Your revenue matters. Your patient data is non-negotiable.

Security

Pure Billing operates as a HIPAA business associate. PHI stays inside your systems of record, access is granted at the minimum level required, and every safeguard below applies from the first day of the engagement.

Approach

Administrative, physical and technical controls

Pure Billing operates as a HIPAA business associate. PHI stays inside your systems of record, access is granted at the minimum level required, and every safeguard below applies from the first day of the engagement.

Administrative

HIPAA-trained workforce

Every team member completes HIPAA Privacy and Security Rule training before being granted access to a practice system, with periodic refresher training and assessment. Access is granted by named individual, never shared.

Administrative

Business Associate Agreement first

A BAA is executed with your practice before any member of our team receives credentials. It defines permitted use of PHI, subcontractor obligations, breach notification duties and what happens to data at the end of the engagement.

Technical

Least-privilege access

We request only the roles required for the agreed scope of work inside your EHR, PMS, clearinghouse and payer portals. Access is reviewed when scope changes and revoked promptly when a team member leaves the account.

Technical

Encrypted transfer, no local copies

Documents such as superbills and remittances move over secure file transfer or inside your own system. PHI is worked within your systems of record rather than copied to local machines or personal storage.

Physical

Controlled work environment

Operations run from access-controlled offices with CCTV monitoring, supervised floors and restricted use of personal devices and removable media in production areas.

Technical

Hardened IT infrastructure

Endpoints and networks are protected with managed antivirus, firewalling, patching and unique authenticated accounts. Technology used in the billing workflow is evaluated for HIPAA suitability before adoption.

Administrative

Internal audit and quality review

Charges are reviewed by quality analysts before submission, and access and handling practices are audited at regular intervals so gaps are found internally rather than by a payer or a patient complaint.

Administrative

Incident response and notification

Suspected privacy or security incidents are escalated immediately to account leadership and reported to the covered entity in line with the BAA and the HIPAA Breach Notification Rule, with a written account of what occurred and what changed.

Administrative

Retention and end-of-engagement handling

Because PHI stays in your systems, offboarding is principally credential revocation. Any working files held for the engagement are returned or securely destroyed on the schedule agreed in the BAA.

Where PHI lives

Your data does not move to us.

We do not ask practices to migrate data into a Pure Billing platform. Eligibility checks, charge entry, claim scrubbing, submission, denial follow-up, payment posting and AR work are all performed inside the EHR, practice management system, clearinghouse and payer portals your practice already uses.

That keeps your audit trail in one place: every action our team takes is recorded against a named user in your own system, and you can review it at any time without asking us for a report.

Where a document must be exchanged — a superbill, a payer letter, a remittance — it moves over a secure file transfer channel agreed during onboarding, never over unencrypted email or consumer messaging apps.

Vendor review

What we provide on request

Pure Billing does not hold SOC 2 or HITRUST certification, and we will not imply otherwise during a vendor review. If your organisation requires an independent attestation, tell us early so we can agree the right scope with you.

Other specialties

Using something unusual, or something home-grown?

Send us your questionnaire and we will complete it directly, including the items where the accurate answer is that a control is handled by your systems rather than ours.

Other specialties

Please do not send protected health information (PHI) through the website forms or by unencrypted email. PHI is exchanged only through secured channels under an executed Business Associate Agreement.

Scroll to Top