← Back to Blog
Compliance9 min read

HIPAA Compliance in Medical Billing: What Every Practice Must Know in 2026

HIPAA violations in billing are more common than most practices realize — and the fines are real. Here's what the rules actually require, where billing operations most often fall short, and how to build a compliant workflow.

M
Medbillytics Team
July 2, 2024

HIPAA is one of those compliance areas where practices tend to feel more confident than the evidence supports. Most have done some training, have a Privacy Policy posted in the waiting room, and have signed a Business Associate Agreement or two. But when you look closely at how patient health information actually flows through a billing operation — from eligibility verification to claim submission to collections — the gaps tend to be specific, common, and expensive.

The Office for Civil Rights (OCR), which enforces HIPAA, has assessed more than $130 million in penalties since 2008. The fines range from $100 to $50,000 per violation, with annual caps up to $1.9 million per violation category. More importantly, the violations that get investigated are rarely the dramatic data breaches. They're the everyday workflow failures — an unencrypted email, an unsigned BAA, a staff member accessing records they had no reason to access.

Here's what HIPAA actually requires in a billing context, where practices most often fall short, and what a compliant billing workflow looks like.

What Counts as PHI in a Billing Operation

Protected Health Information (PHI) is any individually identifiable health information. In the billing context, that includes:

  • Patient name, address, date of birth, phone number
  • Social Security number
  • Insurance member ID and group number
  • Diagnosis codes (ICD-10) and procedure codes (CPT) linked to a specific patient
  • Dates of service
  • Payment history and account balances
  • Any information that could identify a patient and relates to their condition, care, or payment

This matters in practice because billing operations handle PHI constantly — in claim submissions, clearinghouse transmissions, ERA files, patient statements, and collection communications. Every one of those touchpoints is a potential compliance vulnerability.

The Three HIPAA Rules That Matter Most in Billing

The Privacy Rule

The Privacy Rule governs who can access, use, and disclose PHI. In billing, the key provisions are:

Treatment, payment, and healthcare operations (TPO) are permitted uses of PHI without patient authorization. Billing for services rendered falls under "payment" — you don't need a separate patient authorization to use their PHI to submit a claim. But "permitted" doesn't mean "unrestricted."

The Minimum Necessary Standard requires that any use or disclosure of PHI should involve only the minimum amount of information needed to accomplish the purpose. A billing specialist processing a claim doesn't need to read the clinical notes unless those notes are directly relevant to the claim. A collections vendor doesn't need the patient's full diagnosis history to collect a balance.

Business Associate Agreements (BAAs) are required with any third party that accesses PHI on the practice's behalf. This includes billing companies, clearinghouses, coding services, practice management software vendors, cloud storage providers, and collection agencies. A BAA is not optional — it is a legal requirement. Operating without one creates liability for both parties.

The Security Rule

The Security Rule governs electronic PHI (ePHI) — any PHI that's stored, transmitted, or processed electronically. In a billing operation, virtually all PHI is electronic. The Security Rule requires:

Access controls: Only authorized users should be able to access ePHI. In practice, this means role-based access in your billing platform — a front desk scheduler doesn't need the same system access as a billing specialist, and neither should have access to information beyond their function.

Audit logs: Your billing system should maintain a log of who accessed what data and when. This is critical for both internal compliance monitoring and responding to OCR investigations.

Encryption: ePHI transmitted outside your practice's internal network — claim files sent to a clearinghouse, ERAs received from payers, patient data sent to a billing company — should be encrypted in transit and at rest. Unencrypted email containing PHI is one of the most commonly cited HIPAA violations in billing.

Risk assessments: The Security Rule requires regular, documented risk assessments identifying where ePHI is created, received, maintained, or transmitted, and what threats exist. "We've never had a breach" is not a substitute for a documented risk assessment.

The Breach Notification Rule

If unsecured PHI is accessed, used, or disclosed in a way that's not permitted under the Privacy Rule, the practice is required to notify affected individuals within 60 days of discovery. Breaches affecting 500 or more individuals in a single state must also be reported to the OCR and media outlets in that state.

In a billing context, breach scenarios include a misdirected claim (faxed to the wrong provider), an email containing PHI sent to the wrong patient, a stolen laptop with unencrypted billing data, or a billing vendor's data breach.

The Billing Workflows Most Likely to Create HIPAA Violations

Unencrypted email. Billing operations routinely send PHI via email — sending claims to a billing company, sending ERAs back to the practice, communicating about specific patient accounts. Standard email is not secure and is not compliant for PHI transmission. The fix is encrypted email (services like ProtonMail or Paubox) or a secure messaging platform.

Missing or outdated Business Associate Agreements. Every vendor who touches PHI needs a BAA in place before they access a single patient record. Practices frequently sign BAAs when onboarding a new vendor and then never update them when the vendor's services or ownership changes. Review your BAAs annually.

Inadequate access controls. In small practices, everyone often has access to everything because it's "easier." From a HIPAA perspective, broader access than necessary is a violation waiting to happen. Implement role-based access in your practice management system and audit who has access to what on a quarterly basis.

Fax errors. Medical billing still uses fax extensively — sending records to payers, receiving prior authorization determinations, communicating with other providers. A fax sent to the wrong number is a HIPAA breach. Verify fax numbers before sending and use a fax cover sheet with a confidentiality notice. Consider HIPAA-compliant electronic fax services that log transmissions.

Patient statement errors. A patient statement sent to the wrong address is a HIPAA breach. Verify patient address information at every visit. Implement a return mail process so misdelivered statements are caught quickly.

Staff accessing records outside their role. An employee who looks up a neighbor's account, a celebrity patient's records, or a coworker's claims out of curiosity is a HIPAA violation — regardless of whether the information is shared further. This type of insider access violation is among the most reported and hardest to prevent without proper access controls and audit log monitoring.

Building a HIPAA-Compliant Billing Workflow

Compliance isn't built through a single annual training. It's built through workflow design — processes that make the compliant path the easy path.

Step 1: Audit your BAAs. Make a complete list of every vendor, software platform, and third party that handles PHI in your billing operation. Confirm a current, signed BAA is in place with each one. This is the single highest-impact step most practices can take.

Step 2: Implement encrypted communication. Move PHI transmission off standard email. Whether you use a HIPAA-compliant email platform or a secure file transfer system, the transmission method matters.

Step 3: Tighten access controls. Map who in your organization has access to billing data and clinical data. Revoke access that exceeds what's needed for each role. Update access immediately when staff transitions occur.

Step 4: Conduct and document a risk assessment. Document where PHI lives in your systems, who can access it, what the threats are, and what controls are in place. This doesn't need to be complicated — it needs to be documented and updated when your systems or workflows change.

Step 5: Train staff annually, specifically. General HIPAA training is better than nothing. But billing-specific HIPAA training — covering exactly the scenarios your billing team encounters — is meaningfully more effective. Train your billing staff on the specific risks in billing operations, not just general healthcare privacy principles.

Step 6: Create a breach response plan. Know in advance what you'll do if a breach occurs. Who gets notified? Who is responsible for the OCR report? Who communicates with affected patients? Having this documented before you need it makes a stressful situation significantly more manageable.


Questions about your practice's HIPAA compliance in billing? Talk to our team — we operate under BAA with every client and can walk you through what a compliant billing workflow looks like in practice.

Need help with your revenue cycle?

Get a free assessment from our team — we'll show you exactly where you're leaving money on the table.

Get a Free Assessment