Security, Privacy, & Compliance at MedHeave

MedHeave works inside the systems medical practices rely on to manage claims, payments, and patient information. That access comes with clear boundaries.

We are HIPAA-compliant, execute a signed Business Associate Agreement (BAA) with every client, and maintain security controls around where systems can be accessed, which devices can connect, what information each team member can see, and how data can be handled.

Access is limited before work begins

Our systems are designed to keep access inside approved MedHeave environments rather than allowing patient and practice information to be accessed from anywhere.
  • Two-factor authentication is required for system access.
  • Company systems do not function outside approved premises.
  • Staff access client information only through MedHeave’s internal systems.
  • Systems can only be accessed from approved office locations through IP-locked access.
  • Personal laptops, home computers, phones, & other devices can’t be used to access client data.
  • Emails are restricted to our office IP and cannot be accessed from outside the premises.
  • Company provided tablets are used for 2FA which are tethered inside the office and do not work outside company premises.
  • All client and patient phone calls are done on company provided phone lines to avoid the chance of data being saved on personal devices.
These controls mean access depends on both the authorized user and the approved environment in which the work is being performed.

Data stays inside a controlled environment

Restricting logins is only one part of protecting patient information. MedHeave also limits the ways data can be copied, removed, or turned into physical records.
  • Printing is disabled to prevent unauthorized physical copies.
  • Taking a workstation off-site does not provide access to patient data.
  • USB access is disabled to prevent unauthorized transfers to removable storage.
  • Server rooms are locked, with physical access biometrically restricted to authorized personnel.
  • Patient data is stored on secured company servers rather than locally on individual workstations or on cloud servers.
The workstation alone is not the source of access. Patient information remains within the secured infrastructure and approved operating environment.

Staff only receive the access their work requires

MedHeave uses role-based access controls so permissions are tied to the work each team member is responsible for performing.

Billing staff receive access only to the billing information essential to their assigned responsibilities. Broader access is not provided simply because someone works on an account.

Clinical notes are accessed only when necessary for the work being performed, such as when documentation must be reviewed to investigate or resolve a denial.
Access controls are maintained throughout employment and remain aligned with each employee’s responsibilities.

Security also depends on the people using the systems

Technical controls are only effective when the people with access understand the standards expected of them.

MedHeave team members receive ongoing security and HIPAA training throughout their employment. Offshore team members are also hired with verified healthcare or relevant industry experience before being placed into client workflows.

This combines controlled system access with people who understand the environment, responsibilities, and sensitivity of the information they work with.

Compliance continues into the billing workflow

 

Security and compliance risks do not begin and end with access to patient information. Billing configurations, claim preparation, and payment handling can also create unnecessary exposure when they are not carefully controlled.

MedHeave builds review into the revenue cycle before those issues move further downstream.

1. Billing setups are reviewed for risk
Potentially risky billing setups are flagged early when they may create compliance or audit concerns. Problems are surfaced before they become established parts of the billing workflow.


2. Patient funds remain with the practice
Patient payments go directly to the medical practice through the payment portal. MedHeave does not receive, hold, or take custody of patient funds.

HIPAA compliance is part of the operating standard

Every MedHeave client receives a signed Business Associate Agreement, establishing the responsibilities that apply when we access protected health information as part of revenue cycle work.


HIPAA and security requirements are reinforced through ongoing staff training, controlled system access, limited permissions, approved work environments, and safeguards designed to prevent unauthorized access or movement of patient information.


MedHeave has maintained zero reportable HIPAA violations in seven years of operations.

Book a call

We listen and we don’t judge.

30 minutes of this call can save you up to 25% of lost revenue.

In this session, we’ll walk you through
Book a call

If you're not ready to Talk right now , you can give us your info instead