Privacy and security, handled the way a healthcare operation should

We take the protection of patient and practice information seriously. This page describes the safeguards we actually maintain — and is careful about the claims it does not make.

Our commitment

Safeguards built into how we work

MBS Medical Billing Services designs its workflows around appropriate administrative, technical and physical safeguards for protected health information (PHI).

Role-based access

Staff receive the minimum access needed for their role, with unique credentials and no shared logins.

Access controls

Least-privilege permissions, session controls and periodic access reviews for systems containing PHI.

Secure transmission

Encrypted file transfer and secure portals for any exchange of sensitive information.

Workforce HIPAA training

All personnel complete HIPAA privacy and security training and sign confidentiality agreements.

Monitoring

Access to PHI-containing systems is logged and reviewed for unusual activity.

Incident response

A documented process for identifying, containing, investigating and reporting any suspected incident.

Data backup

Regular backup procedures and recovery planning for the systems we operate.

Business Associate Agreements

When we handle PHI for a covered entity, we work under a signed BAA with defined obligations.

HIPAA & BAAs

What we do — and don't — claim

When MBS handles PHI on behalf of a covered entity, we act as a business associate under a signed Business Associate Agreement and maintain policies designed to safeguard that information.

  • We sign BAAs before receiving PHI.
  • We maintain written privacy and security policies.
  • We limit PHI access to workforce members who need it.
We do not describe ourselves as “HIPAA certified.” HIPAA has no official certification program. Any security framework, audit or attestation will be named specifically here only once it genuinely applies.

Handling of protected health information

PHI is used only for the billing and revenue cycle purposes authorized by the practice and permitted under the BAA. We do not sell PHI, and we do not use it for any purpose beyond the services engaged.

Your responsibilities as a covered entity

Practices remain responsible for their own HIPAA obligations, including the accuracy of clinical documentation, their Notice of Privacy Practices, and the security of systems and networks under their control.

Reporting a concern

If you believe information has been handled improperly, contact us at info@mbsbillingservices.com so we can investigate under our incident-response process. See our HIPAA Notice and Privacy Policy for more detail.

Have a security questionnaire?

Many practices and their counsel send a vendor security questionnaire before signing. Send yours over and we'll complete it as part of the assessment.