HIPAA & Security Information
Last updated August 2026.
Our role
When MBS performs billing and revenue cycle services that involve protected health information (PHI) on behalf of a covered entity, MBS acts as a “business associate” as defined by HIPAA.
Business Associate Agreements
MBS enters into a written Business Associate Agreement (BAA) with each covered-entity client before receiving PHI. The BAA defines permitted uses and disclosures, safeguard obligations, subcontractor requirements, breach-notification duties and return or destruction of PHI at the end of the engagement.
Safeguards we maintain
- Role-based access and unique user credentials
- Least-privilege permissions and periodic access reviews
- Encrypted transmission and secure file exchange
- Workforce HIPAA privacy and security training
- Signed confidentiality agreements for all personnel
- Logging and monitoring of systems containing PHI
- A documented incident-response and breach-notification process
- Backup and recovery procedures for systems we operate
What we do not claim
MBS does not represent itself as “HIPAA certified.” HIPAA does not provide an official certification. Where a specific third-party audit, attestation or framework applies, it will be named explicitly on our Security & Compliance page.
Do not send PHI through this website
This website's forms are not a secure channel for PHI. Please do not submit patient information through them. Contact us and we will establish a secure method.
Reporting a concern
To report a suspected privacy or security concern, email info@mbsbillingservices.com. We will investigate under our incident-response process and notify affected clients as required by the applicable BAA and law.
Questions about this document? Email info@mbsbillingservices.com or write to us via our contact page.