Compliance
HIPAA Compliance
247 Medical Billing Services LLC ("247 MBS") handles Protected Health Information as a HIPAA Business Associate. This page is an overview of the safeguards we apply to keep PHI confidential, available, and secure across our revenue-cycle workflows.
Informational overview. This page describes our general approach to HIPAA. It is not a Notice of Privacy Practices, a legal agreement, or a substitute for one. Actual PHI handling is governed by executed Business Associate Agreements. Please have your compliance and legal teams review this content before publishing.
1Our Commitment to HIPAA
247 MBS has managed medical billing and revenue-cycle operations for U.S. healthcare providers since 2005. Protecting Protected Health Information ("PHI") is central to how we work. We handle PHI in accordance with the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), the HITECH Act, and applicable implementing regulations, including the HIPAA Privacy, Security, and Breach Notification Rules.
2Our Role as a Business Associate
When we perform billing, coding, credentialing, and related services for a covered entity, 247 MBS acts as a Business Associate under HIPAA. In that role, we use and disclose PHI only as permitted by our Business Associate Agreement with the covered entity and as required to perform the contracted services — for the purposes of treatment, payment, and healthcare operations.
PHI belongs to the covered entity. We do not sell PHI, and we do not use it for any purpose beyond providing the services set out in our agreements or as required by law.
3Administrative Safeguards
- Documented policies and procedures governing the use, disclosure, and protection of PHI;
- A designated security and privacy function responsible for our HIPAA program;
- Risk analysis and risk-management processes to identify and address vulnerabilities;
- Role-based access so team members can reach only the PHI required for their work;
- Incident-response and sanction procedures for policy violations.
4Physical Safeguards
- Controlled, restricted access to facilities and work areas where PHI may be handled;
- Workstation-use and device policies covering how equipment is positioned, used, and secured;
- Secure handling and disposal of media and any physical materials that may contain PHI.
5Technical Safeguards
- Encryption of PHI in transit and at rest using industry-standard methods;
- Unique user credentials, strong authentication, and access controls;
- Audit logging and monitoring of access to systems that contain PHI;
- Working inside clients' existing practice-management and EHR systems under their access controls, rather than moving PHI to unnecessary locations.
6Workforce Training & Access
Team members who handle PHI receive HIPAA privacy and security training, and access to PHI is granted on a least-privilege, need-to-know basis. Access is reviewed and adjusted as roles change, and is revoked promptly when it is no longer required.
7Business Associate Agreements
Before we handle PHI for a client, we execute a Business Associate Agreement (BAA) that defines the permitted uses and disclosures of PHI, our safeguard obligations, breach-notification responsibilities, and the return or destruction of PHI at the end of the engagement. Where we rely on subcontractors that may access PHI, we require equivalent written assurances from them.
8SOC 2 Type II & Ongoing Assessment
In addition to HIPAA, our controls are evaluated under a SOC 2 Type II framework covering security and related trust-service criteria. We treat compliance as an ongoing program — reviewing policies, controls, and risks on a recurring basis rather than as a one-time exercise.
9Report a Concern or Request Our BAA
To request a Business Associate Agreement, ask about our safeguards, or report a privacy or security concern, please contact us. Do not include PHI in general contact or quote-request forms.
247 Medical Billing Services LLC
16192 Coastal Hwy, Lewes, DE 19958, United States