HIPAA, BAAs and How We Handle Patient Data

Summary

  • A BAA is signed before we see any PHI
  • We work in your systems through logins you control and can switch off
  • We use the minimum PHI needed for billing, follow-up and enrollment
  • Our website form and regular email are not for patient information

MB Claims signs a Business Associate Agreement (BAA) with every client before we access any protected health information (PHI). We work inside your EHR, practice management system and clearinghouse, using user accounts that your practice creates and controls. We use only the access the work requires.

Do you sign a BAA?

Yes, with every client, before we access PHI.

Under HIPAA, a billing company that handles PHI for a medical practice is a business associate of that practice. The practice must have a written agreement with the billing company that meets the requirements of 45 CFR 164.504(e) (HHS: Business Associates). Among other things, a HIPAA business associate agreement must:

  • Limit the business associate to using PHI only for the services in the contract, or as the law requires
  • Require appropriate safeguards to protect the PHI
  • Require the business associate to report unauthorized uses or disclosures, including breaches of unsecured PHI
  • Pass the same restrictions down to any subcontractor that handles the PHI
  • Return or destroy the PHI when the contract ends, where feasible

HHS publishes sample BAA provisions if you want to see what one covers. If your practice has its own BAA template, tell us during onboarding.

How do you access our systems?

You stay in control of access the whole time:

  • Your systems, your accounts. You create user accounts for our team inside your EHR, PM system and clearinghouse. We ask for individual logins, not shared ones, so every action can be traced to a person.
  • Only the access the work needs. You choose the permissions. We ask only for what the agreed scope requires, following HIPAA's minimum-necessary standard.
  • Visible and revocable. The accounts live in your system, so you can review activity and disable any login at any time.
  • Work stays where the data lives. Whenever the work allows, we work inside your systems instead of copying patient records out of them.

How do you handle PHI day to day?

  • We use PHI only to perform the services in our agreement: claim submission, payment posting, denial follow-up, appeals, eligibility checks and enrollment work.
  • We use the minimum PHI needed for each task.
  • When documents have to move between us, we use your system's secure messaging or another secure method we agree on during onboarding, never regular email.
  • If we become aware of a possible privacy or security incident involving your PHI, we notify you as the BAA requires.

What about the website form and email?

Our website is for business inquiries only. Please don't put patient names, dates of birth, member IDs or claim details in the contact form or in email to hello@mbclaims.com. The free audit works from summary reports, so no PHI is needed to get started. If a deeper review needs claim-level data or access to your systems, we sign a BAA first.

What happens when an engagement ends?

  • You disable our user accounts in your systems.
  • We return or destroy any PHI we hold, as the BAA requires.
  • We agree on a handover of open claims and denials with your team, so follow-up work doesn't get lost.

Is there such a thing as "HIPAA certified"?

No. HHS doesn't certify billing companies or any other business associates as HIPAA compliant, and a third-party "certification" doesn't replace the required business associate agreement (HHS FAQ 237). Be cautious with any vendor that leads with a "HIPAA certified" badge. Ask how they actually handle your data.

Questions to ask any billing company about PHI

  1. Will you sign a BAA before you access any PHI?
  2. Will each of your staff get an individual login in our systems, or do you want shared credentials?
  3. Which permissions do you need, and why?
  4. How do documents move between us?
  5. Do you use subcontractors who will touch our PHI, and are they bound by the same terms?
  6. What happens to our data and your access when the contract ends?

Start with a no-PHI audit

Send summary reports and get a written review of your A/R and denials within 5 business days. No patient data is needed to start.

Send summary reports. Written review and your rate within 5 business days.

· Questions about our BAA? hello@mbclaims.com

Frequently asked questions

Do you sign a Business Associate Agreement?

Yes. We sign a BAA with every client before we access any PHI.

Can we remove your access at any time?

Yes. Our team works through user accounts that you create in your own systems, so you can disable them whenever you choose.

Do you need PHI for the free audit?

No. The free audit works from summary reports such as A/R aging by payer and a denial summary. If a deeper review needs claim-level data, we sign a BAA first.

Is MB Claims HIPAA certified?

There is no official HIPAA certification for billing companies. HHS doesn't certify business associates. We work as a business associate under a signed BAA with each client.

Can I email you patient information?

Please don't. Use your system's secure messaging, or a secure method we agree on during onboarding.

Send summary reports. Written review and your rate within 5 business days.