HIPAA Compliant Billing Services for Healthcare Practices
Maximum Billing, LLC provides HIPAA compliant billing services for medical, behavioral health and dental practices. Every claim we touch carries protected health information, and the handling of that information is not a feature we added on top of the billing work — it is how the billing work is built.
HIPAA compliant medical billing is not a separate service from medical billing done properly. It is the same work with the handling written down, the access controlled, and the agreement signed before anything moves.
We have specialized in mental health and dental billing since 2018, backed by more than 20 years in insurance billing and revenue management. We are based in Fort Myers, Florida, and bill for practices in Florida, Texas and elsewhere.
What We Handle
- A signed Business Associate Agreement in place before we touch a single claim
- Claims, eligibility and remittance handled inside your system rather than copied out of it
- Access limited to the staff actually assigned to your account
- Encrypted transmission and storage of anything carrying protected health information
- Secure handling of records requests, appeals and payer correspondence
- Documented procedures for the situations that create most exposure
- Substance use records handled under 42 CFR Part 2, not just HIPAA
- Breach response procedures that exist before they are needed
What HIPAA Actually Requires of a Billing Company
A billing company is a business associate under HIPAA. That is a defined role with defined obligations, not a courtesy title. It means the billing company is directly liable for its own compliance, and the practice remains liable for choosing it.
Three rules do the work. The Privacy Rule governs what may be used and disclosed, and holds everyone to the minimum necessary standard — the least information needed to do the job. The Security Rule requires administrative, physical and technical safeguards over electronic protected health information: risk analysis, workforce training, access controls, encryption, audit logging. The Breach Notification Rule governs what happens when something goes wrong, and it runs on deadlines.
A billing company that cannot describe how it satisfies each of the three in its own workflow is telling you something, whether it means to or not.
It is worth knowing that there is no official HIPAA certification. No government body certifies a vendor as compliant, so any badge to that effect was issued by a private company that was paid to issue it. Medical billing HIPAA compliance is not a certificate you can be shown; it is a set of practices a company either follows every day or does not. Ask to see the BAA and the access list instead of a logo.
The Business Associate Agreement Is Not a Formality
The BAA is the contract that makes the arrangement lawful. Without one in place, disclosing protected health information to a billing company is itself a violation — before anything has actually gone wrong.
A real BAA says what the billing company may do with the information, requires it to safeguard that information, obligates it to report breaches to you, extends the same obligations to any subcontractor it uses, and says what happens to your data when the relationship ends. If a prospective billing partner treats the BAA as paperwork to be signed without reading, assume the rest of their compliance is handled the same way.
We sign a BAA before onboarding begins, not after the first claim goes out.
Protected Health Information in a Billing Workflow
People tend to picture protected health information as the clinical note. In billing it is broader and more mundane, which is exactly why it leaks.
- Names, addresses, dates of birth and Social Security numbers on intake forms
- Insurance member IDs, group numbers and eligibility responses
- Diagnosis codes on every claim — in behavioral health, the diagnosis is the sensitive part
- CPT and CDT codes, which describe what was done and how long it took
- Explanation of benefits documents and remittance advice
- Appeal letters, which often contain the most clinical detail of anything in the cycle
- Aging reports and spreadsheets, which quietly accumulate all of the above
How We Handle It
We work inside your practice management system or EHR wherever possible, so the information stays where it already lives instead of being copied into a second system that also has to be secured. Access is limited to the people assigned to your account, and it is removed when they are no longer on it.
Anything that has to move is encrypted in transit and at rest. We do not send protected health information over unencrypted email, and we do not text it. Records requests and appeals go through secure channels. Where a payer still insists on fax, it is handled as a documented exception rather than a habit.
Where Practices Actually Get Exposed
In our experience the breaches that happen to small practices are rarely sophisticated. They are ordinary workflow, repeated until something goes wrong.
- Unencrypted email. A claim question forwarded to a personal address, or an EOB attached to an ordinary message thread.
- Texting. A front desk photographing an insurance card and sending it to a colleague.
- Spreadsheets. An aging report exported to a laptop and never deleted.
- Shared logins. One clearinghouse account used by the whole office, so no action can be traced to a person.
- Offboarding. A staff member leaves and their access to the EHR, the clearinghouse and the payer portals stays live for months.
- Subcontractors. A billing company quietly outsourcing work with no BAA in place downstream.
Most of these cost nothing to fix. They persist because nobody owns them.
Breach Notification and What It Costs
If protected health information is breached, the covered entity must notify affected individuals without unreasonable delay and no later than 60 days from discovery, notify the Department of Health and Human Services, and where a breach affects 500 or more residents of a state or jurisdiction, notify prominent media outlets serving that area. Smaller breaches are logged and reported annually.
The direct penalties are assessed by the Office for Civil Rights and scale with culpability, from unknowing violations up to willful neglect left uncorrected. For most small practices, though, the notification itself is the expensive part — telling several hundred patients that their diagnoses were exposed is not a cost that appears on any penalty schedule.
Your billing company is obligated to tell you when something happens on its side. That obligation is only as good as the company’s willingness to notice and report it.
Behavioral Health and 42 CFR Part 2
Practices treating substance use disorder are subject to a second regime that is stricter than HIPAA. 42 CFR Part 2 governs records from federally assisted substance use disorder programs, and it is built on patient consent rather than the broader permissions HIPAA allows for treatment, payment and operations.
In practice this means a Part 2 program cannot disclose records for billing the way a general medical practice can, consent requirements are specific and documented, and redisclosure is restricted even after information has been lawfully shared. Recent rulemaking has aligned parts of the two regimes, but the differences that matter for billing remain.
A billing company that treats a substance use program like any other behavioral health client is creating exposure the practice will own. We bill for behavioral health practices as our primary specialty, including programs subject to Part 2, and we handle those records under the stricter rule. See our behavioral health and psychiatric billing services.
HIPAA for Dental Practices
Dental practices are covered entities like any other, and dental billing carries its own exposure. Radiographs, intraoral photographs and perio charting routinely travel as claim attachments, and narratives written for a payer can contain far more clinical detail than the claim form requires.
The minimum necessary standard applies here too: send what substantiates the claim, not the entire record because it was easier to attach. See our dental billing services.
What to Ask a HIPAA Compliant Billing Company
If you are comparing HIPAA compliant billing companies, these questions separate them faster than a capabilities list.
- Will you sign a BAA before onboarding, and may I read it first?
- Who specifically will have access to our data, and how is that access removed?
- Do you subcontract any part of this work, and is there a BAA with those subcontractors?
- How is protected health information transmitted, and what happens when a payer only accepts fax?
- When did you last perform a security risk analysis?
- What is your breach notification procedure, and how quickly would we hear from you?
- What happens to our data if we leave?
Frequently Asked Questions
Is a billing company a business associate under HIPAA?
Yes. A billing company handles protected health information on behalf of a covered entity, which makes it a business associate with direct obligations under the Privacy, Security and Breach Notification Rules — and a BAA is required before any information changes hands.
Do we need a BAA even for a small practice?
Yes. The requirement is based on the relationship, not the size of the practice. A solo therapist needs the same agreement a hospital does.
Can you work inside our EHR?
Usually, yes — SimplePractice, TherapyNotes, Dentrix, Eaglesoft, Open Dental, Kareo and others. Working in your system rather than exporting data out of it is the more secure arrangement, and we prefer it.
How do you send us documents?
Through secure channels. We do not send protected health information by unencrypted email or text message, and we will not ask you to.
Do you handle substance use disorder records?
Yes, under 42 CFR Part 2 rather than HIPAA alone. Consent and redisclosure rules are stricter for these records, and they are handled as a separate workflow.
What happens to our data if we stop working together?
It is returned or destroyed according to the terms of the BAA, and access is revoked. This should be written down before you start, not negotiated at the end.
If you are not certain whether your current billing arrangement is HIPAA compliant, the BAA and the access list are the two places to look first. Contact Maximum Billing, LLC or call 800-820-0364. See also our medical billing services for Florida practices.