Your patients' information, handled the way you would handle it
When you outsource billing or credentialing, you are handing a third party access to protected health information, and you remain responsible for it. This page sets out plainly how Edge RCM treats that access, what a Business Associate Agreement is, and which claims we deliberately do not make.
Protecting patient information is not a feature of the service. It is the condition of doing it at all
A practice that hands us its billing is trusting us with the most sensitive records it holds. That trust is the whole basis of the engagement, and it is easier to lose through carelessness than through anything dramatic.
Most breaches in healthcare are not sophisticated attacks. They are ordinary lapses: a spreadsheet emailed to the wrong address, a shared login nobody revoked when a staff member left, a file kept long after the reason for keeping it expired. Our safeguards are aimed squarely at that kind of failure, because that is the kind that actually happens.
We would rather tell you exactly what we do and let you judge it than publish a page of reassuring language that commits us to nothing. Where we do not do something, this page says so.
The four principles behind everything below
- Minimum necessary. Nobody sees more than the work requires, including us.
- Access is granted, never assumed. Permissions attach to a role on a named account, not to employment.
- Work where you already are. Wherever possible we operate inside your systems, so records stay under your control.
- Say it plainly. If something goes wrong, you hear it from us, early, in writing.
What HIPAA actually requires, and where a billing company fits into it
HIPAA is the Health Insurance Portability and Accountability Act of 1996. The parts that matter here are its Privacy Rule, its Security Rule and its Breach Notification Rule, enforced by the Office for Civil Rights at the US Department of Health and Human Services.
Covered entity vs business associate
A covered entity is a healthcare provider, health plan or clearinghouse, which is your practice. A business associate is an outside organisation that creates, receives, maintains or transmits protected health information on a covered entity's behalf.
A medical billing company is the textbook example of a business associate. So is a credentialing service that handles provider and patient records. When Edge RCM performs that work for you, we are your business associate, and HIPAA applies to us directly, not only through our contract with you.
Why it matters to your practice
Since the HITECH Act, business associates can be penalised by the Office for Civil Rights in their own right. But that does not transfer your exposure to us. If a vendor mishandles your patients' information, it is still your patients, your notification duty and your reputation in the local paper. Choosing who gets access is a clinical-grade decision, and it deserves the same scrutiny you would apply to any other risk.
How Edge RCM operates
We work as a business associate under a signed agreement, apply the minimum-necessary standard to every request for information, restrict access by role, require confidentiality undertakings from staff who touch protected health information, and prefer to work inside your own practice management system or clearinghouse rather than take copies of records we do not need.
Those practices are described in detail further down this page, in the language of what we do rather than the language of what sounds impressive.
Yes, we sign a BAA, before any work touching patient data begins
It is the single most useful question a practice can ask a prospective vendor, and the answer should never be complicated.
What a BAA is, in plain terms
A Business Associate Agreement is a written contract, required by HIPAA, between a covered entity and any outside organisation that will handle protected health information on its behalf. It sets out what the business associate may do with that information, what it may not do, the safeguards it must apply, what happens if there is a breach, and what happens to the data when the relationship ends.
Providers ask for one because HIPAA does not permit you to share protected health information with a vendor without it. Engaging a billing or credentialing company without a BAA in place is itself a compliance failure on the practice's side, which is why the request is not bureaucratic caution, it is the rule.
How it works with us
We execute a BAA before beginning any engagement that involves protected health information. You are welcome to use your own template or have your counsel review ours. We have no interest in arguing about a document whose entire purpose is to protect your patients.
What our BAA commits us to
- Using protected health information only for the services described in your agreement
- Applying appropriate safeguards and the minimum-necessary standard
- Binding any subcontractor to the same obligations before it sees anything
- Reporting any use or disclosure not permitted by the agreement, without delay
- Assisting you with patient access and amendment requests that reach us
- Returning or destroying protected health information when the engagement ends
The safeguards, described as practices rather than buzzwords
Each of these is something a member of our team does or does not do on an ordinary working day. None of them requires you to take a technical claim on faith.
Secure data handling
Protected health information is handled only for the task at hand and is not copied into personal drives, personal email or messaging apps.
Minimum necessary access
Requests are scoped to what the work needs. A credentialing task does not require a patient ledger, so it does not get one.
Role-based permissions
Access follows the role on your account. Joining an account grants it, leaving the account removes it, and no role inherits access company-wide.
Employee confidentiality
Everyone who may encounter protected health information signs a confidentiality undertaking, and those obligations continue after they leave.
Secure communication
Patient identifiers are not sent in ordinary email or chat. Where information must move, it moves through the channel you and we agree in advance.
Individual accounts, strong authentication
Named logins rather than shared credentials, with multi-factor authentication enabled wherever the system you use supports it.
Device security
Work happens on protected, password-locked machines with screen locks and current updates, not on unattended or shared devices.
Ongoing staff awareness
Privacy and security training at onboarding and refreshed regularly, including the phishing and social-engineering patterns aimed at practices.
Responsible retention and disposal
Information is kept only while there is a reason to keep it, then returned or destroyed in line with your Business Associate Agreement.
The commitments that sit behind the safeguards
Controls can be described on a website by anyone. These are the habits that decide whether they are actually followed.
Honest communication
If we make a mistake with your data, you hear it from us promptly, in writing, with what happened and what we are doing about it. A vendor who reports their own error is worth more than one who has never admitted to any.
Ethical business practice
We do not upcode, we do not bill for what was not delivered, and we will tell you when something you have asked for is not defensible. Compliance is not only about privacy.
Transparency about limits
We publish what we do not claim as clearly as what we do. When you ask a question we cannot answer with certainty, you will get "I do not know, I will find out" rather than a confident guess.
Confidentiality that outlasts the contract
Your information is not a case study, a marketing example or a data set. Confidentiality obligations survive the end of the engagement, and your records leave with you.
Long-term partnership
Shortcuts around privacy are how a vendor wins a quarter and loses a client. We are built around keeping practices for years, which makes carelessness expensive for us too.
The questions compliance officers ask us
Something not covered here? Call +1 (855) 307-4535 or email [email protected].
Yes. Where Edge RCM will create, receive, maintain or transmit protected health information on your behalf, we execute a Business Associate Agreement before that work begins. You are welcome to use your own template, or your counsel can review ours. If a prospective vendor is reluctant to sign one, that itself tells you something.
No, and neither is anyone else. The US Department of Health and Human Services does not certify, endorse or accredit any organisation as HIPAA compliant, and no government-issued HIPAA certification exists. Companies advertising themselves as “HIPAA certified” are describing a privately sold training course or audit, not federal approval.
What is real is the legal obligation. As a business associate handling protected health information, Edge RCM is directly subject to the HIPAA Security Rule and to the applicable provisions of the Privacy and Breach Notification Rules, enforceable by the Office for Civil Rights and by the Business Associate Agreement we sign with you. That is a stronger assurance than a badge, because it carries consequences.
Access is limited to the staff assigned to your account, and to the minimum information they need to do the work. Team members sign confidentiality agreements, use individual accounts rather than shared logins, and receive ongoing training on handling protected health information.
Wherever possible we work inside your own practice management system or clearinghouse, so records stay in the environment you already control rather than being copied somewhere else. The full list is in How We Protect Information above.
Yes. Our clients are physicians, group practices, therapy and behavioral health providers, laboratories and telehealth organisations, most of which are covered entities under HIPAA. When we perform billing, credentialing or administrative work involving protected health information for them, Edge RCM acts as their business associate under a signed agreement.
Only the people working your account, and only for the parts of the work they are assigned to. Permissions follow the role rather than the person: access is granted when someone joins an account and removed when they leave it. Access is never a default that everyone in the company inherits, and we can tell you who those individuals are if you ask.
Confidentiality obligations in our agreements survive the end of the engagement, and the Business Associate Agreement governs what happens to protected health information afterwards, including return or destruction where required. Your records remain yours: if you leave, you leave with your data, and we do not hold it back as leverage.
Bring us your compliance questions first
Ask for the BAA, ask who will have access, ask what happens to your data if you leave. Ask us, and ask whoever else you are considering. The answers will tell you a great deal before a single claim is submitted.
This page describes how Edge RCM handles protected health information. It is general information about our practices, not legal advice, and it does not replace your own HIPAA risk analysis or the terms of your signed agreements. For how this website itself handles personal data, see our Privacy Policy.