The Office for Civil Rights (OCR) collected over $135 million in HIPAA settlements and civil monetary penalties in 2023–2024 — and enforcement is accelerating in 2025–2026. New cybersecurity-focused HIPAA rules finalized in early 2025 add specific technical requirements that directly affect billing operations.

Here's what changed, what it means for your billing department, and how to stay compliant.

What's New: HIPAA Security Rule Updates (Effective 2025)

The Department of Health and Human Services finalized significant updates to the HIPAA Security Rule in early 2025. Key changes affecting billing operations:

  1. Multi-factor authentication (MFA): Now required for all access to systems containing ePHI (electronic Protected Health Information). This includes your EHR, practice management system, billing software, and any portal where patient billing data is accessible.
  2. Encryption at rest: ePHI must be encrypted when stored — not just in transit. Cloud storage of billing data must meet this requirement.
  3. Annual vulnerability scanning: Required for all systems containing ePHI. Practices (and their billing vendors) must conduct annual technical vulnerability assessments.
  4. Incident response plans: Must be documented, tested, and updated annually. "We'll deal with it if it happens" is no longer acceptable.

Business Associate Agreements: The Billing Vendor Issue

Every billing company you work with is a Business Associate under HIPAA. A valid Business Associate Agreement (BAA) must be in place before you share any PHI with a billing vendor — including claims data, patient demographics, and ERA/EOB information.

Many practices have BAAs on file but haven't reviewed them since 2013. The 2025 Security Rule updates add new requirements to BAAs, including provisions around the new MFA, encryption, and vulnerability scanning requirements. If your BAA was signed before 2025, it may need to be updated.

Action item: Pull your BAA with every billing vendor and review it against the updated Security Rule requirements. Most reputable billing vendors will have updated their standard BAA. Request the current version and compare.

The 3 Most Common HIPAA Violations in Billing

Violation #1: Impermissible PHI Disclosures in Billing Communications

Patient billing statements, collection letters, and payment portal messages that include excessive PHI are a common violation source. The minimum necessary standard applies: only include PHI that's necessary for the billing purpose.

Example of a violation: A collection letter sent to a patient that includes their diagnosis codes, prescriptions, and treatment dates — when only the balance amount, service date, and provider name are necessary for collections.

Fix: Review your patient billing statement template and collection letter templates. Remove any PHI beyond what's minimally necessary for the billing communication.

Violation #2: Access Controls and Billing System User Management

Former employees retaining billing system access after termination is the #1 access control violation found in OCR audits. It's also completely preventable.

Common scenarios: A front-desk employee leaves and HR notifies the EHR system to deactivate their clinical access — but nobody notifies the billing software vendor, and the former employee can still log into the billing portal for months.

Fix: Create a formal termination checklist that explicitly lists every system with PHI access: EHR, practice management, billing software, clearinghouse portals, payment portals, and any cloud storage. Assign one person responsible for deactivating access across all systems within 24 hours of termination.

Violation #3: Unencrypted PHI Transmission

Sending patient billing information via regular email — even to the patient themselves — is a HIPAA violation if the email contains PHI. This includes superbills, explanation of benefits, billing statements with diagnosis codes, and similar documents.

The FTC Health Breach Notification Rule (which also has 2025 updates) adds additional requirements when health data is transmitted via unsecured channels.

Fix: Use a HIPAA-compliant secure messaging service or patient portal for all electronic communications containing PHI. Most EHR patient portals already provide this. For billing-specific communications, use a billing portal with TLS encryption, not email.

Breach Notification: The 2025 Updates

The updated HIPAA rules accelerate the breach notification timeline:

  • Individual notification: Must still occur within 60 days of discovery
  • HHS/OCR notification: For breaches affecting 500+ individuals in a state/jurisdiction, HHS must now be notified within 15 calendar days (down from 60 days)
  • Small breach reporting: Breaches affecting under 500 individuals must still be reported to HHS annually; the log must now be maintained in a standardized format

Practical Compliance Steps for Billing Departments

  1. Enable MFA on all billing systems immediately — EHR portals, billing software, clearinghouse accounts, payment processors
  2. Review and update BAAs with all billing vendors
  3. Conduct an annual HIPAA Security Risk Assessment (required regardless of practice size)
  4. Audit user access quarterly — deactivate any accounts for terminated or transferred employees
  5. Move all PHI-containing communications to secure, HIPAA-compliant channels
  6. Document your incident response plan — even a one-page plan is better than none

Is Your Billing HIPAA Compliant?

is SOC 2 Type II certified and fully HIPAA compliant. Our billing services include comprehensive BAA execution and follow all 2025 HIPAA Security Rule requirements.

Get a Secure Billing Audit