Skip to main content

Medical Billing Companies | Practice Management & RCM

Billing Compliance and HIPAA Requirements: Essential Guide for Providers

Table of Contents

In April 2025, OCR settled with Northeast Radiology, a clinical imaging provider operating across New York and Connecticut, for $350,000. The cause wasn’t a dramatic hack — it was unauthorized access to radiology images sitting on an unsecured PACS server for the better part of a year, exposing nearly 300,000 patients’ records. The organization’s real failure, according to OCR, was never having conducted an accurate risk analysis in the first place. That single missing document turned an IT oversight into a six-figure settlement and a two-year corrective action plan.

This is the pattern regulators keep finding, case after case: the breach itself is rarely the violation. The absence of a documented risk analysis is. And in billing operations specifically — where claims data, demographics, and diagnosis codes move constantly between systems, vendors, and staff — that gap is one of the easiest to overlook and one of the most consistently penalized.

At Kaizen Systems, compliance is treated as part of the billing workflow itself, not a separate box to check afterward. Here’s what the current enforcement landscape actually shows providers about billing compliance and HIPAA.

The Enforcement Climate Has Shifted

OCR’s Risk Analysis Initiative, launched in late 2024, has produced a steady stream of settlements built around one recurring finding: organizations couldn’t produce evidence they’d ever assessed their own security risks. By early 2026, this initiative alone had closed more than a dozen cases.

A few of the settlements make the pattern impossible to miss:

  • Comstar, LLC — a Massachusetts company handling billing and collections for ambulance services — settled for an undisclosed penalty in May 2025 after a ransomware attack it didn’t detect for a full week exposed the ePHI of over 585,000 individuals across more than seventy covered-entity clients. OCR’s finding: no accurate, thorough risk analysis.
  • Assured Imaging, a medical imaging and screening provider, paid $375,000 in April 2026 after failing to produce any evidence a risk analysis had ever been completed — on top of an impermissible disclosure affecting 244,813 individuals and a breach notification that arrived well past the required 60-day window.
  • Regional Women’s Health Group paid $320,000 for a similar risk-analysis failure tied to a breach affecting nearly 38,000 individuals.
  • MMG Fusion, a healthcare software vendor, settled for $10,000 in March 2026 — a smaller figure OCR explicitly tied to the company’s financial condition — despite a breach that impermissibly disclosed PHI belonging to roughly 15 million individuals.

That last case is worth sitting with. The settlement amount had almost nothing to do with the size of the breach and everything to do with whether the organization could show it had acted responsibly. Scale doesn’t drive the penalty. Documentation does.

What the Penalty Tiers Actually Look Like in 2026

HIPAA fines run on a four-tier structure tied to culpability, and the dollar figures adjust for inflation each year. As of 2026:

TierBasisPer-Violation RangeAnnual Cap (Identical Violations)
1No knowledge, couldn’t reasonably have known$145 – $73,011$2,190,294
2Reasonable cause, not willful neglect$1,461 – $73,011$2,190,294
3Willful neglect, corrected within 30 days$14,602 – $73,011$2,190,294
4Willful neglect, not corrected$73,011 – $2,190,294$2,190,294

Most billing-related settlements land in Tier 1 or 2 — not because the violations are minor, but because OCR generally treats an incomplete compliance program differently from a knowingly ignored one. Still, the practical cost of a HIPAA incident rarely stops at the fine itself. Forensic investigation, breach notification mailings, credit monitoring for affected patients, and legal fees typically add far more than the civil penalty, and healthcare breaches now average well over $10 million per incident industry-wide when every downstream cost is counted.

The Three Rules That Govern Billing Data Specifically

The Privacy Rule (45 C.F.R. Part 160 and Subparts A and E of Part 164) sets the “minimum necessary” standard — a biller submitting a claim needs the patient’s demographics, insurance details, and the relevant CPT and ICD-10 codes. Full clinical notes or unrelated chart history aren’t part of that job.

The Security Rule (45 C.F.R. Part 160 and Subparts A and C of Part 164) requires a documented risk analysis under §164.308(a)(1)(ii)(A) — the exact provision cited in nearly every recent settlement — paired with administrative, physical, and technical safeguards like role-based access, unique logins, and encryption.

The Breach Notification Rule (45 C.F.R. Part 160 and Subpart D of Part 164) requires notifying affected individuals and HHS within 60 days of discovering a breach. Assured Imaging’s settlement shows this is treated as its own separate, “stackable” violation — missing the window compounds the penalty even when the underlying breach is otherwise handled correctly.

Where Billing Operations Specifically Get Flagged

No documented risk analysis, or one that’s gone stale. This is the single most common finding across nearly every recent settlement. A risk analysis completed three years ago, before a new billing vendor or EHR migration, doesn’t count as current.

Missing or outdated Business Associate Agreements. Every vendor touching PHI on your behalf — billing companies, clearinghouses, statement vendors, cloud storage, even a shredding service — needs a signed BAA before any data changes hands. Comstar’s case is a reminder of how much exposure sits with a single billing vendor serving dozens of covered entities at once.

Access that isn’t role-based. Billing staff need financial and demographic data, not full clinical charts. Unrestricted “general admin” access is a recurring finding auditors flag, and it’s also how insider snooping incidents happen in the first place.

Delayed or incomplete breach notification. The 60-day clock starts at discovery, not confirmation. Waiting to notify until an investigation is “complete” is itself a separate violation.

Right of Access delays. OCR’s Right of Access initiative has produced over 50 enforcement actions, including a $112,500 settlement with Concentra, Inc. in 2025 over a patient who waited more than a year for records after six separate requests. This applies directly to billing departments that field record and account requests.

Building a Program That Holds Up Under Scrutiny

Conduct — and redo — a real risk analysis. Not a template. OCR consistently asks organizations to prove they identified specific vulnerabilities and then acted on them, not just that a document exists. Repeat it after any meaningful change: a new vendor, a new billing platform, expanded remote access.

Keep every BAA current and accessible. If you can’t produce it during an audit, it doesn’t count, regardless of whether the vendor itself was actually compliant.

Lock down access by role. Unique logins, automatic log-off, and encrypted communication are quickly moving from “recommended” to effectively mandatory as proposed Security Rule updates remove the “addressable” flexibility many practices have relied on.

Treat the 60-day breach clock as non-negotiable. Build the notification workflow before you need it, not while you’re investigating an active incident.

Connect billing compliance to broader fraud exposure. Upcoding, unbundling, and billing without supporting documentation intersect with the False Claims Act, Anti-Kickback Statute, and Stark Law — a HIPAA gap and a billing-accuracy gap often trace back to the same underlying process failure.

Compliance Protects Revenue as Much as Reputation

The organizations named above didn’t just pay a settlement — they signed multi-year corrective action plans with ongoing OCR monitoring, and in several cases had to rebuild processes that should have existed from day one. The same discipline that prevents that outcome — current BAAs, role-based access, a risk analysis that’s actually acted on — also tends to be the discipline that keeps claims clean and denials down.

Let’s Get Your Billing Compliance Audit-Ready

If your last risk analysis predates your current billing vendor, or you’re not certain every BAA on file is current, that’s worth resolving on your own timeline rather than OCR’s. Kaizen Systems can run a focused compliance review across your billing workflow and help close the gaps before they become a finding. Reach out to get started.

    More
    articles