
HIPAA Compliance in Medical Billing: What Every Practice Owner Must Understand in 2026
When practice owners think about HIPAA compliance, the focus often lands on the clinical side of operations: patient records, electronic health systems, staff training. But the billing and revenue cycle function of a medical practice carries its own distinct HIPAA obligations, and the relationship between a practice and its medical billing company is one of the most compliance-significant business arrangements a practice enters.
This guide covers what you need to understand about HIPAA as it applies specifically to medical billing, what obligations fall on your practice and on any billing vendor you work with, and what questions to ask before signing with a billing company.
The Business Associate Agreement: The Foundation of Billing Compliance
Under HIPAA, any vendor or contractor who receives, processes, stores, or transmits protected health information (PHI) on behalf of a covered entity, including a medical practice, must sign a Business Associate Agreement (BAA). A medical billing company is one of the clearest examples of a business associate: by definition, they receive patient names, dates of service, diagnosis codes, procedure codes, insurance information, and claim data in order to perform their services.
A BAA is not optional and it is not a formality. It is a legally required contract that specifies how the business associate may use PHI, what security standards they must maintain, how they must respond to a breach, and what happens to PHI if the business relationship ends. Operating with a billing company that has not signed a BAA is a HIPAA violation on the part of the practice, regardless of whether a breach actually occurs.
Before signing any billing services agreement, verify that a BAA is included or will be executed as a companion document. If a billing company is reluctant to sign a BAA or cannot produce their standard form, that is a significant compliance red flag.
Data Transmission Security
PHI transmitted between a practice and its billing company, claim data, patient records, remittance information, must be secured in compliance with the HIPAA Security Rule. This means:
- Electronic transmission must be encrypted; unencrypted email is not a compliant method for transmitting PHI.
- Secure file transfer or a HIPAA-compliant billing platform should be used for any data exchange.
- Access to PHI must be limited to individuals who need it to perform their role, with audit logging of who accessed what and when.
- Any third-party systems or clearinghouses used in the claim submission process must also be HIPAA-compliant, with BAAs in place.
Breach Notification Obligations
If a security breach occurs that involves PHI, whether on the billing company’s side or the practice’s side, HIPAA’s Breach Notification Rule applies. The covered entity (the practice) is ultimately responsible for notifying affected individuals within 60 days of discovering the breach, notifying the Department of Health and Human Services, and in cases involving more than 500 individuals in a state, notifying prominent media outlets in that state.
Your BAA with your billing company should specify their obligation to notify you of any breach within a defined timeframe, typically without unreasonable delay and within 60 days of discovery. Confirm that your billing company has incident response procedures in place and that they carry appropriate cyber liability insurance.

Minimum Necessary Standard
HIPAA’s minimum necessary standard requires that access to PHI be limited to the minimum amount of information necessary to accomplish the intended purpose. For billing, this means a billing company should not be receiving or storing information about patients that is not relevant to the billing function. Review what data your billing company collects, how long they retain it, and what their data destruction policy is when the business relationship ends.
Questions to Ask Any Billing Company Before Signing
- Will you sign a Business Associate Agreement, and can I see your standard form before we proceed?
- How is PHI transmitted between your systems and ours, and what encryption standards do you use?
- What is your breach notification procedure, and what is your typical timeline for notifying clients?
- Do you carry cyber liability insurance, and what are the coverage limits?
- What access controls and audit logging do you have in place for PHI?
- What is your data retention and destruction policy after the service agreement ends?
- Are all clearinghouses and third-party platforms you use in the claim submission process covered by BAAs?
A reputable billing company should be able to answer all of these questions clearly and without hesitation. Vague answers or resistance to providing documentation are warning signs that deserve follow-up before any PHI changes hands.
ProCareMedex operates under a full HIPAA compliance framework, including signed BAAs with every client and rigorous data security standards. We are happy to walk through our compliance documentation with any practice we are speaking with. Contact us to learn more.