HIPAA compliance
Medheave Healthcare Services LLC
At MedHeave, HIPAA compliance is not a checkbox. It is the operational baseline from which every client engagement is built. As a business associate handling protected health information on behalf of healthcare providers, we are bound by the same standards that govern your practice and we treat that responsibility accordingly.
What it means to work with a HIPAA-compliant billing partner.
When a medical billing company accesses patient records, claim data, or any information that identifies a patient in connection with care or payment, it becomes a business associate under HIPAA. That designation carries legal weight.
As your business associate, MedHeave operates under the full requirements of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. We do not handle PHI casually, and we do not work with clients or vendors who do.
How we protect patient information.
Business associate agreements
Every client engagement begins with a signed Business Associate Agreement. The BAA defines how PHI may be used, the safeguards MedHeave maintains, and our obligations in the event of a breach. No PHI changes hands without one in place.
Staff training
Every MedHeave team member who touches PHI completes HIPAA training. This is not a one-time onboarding exercise. Training is ongoing, and staff are held to strict standards governing how patient information is accessed, handled, and protected.
Technical safeguards
MedHeave maintains the technical safeguards required under the HIPAA Security Rule, including controls over who can access PHI, how that access is monitored, and how data is transmitted and stored. Access to patient information is role-based and limited to what each team member needs to perform their function.
Vendor and subcontractor compliance
Any third party that accesses PHI in connection with MedHeave’s services is required to operate under a signed BAA and demonstrate HIPAA compliance. We do not pass PHI to vendors who cannot meet that standard.
Breach notification
In the event of a suspected or confirmed breach involving PHI, MedHeave follows the notification procedures required under the HIPAA Breach Notification Rule. Affected clients are notified within the timeframes the law requires, and we work directly with your practice to manage the response.
Risk management
We conduct assessments of the risks to PHI and maintain written policies and procedures governing our compliance program. These are reviewed and updated as regulatory requirements evolve.
We access only what billing requires.
PHI accessed in connection with billing and revenue cycle work is used solely for the purposes defined in your service agreement and BAA. It is not sold, shared with unauthorized parties, or used for any purpose outside the scope of your engagement with MedHeave.
Questions about compliance
If you have questions about MedHeave’s HIPAA compliance program, want to review our policies, or need to discuss Business Associate Agreement requirements before engaging our services, contact us at info@medheave.com.
We understand that compliance due diligence is part of choosing a billing partner. We are happy to have the conversation.