Billing in all 50 statesHIPAA · SOC 2 Type IIMon–Fri, 7:00 AM – 7:00 PM CT
+1 (855) 402-7188
Get a quote

Last Updated: 10/7/2026

1. Our Role as a HIPAA Business Associate

LabMed Billing ("LabMed Billing") provides laboratory credentialing, coding, denial management, insurance verification, and accounts receivable management services to laboratory clients. In performing these services, we create, receive, maintain, and transmit protected health information (PHI) on behalf of our clients, which makes us a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

Every client relationship involving PHI is governed by a signed Business Associate Agreement (BAA), which defines the permitted uses and disclosures of PHI and our obligations to safeguard it.

2. Our Safeguards

We maintain administrative, physical, and technical safeguards consistent with the HIPAA Security Rule:

Administrative Safeguards

Written policies governing PHI access, workforce training, role-based access controls, and periodic risk assessments.

Physical Safeguards

Controlled access to facilities and workstations where PHI is accessed, along with device and media controls for any hardware handling PHI.

Technical Safeguards

Encryption of PHI in transit and at rest, unique user authentication, audit logging, and automatic session timeouts on systems handling PHI.

3. Workforce Training

All team members who access PHI complete HIPAA training before handling client data and receive periodic refresher training thereafter. Access to PHI is limited to personnel whose role requires it, consistent with the HIPAA minimum necessary standard.

4. Minimum Necessary Standard

We limit our use, disclosure, and request of PHI to the minimum necessary to accomplish the billing, coding, credentialing, or collections task at hand, in accordance with HIPAA's minimum necessary requirement.

5. Subcontractors

Where we engage subcontractors that may access PHI in support of our services, those subcontractors are bound by written agreements requiring the same HIPAA safeguards and restrictions that apply to us, consistent with HIPAA's Business Associate subcontractor requirements.

6. Breach Notification

In the event of a breach involving unsecured PHI, we follow the notification procedures required under the HIPAA Breach Notification Rule, including timely notification to the affected client, so that the client, as the HIPAA Covered Entity, can meet its own notification obligations to affected patients and, where required, regulators.

7. Business Associate Agreements

Before any PHI is exchanged, we execute a Business Associate Agreement with each client laboratory or provider. This agreement defines permitted uses and disclosures of PHI, safeguard requirements, breach notification obligations, and terms for the return or destruction of PHI at the end of the engagement.

8. Patient Inquiries

If you have questions about your health information, please contact your healthcare provider or the laboratory directly. As a Business Associate, LabMed Billing processes PHI on behalf of client laboratories, which serve as the HIPAA Covered Entity responsible for responding to patient requests regarding access, amendment, or accounting of disclosures.

9. Ongoing Compliance

We periodically review our policies, safeguards, and workforce training to reflect changes in HIPAA regulations and evolving security practices, and we update our Business Associate Agreements and internal procedures as needed to maintain compliance.

10. Contact Our Compliance Officer

Questions about our HIPAA compliance practices can be directed to:

Attn: [Compliance/Security Officer name or title]

Email: [Insert compliance contact email]

Phone: [Insert phone number]

Address: [Insert business address]