What is HIPAA Compliance, And How Does It Work in Medical Billing?

Understand HIPAA compliance in medical billing, including PHI protection, Privacy and Security Rules, compliance requirements, common violations, penalties, and best practices for healthcare providers.

Ricky Bell

Published

July 14, 2026

Read Time

16 min read

HIPAA Compliance

HIPAA compliance governs every claim, patient record, and data transfer in a healthcare practice, yet many providers still treat it as a secondary obligation rather than an operational requirement embedded in daily workflows. This guide defines HIPAA compliance for medical billing, outlines how the rules apply operationally, and explains how Dastify Solutions administers compliance across client revenue cycles.

What is HIPAA Compliance?

HIPAA compliance refers to being in line with the Health Insurance Portability and Accountability Act of 1996 – a federal law that was put in place to safeguard health information and establish some basic standards for how that information gets used. In practical terms, HIPAA compliance governs how patient data – including medical records, billing details and insurance information – gets created, stored, shared and protected.

Compliance obligations apply to covered entities (healthcare providers, health plans, and healthcare clearinghouses) and to their business associates, including outsourced billing companies such as Dastify Solutions. HIPAA compliance is a federal legal requirement for any U.S. healthcare organization or vendor that handles PHI. 

If you’ve been searching for “HIPPA Compliant” or “HIPPA Compliance”, you’re looking for the exact same thing – just spelled slightly wrong. HIPAA is frequently misspelled, but the underlying regulatory requirements remain identical.

Background: How HIPAA Came To Be

In August 1996, Congress enacted the Health Insurance Portability and Accountability Act to address three objectives: preserving health insurance coverage during employment transitions, reducing healthcare fraud and abuse, and standardizing the secure exchange of health information between providers, payers, and vendors.

The portability provisions preserved health insurance protections during employer or plan changes, which required standardized, secure electronic transactions between HMOs, insurers, and providers. 

HIPAA has been implemented through a series of rules issued by the U.S. Department of Health and Human Services, beginning in 2000 and extending through the 2013 Omnibus Rule and subsequent amendments. HIPAA compliance protects patient privacy and enforces cybersecurity standards across all healthcare operations.

For medical billing and revenue cycle management, the core HIPAA components include the Privacy Rule, data security requirements, standardized electronic claims formats (such as the 837 and 835 transactions), and mandatory breach notification obligations.

How HIPAA Came To Be

Key HIPAA Terms: PHI, ePHI, Covered Entities, Business Associates

Before examining HIPAA compliance requirements in detail, the following core definitions apply.

Protected Health Information (PHI) refers to any individually identifiable health information, including diagnoses, treatment notes, lab results, claim forms, insurance member IDs, addresses, and dates of birth. Any health data that can identify an individual qualifies as PHI under HIPAA. 

Electronic Protected Health Information (ePHI) is PHI in electronic form, stored or transmitted through electronic health records, billing software, clearinghouses, email, cloud storage, or AI-driven workflows.

Covered entities are:

  • Healthcare providers that transmit health information electronically, including physician groups, mental health clinics, ambulatory surgery centers, and laboratories.
  • Health plans, including commercial insurers, HMOs, Medicare, Medicaid, group health plans, and Medicare supplement insurers.
  • Healthcare clearinghouses that process claims data

Business Associates are organizations or individuals that handle PHI on behalf of covered entities. This category includes billing companies such as Dastify Solutions, IT vendors, cloud hosting providers, EHR vendors, and accounting firms that access PHI. Under HIPAA, covered entities and business associates share direct compliance liability.

The Main HIPAA Rules That Drive Compliance

HIPAA is not a single regulation but a framework of four interlocking rules, each with distinct compliance requirements. HIPAA includes four main rules: Privacy, Security, Breach Notification and Omnibus.

HIPAA Privacy Rule (effective April 14, 2003): The privacy rule controls the use and disclosure of PHI. It deals with how healthcare organizations can share patient data and what rights patients have over their medical records. It sets national standards for when authorisation is needed and when it’s not.

HIPAA Security Rule (effective April 21, 2005): The security rule requires safeguards for electronic protected health information. It mandates administrative, physical and technical safeguards to make sure that ePHI stays confidential, accessible and intact. The security rule protects data across all the electronic systems that store, process or transmit patient information.

HIPAA Breach Notification Rule (effective September 23, 2009): This rule requires covered entities to notify affected individuals and HHS following any breach of unsecured PHI. Notification must occur within 60 days of discovery, and in certain cases, notification to prominent media outlets is also required. 

2013 Omnibus Rule: The Omnibus Rule extended direct HIPAA liability to business associates, restricted marketing and fundraising uses of PHI, prohibited the sale of PHI without authorization, and increased civil penalty tiers.

HIPAA Privacy Rule: Where Does Your PHI Go?

The HIPAA Privacy Rule sets national standards for handling PHI across America’s healthcare system and is outlined in 45 CFR Parts 160 and 164.

Covered entities may use and share PHI for three permitted purposes without asking patient permission: treatment, payment, and healthcare operations (TPO). For example, a physician practice sharing patient data with a billing vendor to process payment does not require a separate patient authorization.

However, patient authorization is required for uses of PHI outside TPO, including unrelated marketing, research unconnected to patient care, and disclosures to employers or third parties not directly involved in care. All these situations require written authorization from the patient.

HIPAA gives patients significant control over their medical records. Specifically, they can:

  • Get copies of their records
  • Ask for corrections to information that is wrong
  • Get a notice on how their data is being used and protected
  • Ask for a restriction on who is allowed to see their PHI

One of the main principles of the Privacy Rule is that you should not access more PHI than the job requires. This applies not only to on-screen data but also to how system access is provisioned in the first place.

HIPAA Security Rule: Keeping Your Systems Secure

The HIPAA Security Rule governs the security of electronic PHI and falls into three categories: administrative, physical, and technical.

Administrative Safeguards require documented policies and procedures, including regular risk assessments, workforce training, and incident response planning for when things go wrong.

Physical Safeguards protect the physical space through measures such as controlled facility access and secure destruction of paper records.

Technical Safeguards protect the systems themselves, ensuring that data is encrypted, maintaining strong access controls, and preserving audit logs of who accessed what and when.

HIPAA Security

Who Has To Be HIPAA Compliant in the Revenue Cycle

If you are handling PHI in connection with U.S. healthcare providers or health insurance, then you must follow the HIPAA rules. This applies across the revenue cycle, from doctor’s offices to hospitals and every entity in between.

Some of the people and companies that come under this rule include:

  • Small and large physician groups
  • Specialty clinics
  • Hospitals
  • Labs
  • Specialized billing companies such as Dastify Solutions

You must also monitor who you are sharing PHI with, including clearinghouses, vendors, and collection agencies. Each qualifies as a business associate and must comply with HIPAA as well. They have to sign a Business Associate Agreement with you before handling any PHI.

Even if you are a solo practice that submits electronic claims to Medicare, you still need to follow HIPAA rules.

The Real Meaning of “HIPAA Compliant”

Many assume that being HIPAA compliant is a simple checklist exercise. It is not. Compliance means you must be able to prove that you are doing everything you can to keep PHI secure. That is a continuous process and needs to be reflected in how you run your systems, processes, and documentation. The program must be defensible enough to withstand an OCR audit.

The key technical safeguards required under current rules and the 2025 proposed amendments include:

  • Encrypting PHI at rest and in transit. Current best practice is AES-256 for databases and TLS 1.2 or higher for web traffic. Note that the 2025 proposed rule changes will make encryption mandatory.
  • Strict access controls, including unique user credentials, strong password policies, multi-factor authentication (MFA), and documented emergency access procedures for system failures or breaches.
  • Automatic session timeouts and enforced device locking to prevent unauthorized access.

Logging and monitoring are equally important:

  • Systems must maintain oversight through audit logs that record who logged in, when data was accessed, what changes were made, and what was transmitted, including claim submissions.
  • These logs must be securely stored and readily accessible for any internal audit or OCR investigation to demonstrate data integrity.

Secure integrations matter at every connection point: secure FTP (SFTP) or encrypted APIs for claims and remittance data, VPNs for remote billing staff, and a hardened cloud environment with documented security standards. This covers every channel where ePHI moves between systems.

Dastify Solutions builds its AI billing platform on top of these technical safeguards so automated coding, claim scrubbing, and AR workflows never expose PHI directly.

HIPAA Compliance Rules in Everyday Medical Billing

HIPAA applies throughout every billing workflow: patient sign-up, coding, claim submission, accounts receivable follow-up, and denial management. Every single step involves moving PHI that we must protect.

Secure patient intake requires using secure forms or EHR portals, secure scanning of paper documents, and limiting access to raw demographic and insurance data. We must retain all documents for at least six years, which means planning for secure long-term storage.

Billing and coding correctly requires:

  • Medical records restricted to authorized personnel only
  • Billers granted only the minimum PHI required for accurate claim submission
  • Standardized electronic transactions (837, 835, 270/271) sent through secure channels

AR and denial management must remain compliant:

  • Handling EOBs and remittance advice with PHI through secure channels
  • Prohibiting unencrypted PHI in email communications with payers or patients
  • Keeping patient information confidential when working with collection firms

We also need to train everyone on HIPAA policies so they understand their obligations. Every biller, coder, and AR specialist needs to know the security measures required in their daily work.

Dastify Solutions builds HIPAA-compliant workflows directly into RCM services so medical offices can collect revenue without compromising privacy or security.

How HIPAA Violations Typically Happen in Billing, and How to Fix Them

Most HIPAA violations stem from everyday oversights and process gaps rather than advanced cyberattacks, especially within billing operations. HIPAA compliance is enforced by the Office for Civil Rights (OCR), and ignorance is not a legal defense.

Some common mistakes include:

  • Sending unencrypted patient balance spreadsheets through standard email
  • Using shared logins for billers or coders, which breaks individual audit accountability
  • Leaving printed superbills or encounter forms in unsecured public areas
  • Accessing a relative’s or public figure’s account without a work-related purpose, which is an unauthorized disclosure of PHI

The consequences can be significant. HIPAA civil monetary penalties range from $100 to $50,000 per violation, depending on the level of culpability, with annual penalty limits established under federal law. Criminal penalties for the wrongful disclosure of protected health information (PHI) can include fines of up to $250,000 and up to 10 years of imprisonment in certain cases. In 2017, the HHS Office for Civil Rights (OCR) fined Presence Health $475,000 for failing to provide timely breach notification. Since HIPAA enforcement began, OCR has collected more than $144 million in settlements and civil monetary penalties. Source

Avoiding legal and financial penalties is one reason to follow HIPAA rules, but prevention is straightforward:

  • Enforce unique credentials and role-based access control across all systems
  • Prohibit PHI from being sent via standard email or messaging apps
  • Lock screens and secure any printed reports
  • Use secure portals or approved encryption for all patient statements and AR communication

Dastify Solutions structures its operations so our billing and coding teams are protected from these risks. We maintain clear internal rules, secure portals, and structured permissions.

HIPAA Violations

Risk Analysis, Policies, and Training: What HIPAA Compliance Means

OCR expects to see documented risk analysis, written policies and procedures, and ongoing employee training as the foundation of any compliance program. Failing to do so is the leading cause of OCR fines.

Risk analysis for small and mid-sized practices involves:

  • Identifying where PHI resides (EHRs, billing software, cloud drives, faxes, and email)
  • Cataloging active threats (ransomware, lost laptops, unauthorized internal access, security vulnerabilities)
  • Prioritizing remediation to protect PHI (encryption, backups, secure access)

We need to conduct regular risk assessments to remain current. A one-off assessment from three years ago does not meet HIPAA requirements.

Key written policies that apply to the revenue cycle include:

  • Access control and defining roles for billing staff
  • PHI use and disclosure guidelines tied to treatment, payments, and healthcare operations
  • Data retention and secure destruction of billing reports and aging lists

Workforce Training

Workforce training must cover the following areas:

  • New staff must be trained on HIPAA Privacy and Security Rules
  • Annual refresher training that addresses real workflow scenarios such as claim attachments, payer portals, and remote work
  • A documented sanctions policy for workforce violations

Dastify Solutions maintains its own HIPAA compliance programs, including internal audits and staff training, and we help clients align their office policies with billing operations.

Business Associate Agreements (BAAs) and Working With Vendors

Business Associate Agreements are required with vendors that handle your protected health information. There are no exceptions: a BAA is required for every vendor who handles PHI.

A BAA must contain the following provisions:

  • Permitted and prohibited uses of PHI
  • Required security measures to keep PHI safe, including breach response procedures
  • Subcontractor authorization requirements and audit rights

Vendors that require a BAA include:

  • Outsourced billing companies such as Dastify Solutions
  • Cloud-based practice management vendors
  • Firms that store and shred documents off-site

A signed BAA alone does not mean your PHI is automatically safe. You must still independently verify the vendors’ security measures, their data security certifications, and their incident response procedures. HHS has made it clear that both the covered entity and the business associate are directly liable if HIPAA security safeguards are not in place, so a paper agreement alone will not satisfy auditors.

Dastify Solutions signs compliant BAAs with all our clients, and in turn we require the same agreements from any subcontractors supporting our RCM services. This chain of accountability is critical because the 2013 Omnibus Rule made business associates directly responsible for their own compliance programs.

HIPAA Compliance and AI-Powered Revenue Cycle Management

AI can increase HIPAA risk when improperly configured, but it can also strengthen security and reduce errors when built correctly. The key is to build HIPAA security safeguards directly into the platform from the design phase.

Common AI use cases in RCM include:

  • Automated coding and charge capture
  • Claim scrubbing and denial prediction
  • Accounts receivable analytics to reduce Days in A/R

However, HIPAA applies at every stage of these workflows:

  • AI models must be trained and run on PHI that is encrypted at every stage
  • Access to AI outputs must follow the minimum necessary standard (for example, a denial prediction dashboard should not expose the entire medical record)
  • Logs must capture what PHI was accessed and transformed by automated workflows to support full audit controls

Dastify Solutions builds HIPAA security safeguards into our AI stack by:

  • Encrypting at every layer (input, processing, storage)
  • Restricting access to AI dashboards and analytics to authorized personnel only
  • Regularly auditing AI decisions for any potential impact on patient privacy or accuracy

For healthcare providers concerned about AI-related risk, outsourcing to a HIPAA-compliant AI billing partner can be safer than in-house implementation. A well-designed AI platform centralizes security measures, enforces consistent access controls, and maintains the audit trail that regulators require.

AI-Powered Revenue Cycle Management

How Dastify Solutions Manages HIPAA Compliance for Clients

As a specialized, AI-powered medical billing and RCM provider, Dastify Solutions operates as a HIPAA business associate for U.S. healthcare providers. Compliance is not an afterthought. It is built into every system, process, and team interaction.

Our internal controls include:

  • Role-based access for our billers, coders, and AR specialists. Each person has their own credentials and only sees the PHI required for their role
  • Encrypted, U.S.-hosted infrastructure for storing and processing PHI, using security standards aligned with current and proposed HIPAA requirements
  • Routine security updates, backups, and disaster recovery planning to maintain uptime during system disruptions

Our compliance processes include:

  • Regular reviews and updates to our HIPAA privacy and security policies
  • Periodic internal audits and risk assessments focused on billing workflows
  •  Workforce HIPAA training tailored to revenue cycle scenarios

Client collaboration includes:

  • Executing BAAs and defining clear data flows and responsibilities
  • Configuring minimum-necessary access to your EHR and practice management systems
  • Helping strengthen your billing-related policies and procedures

Dastify Solutions is more than a billing vendor. We are a partner that helps you improve revenue while reinforcing HIPAA compliance across the entire billing lifecycle. This combination of financial performance and regulatory protection is what defines a compliance-focused RCM partner.

Steps for Practices to Strengthen HIPAA Compliance in Billing

You do not need to be a legal expert to improve your compliance posture. But you do need a practical action plan that addresses the specific points where PHI is most at risk in your billing process.

A concise step-by-step approach:

1. Identify where PHI resides in your billing process. It may be found on intake forms, in coding queues, during claims processing, in AR aging reports, on patient statements, or in ad hoc exports or spreadsheets.

2. Execute or renew BAAs with all your billing-related vendors. Make sure they include breach reporting timelines, subcontractor requirements, and audit rights.

3. Enforce access controls in your EHR and billing software. Every user needs their own login with permissions that match their role.

4. Enforce encryption on laptops, mobile devices, and cloud storage that may hold PHI exports. This is a baseline security requirement, not an option.

5. Schedule structured HIPAA training focused on billing and collections, not a generic PHI awareness course.

Beyond these steps, conduct a targeted risk assessment at least once a year, focused specifically on your revenue cycle systems and workflows. If your compliance programs are underdeveloped or your in-house controls are inconsistent, consider outsourcing your billing to an RCM partner that understands HIPAA, such as Dastify Solutions.

Regulatory expectations and threat activity continue to escalate. The proposed 2025 NPRM from HHS would make measures such as encryption at rest and multi-factor authentication obligatory across all covered entities and business associates. You need to stay current with compliance. It is not a document you can check off and file away.

Conclusion: Turning HIPAA Compliance into a Competitive Advantage

HIPAA compliance is about keeping patient data safe while running your healthcare and billing operations smoothly and accurately. It is not a project you complete and set aside. It is a discipline that needs to be woven into every claim, every phone call, and every system decision you make.

If you can execute your HIPAA compliance in revenue cycle management well, you should see fewer denials, fewer costly HIPAA violations, and greater trust from patients, payers, and regulators alike. Practices that treat compliance as an obstacle often struggle to remain competitive financially and operationally. Those that treat it as a core part of the business, like Dastify Solutions with its AI-powered, HIPAA-compliant medical billing, consistently outperform.

Next Step: Review your billing workflows, identify where PHI is most exposed, review your vendor agreements, and evaluate whether your compliance programs are sufficient. To work with a partner that handles both revenue and compliance, contact Dastify Solutions to explore how our HIPAA-aligned RCM services support your practice.

End
Ricky Bell

Head of Operations

Authored by Ricky Bell, Head of Operations at Dastify Solutions with 10+ years of experience. Reviewed for compliance and accuracy by Anum Naveed the company’s Director of Compliance She has 8+ years of experience. Ricky brings more than nine years of hands-on experience in revenue cycle management, including leadership roles at CureMD and MedCare MSO. Anum adds over a decade of U.S. healthcare compliance expertise, ensuring each publication aligns with HIPAA, CMS, and payer policy standards.