HIPAA Notice
Last updated: 10 October 2026
This notice explains how MBCA (“we”) approaches the Health Insurance Portability and Accountability Act of 1996 (HIPAA) when providing medical billing, coding and revenue cycle services.
Our role under HIPAA
Healthcare providers that bill electronically are “covered entities” under HIPAA. When we perform billing, coding, accounts-receivable, credentialing or prior-authorization work for a provider and need access to patient information to do it, we act as that provider’s business associate.
This page is not a Notice of Privacy Practices. Patients should contact their own healthcare provider for that provider’s Notice of Privacy Practices and to exercise their HIPAA rights. If we receive a patient request about a client’s records, we refer it to the client as our Business Associate Agreement requires.
A Business Associate Agreement comes first
We do not receive, create, maintain or transmit protected health information (PHI) for a practice until a signed Business Associate Agreement (BAA) is in place. The BAA sets out how we may use and disclose PHI, how we protect it and what happens if something goes wrong. See our BAA page.
This Website does not collect PHI
- Our assessment and contact forms ask for practice details only.
- The forms check entries and reject anything that looks like patient information, such as dates of birth, Social Security numbers, member IDs or medical record numbers.
- Please do not send PHI through Website forms, ordinary email, text message or social media. Once a BAA is signed, we set up the secure methods you will use to share patient and claim data.
- Website analytics does not receive the contents of our forms.
How we protect PHI for clients
Under each BAA we implement administrative, physical and technical safeguards as required by the HIPAA Security Rule, including:
- Access limited to staff who need it for the client’s work (minimum necessary), with unique user accounts
- HIPAA training for workforce members before access and at least annually
- Encryption of PHI in transit and at rest; secure file-transfer method used
- Work performed within the client’s EHR/PM system where possible
- BAAs with any subcontractors that handle PHI; offshore staff policy, if any
- Periodic risk analysis
If an incident happens
If we discover a breach of unsecured PHI, or a security incident involving a client’s data, we notify the affected client as required by HIPAA and within the time set in our BAA, and we cooperate with the client in its investigation and any required notifications.
Questions
Contact our privacy officer: Martin Jhones, martin@medicalbillingandcoding.services, +1 (737) 332-2245.
