Billing work involves names, dates of birth, diagnoses, insurance details, and payment information. The Health Insurance Portability and Accountability Act (HIPAA) sets rules for how this protected health information is used, shared, and secured. This article covers everyday habits, not legal advice.
Everyday habits that matter
- Share information only with people who need it to do their job, which is the minimum necessary standard
- Verify identity before discussing a balance by phone or email
- Never send protected health information through unencrypted personal email or messaging apps
- Lock screens when stepping away, and use unique logins rather than shared accounts
- Dispose of paper statements and printouts with a shredder or secure bin
Business associate agreements
When an outside company handles protected health information on your behalf, HIPAA generally requires a written business associate agreement. Check that one is in place before any data is shared, and keep a copy on file.
Know what to do after an incident
Every team should know who to notify when data may have been exposed, such as a misdirected statement or a lost laptop. Write the steps down, practice them, and involve your compliance advisor early, because timelines for reporting can be short.
Want a second opinion?
Bring us your denial and A/R reports.
We will review them with you and tell you which problems are process issues and which are one-off losses.
Book a free review