No software is HIPAA-compliant through a label alone. In 2026, billing software must support the practice’s documented HIPAA Privacy, Security and Breach Notification obligations through appropriate administrative, physical and technical safeguards, a business associate agreement, secure configuration, trained users and ongoing risk management.
Use the HIPAA rule currently in effect
The HHS Office for Civil Rights states that the current Security Rule requires reasonable and appropriate administrative, physical and technical safeguards for electronic protected health information. A January 2025 proposal would strengthen cybersecurity requirements, but HHS’s current summary distinguishes that proposal from the rule now in effect. Practices should monitor final regulatory changes without treating proposed provisions as current law.
HIPAA is technology-neutral and risk-based. A vendor’s badge or marketing statement does not transfer the practice’s responsibility to assess and manage risk in its actual environment.
Confirm the vendor’s business associate role
A billing software company or cloud provider that creates, receives, maintains or transmits protected health information for a covered entity may be a business associate. Review and sign an appropriate business associate agreement before production use. Identify subcontractors that handle the information and how contractual protections extend to them.
Clarify breach and security-incident notification, permitted uses, data return or destruction and termination. A vendor that refuses an applicable business associate agreement is a major warning sign.
Require individual access and minimum-necessary permissions
Users should have unique accounts rather than shared credentials. The system should support roles that limit access to the information and functions needed for each job. Review administrative privileges, temporary access, inactive users and emergency access procedures.
Use multifactor authentication where appropriate and available, especially for remote and privileged access. Test how users are added, changed and removed. Software features matter only when the practice configures and reviews them consistently.
Inspect audit controls and data integrity
HHS identifies audit controls as mechanisms to record and examine activity in systems containing electronic protected health information. Ask what user, patient, record, action, timestamp and source details are logged; how long logs are retained; who can alter them; and how administrators search and export them.
The software should also support integrity by helping prevent or detect improper alteration or destruction. Test corrections, voids, payment changes, deleted documents and permission changes. Require an accountable record of important billing actions.
Protect information in storage and transmission
Ask how electronic protected health information is protected when transmitted and stored, how encryption keys are managed and how backups are secured. HHS explains that encryption decisions under the current rule are evaluated through the applicable requirements and risk analysis; a practice should not accept a vague claim that data is encrypted without scope and method.
Review interfaces, exports, email, file transfer, mobile access, printed reports and local downloads. A secure cloud application can still leak information through an unsafe connected workflow.
Plan availability, backups and incident response
Billing depends on access to coverage, claims, payer responses, payments and balances. Review backups, recovery objectives, redundancy, downtime communication and tested restoration. Determine how urgent work continues when the platform or an interface is unavailable.
Ask the vendor to explain security-incident handling and notification. The practice needs its own documented response process, contacts and decision authority. Include vendor outages and account compromise in tabletop exercises.
Apply HIPAA controls to specialty billing teams
A billing platform may serve employees, external coders, billing companies and multiple locations. Design roles and work queues around the real team. A multi-location radiology group can use the radiology billing service guide to identify facility and interface access, while a small practice should minimize administrative accounts and remove departed users promptly.
Train users on secure access, exports, messaging, phishing, incident reporting and permitted use. HIPAA compliance is an operating process, not a one-time software purchase.
Document due diligence before signing
Request the business associate agreement, security summary, relevant independent assessments, breach-notification process, data locations, subcontractor information, support procedures and sample audit reporting. Review the contract’s security responsibilities, data return, retention and termination.
Use the HIPAA billing software checklist and vendor security evidence guide. Then compare secure medical billing software prices only after mandatory safeguards are established. A platform supports compliance when its capabilities, agreements, configuration and the practice’s procedures work together.


