Evaluate a medical billing company on proof, not promises: a complete BAA, a current risk analysis or SOC 2 Type 2 report, monthly OIG exclusion screening, certified coders with outside audits, and raw access to your clearinghouse and remits. In our billing reviews, 19% of denied claims were never reworked or appealed.
We think the fee percentage is the least useful number in a billing contract. The compliance risk sits in what the practice cannot see: in our billing reviews, 19% of denied claims were never reworked or appealed, and the practice was rarely told. Ask for raw clearinghouse and remit access before you ask for a discount.
Methodology:Luxen figures come from four datasets: Luxen billing reviews (410 practice billing reviews, Jan 2025 to Jun 2026), Luxen claim audit (61,400 claims audited, Jan 2025 to Jun 2026), Luxen Practice Manager Survey 2026 (286 practice managers, March 2026) and Luxen client data (38 client practices, Jan 2024 to Jun 2026). Regulatory figures and penalty amounts come from the primary federal sources listed on this page. The worked example applies audit rates to a sample 3-provider practice.
Medical billing compliance means every claim sent under your NPI is coded from the documentation, billed to the right payer, protected under HIPAA and corrected when it is wrong. Outsourcing moves the work to a billing company. It does not move the liability. Medicare pays the practice, the claim carries your provider number, and the False Claims Act treats reckless disregard as knowing, with no proof of intent to defraud required.
Two rules make this sharper than most vendor pitches admit. Since January 1, 2025, CMS says a practice has identified an overpayment when it knowingly receives or retains one, using the False Claims Act definition, with a 6-year lookback and a 60-day deadline to report and return. And the OIG’s Compliance Program Guidance for Third-Party Medical Billing Companies, published in 1998 and still the only guidance written for billing vendors, lists seven elements a billing company should run: written policies, a compliance officer, training, a hotline, discipline, audits and monitoring, and correction of systemic problems, including a policy against employing sanctioned people.
So the evaluation question is not whether a vendor says it is compliant. It is whether it can show you each of those seven elements, and whether you can see enough of your own data to catch a problem before it becomes an overpayment you knowingly kept.
Both of you can be, and the practice is the easier target because it received the money. The OIG guidance names the risk areas it expects billing companies to police, including billing for services not documented, unbundling, upcoding, duplicate billing, failure to use modifiers correctly and inadequate resolution of overpayments. It also warns that percentage billing arrangements may increase the risk of upcoding. A clause saying the vendor indemnifies you helps with cost, not with exposure: the payer still recoups from your practice.
The stakes are specific. HIPAA penalties in tiers 1 to 3 reach $73,011 per violation, each False Claims Act claim carries $14,308 to $28,619 plus three times the damages, and contracting with an excluded person or keeping a known overpayment each carry $25,595 per item.
Evaluate a billing company by asking for documents and access, then checking them yourself. This order works in about two weeks of calls and document review:
A HIPAA compliant medical billing company signs a BAA that covers every element in 45 CFR 164.504(e): permitted uses only, appropriate safeguards and compliance with the Security Rule, reporting of any non-permitted use including breaches, the same terms flowed down to subcontractors, support for patient access, amendment and accounting of disclosures, books open to HHS, and return or destruction of all PHI at termination. HHS lists billing as business associate work, so there is no exception for small vendors.
Two more lines matter in practice. The vendor must notify you of a breach without unreasonable delay and in no case later than 60 calendar days after discovery. And the vendor must run its own risk analysis under 45 CFR 164.308. A SOC 2 Type 2 report shows its controls operated over a period; it is not a HIPAA certification, because no such federal certification exists.
Usually yes, when payer money goes into the practice’s own account. When Medicare pays a billing agent directly, 42 CFR 424.73 and 424.80 require that the agent’s pay is not related in any way to the dollar amounts billed or collected, and Medicaid’s rule at 42 CFR 447.10 says the same. Most percentage contracts stay outside those rules because the payer deposits to the practice and the vendor invoices separately. The fee shape still matters: 44% could not name the fee basis in their current billing contract, which means they cannot tell whether the vendor is paid on charges, collections or net collections. For how fee models compare on cost, see our guide on what billing companies charge and how to compare them.
Medical billing transparency means you can see your raw data without asking the vendor to pull it. Reports summarize; raw access lets you check the summary. The minimum is a read-only login to your clearinghouse, every 835 ERA, a write-off and adjustment log showing who approved each entry, a denial report by CARC reason code, and an underpayment report against your contracted rates.
This is where vendors differ most. The top three denial reasons accounted for 58% of denied dollars in the average practice we reviewed, yet 63% could not name their top three denial reasons. 52% of practices that switched billing vendors cited missing denial reporting as the main reason. A vendor that reports denials by reason, with dollars and the fix owned by a named person, is doing the part most practices never see. Our denial and AR recovery work starts from that report.
In the Luxen claim audit of 61,400 claims, eligibility and coverage errors caused 24% of denials, coding and modifier errors 21%, missing or invalid prior authorization 17%, duplicate claims 9% and timely filing 6%, leaving 23% for all other causes.
Duplicates and timely filing are the two causes that point straight at vendor process. Duplicates come mostly from resubmitting instead of correcting. Timely filing losses are nearly permanent: Medicare’s limit is one calendar year from the date of service, and only 4% of timely filing denials were recovered.
A medical billing audit of your vendor takes one staff day a quarter and a sample of your own claims. Do it this way:
Underpayments against contracted rates appeared on 7.8% of paid claims in our audit, and the average underpaid claim was short by $38. Most practices never see either number because nobody compares the ERA with the contract.
Take a practice with 3 providers collecting $90,000 a month on 800 paid claims, an average of $112.50 a claim. At 7.8% underpaid and $38 short each, 62.4 claims a month lose $2,371, or $28,454 a year. At the 14.2% first-pass denial rate our client practices started with, 113.6 claims a month are denied. If 19% of those are never reworked, 21.6 claims a month at $112.50 is $2,428, or $29,138 a year.
That is $57,592 a year of leakage against a vendor fee of $54,000 at 5% of collections. The chart shows the vendor fee at $54,000, underpaid claims at $28,454 and denials never reworked at $29,138 a year.
The compliance side of the same practice is worse. If an outside audit finds 60 claims upcoded, the False Claims Act minimum of $14,308 per claim is $858,480 before treble damages. That is why the audit rights and the monthly raw data matter more than the fee.
Compliance duties are the same either way; what changes is who runs them and what they cost. Fully loaded in-house billing cost 7.9% of collections for practices under $2M, across 96 practices that shared payroll data, against 3% to 6% of collections for an outsourced service. In-house, you still need the seven elements, a risk analysis and exclusion screening for your own staff, and 34% of practice managers replaced a biller in the past two years, which resets training and access control each time.
Outsourcing makes sense when the vendor can show every document in the checklist above and gives you raw access. Keep billing in-house when you already have a certified coder, a compliance lead and someone who reads denials weekly. If you are comparing vendors now, our comparison of medical billing companies covers the market, and how the full revenue cycle works shows where a vendor’s work starts and stops. A full-service billing arrangement should include every step above. To see where your own claims stand, book a free billing review and send your AR ageing report.
Want to know how this applies to your practice? We will review your AR and denials, free, in 30 minutes.
Book the reviewAsk for each of these before you sign, and read what each one does not prove. No single document covers HIPAA, OIG and coding risk together.
| Document | What it proves | What it does not prove | What to check |
|---|---|---|---|
| Business associate agreement | Legal duty to protect PHI and report breaches | That safeguards exist | All 164.504(e) elements, 60-day breach notice, subcontractor flow-down |
| HIPAA security risk analysis | The vendor assessed its own ePHI risks | That risks were fixed | Date within 12 months, remediation plan |
| SOC 2 Type 2 report | Controls operated over a review period | HIPAA compliance or coding accuracy | Period covered, exceptions section, scope includes billing systems |
| HITRUST i1 or r2 certification | Controls tested against a healthcare framework | Coding accuracy | Level and expiry: i1 is valid 1 year, r2 is valid 2 years |
| Compliance program | OIG seven elements in place | That the program is followed | Named officer, training log, last internal audit |
| OIG exclusion screening log | Staff checked against the LEIE | Screening frequency, unless dated | Monthly dates, every person on your account |
| Coder credentials and outside audit | Coding skill and accuracy on a sample | Accuracy on your specialty | CPC or CCS by name, audit sample from your claims |
| Subcontractor and offshore list | Who touches your data | Their safeguards | A BAA for each, location of each team |
Dental billing runs on CDT codes and the ADA claim form, but the compliance checks are the same: a BAA, a risk analysis and screened staff. The transparency test is PPO fee checking. 12% of paid PPO dental claims came in below the contracted fee, and dental practices wrote off a median $23,400 a year in restorative claims denied for missing narratives or X-rays. Ask the vendor for a PPO underpayment report and a list of denied restorative claims by reason. In our dental practice case study, reworking old claims recovered $86,000.
Therapy billing carries Medicare rules a vendor must track per patient: the 8-minute rule for timed units, the KX modifier past the annual threshold and plan of care certification. The KX modifier was missing on 21% of Medicare therapy claims past the threshold, and 8-minute rule unit errors appeared on 9% of therapy claims. Ask the vendor how it tracks each patient’s threshold and who checks units against minutes before submission. See our physical therapy billing page for the full rule set.
Behavioral health adds two compliance layers. Substance use disorder records fall under 42 CFR Part 2, and the HHS final rule of February 8, 2024 set a compliance date of February 16, 2026, allowing a single patient consent for treatment, payment and operations. A vendor handling those records must follow Part 2, not just HIPAA. The coding risk is time: 18% of 90837 claims had documented session time under 53 minutes, and claims sent to the medical plan instead of the behavioral health carve-out caused 12% of behavioral health denials. More on psychiatry billing.
Ambulance billing compliance turns on documentation the crew and the facility produce, not the biller. Physician Certification Statements were missing or unsigned on 18% of non-emergency transports, and ambulance agencies carried 37% of AR past 90 days. Ask the vendor how it holds a claim until the PCS is signed and how it reports aged transports by payer. In our King-American Ambulance case study, days in AR went from 71 to 38.
Primary care compliance risk sits in modifiers and time-based services. Problem-oriented visits billed with an annual wellness visit lacked modifier 25 on 12% of claims, and chronic care management time went uncaptured for 58% of eligible patients. A vendor should show you both numbers each quarter, because one is a denial risk and the other is revenue you earned but never billed. See our primary care billing page for code-level detail.
The billing company must tell you without unreasonable delay and no later than 60 calendar days after it discovers the breach. Your practice, as the covered entity, then owns notifying patients and HHS. Your BAA should name a shorter notice window, a contact person and who pays for notification and credit monitoring.
Monthly. The OIG updates its exclusion list every month and recommends screening billing and coding contractors, and contracting with an excluded person can bring a civil penalty for each item billed. Ask for a dated screening log that covers every person who touches your claims, including subcontractors and offshore staff.
No. A SOC 2 Type 2 report shows that a vendor’s security controls worked over a review period, as tested by an outside auditor. It does not check HIPAA’s specific rules, the BAA or coding accuracy. There is no federal HIPAA certification, so you still need the BAA, the risk analysis and a coding audit.
Only if your contract lets it. Set a dollar threshold in writing above which every adjustment needs your approval, and ask for a monthly adjustment log that shows the reason code and the person who approved each write-off. Unexplained small-balance and timely filing write-offs are the first place to look in an audit.
Your practice does, because the payer paid you. Once you knowingly have an overpayment, you have 60 days to report and return it, with a 6-year lookback. Your contract should require the vendor to tell you about any overpayment it finds within a set number of days so you can meet that deadline.
Run a small internal sample every quarter, such as 30 paid claims, 20 denials and all large write-offs, and an outside coding audit once a year. The quarterly check catches underpayments and unworked denials, and the annual audit tests coding accuracy against documentation by a certified coder who does not work for the vendor.
A free 30 minute review of your AR ageing and denial reasons. We tell you what is recoverable and what it would take. No deck, no commitment, no fee.
Book a free billing review