HIPAA Compliance for Medical Billing Companies: You Are a Business Associate, and OCR Can Fine You Directly

Practical guidance for healthcare teams and business associates

A medical billing company with fourteen physician clients has nine remote billers, an overflow coding subcontractor two time zones away, VPN logins into fourteen different EHRs, a clearinghouse account, and a shared drive of scanned explanation-of-benefits forms going back years. It has never seen a patient. It holds more complete records on those patients than several of its clients do.

The HHS Office for Civil Rights (OCR) does not treat that as a technicality. Its enforcement listing shows a $350,000 settlement with MedEvolve, an Arkansas business associate, following unlawful disclosure of protected health information on an unsecured server (May 2023); a settlement with the clearinghouse Inmediata Health Group over an impermissible disclosure (December 2024); a ransomware settlement with Doctors' Management Services (October 2023); and a $2.3 million settlement with a business associate over a breach affecting more than 6 million individuals (September 2020). In March 2026 OCR announced a settlement with MMG Fusion, LLC, a Maryland software company and business associate, after a December 2020 intrusion exposed the protected health information of approximately 15 million individuals; OCR found no accurate and thorough risk analysis and a failure to notify the affected covered entities, and imposed a $10,000 payment with a three-year corrective action plan after considering the company's financial condition.

This guide covers why a billing company is a business associate and what that carries, what protected health information looks like in revenue cycle work, the violations OCR keeps finding in this sector, how to build the program, and which of the company's own vendors need a Business Associate Agreement.

HIPAA Compliance for Medical Billing Companies: The Business Associate Rules

Why HIPAA Applies to a Billing Company

The definition at 45 CFR 160.103 settles the status. A business associate is a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance ... billing, benefit management, practice management, and repricing." Billing appears in the list by name. Claims processing appears first. A medical billing company is a business associate of every client it bills for, and the client is required by 164.502(e) and 164.308(b) to have a written B.A.A. (Business Associate Agreement) with it. The agreement itself is explained in the Business Associate Agreement guide.

Business associate status is not a lighter category. The Security Rule at 164.302 applies to business associates directly, every standard in 164.308 through 164.316 reads "a covered entity or business associate must," and the Breach Notification Rule at 164.410 imposes its own duty on the business associate. 160.402(a) states that the Secretary "will impose a civil money penalty upon a covered entity or business associate" that violates the rules. The MedEvolve and MMG Fusion actions were taken against the business associates, not their clients. Privacy Rule duties reach a business associate through the B.A.A.: under 164.502(a)(3), a business associate "may use or disclose protected health information only as permitted or required by its business associate contract or other arrangement," and under 164.504(e)(2)(ii)(H) it must comply with the Privacy Rule to the extent it carries out a client's obligation.

One wrinkle deserves a look. 160.103 defines a health care clearinghouse, which is a covered entity, as "a public or private entity, including a billing service, repricing company ... that ... processes or facilitates the processing of health information received from another entity in a nonstandard format or containing nonstandard data content into standard data elements or a standard transaction." A billing company that itself converts client charge data into standard claim transactions, rather than routing through a clearinghouse, may fit that definition and become a covered entity in its own right. Most billing companies do route through a clearinghouse and remain business associates. Which one a given company is deserves a documented answer, and counsel if the workflow is unusual.

What P.H.I. Looks Like in a Billing Company

P.H.I. (Protected Health Information) in revenue cycle work is not limited to account numbers. Diagnosis codes, procedure codes, and dates of service are health information tied to a name, and the appeals process pulls in the full chart.

  • Charge entry and encounter data. Superbills, ICD-10 diagnosis codes, CPT procedure codes, modifiers, and provider notes used to support the coding.
  • Claim and remittance files. Outbound 837 claim files, inbound 835 remittances and ERAs, EOBs, and the payer portal screenshots billers keep for proof.
  • Eligibility and authorization responses. Coverage details, deductible status, and prior authorization numbers.
  • Denial and appeal packets. Operative reports, progress notes, imaging reports, and letters of medical necessity: often the most detailed clinical records the billing company holds.
  • Patient statements and collections. Balances, payment plans, and the accounts sent to a collection agency.
  • Call recordings and notes. Recorded patient calls about balances and the AR follow-up notes that reference diagnoses.
  • Client reports. Spreadsheets emailed to practice managers with patient-level detail, and the historical exports on the shared drive.

The minimum necessary standard at 164.502(b) applies to business associates by its own terms: "a covered entity or business associate must make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose." A biller who needs the procedure code does not need the full chart in the inbox.

Common Violations in Billing Companies

Unsecured servers and file transfer. The MedEvolve settlement (unsecured server, May 2023) and a $75,000 settlement with iHealth Solutions over protected health information on an unsecured server (June 2023) describe the same failure: a server or file share reachable from the internet without authentication. Old FTP servers for EOB scans and client uploads are the classic example.

No risk analysis. OCR described the MMG Fusion action as its twelfth under the Risk Analysis Initiative. 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate." The last four words are the point: the obligation belongs to the business associate. The business-associate version of the process is in HIPAA risk assessments for business associates.

Subcontractors with no agreement. The overflow coding firm, the offshore data entry team, and the transcription vendor are each "a subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate," which 160.103 defines as a business associate too. 164.502(e)(1)(ii) requires the billing company to obtain "satisfactory assurances" from each subcontractor through a written agreement, and 164.314(a)(2)(i)(B) requires the same on the Security Rule side.

Remote billers on family computers. The workstation use and workstation security standards at 164.310(b) and (c) apply to a kitchen-table workstation exactly as they do to an office cubicle. The setup rules are in HIPAA remote work rules.

Late or missing breach notice to clients. 164.410(b) requires a business associate to notify the covered entity of a breach of unsecured P.H.I. "without unreasonable delay and in no case later than 60 calendar days after discovery." The clock starts on the first day the breach is known, or would have been known with reasonable diligence, to anyone at the company other than the person who caused it. MMG Fusion's failure to notify affected covered entities was one of OCR's findings.

Ransomware. The Doctors' Management Services settlement (October 2023) and OCR's eighth and ninth ransomware settlements, with Elgon Information Systems and Virtual Private Network Solutions (January 2025), are reminders that a company holding data for many clients is a more attractive target than any single client. The sector-wide lesson is in Change Healthcare breach: one year later.

Building the Program

Assign the security official. 164.308(a)(2) requires a named person responsible for the security policies. In a small billing company that is usually the owner, in writing.

Do the risk analysis and the risk management plan. The analysis under 164.308(a)(1)(ii)(A) has to cover the practice management platform, the clearinghouse connection, the shared drive, email, the remote workstations, and every client VPN. Risk management under 164.308(a)(1)(ii)(B) means fixing what the analysis found, in a dated plan.

Write the policies and keep them. 164.316 requires written policies and procedures, retained for six years from creation or last effective date, along with the records of every required action or assessment.

Train the billers. 164.308(a)(5) requires a security awareness and training program for the whole workforce, "including management." Phishing is a leading way billing companies get breached, and the training has to say so.

Build the incident and contingency procedures. 164.308(a)(6) requires procedures to identify, respond to, mitigate, and document security incidents. 164.308(a)(7) requires a data backup plan, disaster recovery plan, and emergency mode operation plan. When a billing company goes down, fourteen practices stop getting paid; the contingency plan is a client-retention document.

Track B.A.A.s in both directions. Upstream, every client must have signed one, and a billing company should refuse to start work without it. Downstream, every subcontractor must have signed one. The contract terms required by 164.504(e)(2) include returning or destroying P.H.I. at termination, making records available for patient access under 164.524, and reporting breaches. When a client leaves, the return-or-destroy clause has to actually be executed and documented.

Vendor and Subcontractor B.A.A. Checklist for Billing Companies

Vendor categoryTypical examplesB.A.A. required?
Practice management and RCM platform licensed by the billing companyTebra, AdvancedMD, athenahealthYes
ClearinghouseAvaility, Waystar, Change HealthcareYes. A clearinghouse is a covered entity, and 160.103 confirms "a covered entity may be a business associate of another covered entity."
Overflow or offshore coding and data entry firmsAny subcontracted coding or billing laborYes. Subcontractors are business associates under 160.103(3)(iii).
Patient statement printing and mailingAny print-and-mail vendorYes
Collection agencyAny agency receiving accountsYes, when engaged by the billing company on the client's behalf
Email and productivity suiteMicrosoft 365, Google WorkspaceYes. Setup details are in is Microsoft 365 HIPAA compliant.
Cloud storage and file transferAny shared drive or SFTP serviceYes
VoIP and call recordingAny phone platform storing recordingsYes
IT managed services, e-fax, shreddingThe MSP, the fax service, the document destruction vendorYes
PayersHealth plans receiving claimsNo. The payer receives P.H.I. for payment as a covered entity in its own right, not on the billing company's behalf.
Client practicesThe covered entities the company bills forYes, in the other direction. The client signs a B.A.A. with the billing company before any P.H.I. is shared.

The Proposed Security Rule Update (Proposed, Not Final)

HHS published a Notice of Proposed Rulemaking on January 6, 2025 that would apply to business associates and covered entities alike. It would make encryption and multifactor authentication required rather than addressable, require a written asset inventory and network map, require restoration of critical systems within 72 hours, and require vulnerability scans "at least once every six months" and penetration testing "at least once every 12 months." It is proposed, not final, and OCR is not enforcing it. The status is tracked in HIPAA Security Rule delayed to 2027. For a billing company, a network map that shows fourteen client VPN tunnels is a useful document today, whatever happens to the proposal.

---

FAQ

Is a medical billing company a covered entity or a business associate?

A business associate. 45 CFR 160.103 defines a business associate as a person who creates, receives, maintains, or transmits protected health information on a covered entity's behalf for functions including claims processing and billing. A billing company that itself converts client data into standard transactions may also meet the health care clearinghouse definition, which is a covered entity; that question deserves a documented answer.

Can OCR fine a billing company directly?

Yes. 45 CFR 160.402(a) provides for civil money penalties against a covered entity or business associate. The Security Rule and Breach Notification Rule apply to business associates directly, and OCR has settled with billing and revenue cycle business associates by name.

Does a billing company need BAAs with its own vendors?

Yes. Any subcontractor that creates, receives, maintains, or transmits protected health information on the billing company's behalf is itself a business associate under 160.103, and 164.502(e)(1)(ii) requires a written agreement with each one: coding firms, print-and-mail vendors, cloud storage, email, and IT support included.

What must a billing company do when it discovers a breach?

Notify each affected covered entity without unreasonable delay and no later than 60 calendar days after discovery, under 164.410(b), including the identity of each affected individual to the extent possible. The B.A.A. may set a shorter deadline. The covered entity then handles notice to individuals, HHS, and media.

Can medical billers work from home?

Yes, if the home workstation meets the same Security Rule standards as the office: a work-only device, encryption, screen lock, unique login, secured connection, and a written remote work policy. A family-shared computer does not qualify.

Conclusion

A billing company's HIPAA program is also its sales pitch: the risk analysis, the subcontractor B.A.A.s, and the breach procedure are what a careful practice asks to see before signing. One Guy Consulting's Full-Scope plan builds that program for business associates, from the risk analysis through the policy set, workforce training, and B.A.A. tracking in both directions. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading