Healthcare SBC

HIPAA Compliance & Data Protection

Last updated: September 19, 2026

Healthcare SBC follows HIPAA. This page describes, in general terms, how we safeguard protected health information (PHI) under the HIPAA Privacy, Security and Breach Notification Rules. It is not a Notice of Privacy Practices. That document is issued by your healthcare provider as the covered entity.

Compliance is not optional and it is not a feature we upsell. The safeguards below are the baseline we operate to for every client, on every engagement.

Our role

When we provide revenue cycle management, coding, credentialing, interoperability, transcription, document indexing, staffing or platform services, we create, receive, maintain or transmit PHI on behalf of healthcare providers. In that capacity we are directly subject to applicable provisions of the HIPAA Privacy, Security and Breach Notification Rules, and we apply the safeguards described below to every engagement.

Administrative safeguards

  • Documented policies and procedures governing PHI access, use and disclosure
  • Workforce HIPAA training at hire and annually thereafter, with completion tracked
  • Role-based access provisioning under the minimum necessary standard
  • Periodic security risk analysis with documented remediation
  • Sanctions policy for workforce members who violate PHI policies
  • Documented incident response and breach notification procedures

Technical safeguards

  • Encryption of PHI in transit and at rest using current industry-standard algorithms
  • Unique user identification with multi-factor authentication on remote access
  • Automatic session termination after defined periods of inactivity
  • Comprehensive audit logging of PHI access, with logs retained and reviewed
  • Network segmentation, endpoint detection and response, and vulnerability management
  • Encrypted, access-controlled backups with tested restore procedures

Physical safeguards

  • Access-controlled facilities for workforce members handling PHI
  • Restrictions on removable media and printing in PHI-handling environments
  • Secure device management, including full-disk encryption and remote wipe capability
  • Documented media disposal and sanitization procedures

International and subcontractor operations

Some services, including coding, A/R follow-up and document indexing, may be performed by workforce members located outside the United States. Those personnel operate in secure, access-controlled facilities, with restrictions on data export and removable media, role-based access to client systems, full audit logging and annual HIPAA training. Clients are told where their work is performed and may restrict it.

Breach notification

We maintain a documented incident response process. If we discover a breach of unsecured PHI, we will notify the affected healthcare provider without unreasonable delay and no later than the timeframe required by the HIPAA Breach Notification Rule, and we will cooperate in that provider’s investigation, risk assessment and notification obligations.

Return or destruction of PHI

At termination of a client engagement, we return or destroy the PHI we hold. Where return or destruction is infeasible, we continue to apply the safeguards described on this page to the retained information and limit further uses and disclosures to those that make return or destruction infeasible.

Reporting a concern

To report a suspected privacy or security incident involving Healthcare SBC, contact privacy@healthcaresbc.com immediately, or call our support line and ask to escalate to the security on-call team. Suspected breaches are triaged ahead of every other queue during our support hours, Monday to Friday, 8 a.m. to 8 p.m. ET.