy summary, and training attestations before signing anything.