Your revenue matters. Your patient data is non-negotiable.
Security
Pure Billing operates as a HIPAA business associate. PHI stays inside your systems of record, access is granted at the minimum level required, and every safeguard below applies from the first day of the engagement.
Approach
Administrative, physical and technical controls
Pure Billing operates as a HIPAA business associate. PHI stays inside your systems of record, access is granted at the minimum level required, and every safeguard below applies from the first day of the engagement.
Administrative
HIPAA-trained workforce
Every team member completes HIPAA Privacy and Security Rule training before being granted access to a practice system, with periodic refresher training and assessment. Access is granted by named individual, never shared.
Administrative
Business Associate Agreement first
A BAA is executed with your practice before any member of our team receives credentials. It defines permitted use of PHI, subcontractor obligations, breach notification duties and what happens to data at the end of the engagement.
Technical
Least-privilege access
We request only the roles required for the agreed scope of work inside your EHR, PMS, clearinghouse and payer portals. Access is reviewed when scope changes and revoked promptly when a team member leaves the account.
Technical
Encrypted transfer, no local copies
Documents such as superbills and remittances move over secure file transfer or inside your own system. PHI is worked within your systems of record rather than copied to local machines or personal storage.
Physical
Controlled work environment
Operations run from access-controlled offices with CCTV monitoring, supervised floors and restricted use of personal devices and removable media in production areas.
Technical
Hardened IT infrastructure
Endpoints and networks are protected with managed antivirus, firewalling, patching and unique authenticated accounts. Technology used in the billing workflow is evaluated for HIPAA suitability before adoption.
Administrative
Internal audit and quality review
Charges are reviewed by quality analysts before submission, and access and handling practices are audited at regular intervals so gaps are found internally rather than by a payer or a patient complaint.
Administrative
Incident response and notification
Suspected privacy or security incidents are escalated immediately to account leadership and reported to the covered entity in line with the BAA and the HIPAA Breach Notification Rule, with a written account of what occurred and what changed.
Administrative
Retention and end-of-engagement handling
Because PHI stays in your systems, offboarding is principally credential revocation. Any working files held for the engagement are returned or securely destroyed on the schedule agreed in the BAA.
Where PHI lives
Your data does not move to us.
Vendor review
What we provide on request
Other specialties
Using something unusual, or something home-grown?
Send us your questionnaire and we will complete it directly, including the items where the accurate answer is that a control is handled by your systems rather than ours.
Other specialties
Please do not send protected health information (PHI) through the website forms or by unencrypted email. PHI is exchanged only through secured channels under an executed Business Associate Agreement.