Security & HIPAA

Security and HIPAA: how we handle patient data

We sign a business associate agreement (BAA) with every client, our staff are HIPAA-trained, and we access only the patient information the work requires. We work inside your own EHR and clearinghouse, so your records stay in your systems.

  • BAA signed with every client
  • HIPAA-trained staff
  • Minimum-necessary access
  • We work inside your systems

The BAA

A business associate agreement with every client

We sign a BAA before we access any protected health information (PHI). No exceptions.

Under HIPAA, a billing company that handles PHI for a practice is a business associate. The BAA sets out how we may use and protect that information and what happens if something goes wrong.

We sign it at the start of every relationship, including before a free claims audit when the audit involves PHI.

How we work

Practices we follow every day

These are the rules our team works by. They describe how we work; they are not a third-party certification.

HIPAA-trained staff

Every team member who touches client work is trained on HIPAA privacy and security rules.

Minimum necessary

Staff get access only to the practices and data their work requires.

Your systems, not ours

We work inside your EHR and clearinghouse (SimplePractice, TherapyNotes, Tebra (Kareo), AdvancedMD, Valant and others), so records stay where you already keep them.

No PHI by plain email

We do not send patient information by regular email, and we ask clients not to either.

Sharing files

How to send us patient information

Use your EHR, your clearinghouse or another secure channel we agree on. Please do not send PHI by plain email or text.

  • Give us a user account in your EHR or clearinghouse, with only the permissions we need
  • Share reports through the secure messaging or file tools in your own systems
  • If you need another way to send files, ask us and we will agree on a secure method first
  • Use email only for questions that do not include patient details

Your part

Security is shared

You control access to your systems. A few habits keep that control strong.

  • Turn on multi-factor authentication in your EHR and clearinghouse where available
  • Review who has access to your systems from time to time
  • Give each person, including our team, a named login instead of a shared password
  • Remove accounts for staff and vendors who no longer need them, including ours if we stop working together
  • Tell us right away if you suspect a login has been misused

What we do not claim

Plain facts, no badges

We do not claim certifications we do not hold. What we offer is a signed BAA, trained staff and careful day-to-day practices.

There is no official “HIPAA certification” for companies. If you need specific security documentation for your own compliance program, ask us and we will tell you plainly what we can provide.

Before you hire any billing company, ask three questions: Will you sign a BAA? Who on your team will access our data, and where? How do you want us to send files? Clear answers to all three matter more than a logo on a website.

Common questions

Do you sign a BAA?

Yes. We sign a business associate agreement with every client before we access any protected health information.

Are your staff HIPAA-trained?

Yes. Every team member who works on client accounts is trained on HIPAA privacy and security rules.

Can I email you patient reports?

Please do not. Send PHI through your EHR, your clearinghouse or another secure channel we agree on. Plain email is fine for questions without patient details.

Do you store our patient records?

We work inside your own EHR and clearinghouse, so your records stay in your systems. We access only what the work requires.

Are you HIPAA certified?

No company can be officially “HIPAA certified”; no government certification exists. We sign a BAA, train our staff and follow minimum-necessary access.

Does offshore staff access our data?

Our team is a mix of US-based and offshore staff. Everyone who works on client accounts is HIPAA-trained, access follows the minimum-necessary rule, and our BAA covers the work.

Find out what your claims are leaving on the table

Tell us about your practice. We will review 90 days of claims and show you what is recoverable, at no cost.

Prefer to talk? +1 770-520-0840

Please do not include patient information.

We never share your information.