
Medical billing touches more protected health information than almost any other function in a practice. That makes it one of the highest-risk areas for HIPAA violations. Denied claims, unsecured servers, and OCR fines are all trending in the wrong direction: OCR received 663 large-breach reports in 2024 alone, affecting roughly 242.9 million individuals, with hacking incidents behind 81% of them.
Behavioral health and TMS practices face even sharper scrutiny, since psychiatric diagnosis codes and treatment notes carry extra sensitivity.
This guide breaks down what HIPAA compliance actually requires in medical billing: who must comply, the safeguards you need, the violations that trip up practices most often, what non-compliance costs, and how to vet a billing partner that won't put your practice at risk.
Key Takeaways
- Every billing touchpoint—from intake to payment posting—transmits PHI, so billing is a top HIPAA risk area
- Any third-party biller handling PHI is a Business Associate and needs a signed BAA before work begins
- HIPAA penalties run $145 to over $2.19M per year—even for unintentional violations
- Outdated code sets and shared logins rank among the most common, and most preventable, billing violations
- Vet billing partners for signed BAAs, certified coders, and U.S.-based operations
What Is HIPAA Compliance in Medical Billing?
Medical billing isn't a single transaction. It's a chain of steps, and each one carries protected health information:
- Patient registration and insurance intake
- Eligibility and benefits verification
- Medical coding
- Claims submission
- Claim tracking, denial review, and appeals
- Payment posting and remittance
HIPAA compliance means every link in that chain, whether handled in-house or by an outside vendor, must protect PHI according to federal rules governing electronic transactions, privacy, and security.
The HIPAA Rules That Govern Billing Transactions
Billing falls under several overlapping HIPAA rules:
- The Transaction Rule (Part 162): Requires standardized electronic formats for eligibility checks, authorization requests, claims, and remittances, such as ASC X12N 837 for claims or 270/271 for eligibility.
- The Privacy Rule: Governs how PHI is disclosed, whether spoken, written, or typed. It applies the minimum necessary standard to payment activities, meaning billers only share what's needed to process a claim.
- The Security Rule: Covers ePHI specifically, requiring administrative, physical, and technical safeguards that protect confidentiality, integrity, and availability.
- The Breach Notification Rule: Requires notifying affected individuals within 60 days of discovery. Some state laws set shorter deadlines, which can override HIPAA's federal timeline.
Where PHI Flows Through the Billing Lifecycle
PHI is exposed at every touchpoint:
- Intake: demographic and insurance details collected at registration
- Eligibility verification: coverage and benefits data shared with payers
- Coding: diagnosis and procedure codes tied to the patient's clinical record
- Claims submission: full claim data transmitted to payers or clearinghouses
- Denial review and appeals: clinical documentation often re-shared to support an appeal
- Payment posting: remittance data reconciled against patient accounts

Billing and revenue-cycle vendors have become frequent breach targets. In late 2023, RCM vendor Medusind discovered unauthorized access to its systems. The breach affected 701,475 individuals and exposed billing information, medical record numbers, and payment-account data, according to HIPAA Journal.
Choosing a billing vendor is as much a security decision as a financial one.
Who Is Required to Be HIPAA Compliant in Medical Billing?
HIPAA compliance obligations extend well beyond hospitals and doctors' offices.
Covered entities, meaning providers, health plans, and clearinghouses, are automatically bound by HIPAA. Staff performing in-house billing are covered under the entity's own compliance program; there's no separate agreement needed for employees.
Business associates follow a separate set of rules. Any third-party billing company, RCM vendor, or clearinghouse that handles PHI on a provider's behalf qualifies as a Business Associate (BA).
The U.S. Department of Health and Human Services specifically names claims processing, billing, and practice management as business associate functions.
That classification triggers a hard rule: no PHI can be disclosed to a BA until a signed Business Associate Agreement (BAA) is in place. No BAA, no data. Period.
One nuance practices often miss: even a covered entity can be a business associate of another covered entity.
A clearinghouse translating a nonstandard claim into a standard format for a provider is still acting as a BA in that transaction. It needs its own BAA, even though it's also a covered entity in its own right.
For practice owners, the takeaway is simple:
- In-house billing staff: covered under your existing compliance program
- Outsourced billing company: requires a signed BAA before any PHI changes hands
- Clearinghouses and sub-vendors: also require BAAs, regardless of their own covered-entity status
Key HIPAA Requirements & Safeguards for Compliant Medical Billing
Billing companies and in-house teams alike must build compliance around three categories of safeguards defined in HIPAA's Security Rule:
- Administrative safeguards: written policies, staff training, sanction policies for violations, and a documented risk analysis
- Physical safeguards: secure facilities, locked storage for records, and controls over which devices can access PHI
- Technical safeguards: encryption, access controls, audit logs, and automatic logoff on idle systems

Skipping any one of these categories leaves a gap that an auditor, or a hacker, will eventually find.
Business Associate Agreements and the Minimum Necessary Standard
A valid BAA has to spell out specifics, not vague promises. At minimum, it should stipulate:
- What uses and disclosures of PHI are permitted
- What safeguards the business associate must maintain
- How and when breaches must be reported back to the covered entity
If a BAA is missing a required element, or was never properly executed, any PHI disclosed under it counts as a HIPAA violation, regardless of intent.
The minimum necessary standard applies directly to daily billing communication. A biller working a denied claim only needs the diagnosis and procedure codes tied to that claim, not the patient's entire chart. The same logic applies to conversations with patients, providers, and payers: share only what is needed to resolve the specific claim, appeal, or coding question.
HIPAA-Approved Code Sets Used in Medical Billing
HIPAA's Transaction Rule mandates standardized code sets for billing transactions:
| Code Set | Used For |
|---|---|
| ICD-10-CM/PCS | Diagnoses and inpatient procedures |
| CPT/HCPCS | Outpatient procedures, services, and supplies |
Using outdated or mismatched codes doesn't just risk compliance issues. It triggers claim delays and rejections outright.
This is where certified coders earn their keep. Persistex's AAPC CPC-certified coders stay current on annual code updates, supporting a 99.2% coding accuracy rate and a 35% reduction in coding-related denials across its client base.
NPIs matter just as much as diagnosis and procedure codes. An incorrect or mismatched NPI on an eligibility check, authorization request, or claim can delay payment just as effectively as a wrong diagnosis code.
Common HIPAA Violations in Medical Billing (and How to Avoid Them)
Most billing-related HIPAA violations stem from everyday habits that slip past busy staff.
Everyday disclosure risks:
- Discussing patient balances or claim details within earshot of other patients or unauthorized staff
- Emailing claims data through personal or unsecured email accounts
- Losing an unencrypted laptop or phone containing claims data
- Sharing login credentials between billing staff to save time during high-volume periods
Any of these can trigger an OCR investigation. Impermissible disclosures and missing safeguards remain among the most frequently cited HIPAA complaint categories nationally.
Billing fraud that overlaps with compliance risk:
The OIG also scrutinizes coding practices that blur into fraud territory:
- Upcoding: billing for a more expensive service than what was actually performed
- Undercoding: deliberately billing a lower-level service, distorting utilization data and inviting payer audits
- Unbundling: separately billing components that should be billed under one combined code
- Falsifying records: altering documentation to justify a billed service

Incorrect coding practices also intersect with HIPAA documentation and safeguard requirements. Payers treat them as red flags worth investigating.
Prevention comes down to two habits:
- Ongoing staff training: not a one-time onboarding session, but recurring refreshers on PHI handling as claim volume grows
- Role-based access controls: limiting each staff member's system access to only what their specific job requires
A biller processing eligibility checks doesn't need a patient's full clinical history. Chart review for coding shouldn't require billing-system admin rights either. Tightening access by role closes off a large share of accidental-disclosure risk before it happens.
How Much Does HIPAA Compliance Cost, and What Are the Penalties for Non-Compliance?
Maintaining HIPAA compliance in-house is an ongoing commitment, not a one-time expense.
In-House Compliance Costs
Typical costs include:
- Staff training programs (initial and recurring)
- Secure IT infrastructure and encrypted billing software
- A designated security official and documented risk analysis
- Periodic compliance audits and policy updates
- Business Associate Agreement management for every vendor touching PHI
Outsourcing to a compliant billing partner shifts much of this burden. The vendor absorbs its own security infrastructure and staff training costs, while the practice still needs a signed BAA and basic oversight rather than a full internal compliance program.
Penalties for Non-Compliance
The penalties for getting it wrong are steep, and they scale with culpability:
| Culpability Tier | Per-Violation Minimum | Per-Violation Maximum | Annual Cap |
|---|---|---|---|
| No knowledge, reasonable diligence | $145 | $73,011 | $2,190,294 |
| Reasonable cause, no willful neglect | $1,461 | $73,011 | $2,190,294 |
| Willful neglect, corrected within 30 days | $14,602 | $73,011 | $2,190,294 |
| Willful neglect, not corrected | $73,011 | $2,190,294 | $2,190,294 |
Source: HHS 2025 inflation-adjusted penalty amounts
Even the lowest tier (no knowledge, with reasonable diligence) still carries real financial exposure. Accidental disclosures are not exempt from fines.
Beyond the fine itself, non-compliance costs practices in ways that don't show up on a single invoice:
- Reputational damage that follows a breach announcement
- Patient attrition after trust erodes following a public incident
- Legal exposure from state attorneys general or private lawsuits
- Corrective action plans that require years of OCR monitoring
Those indirect costs often outweigh the fine itself, especially for smaller practices operating on thin margins.
Choosing a HIPAA-Compliant Medical Billing Partner
Not every billing company that claims to be HIPAA compliant can back that claim up. Before signing on with any vendor, run through this checklist:
- Signed BAA: non-negotiable, before any PHI is shared
- Documented Security Rule safeguards: administrative, physical, and technical controls—not a website compliance badge
- Encrypted EHR/PM integrations: secure connections into systems like AdvancedMD, Kareo, athenahealth, DrChrono, or TherapyNotes
- U.S.-based operations: avoid offshore call centers handling PHI without direct oversight
- Certified staff: coders and billers holding CPC, CPB, RHIT, or CCS credentials
Certification matters more than it might seem. Coding accuracy directly affects both denial rates and compliance risk. A miscoded claim isn't just a revenue problem. It's a documentation and disclosure problem too.
Transparency is the other piece practices tend to overlook. A vendor offering real-time dashboards and audit trails lets you verify what's happening with your claims and your data, rather than trusting a black-box relationship where you only find out about a problem after it's already cost you money.
Persistex is built around this standard. The company is Massachusetts-based and 100% U.S.-based, with no offshore call centers touching patient data. Its coders and billers hold AAPC and AHIMA credentials, including CPC, CPB, RHIT, and CCS, and the company reports a 98% clean claim rate with 99.2% coding accuracy.
HIPAA compliance is built into every process rather than treated as a separate checklist. Integrations span AdvancedMD, Kareo, athenahealth, DrChrono, and TherapyNotes for behavioral health and general outpatient practices nationwide.
Practices that switch to a specialized, compliant partner often see the difference quickly. One multi-provider behavioral health clinic with a 35% denial rate across eight providers cut denials by 40%, adding $85,000 in monthly revenue and dropping average A/R to 22 days.

A solo psychiatry practice reported 28% higher collections and 15 hours per week returned to patient care instead of paperwork.
Stronger compliance and stronger cash flow move together. A vendor cutting corners on one is usually cutting corners on the other.
Frequently Asked Questions
How much does HIPAA compliance cost for medical billing?
Costs depend on whether billing stays in-house—training, encrypted software, audits, and a security official—or is outsourced. A compliant vendor usually lowers overhead by covering most infrastructure and training.
Who is required to be HIPAA-compliant in medical billing?
Covered entities, meaning providers, health plans, and clearinghouses, are automatically bound by HIPAA. Any third-party billing company or clearinghouse handling PHI on their behalf is a Business Associate and must operate under a signed BAA.
What are the HIPAA-approved code sets used in medical billing?
HIPAA's Transactions and Code Sets Rule requires ICD-10-CM/PCS for diagnoses and procedures and CPT/HCPCS for services and supplies. Claims also need a valid NPI for provider identification on eligibility checks, authorizations, and submissions.
Is medical billing outsourcing HIPAA compliant?
Yes—if a BAA is signed before any PHI is shared and the vendor maintains required administrative, physical, and technical safeguards. The risk is an unvetted vendor, not outsourcing itself.
What is a Business Associate Agreement (BAA) and why does it matter for billing?
A BAA is the legal contract required before PHI can go to a billing vendor. It sets permitted uses, safeguard duties, and breach-reporting rules; disclosures without one are HIPAA violations regardless of intent.
What happens if a medical billing company violates HIPAA?
Violations can trigger OCR fines, mandatory breach notifications, and multi-year corrective action plans. Both the billing company and the practice that hired it can face reputational damage and legal exposure.


