HIPAA & Security Information

Last updated August 2026.

Our role

When MBS performs billing and revenue cycle services that involve protected health information (PHI) on behalf of a covered entity, MBS acts as a “business associate” as defined by HIPAA.

Business Associate Agreements

MBS enters into a written Business Associate Agreement (BAA) with each covered-entity client before receiving PHI. The BAA defines permitted uses and disclosures, safeguard obligations, subcontractor requirements, breach-notification duties and return or destruction of PHI at the end of the engagement.

Safeguards we maintain

  • Role-based access and unique user credentials
  • Least-privilege permissions and periodic access reviews
  • Encrypted transmission and secure file exchange
  • Workforce HIPAA privacy and security training
  • Signed confidentiality agreements for all personnel
  • Logging and monitoring of systems containing PHI
  • A documented incident-response and breach-notification process
  • Backup and recovery procedures for systems we operate

What we do not claim

MBS does not represent itself as “HIPAA certified.” HIPAA does not provide an official certification. Where a specific third-party audit, attestation or framework applies, it will be named explicitly on our Security & Compliance page.

Do not send PHI through this website

This website's forms are not a secure channel for PHI. Please do not submit patient information through them. Contact us and we will establish a secure method.

Reporting a concern

To report a suspected privacy or security concern, email info@mbsbillingservices.com. We will investigate under our incident-response process and notify affected clients as required by the applicable BAA and law.


Questions about this document? Email info@mbsbillingservices.com or write to us via our contact page.