How hipaa works
HIPAA's Privacy Rule sets limits on how protected health information can be used and disclosed, while its Security Rule requires administrative, physical and technical safeguards for information held or transmitted electronically, including access controls, encryption and audit logging. Covered entities must also have a breach notification process for reporting unauthorized disclosures.
A vendor that handles protected health information on behalf of a covered entity, such as a billing or bookkeeping provider working with medical billing data, is a business associate under HIPAA and must sign a business associate agreement committing to the same safeguards. Staff handling this data are expected to receive HIPAA training, not a personal HIPAA certification, which does not exist as an official credential.
Example
A medical practice hires an outside billing company to post insurance payments and follow up on patient balances. Because that work involves protected health information, the billing company signs a business associate agreement with the practice, restricts access to trained staff on a need-to-know basis, and logs who accesses each patient's billing record, consistent with HIPAA's Security Rule requirements.
HIPAA in QuickBooks Online vs Xero
Not software-specific: HIPAA compliance depends on how protected health information is handled across whatever systems touch it, including the practice management, billing and any accounting software involved, rather than any single tool being HIPAA software. Businesses typically confirm a signed agreement is in place with each vendor and cloud provider that stores or processes this data.
Common mistakes
- Sharing protected health information with a billing or bookkeeping vendor before a business associate agreement is signed, which puts the covered entity out of compliance regardless of the vendor's practices.
- Claiming staff are 'HIPAA certified,' which is not an official credential; the accurate description is HIPAA-trained staff following the covered entity's required safeguards.
- Giving broad, unrestricted access to billing data instead of limiting it to staff who need it for the specific work, which increases exposure if an account is ever compromised.
Why it matters
HIPAA compliance protects a healthcare provider from significant penalties and reputational damage if patient information is mishandled or breached, which matters directly to a practice's ability to keep operating and billing payers. For a medical practice choosing a billing or bookkeeping vendor, confirming a signed business associate agreement and real HIPAA training, not an invented certification, is a basic and necessary due-diligence step.
Related terms
How LedgerBPO handles hipaa
We sign a business associate agreement with healthcare clients before any protected health information is shared, and our staff working on medical billing accounts are HIPAA-trained, with access restricted to those who need it for the work. Details on our safeguards are covered on our compliance page.