HIPAA Risk Analysis for Medical Billing Companies

Medical billing security guide · Reviewed September 10, 2026

A billing platform’s security documentation does not describe every place your team handles patient information. Your risk analysis needs to follow the work: from provider access and claim preparation to exports, denial follow-up, and staff departures.

Risk analysis scope covering people, systems, partners and evidence

Start with the actual billing workflow

HHS identifies billing and claims processing as examples of business-associate activities. When those services involve PHI on behalf of a covered entity, the relationship can bring direct HIPAA responsibilities. A signed BAA is part of the arrangement; it does not implement the security program. HHS business associate guidance.

Choose one representative provider account and walk a claim through its lifecycle with an operations lead. Record each handoff, system, download, shared folder, and outside organization. Repeat for workflows that use different software or staffing arrangements. Use invented records for walkthroughs when possible; the assessment intake should not collect patient records.

Define a scope that covers all electronic PHI

HHS guidance describes risk-analysis scope as all ePHI created, received, maintained or transmitted by the organization. It includes more than the primary EHR or billing application. Document the boundaries, evidence sources, and any visibility limitations. A vulnerability scan can inform the analysis but cannot replace it. HHS risk-analysis guidance.

Workflow Ask the team Evidence to review
Provider and payer access Who approves access, and can each person be identified? Account inventory, role exports, approval samples
Remote claim processing Can staff download PHI to unmanaged equipment? Device inventory, configuration and encryption reports
Clearinghouse submissions How do we work if the clearinghouse is unavailable? Dependency map, escalation contacts, continuity exercise
Reports and exports Where do spreadsheet copies and attachments remain? Storage permissions, retention rules, transfer methods
Staff departures Which client-managed accounts require a separate request? Offboarding tickets, revocation confirmation

Make each finding a decision

Describe a specific risk scenario

Use a statement such as: “A former contractor retains payer-portal access because revocation depends on a provider contact and no confirmation is tracked.” That identifies the exposure, the process weakness, and the potential impact. “Access control needs improvement” does not tell an owner what to fix.

Separate evidence from assumptions

Record whether a finding comes from a live configuration export, a sample ticket, an interview, or an unverified assertion. If the MSP cannot provide a report, mark the evidence missing; do not automatically label the control absent. Assess likelihood and impact consistently, with written definitions that match your operation.

Assign an owner and a verification method

The remediation record should name a responsible person, a target date, affected systems, and what will show completion. For the former-contractor example, closure might require confirmations from each provider, a revised checklist, and a later sample demonstrating that the new process was used.

A useful risk register entry

Risk: unmanaged laptops retain exported claim data.
Owner: operations lead with the MSP.
Action: inventory devices, restrict approved storage, apply supported device controls and agree exceptions.
Evidence: coverage report, policy approval and a sample workflow test.
Review: revisit unresolved exceptions at the monthly security meeting.

This is an illustrative management example, not a finding about your business.

Include administrative and physical safeguards

The current rule addresses security responsibility, workforce safeguards, training, incident handling, contingency planning and evaluation. An assessment should therefore include the people and operating procedures that surround technical controls. 45 CFR 164.308.

For a remote billing team, examine private workspace expectations, printed records, device loss reporting and who authorizes exceptions. Ask how a newly hired biller learns the approved process and how a supervisor detects that the process is drifting. A policy copied from another organization is weak evidence if it describes tools or roles you do not have.

Turn the assessment into an operating cycle

01 · IDENTIFY

Find the gaps

Map data, devices, accounts and vendors. Agree priorities through a risk assessment and compliance gap review.

02 · IMPLEMENT

Fix what matters

Use NCBGuard to implement scoped endpoint, identity, email, encryption and configuration improvements.

03 · PROVE

Keep usable evidence

Document settings, approvals, exceptions, policies and completed remediation in a dated evidence register.

04 · VERIFY

Keep checking

Review control coverage, access changes and exceptions, then report progress and next decisions.

Keep implementation and verification distinct. A ticket saying encryption was enabled is an implementation record. A later device report showing encryption remains active provides a different kind of evidence. Both are useful, and neither proves every HIPAA requirement is satisfied.

Questions billing leaders ask

Is an annual review required in every situation?

HIPAA requires risk analysis and ongoing review appropriate to changing risks; it does not set a universal annual interval for every risk analysis. An annual review can be a sensible program baseline, with additional reviews after material changes, incidents or new dependencies. Contracts may set their own cadence.

Does a vulnerability scan count as the assessment?

No. A scan tests a defined technical scope. It does not by itself evaluate workflows, physical safeguards, ownership, vendor responsibilities or the likelihood and impact of all relevant risks.

Can NCB Cyber work with our MSP?

Yes. Scope the assessment so the MSP supplies configuration evidence and operational context, while NCB Cyber helps prioritize risks, plan scoped remediation and review evidence. Responsibility should be documented in the engagement.

Know which gaps to address first

Explore cybersecurity for medical billing companies, then request a free readiness conversation to scope a paid assessment. A readiness conversation is not a HIPAA risk analysis.

Request a free readiness conversation →

Further reference: NIST SP 800-66 Rev. 2 maps Security Rule implementation considerations. Also read our remote billing security checklist.