HIPAA Compliance & Data Protection
Last updated: September 19, 2026
Healthcare SBC follows HIPAA. This page describes, in general terms, how we safeguard protected health information (PHI) under the HIPAA Privacy, Security and Breach Notification Rules. It is not a Notice of Privacy Practices. That document is issued by your healthcare provider as the covered entity.
Compliance is not optional and it is not a feature we upsell. The safeguards below are the baseline we operate to for every client, on every engagement.
Our role
When we provide revenue cycle management, coding, credentialing, interoperability, transcription, document indexing, staffing or platform services, we create, receive, maintain or transmit PHI on behalf of healthcare providers. In that capacity we are directly subject to applicable provisions of the HIPAA Privacy, Security and Breach Notification Rules, and we apply the safeguards described below to every engagement.
Administrative safeguards
- Documented policies and procedures governing PHI access, use and disclosure
- Workforce HIPAA training at hire and annually thereafter, with completion tracked
- Role-based access provisioning under the minimum necessary standard
- Periodic security risk analysis with documented remediation
- Sanctions policy for workforce members who violate PHI policies
- Documented incident response and breach notification procedures
Technical safeguards
- Encryption of PHI in transit and at rest using current industry-standard algorithms
- Unique user identification with multi-factor authentication on remote access
- Automatic session termination after defined periods of inactivity
- Comprehensive audit logging of PHI access, with logs retained and reviewed
- Network segmentation, endpoint detection and response, and vulnerability management
- Encrypted, access-controlled backups with tested restore procedures
Physical safeguards
- Access-controlled facilities for workforce members handling PHI
- Restrictions on removable media and printing in PHI-handling environments
- Secure device management, including full-disk encryption and remote wipe capability
- Documented media disposal and sanitization procedures
International and subcontractor operations
Some services, including coding, A/R follow-up and document indexing, may be performed by workforce members located outside the United States. Those personnel operate in secure, access-controlled facilities, with restrictions on data export and removable media, role-based access to client systems, full audit logging and annual HIPAA training. Clients are told where their work is performed and may restrict it.
Breach notification
We maintain a documented incident response process. If we discover a breach of unsecured PHI, we will notify the affected healthcare provider without unreasonable delay and no later than the timeframe required by the HIPAA Breach Notification Rule, and we will cooperate in that provider’s investigation, risk assessment and notification obligations.
Return or destruction of PHI
At termination of a client engagement, we return or destroy the PHI we hold. Where return or destruction is infeasible, we continue to apply the safeguards described on this page to the retained information and limit further uses and disclosures to those that make return or destruction infeasible.
Reporting a concern
To report a suspected privacy or security incident involving Healthcare SBC, contact privacy@healthcaresbc.com immediately, or call our support line and ask to escalate to the security on-call team. Suspected breaches are triaged ahead of every other queue during our support hours, Monday to Friday, 8 a.m. to 8 p.m. ET.
