HIPAA & Security
How We Protect Patient Information
Remote billing deserves specific security answers, not badge graphics. This page documents our safeguards framework — and invites your compliance reviewer's scrutiny.
An honest note about “HIPAA certification”: HIPAA does not provide a government certification for billing companies — vendors displaying “HIPAA Certified” badges are displaying marketing, not credentials. What exists instead is compliance: safeguards implemented, documented, and contractually committed. That is what this page describes.
Our Safeguards Framework
The framework below reflects HIPAA-aligned administrative, physical, and technical safeguards as we implement them. Every item is intended to be verifiable in diligence — ask for the documentation.
Access controls and role-based access
Every team member accesses client systems through named individual accounts — never shared credentials — with permissions scoped to the billing functions their role requires under minimum-necessary principles.
Multi-factor authentication
MFA is required on our internal systems and used on client systems wherever the platform supports it; where a client platform lacks MFA, compensating controls are documented.
Client-authorized systems only
We work within systems the client authorizes, under the client’s user management, subject to each platform’s access and licensing requirements — your system’s audit logs record our activity alongside your own staff’s.
Minimum necessary access
Access requests specify the functions and data scopes each role needs; access beyond billing necessity is neither requested nor accepted.
Staff training
Team members complete privacy and security training at onboarding and on a recurring schedule, with training records maintained; role changes trigger access review.
Device security
Work is performed on managed devices under documented policies: disk encryption, screen locking, endpoint protection, and prohibition of PHI storage on local devices outside approved workflows.
Audit trails
Client-system activity is traceable through the platform’s native audit logging; our internal systems maintain their own access logs. We treat auditable work as a feature, not a burden.
Secure communication
PHI moves only through approved channels — client systems, encrypted transfer, secure messaging — never through ordinary email attachments or consumer file-sharing.
Business Associate Agreements
A BAA is executed with every client before any PHI access, and with any subcontractor or vendor whose services touch PHI — the agreement chain is complete or the work does not start.
Vendor management
Vendors with PHI access are inventoried, contracted under BAAs, and reviewed; vendors without a business need for PHI do not receive it.
Incident response
A documented incident response process covers detection, containment, assessment, client notification, and remediation — with client notification obligations honored per the BAA and applicable law.
Data retention
Records are retained per client agreements and applicable requirements, and returned or destroyed at engagement end per the BAA’s terms — your data remains yours throughout.
Secure onboarding and offboarding
Access is provisioned through a documented checklist at engagement start and revoked through the same discipline at role changes and engagement end — orphaned accounts are a failure mode we design against.
Workforce location and disclosure
Where any work is performed outside the United States, that fact, the functions involved, and the governing controls are disclosed contractually before engagement — clients with US-only requirements should state them at scoping, and we will scope accordingly or decline honestly.
For Your Compliance Reviewer
We welcome security diligence and answer it specifically: access architecture, BAA templates, training records structure, device policy summaries, and incident response outlines are available to prospective clients under appropriate confidentiality. If your organization runs vendor security assessments, send the questionnaire — a billing partner that resists security scrutiny is answering your real question.
Owner review notice: statements on this page describe our intended and contractually committed safeguards framework. Before relying on any specific control for your own compliance obligations, verify current implementation details during scoping — we will document them in the agreement rather than leave them as website prose.
Bring your hardest security questions
Scoping conversations include security architecture on request — with documentation, not slogans.