HIPAA Compliance

[VERIFY] — legal review required. Every specific safeguard, certification and vendor claim on this page must be confirmed as currently accurate before launch. An unverifiable compliance claim carries more risk than a modest one.

Last updated: 27 August 2026

Medway Billing acts as a HIPAA Business Associate to the practices we bill for. That is a legal role with defined obligations, not a marketing position — and it means protected health information (PHI) we handle on a client's behalf is governed by the Business Associate Agreement between us.

Business Associate Agreement

We sign a BAA with every client practice before handling PHI. This is a legal requirement for a billing partner, not an optional extra, and we will not begin work without one in place.

Safeguards

[VERIFY] Restate your actual technical and administrative safeguards here — encryption in transit and at rest, role-based access controls, audit logging, workforce training cadence, and incident response. Describe what you genuinely do, at the level of specificity you can evidence in an audit.

Where we rely on third parties for infrastructure or security services, each is bound by contract to handle data only as instructed, and every one that could touch PHI is covered by its own agreement.

Minimum necessary

We work with the minimum PHI required to bill and to resolve a claim. Staff access is scoped to the accounts they work on.

Audit trail

Every claim carries a record of what was coded, from what documentation, when it was submitted, and every action taken on it afterwards. This is what makes an account defensible under a payer or RAC audit.

Certified staff

Our coders hold AAPC and AHIMA credentials. We give the current number, and the specific certifications, on request rather than publishing a figure that drifts out of date between hires.

This website is not a PHI channel

Do not submit patient health information through any form on this site, or to the voice assistant. Claim-level financial data — an AR aging report, a denial export — is what we need for an audit, and it does not contain PHI. For anything that does, we establish a secure channel first.

Breach notification

If a breach affecting your PHI occurs, we notify you without unreasonable delay and within the timeframe set by the HIPAA Breach Notification Rule and your BAA, with what we know, what we are doing, and what it affects.

Questions

Compliance and security questions go through the Contact page marked “Compliance”, and are routed to the person who owns HIPAA compliance at Medway.