Security, Privacy, & Compliance at MedHeave
MedHeave works inside the systems medical practices rely on to manage claims, payments, and patient information. That access comes with clear boundaries.
We are HIPAA-compliant, execute a signed Business Associate Agreement (BAA) with every client, and maintain security controls around where systems can be accessed, which devices can connect, what information each team member can see, and how data can be handled.
Access is limited before work begins
- Two-factor authentication is required for system access.
- Company systems do not function outside approved premises.
- Staff access client information only through MedHeave’s internal systems.
- Systems can only be accessed from approved office locations through IP-locked access.
- Personal laptops, home computers, phones, & other devices can’t be used to access client data.
- Emails are restricted to our office IP and cannot be accessed from outside the premises.
- Company provided tablets are used for 2FA which are tethered inside the office and do not work outside company premises.
- All client and patient phone calls are done on company provided phone lines to avoid the chance of data being saved on personal devices.
Data stays inside a controlled environment
- Printing is disabled to prevent unauthorized physical copies.
- Taking a workstation off-site does not provide access to patient data.
- USB access is disabled to prevent unauthorized transfers to removable storage.
- Server rooms are locked, with physical access biometrically restricted to authorized personnel.
- Patient data is stored on secured company servers rather than locally on individual workstations or on cloud servers.
Staff only receive the access their work requires
MedHeave uses role-based access controls so permissions are tied to the work each team member is responsible for performing.
Billing staff receive access only to the billing information essential to their assigned responsibilities. Broader access is not provided simply because someone works on an account.
Clinical notes are accessed only when necessary for the work being performed, such as when documentation must be reviewed to investigate or resolve a denial.
Access controls are maintained throughout employment and remain aligned with each employee’s responsibilities.
Security also depends on the people using the systems
Technical controls are only effective when the people with access understand the standards expected of them.
MedHeave team members receive ongoing security and HIPAA training throughout their employment. Offshore team members are also hired with verified healthcare or relevant industry experience before being placed into client workflows.
This combines controlled system access with people who understand the environment, responsibilities, and sensitivity of the information they work with.
Compliance continues into the billing workflow
Security and compliance risks do not begin and end with access to patient information. Billing configurations, claim preparation, and payment handling can also create unnecessary exposure when they are not carefully controlled.
MedHeave builds review into the revenue cycle before those issues move further downstream.
1. Billing setups are reviewed for risk
Potentially risky billing setups are flagged early when they may create compliance or audit concerns. Problems are surfaced before they become established parts of the billing workflow.


2. Patient funds remain with the practice
Patient payments go directly to the medical practice through the payment portal. MedHeave does not receive, hold, or take custody of patient funds.
HIPAA compliance is part of the operating standard
Every MedHeave client receives a signed Business Associate Agreement, establishing the responsibilities that apply when we access protected health information as part of revenue cycle work.

HIPAA and security requirements are reinforced through ongoing staff training, controlled system access, limited permissions, approved work environments, and safeguards designed to prevent unauthorized access or movement of patient information.

MedHeave has maintained zero reportable HIPAA violations in seven years of operations.