HIPAA Compliance
-
We are committed to safeguarding the privacy and security of all Protected Health Information (PHI) entrusted to us. As a mental health billing service provider, we operate as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) and fully comply with all applicable requirements under the HIPAA Privacy Rule and Security Rule.
Our policies, procedures, and systems are designed to ensure that sensitive client information is handled with the highest level of confidentiality and security.
-
We provide billing and administrative support services to licensed mental health professionals. In this role, we access and manage limited PHI strictly as necessary to perform billing functions:
Submitting insurance claims in a HIPAA-compliant practice management system
Verifying coverage and benefits with insurance payers
Reviewing service dates, POS codes, CPT codes, and ICD-10 diagnostic codes to ensure clean claims
Tracking claims and payments
We do not use or disclose PHI beyond what is required to perform these services and as permitted under our Business Associate Agreements (BAAs).
We maintain signed BAAs with:
Each healthcare provider (covered entity) we serve
All third-party vendors that may store or process PHI on our behalf
These agreements ensure that all parties uphold HIPAA compliance standards and strict confidentiality.
-
We strictly follow the “minimum necessary” standard under the Health Insurance Portability and Accountability Act, meaning we access, use, and disclose only the limited protected health information required to perform billing services.
Disclosures are made only as permitted under HIPAA for treatment, payment, and healthcare operations, and only to appropriate entities such as the treating provider, insurance payers, and authorized clearinghouses (e.g., Availity).
-
We maintain strong administrative controls to reduce risk and ensure compliance:
Completion of HIPAA training and ongoing security awareness practices (initial and every 2 years)
Annual risk analyses and annual reviews of company HIPAA policies and procedures signed by our compliance officer (Allison Outlund)
We maintain minimal records, using password-protected Excel spreadsheets with anonymous alphanumeric codes to track revenue, monitor delays, and submit clear monthly reports through the therapist’s secure practice management system
Policies, procedures, and systems in place to protect PHI
Strict access control (only authorized individual access)
Strong password policies and secure two-factor authentication practices
Active Business Associate Agreements with all clients and applicable vendors
Breach notification process to handle and notify individuals of improper uses or disclosures
-
We take appropriate measures to secure the physical environment and devices used to access PHI:
Work is conducted in a private, secure office environment
Devices are stored securely when not in use
External backup drives are encrypted (Windows BitLocker) and physically protected
Access to all devices is restricted to authorized use only
No physical record retention of PHI
-
We use secure, HIPAA-compliant technologies to protect electronic PHI (ePHI):
Encryption:
Full-disk encryption on all work devices (BitLocker on Windows PC)
ePHI accessed only through HIPAA-compliant practice management systems with strong passwords and two-factor authentication
Secure Systems:
HIPAA-compliant practice management systems (e.g., billing platform access via secure login)
We maintain minimal records, using password-protected Excel spreadsheets with only client initials or alphanumeric codes to track revenue, monitor delays, and submit clear monthly reports through the therapist’s secure practice management system
Access Controls:
Unique login credentials
Automatic session timeouts and device auto-lock
Two-factor authentication where available
Email Security:
PHI is not transmitted via unencrypted email
Secure or encrypted communication methods are used when necessary
-
In the unlikely event of a data breach or suspected security incident, we follow a structured response protocol:
Immediate documentation and assessment of the incident
Notification to the affected covered entity within 24 hours
Preservation of relevant data and system logs
Investigation and mitigation
Implementation of corrective actions to prevent recurrence
-
We conduct regular risk assessments to identify and address potential vulnerabilities, including:
Device security risks
Data storage and backup practices
Email and phishing threats
Environmental and operational risks
Our goal is to reduce all risks to a reasonable and appropriate level, in accordance with HIPAA standards.
-
This policy and our internal procedures are
Reviewed at least annually
Updated as needed based on regulatory changes or operational updates
Continuously improved to reflect best practices in data security and privacy