HIPAA Risk Analysis for Medical Billing Companies
Medical billing security guide · Reviewed September 10, 2026
A billing platform’s security documentation does not describe every place your team handles patient information. Your risk analysis needs to follow the work: from provider access and claim preparation to exports, denial follow-up, and staff departures.

Start with the actual billing workflow
HHS identifies billing and claims processing as examples of business-associate activities. When those services involve PHI on behalf of a covered entity, the relationship can bring direct HIPAA responsibilities. A signed BAA is part of the arrangement; it does not implement the security program. HHS business associate guidance.
Choose one representative provider account and walk a claim through its lifecycle with an operations lead. Record each handoff, system, download, shared folder, and outside organization. Repeat for workflows that use different software or staffing arrangements. Use invented records for walkthroughs when possible; the assessment intake should not collect patient records.
Define a scope that covers all electronic PHI
HHS guidance describes risk-analysis scope as all ePHI created, received, maintained or transmitted by the organization. It includes more than the primary EHR or billing application. Document the boundaries, evidence sources, and any visibility limitations. A vulnerability scan can inform the analysis but cannot replace it. HHS risk-analysis guidance.
| Workflow | Ask the team | Evidence to review |
|---|---|---|
| Provider and payer access | Who approves access, and can each person be identified? | Account inventory, role exports, approval samples |
| Remote claim processing | Can staff download PHI to unmanaged equipment? | Device inventory, configuration and encryption reports |
| Clearinghouse submissions | How do we work if the clearinghouse is unavailable? | Dependency map, escalation contacts, continuity exercise |
| Reports and exports | Where do spreadsheet copies and attachments remain? | Storage permissions, retention rules, transfer methods |
| Staff departures | Which client-managed accounts require a separate request? | Offboarding tickets, revocation confirmation |
Make each finding a decision
Describe a specific risk scenario
Use a statement such as: “A former contractor retains payer-portal access because revocation depends on a provider contact and no confirmation is tracked.” That identifies the exposure, the process weakness, and the potential impact. “Access control needs improvement” does not tell an owner what to fix.
Separate evidence from assumptions
Record whether a finding comes from a live configuration export, a sample ticket, an interview, or an unverified assertion. If the MSP cannot provide a report, mark the evidence missing; do not automatically label the control absent. Assess likelihood and impact consistently, with written definitions that match your operation.
Assign an owner and a verification method
The remediation record should name a responsible person, a target date, affected systems, and what will show completion. For the former-contractor example, closure might require confirmations from each provider, a revised checklist, and a later sample demonstrating that the new process was used.
A useful risk register entry
Risk: unmanaged laptops retain exported claim data.
Owner: operations lead with the MSP.
Action: inventory devices, restrict approved storage, apply supported device controls and agree exceptions.
Evidence: coverage report, policy approval and a sample workflow test.
Review: revisit unresolved exceptions at the monthly security meeting.
This is an illustrative management example, not a finding about your business.
Include administrative and physical safeguards
The current rule addresses security responsibility, workforce safeguards, training, incident handling, contingency planning and evaluation. An assessment should therefore include the people and operating procedures that surround technical controls. 45 CFR 164.308.
For a remote billing team, examine private workspace expectations, printed records, device loss reporting and who authorizes exceptions. Ask how a newly hired biller learns the approved process and how a supervisor detects that the process is drifting. A policy copied from another organization is weak evidence if it describes tools or roles you do not have.
Turn the assessment into an operating cycle
Find the gaps
Map data, devices, accounts and vendors. Agree priorities through a risk assessment and compliance gap review.
Fix what matters
Use NCBGuard to implement scoped endpoint, identity, email, encryption and configuration improvements.
Keep usable evidence
Document settings, approvals, exceptions, policies and completed remediation in a dated evidence register.
Keep checking
Review control coverage, access changes and exceptions, then report progress and next decisions.
Keep implementation and verification distinct. A ticket saying encryption was enabled is an implementation record. A later device report showing encryption remains active provides a different kind of evidence. Both are useful, and neither proves every HIPAA requirement is satisfied.
Questions billing leaders ask
Is an annual review required in every situation?
HIPAA requires risk analysis and ongoing review appropriate to changing risks; it does not set a universal annual interval for every risk analysis. An annual review can be a sensible program baseline, with additional reviews after material changes, incidents or new dependencies. Contracts may set their own cadence.
Does a vulnerability scan count as the assessment?
No. A scan tests a defined technical scope. It does not by itself evaluate workflows, physical safeguards, ownership, vendor responsibilities or the likelihood and impact of all relevant risks.
Can NCB Cyber work with our MSP?
Yes. Scope the assessment so the MSP supplies configuration evidence and operational context, while NCB Cyber helps prioritize risks, plan scoped remediation and review evidence. Responsibility should be documented in the engagement.
Know which gaps to address first
Explore cybersecurity for medical billing companies, then request a free readiness conversation to scope a paid assessment. A readiness conversation is not a HIPAA risk analysis.
Further reference: NIST SP 800-66 Rev. 2 maps Security Rule implementation considerations. Also read our remote billing security checklist.