Help Center · 7 answers
HIPAA Compliance & Data Security
How MedPrecision Billing handles BAAs, PHI, breach notification, encryption, employee training, and ongoing security audits.
What this topic covers
How MedPrecision Billing handles BAAs, PHI, breach notification, encryption, employee training, and ongoing security audits.
- Does MedPrecision Billing sign a HIPAA Business Associate Agreement?
- How does MedPrecision protect Protected Health Information (PHI)?
- What is MedPrecision's breach notification process?
- Is MedPrecision SOC 2 Type II certified?
All Answers
Every question in hipaa compliance & data security
Does MedPrecision Billing sign a HIPAA Business Associate Agreement?
Yes. A Business Associate Agreement under HIPAA 45 CFR 164.504(e) is signed before any Protected Health Information (PHI) exchange occurs, including before access credentials are issued for the practice EHR or PM system. The BAA carries the provisions 45 CFR 164.504(e)(2) requires of a business associate contract, rule text checked 17 September 2026: the permitted and required uses and disclosures; the obligation to use appropriate safeguards and to comply with the Security Rule for electronic PHI; reporting to the covered entity any use or disclosure not provided for, including breaches under 45 CFR 164.410; flow-down of the same restrictions to any subcontractor; making PHI available for access, for amendment and for an accounting of disclosures; making internal practices, books and records available to the Secretary; return or destruction of PHI at termination where feasible; and the covered entity's right to terminate for a material breach. The rule states these as contract provisions rather than as a numbered checklist. The BAA explicitly limits PHI use to the minimum necessary for billing operations under 45 CFR 164.502(b). PHI access is restricted to US-based staff under signed individual confidentiality agreements. Hold that as a written term of your BAA rather than as a claim on a web page: ask for it and it goes in. The BAA template is available for legal review during the proposal stage and accommodates practice-specific addenda where state law adds requirements on top of HIPAA. Which of those apply to your practice, and how they read against an outsourced billing arrangement, depends on the states you operate in and is a question for your own counsel rather than one a help-center page can settle for every state.
How does MedPrecision protect Protected Health Information (PHI)?
PHI safeguards follow the HIPAA Security Rule under 45 CFR Part 164 Subpart C across three control families. Administrative safeguards include role-based access control with least-privilege provisioning, mandatory annual HIPAA training for all staff with billing access, documented sanction policies for violations, and a designated Privacy Officer per 45 CFR 164.530. Physical safeguards include facility access controls, workstation lock screens after 10 minutes of inactivity, and a clean-desk policy preventing PHI exposure. Technical safeguards include AES-256 encryption for PHI at rest, TLS 1.2 or higher for PHI in transit, multi-factor authentication on all systems handling PHI, audit logging on PHI access events, with the Security Rule documentation retained for six years as 45 CFR 164.316 requires, and quarterly access reviews. All PHI is processed inside a HIPAA-aligned production environment; no PHI flows through email, consumer messaging, or unencrypted file shares.
What is MedPrecision's breach notification process?
Breach response follows the timing 45 CFR 164.410 sets for a business associate: notification to the covered entity without unreasonable delay and in no case later than 60 calendar days after discovery (rule text checked 17 September 2026). Sixty days is the legal outer limit, not the plan; MedPrecision's own commitment is to reach the practice's Privacy Officer within 24 hours of detecting a suspected breach involving your PHI. The process runs in four stages: (1) containment, including credential rotation and isolation of affected systems; (2) assessment of scope, root cause and what PHI was exposed, using the risk assessment 45 CFR 164.402 requires, which presumes a breach unless a low probability of compromise can be demonstrated on at least four factors — the nature and extent of the PHI involved, who used or received it, whether it was actually acquired or viewed, and the extent to which the risk has been mitigated; (3) written notification to the practice with an incident report and a remediation plan; and (4) support for the notifications the covered entity itself owes to individuals, to HHS and, where the rule requires it, to the media, because under the Breach Notification Rule those obligations stay with the covered entity rather than transferring to its business associate. Insurance, including any cyber liability coverage, is evidenced in writing during contracting rather than asserted on this page.
Is MedPrecision SOC 2 Type II certified?
Ask us and we will tell you exactly what we hold, in writing, before any sales conversation. We are not publishing an attestation summary here while we cannot publish the artifact behind it — a security claim you cannot check is worth nothing to you, and you should apply that test to every vendor you are evaluating, including us. What we can state plainly today. We sign a HIPAA Business Associate Agreement, and the contracting entity on it is H Holdings Group LLC, trading as MedPrecision Billing — one entity, and the same name that appears on your service agreement, which is worth checking on any vendor's paperwork. We operate under the HIPAA Security Rule's administrative, physical and technical safeguards, including the risk analysis required by 45 CFR 164.308(a)(1)(ii)(A), and we work on least-privilege access with no shared logins. Keep one thing separate that procurement reviewers often merge. The cloud providers hosting production systems hold their own SOC 2 Type II attestations, described on our HIPAA compliance page. Those are assurances about vendor infrastructure, not about this company, and no billing vendor should let you read them as its own. Tell us what your security review needs and we will say what we can send, under what NDA and on what timeline — including where the answer is that we do not hold the document you are asking for.
How is PHI encrypted in transit and at rest?
Encryption follows NIST SP 800-111 (storage) and NIST SP 800-52 Rev 2 (transport) standards, exceeding HIPAA Security Rule encryption guidance under 45 CFR 164.312(a)(2)(iv) and 164.312(e)(2)(ii). Data at rest uses AES-256 encryption on all production databases, application servers, and backup volumes; encryption keys are held in a managed key service rather than in application code or configuration, and rotated on a documented schedule. If your security review requires a specific cryptographic-module validation, ask for the current certificate rather than a label: NIST's Cryptographic Module Validation Program stopped accepting new FIPS 140-2 submissions and moves FIPS 140-2 certificates to its historical list after 21 September 2026, which makes FIPS 140-3 the validation that carries weight from that date (CMVP program page checked 17 September 2026). Data in transit uses TLS 1.2 or higher for all external connections and mutual TLS for clearinghouse and EHR API connections; SSH connections use Ed25519 or RSA-4096 keys. Endpoints (laptops, workstations) use full-disk encryption (FileVault on macOS, BitLocker on Windows) and are managed through MDM with remote wipe capability. X12 837 claim files and 835 remittance files move under the trading-partner agreement with each clearinghouse or direct-submission payer, over whatever secured channel that partner supports — commonly AS2 with X.509 certificates, or SFTP. The method is set by the trading partner rather than chosen by us, and it is named in that agreement.
What HIPAA training do MedPrecision employees receive?
All employees with PHI access complete documented HIPAA training within 30 days of hire and annually thereafter, satisfying 45 CFR 164.530(b)(1) workforce training requirements. The curriculum covers six modules: Privacy Rule fundamentals (45 CFR Part 164 Subpart E), Security Rule controls (Subpart C), Breach Notification Rule (Subpart D), the minimum-necessary standard, role-based PHI access policies, and incident reporting procedures. Specialty roles receive additional training: billing staff complete a 4-hour module on payer-specific PHI handling, IT staff complete the HHS HIPAA Security Series modules covering technical safeguards, and the Privacy Officer maintains AAPC, AHIMA, or HCCA HIPAA-specialized certification. Training completion is documented per employee with quiz score (80 percent passing required), retained for 6 years per HIPAA documentation requirements. Sanction policy includes documented warnings, suspension, and termination paths for violations, applied uniformly under 45 CFR 164.530(e).
Does MedPrecision use offshore staff for billing work?
MedPrecision's billing operations team handling US claims is US-based: PHI access for charge entry, coding review, denial management, payer phone work and patient phone support is restricted to US employees under direct W-2 employment, with signed individual confidentiality agreements layered on top of the HIPAA BAA. Treat that as a contractual commitment to obtain in writing rather than a claim to accept on trust — ask for it as a term of your BAA and it goes in, which is also how you would enforce it. On the regulation itself: HIPAA does not prohibit offshore PHI access where the business associate contract flows down properly under 45 CFR 164.504(e). What varies is everything layered on top of it — some state requirements, some Medicaid program rules and many payer contracts attach their own conditions on where PHI may be accessed or stored, and those differ by state and by contract, so for a multi-state practice the answer depends on the specific rules that apply to it and on advice from its own counsel. The operational reasons we staff it this way are payer phone navigation and appeals work, which depend on fluency with US payer systems, and client preference expressed during evaluation. Non-PHI engineering, infrastructure and product work may involve contributors outside the US; production PHI does not leave the country.
Related Topics
Continue reading
Getting Started
Onboarding timelines, parallel billing, EHR integration, and what the first 30 to 90 days look like for practices switching to MedPrecision Billing.
Read topicEHR and Software Integrations
Supported EHR and practice management platforms, integration timelines, custom HL7 and FHIR builds, and how MedPrecision handles legacy system support.
Read topicPerformance, KPIs, and Benchmarks
Net collection rate, denial rate, days in A/R and clean claim rate: how each one is defined, which targets have a public source behind them, and which do not.
Read topicFree Billing Audit · No obligation
Still not sure how this would work for you?
Send us the specifics of your practice - specialty, provider count, current biller and what is not working - and we will answer against your situation rather than in general. Written findings in 3-5 business days.
Prefer to talk? Book a 15-minute callRequest received
A billing specialist will review your practice details and reach out within 1 business day. No confirmation email is sent — if you need to reach us sooner, call +1-872-297-2815.
Still have a question?
The MedPrecision operations team can answer your specific situation in one business day. Start with a free billing audit.
- No contract
- No setup fees
- Reply within 1 business day