HIPAA & Data Security

Your patients' information, handled the way you would handle it

When you outsource billing or credentialing, you are handing a third party access to protected health information, and you remain responsible for it. This page sets out plainly how Edge RCM treats that access, what a Business Associate Agreement is, and which claims we deliberately do not make.

A patient record card protected behind a shield with a padlock, beside role-based access rows showing which team members are permitted to open the file
Our Commitment

Protecting patient information is not a feature of the service. It is the condition of doing it at all

A practice that hands us its billing is trusting us with the most sensitive records it holds. That trust is the whole basis of the engagement, and it is easier to lose through carelessness than through anything dramatic.

Most breaches in healthcare are not sophisticated attacks. They are ordinary lapses: a spreadsheet emailed to the wrong address, a shared login nobody revoked when a staff member left, a file kept long after the reason for keeping it expired. Our safeguards are aimed squarely at that kind of failure, because that is the kind that actually happens.

We would rather tell you exactly what we do and let you judge it than publish a page of reassuring language that commits us to nothing. Where we do not do something, this page says so.

The four principles behind everything below

  • Minimum necessary. Nobody sees more than the work requires, including us.
  • Access is granted, never assumed. Permissions attach to a role on a named account, not to employment.
  • Work where you already are. Wherever possible we operate inside your systems, so records stay under your control.
  • Say it plainly. If something goes wrong, you hear it from us, early, in writing.
HIPAA, Briefly

What HIPAA actually requires, and where a billing company fits into it

HIPAA is the Health Insurance Portability and Accountability Act of 1996. The parts that matter here are its Privacy Rule, its Security Rule and its Breach Notification Rule, enforced by the Office for Civil Rights at the US Department of Health and Human Services.

Covered entity vs business associate

A covered entity is a healthcare provider, health plan or clearinghouse, which is your practice. A business associate is an outside organisation that creates, receives, maintains or transmits protected health information on a covered entity's behalf.

A medical billing company is the textbook example of a business associate. So is a credentialing service that handles provider and patient records. When Edge RCM performs that work for you, we are your business associate, and HIPAA applies to us directly, not only through our contract with you.

Why it matters to your practice

Since the HITECH Act, business associates can be penalised by the Office for Civil Rights in their own right. But that does not transfer your exposure to us. If a vendor mishandles your patients' information, it is still your patients, your notification duty and your reputation in the local paper. Choosing who gets access is a clinical-grade decision, and it deserves the same scrutiny you would apply to any other risk.

How Edge RCM operates

We work as a business associate under a signed agreement, apply the minimum-necessary standard to every request for information, restrict access by role, require confidentiality undertakings from staff who touch protected health information, and prefer to work inside your own practice management system or clearinghouse rather than take copies of records we do not need.

Those practices are described in detail further down this page, in the language of what we do rather than the language of what sounds impressive.

One thing we will not claim. Edge RCM is not "HIPAA certified", and neither is any other company, because there is no such thing. The Department of Health and Human Services does not certify, accredit or endorse any organisation as HIPAA compliant, and it has said so publicly. A vendor advertising a HIPAA certification badge is showing you a privately sold training course or a paid audit, not federal approval. Compliance under HIPAA is an ongoing obligation demonstrated by practice, and by a signed Business Associate Agreement that makes it enforceable, not a certificate on a wall.
Business Associate Agreement

Yes, we sign a BAA, before any work touching patient data begins

It is the single most useful question a practice can ask a prospective vendor, and the answer should never be complicated.

What a BAA is, in plain terms

A Business Associate Agreement is a written contract, required by HIPAA, between a covered entity and any outside organisation that will handle protected health information on its behalf. It sets out what the business associate may do with that information, what it may not do, the safeguards it must apply, what happens if there is a breach, and what happens to the data when the relationship ends.

Providers ask for one because HIPAA does not permit you to share protected health information with a vendor without it. Engaging a billing or credentialing company without a BAA in place is itself a compliance failure on the practice's side, which is why the request is not bureaucratic caution, it is the rule.

How it works with us

We execute a BAA before beginning any engagement that involves protected health information. You are welcome to use your own template or have your counsel review ours. We have no interest in arguing about a document whose entire purpose is to protect your patients.

What our BAA commits us to

  • Using protected health information only for the services described in your agreement
  • Applying appropriate safeguards and the minimum-necessary standard
  • Binding any subcontractor to the same obligations before it sees anything
  • Reporting any use or disclosure not permitted by the agreement, without delay
  • Assisting you with patient access and amendment requests that reach us
  • Returning or destroying protected health information when the engagement ends
How We Protect Information

The safeguards, described as practices rather than buzzwords

Each of these is something a member of our team does or does not do on an ordinary working day. None of them requires you to take a technical claim on faith.

Secure data handling

Protected health information is handled only for the task at hand and is not copied into personal drives, personal email or messaging apps.

Minimum necessary access

Requests are scoped to what the work needs. A credentialing task does not require a patient ledger, so it does not get one.

Role-based permissions

Access follows the role on your account. Joining an account grants it, leaving the account removes it, and no role inherits access company-wide.

Employee confidentiality

Everyone who may encounter protected health information signs a confidentiality undertaking, and those obligations continue after they leave.

Secure communication

Patient identifiers are not sent in ordinary email or chat. Where information must move, it moves through the channel you and we agree in advance.

Individual accounts, strong authentication

Named logins rather than shared credentials, with multi-factor authentication enabled wherever the system you use supports it.

Device security

Work happens on protected, password-locked machines with screen locks and current updates, not on unattended or shared devices.

Ongoing staff awareness

Privacy and security training at onboarding and refreshed regularly, including the phishing and social-engineering patterns aimed at practices.

Responsible retention and disposal

Information is kept only while there is a reason to keep it, then returned or destroyed in line with your Business Associate Agreement.

Transparency & Trust

The commitments that sit behind the safeguards

Controls can be described on a website by anyone. These are the habits that decide whether they are actually followed.

Honest communication

If we make a mistake with your data, you hear it from us promptly, in writing, with what happened and what we are doing about it. A vendor who reports their own error is worth more than one who has never admitted to any.

Ethical business practice

We do not upcode, we do not bill for what was not delivered, and we will tell you when something you have asked for is not defensible. Compliance is not only about privacy.

Transparency about limits

We publish what we do not claim as clearly as what we do. When you ask a question we cannot answer with certainty, you will get "I do not know, I will find out" rather than a confident guess.

Confidentiality that outlasts the contract

Your information is not a case study, a marketing example or a data set. Confidentiality obligations survive the end of the engagement, and your records leave with you.

Long-term partnership

Shortcuts around privacy are how a vendor wins a quarter and loses a client. We are built around keeping practices for years, which makes carelessness expensive for us too.

Compliance FAQs

The questions compliance officers ask us

Something not covered here? Call +1 (855) 307-4535 or email [email protected].

Yes. Where Edge RCM will create, receive, maintain or transmit protected health information on your behalf, we execute a Business Associate Agreement before that work begins. You are welcome to use your own template, or your counsel can review ours. If a prospective vendor is reluctant to sign one, that itself tells you something.

No, and neither is anyone else. The US Department of Health and Human Services does not certify, endorse or accredit any organisation as HIPAA compliant, and no government-issued HIPAA certification exists. Companies advertising themselves as “HIPAA certified” are describing a privately sold training course or audit, not federal approval.

What is real is the legal obligation. As a business associate handling protected health information, Edge RCM is directly subject to the HIPAA Security Rule and to the applicable provisions of the Privacy and Breach Notification Rules, enforceable by the Office for Civil Rights and by the Business Associate Agreement we sign with you. That is a stronger assurance than a badge, because it carries consequences.

Access is limited to the staff assigned to your account, and to the minimum information they need to do the work. Team members sign confidentiality agreements, use individual accounts rather than shared logins, and receive ongoing training on handling protected health information.

Wherever possible we work inside your own practice management system or clearinghouse, so records stay in the environment you already control rather than being copied somewhere else. The full list is in How We Protect Information above.

Yes. Our clients are physicians, group practices, therapy and behavioral health providers, laboratories and telehealth organisations, most of which are covered entities under HIPAA. When we perform billing, credentialing or administrative work involving protected health information for them, Edge RCM acts as their business associate under a signed agreement.

Only the people working your account, and only for the parts of the work they are assigned to. Permissions follow the role rather than the person: access is granted when someone joins an account and removed when they leave it. Access is never a default that everyone in the company inherits, and we can tell you who those individuals are if you ask.

Confidentiality obligations in our agreements survive the end of the engagement, and the Business Associate Agreement governs what happens to protected health information afterwards, including return or destruction where required. Your records remain yours: if you leave, you leave with your data, and we do not hold it back as leverage.

Before You Engage Anyone

Bring us your compliance questions first

Ask for the BAA, ask who will have access, ask what happens to your data if you leave. Ask us, and ask whoever else you are considering. The answers will tell you a great deal before a single claim is submitted.

This page describes how Edge RCM handles protected health information. It is general information about our practices, not legal advice, and it does not replace your own HIPAA risk analysis or the terms of your signed agreements. For how this website itself handles personal data, see our Privacy Policy.