
- Business associate breaches rose from 20% (2009–2017) to 34% (2018–2026) on average.
- Providers now expect proof of active cybersecurity programs, not just “HIPAA compliant.”
- Core program pillars: governance, risk assessments, access control, training, safeguards.
- Cybersecurity is now a vendor-selection differentiator alongside coding and denial rates.
- Owners should be ready to answer 7 specific questions before contracts are signed.
TL;DR
Medical billing companies handle sensitive data for many practices at once, making them prime cyberattack targets. Providers no longer accept vague "HIPAA compliant" claims — they want specifics on risk assessments, access controls, employee training, technical safeguards, incident response, and disaster recovery. Billing company owners who can clearly answer these questions turn cybersecurity into a competitive advantage that builds provider trust and supports client retention.
Billing companies are prime targets for data thieves because they maintain large volumes of sensitive data and may have direct access to electronic health records and practice management systems.
As a medical billing company owner, this statistic about business associate cybersecurity should catch your attention: Between 2018 and 2026, an average of 34% data breaches had business associate involvement, according to a recent analysis. That’s up from an average of 20% between 2009 and 2017.
In addition, billing companies may serve dozens or hundreds of practices, so one breach of healthcare data security can affect many organizations simultaneously. This inherent vulnerability means billing company owners must be ready and willing to answer questions from providers about security practices for their business. Owners should be able to provide clear, specific answers about billing company cybersecurity rather than relying on general assurances that the company is ‘HIPAA compliant.’
What do healthcare providers want to know about a billing company’s cybersecurity practices?
Today’s healthcare providers want evidence of a structured, actively managed healthcare cybersecurity program capable of protecting patient information, maintaining business continuity, and responding quickly when something goes wrong. This type of ‘best practice’ medical billing cybersecurity program typically includes the following:
| Program component | What it entails | Why providers care |
|---|---|---|
| Security governance | Defined billing company cybersecurity policies, assigned leadership responsibilities, and regular oversight by management. | Demonstrates that cybersecurity is an organizational priority, not just an IT function. |
| Risk assessments | Annual HIPAA Security Rule risk analyses and ongoing evaluations of new threats, vulnerabilities, and technology changes. | Shows the company proactively identifies and addresses medical billing security risks. |
| Access management | Role-based access, multifactor authentication, strong passwords, and prompt removal of access for departing employees. | Reduces the risk of unauthorized access to patient information. |
| Employee training | Initial and ongoing HIPAA and cybersecurity training, phishing simulations, and security awareness campaigns. | Employees remain one of the leading causes of breaches, making training essential. |
| Technical safeguards | Encryption, endpoint protection, firewalls, antivirus software, email security, system monitoring, and timely software updates. | Helps prevent malware, ransomware, and unauthorized access. |
| Incident response | A documented healthcare cybersecurity plan outlining how security incidents are detected, contained, investigated, communicated, and resolved. | Providers want confidence that disruptions will be managed quickly and effectively. |
| Business continuity and disaster recovery | Tested backups, recovery procedures, and contingency plans to maintain operations during outages or ransomware attacks. | Ensures billing, claims submission, and payment processing can resume as quickly as possible. |
| Documentation and accountability | Written policies, audit logs, training records, risk assessment reports, and remediation plans. | Providers often request documentation during vendor evaluations or security questionnaires. |
Why has cybersecurity become a competitive differentiator for billing companies?
For many providers, business associate cybersecurity has become part of the vendor selection process alongside coding accuracy, denial rates, turnaround times, and customer service. A strong security program is no longer just a compliance requirement — it is a business differentiator.
Ultimately, providers want answers to these three critical questions about medical billing security:
- Can the billing company prevent a cyberattack? While no organization can eliminate risk entirely, providers expect to see reasonable administrative, technical, and physical safeguards designed to reduce the likelihood of an incident.
- Can the billing company continue supporting the provider’s revenue cycle if an attack occurs? A ransomware attack or prolonged outage can halt claims submission, payment posting, denial management, and patient billing. Providers want assurance that the billing company has tested recovery plans and can restore operations quickly.
- Will the billing company be transparent if something happens? Providers expect prompt notification, clear communication, a coordinated response, and a well-defined plan for meeting contractual and regulatory obligations if a security incident affects their data.
However, providers also increasingly expect billing companies to monitor threats continuously, apply security patches promptly, and regularly test their defenses. Continuous monitoring and regular testing help identify threats before they escalate into incidents that could disrupt claims submission, delay reimbursement, or expose protected health information.
What cybersecurity questions will providers ask before signing a billing company contract?
Billing company owners should expect providers to scrutinize their cybersecurity practices as carefully as they evaluate coding accuracy, denial management, and financial performance. Because billing companies often access EHRs, practice management systems, payer portals, patient demographics, insurance information, and financial data, providers need assurance that their information will be protected throughout the relationship. That’s why billing company owners should be prepared to answer these seven questions.
1. When was your last HIPAA security risk assessment?
Be prepared to explain when you completed the assessment, who conducted it (internally or through an outside expert), what major risks you identified, and how you addressed those risks. Providers may also ask how often you reassess risks when you implement new technology, hire remote employees, or expand your services.
2. How do you control employee access to our systems and patient information?
Be ready to describe how you grant, review, and remove employee access throughout the employment lifecycle. Providers may also ask how you enforce multifactor authentication, manage privileged accounts, and prevent former employees from retaining access after termination.
3. How do you protect patient data from cyberattacks?
Expect to discuss the layers of security you use to protect PHI, including encryption, endpoint protection, firewalls, email security, antivirus software, and patch management. Providers may also ask how you evaluate new threats and ensure security controls remain effective as cyber risks evolve.
4. How do you train and monitor employees?
When it comes to cybersecurity for medical billing companies, providers often want to know how frequently employees complete HIPAA and cybersecurity training, whether you conduct phishing simulations, and how you reinforce security awareness throughout the year. Be prepared to discuss how you address employees who repeatedly fail security training or simulated phishing exercises.
5. What happens if you discover a breach or cyberattack?
Be ready to walk providers through your incident response process from detection through recovery. They may ask who leads the response, how you notify clients, how quickly you can restore systems, how you preserve evidence, and what steps you take to prevent similar incidents in the future.
6. How would you continue billing operations during ransomware, an outage, or another disruption?
Expect questions about your business continuity and disaster recovery plans. Providers may ask how often you test backups, what is your expected recovery time, which billing functions receive priority during an outage, and how you would communicate with clients while restoring operations.
7. How do you continuously monitor your systems for cybersecurity threats?
Be prepared to explain how you identify, monitor, and investigate suspicious activity. Providers may also want to know who reviews security alerts, how quickly you escalate potential threats, how you identify and remediate vulnerabilities, and whether monitoring occurs around the clock or through a managed security service provider.
How billing companies can strengthen their cybersecurity
Cybersecurity is not a one-time compliance exercise — it's an ongoing business priority that begins with knowing your risks. Consider these tips:
- Perform assessments regularly. Conduct a HIPAA Security Rule risk assessment at least annually and whenever significant technology, workforce, or operational changes occur.
- Evaluate your entire security program. Assess administrative, technical, and physical safeguards, including employee access, security policies, remote work practices, and systems that store or transmit protected health information.
- Prioritize your highest risks. Focus first on vulnerabilities that pose the greatest likelihood to impact patient data, business operations, and client services.
- Document and track remediation efforts. Develop a corrective action plan, assign ownership, establish deadlines, and monitor progress until identified risks have been addressed.
- Treat risk assessments as an ongoing process. Review and update your assessment as new cyber threats emerge, technologies change, or business operations evolve rather than viewing it as a once-a-year compliance exercise.
Employee education and training on HIPAA security requirements is also critical. Consider these best practice strategies to ensure HIPAA compliance for billing companies:
- Provide training from day one. Require all new employees to complete HIPAA and cybersecurity training before they are granted access to client systems or protected health information.
- Offer ongoing education throughout the year. Reinforce security awareness with periodic training sessions that address emerging threats, policy updates, and evolving cybersecurity best practices.
- Conduct phishing simulations. Regularly test employees' ability to recognize phishing emails and other social engineering attacks, then provide targeted coaching to those who need additional support.
- Tailor training to employee roles. Customize training based on job responsibilities so staff understand the specific cybersecurity risks associated with coding, billing, payment posting, customer service, or IT functions.
- Measure and reinforce training effectiveness. Track training completion, evaluate employee performance during simulations, address recurring knowledge gaps, and update training materials as threats and organizational risks evolve.
Cybersecurity is more than a regulatory obligation — it's an opportunity for billing companies to strengthen provider trust, protect sensitive patient information, and demonstrate their value as reliable revenue cycle partners. By maintaining strong security practices and continuously improving their cybersecurity programs, billing companies can help safeguard patient data, support uninterrupted operations, and contribute to better outcomes for both the providers and communities they serve.
Frequently asked questions
Build trust that keeps clients loyal
Cybersecurity questions won't stop once you sign a contract. Providers expect ongoing transparency, so keep your answers current as your business grows, adds staff, or adopts new technology.
A strong healthcare cybersecurity program does more than protect patient data — it shows providers you're a partner they can rely on, not just a vendor they hired. Billing companies that can speak confidently to governance, risk assessments, and incident response stand out in a crowded market and earn longer-term client relationships.
Ready to see how Tebra supports billing companies with security and revenue cycle performance in mind?





