HIPAA compliance

Compliance isn't an add-on. It's in everything we do.

We offer HIPAA compliance as a service in its own right. We also hold every other service we deliver to the same standard, because a revenue cycle partner handles your most sensitive data every day.

Built into every service

Your patient data stays in one locked room

Think of a locked operatory. The records stay in the room. Our team works inside it but carries nothing out.

BAA first

A business associate agreement is signed before any patient data moves, and every vendor we use signs one with us.

One locked workspace

All work happens in a single hardened, cloud-hosted workspace. Nothing sits on laptops or personal devices.

Nothing leaves

Remote access only. Downloading, copying and printing are disabled.

Only two doors open

Network access is limited to what the work needs: your systems, the clearinghouse and payers, and our internal procedures.

Every action recorded

Every login, change and AI request is logged and reviewed regularly.

Encrypted, with strong sign-in

Data encrypted at rest and in transit. Multi-factor sign-in, least-privilege roles, no shared accounts.

HIPAA compliance service

A compliance program that reflects how your practice really works

Checklists ask whether things are in place. We look at how your people, processes and systems actually work, and close the gaps before an auditor or a breach finds them.

  • Security risk analysis: the accurate, thorough assessment HIPAA requires, kept current as your practice changes
  • Policies and procedures: written for your practice, not copied from a template
  • Workforce training, with signed acknowledgments on file
  • Business associate management: who can touch your data, under which agreement
  • Incident response: a breach notification plan ready before you need it
  • Audit readiness: self-audit against the federal audit protocol, with evidence organized
  • Ongoing monitoring, so compliance doesn't decay between assessments

Billing compliance, too

Compliance in RCM also means billing honestly.

  • Every code supported by the documentation. No upcoding, no undercoding.
  • Errors are disclosed and corrected, then rebilled or refunded
  • Payer overpayments identified and refunded

We practise what we offer

We run our own security risk analysis, policies, training and audit-log review, to the same standard we apply for our clients. You'll get our security summary on request, before you sign.

Know where you stand

Start with a conversation about your current risk analysis and policies.

Book a discovery call