The Intake

Insights for those starting, managing, and growing independent healthcare practices

Cybersecurity in medical billing: Protecting patient data in the age of AI

Cybersecurity has shifted from an IT concern to business-critical priority.

Last updated on 06/17/2025
This post is a part of the Medical Biller's Triple Threat series
medical billing staff practicing cybersecurity to protect patient data

At a Glance

  • AI-powered cyberattacks make protecting patient data a business-critical priority for medical billers.
  • Prepare for 2025 HIPAA Security Rule updates, which will make most safeguards mandatory.
  • Build a layered defense with staff training, advanced tools, and strict data-handling policies.

This post is the second installment of the Medical Biller's Triple Threat series that explores how billing leaders are navigating AI, compliance, and cybersecurity.

Billing companies hold vast amounts of protected health information (PHI) and financial data — making them prime targets for increasingly sophisticated cyberattacks. With HIPAA enforcement entering a new era through proposed 2025 Security Rule updates, and attackers now using AI to enhance phishing attempts, cybersecurity has shifted from an IT concern to business-critical priority.

According to Tebra's 2024 survey of medical billing professionals, gaps exist with cybersecurity preparedness:

  • 35% use intrusion detection tools
  • 58% have implemented multi-factor authentication
  • 45% have trained staff to identify phishing attempts

Of respondents, 83% also express concern about a breach's financial or reputational impact.

Here's how billing leaders are building layered defenses — ones that not only protect against evolving cyber threats but also position their companies as trusted partners.

Learn how to navigate AI, cybersecurity, and compliance with our briefing for medical billers. Get the free resource now.

The evolving threat landscape

Modern cybercriminals are targeting medical billing companies with increasingly complex methods, and some are beginning to layer in AI to mimic tone, target at scale, and make phishing attempts harder to spot.

Here are some top threats to watch out for:

  • Phishing attacks: Cybercriminals send deceptive emails to trick employees into revealing login credentials or downloading malware.​
  • Spoofing: Attackers disguise their contact information, such as by changing one letter or number in an email address, website URL, or phone number, to impersonate a trusted contact or organization.​
  • Data breaches: Unauthorized access to confidential patient data can lead to significant financial and reputational damage.​

Proposed HIPAA Security Rule updates

The United States Office of Civil Rights (OCR) has seen a sharp increase in reports of large breach reports received over the last 5 years. Reports of large breaches increased by 102% from 2018 to 2023, and the number of individuals affected by such breaches increased by 1002%. 

To respond to this substantial increase of reports, OCR issued proposed changes that would fundamentally change HIPAA Security Rule requirements. Some of the proposed updates include:

  • Business associates (BAs) needing a subject matter expert verify to covered entities at least once every 12 months that they have deployed technical safeguards
  • BAs notifying covered entities upon activation of their contingency plans without unreasonable delay, but no later than 24 hours after activation
  • The security rule no longer distinguishes between "required" and "addressable" implementation specifications. Instead, it will make all implementation specifications "required" with specific, limited exceptions

These changes represent the most substantial HIPAA security updates in nearly 2 decades, with compliance timelines that will require immediate action from billing companies once finalized.

Aimee Heckman, Director of Revenue Cycle Management at Ash Business Solutions, emphasizes the urgency: "It has been nearly 20 years since the HIPAA Security Rule had any significant updates — but that's changing in 2025. Billing companies must act now to protect ePHI and avoid costly audits or breaches."

Billing companies must act now to protect ePHI and avoid costly audits or breaches.

Building layered defense systems

The most effective cybersecurity approach involves multiple protective measures working together. Build a robust cybersecurity posture with these 3 layers:

  • Employee training through regular sessions to recognize and respond to cyber threats, since human error remains the most common entry point for attackers.
  • Advanced security tools including intrusion detection systems and secure communication platforms that can identify threats in real-time.
  • Policy enforcement with strict access controls and data handling procedures that limit exposure points and ensure consistent security practices.

Alexis Marshall, Client Solutions Manager at Medical Billing Strategies, describes her team's comprehensive strategy: "We've embedded phishing alerts, cloud-based sharing, and file access controls across the board — so even if one point fails, the others hold."

Practical cybersecurity framework

Aimee Heckman offers a practical approach for billing companies working with limited resources: "Start with the basics — email filtering, antivirus, and regular updates — then layer on affordable support like using MSSPs, quarterly phishing training, and a clear breach response plan."

Here's further guidance on each of the basics:

  • Follow Department of Health and Human Services (HHS) Cybersecurity Performance Goals with basic safeguards like email filtering and regular software updates
  • Use managed security service providers (MSSPs) for monitoring and incident response without requiring in-house expertise
  • Run quarterly phishing and security training using free Cybersecurity and Infrastructure Security Agency (CISA) or National Institute of Standards and Technology (NIST) resources
  • Limit ePHI access to only what each role truly needs
  • Create a concise breach response plan outlining steps for detecting, containing, and reporting breaches, including contact information for legal and regulatory support

Advancing to AI-enhanced security

Once fundamental protections are in place, you can join proactive billing companies who are incorporating AI into their cybersecurity strategies. AI solutions can help security systems:

  • Detect anomalies by identifying unusual patterns in network traffic and flagging potential intrusions before they cause damage.
  • Automate responses to quickly isolate affected systems and prevent malware spread across the network.
  • Provide predictive analysis to anticipate potential vulnerabilities based on emerging threat intelligence and industry patterns.

Preparing for the future

In 2025, cybersecurity should be treated as a core business risk rather than an IT afterthought. Building layered defenses is the most effective way to avoid costly breaches, meet rising HIPAA standards, and protect the client trust that drives business growth.

As cyber threats continue evolving and regulatory scrutiny intensifies, implementing proactive security measures become non-negotiable for long-term business sustainability.

Ready to strengthen your cybersecurity defenses?

Download our complete guide to facing the triple threats in medical billing for 2025: AI and automation, cybersecurity risks, and increasing regulatory scrutiny. Get expert strategies from industry leaders who are successfully building resilient, secure billing operations.

Learn more about cybersecurity and AI in medical billing:

Stay Ahead with Expert Healthcare & Billing Insights

Get the latest industry updates, financial tips, and expert strategies — delivered straight to your inbox.

Jean Lee, managing editor at The Intake

Jean Lee is a content expert with a background in journalism and marketing, driven by a passion for storytelling that inspires and informs. As the managing editor of The Intake, she is committed to supporting independent practices with content, insights, and resources tailored to help them navigate challenges and succeed in today’s evolving healthcare landscape.

Stay Ahead with Expert Healthcare & Billing Insights

Get the latest industry updates, financial tips, and expert strategies — delivered straight to your inbox.