Home/Research/How to evaluate medical billing companies for transparency and compliance
Billing vendor compliance

How to evaluate medical billing companies for transparency and compliance

Short answer

Evaluate a medical billing company on proof, not promises: a complete BAA, a current risk analysis or SOC 2 Type 2 report, monthly OIG exclusion screening, certified coders with outside audits, and raw access to your clearinghouse and remits. In our billing reviews, 19% of denied claims were never reworked or appealed.

Key takeaways
  • Outsourcing billing moves the work, not the liability, because claims go out under your NPI and you must return known overpayments within 60 days.
  • A compliant vendor can show a full BAA, a current risk analysis, a SOC 2 or HITRUST report, the OIG seven elements and monthly exclusion screening.
  • Transparency means raw access to your clearinghouse, ERAs and write-off log, not just a monthly summary.
  • A quarterly sample audit of 50 claims catches underpayments, unworked denials and coding drift before a payer does.
  • A percentage fee is usually compliant when payer money lands in your own account, but the fee basis must be written down.
Luxen's take

We think the fee percentage is the least useful number in a billing contract. The compliance risk sits in what the practice cannot see: in our billing reviews, 19% of denied claims were never reworked or appealed, and the practice was rarely told. Ask for raw clearinghouse and remit access before you ask for a discount.

Shivam Pujara,Founder, Luxen Talent

What our billing data shows

44%
Of 286 practice managers, 44% could not name the fee basis in their current billing contract (Luxen Practice Manager Survey 2026).
19%
Across 410 practice billing reviews, 19% of denied claims were never reworked or appealed (Luxen billing reviews).
52%
52% of practices that switched billing vendors cited missing denial reporting as the main reason (Luxen Practice Manager Survey 2026).

Methodology:Luxen figures come from four datasets: Luxen billing reviews (410 practice billing reviews, Jan 2025 to Jun 2026), Luxen claim audit (61,400 claims audited, Jan 2025 to Jun 2026), Luxen Practice Manager Survey 2026 (286 practice managers, March 2026) and Luxen client data (38 client practices, Jan 2024 to Jun 2026). Regulatory figures and penalty amounts come from the primary federal sources listed on this page. The worked example applies audit rates to a sample 3-provider practice.

Cite thisLuxen,How to evaluate medical billing companies for transparency and compliance(luxentalent.com)

What does medical billing compliance mean when you outsource billing?

Medical billing compliance means every claim sent under your NPI is coded from the documentation, billed to the right payer, protected under HIPAA and corrected when it is wrong. Outsourcing moves the work to a billing company. It does not move the liability. Medicare pays the practice, the claim carries your provider number, and the False Claims Act treats reckless disregard as knowing, with no proof of intent to defraud required.

Two rules make this sharper than most vendor pitches admit. Since January 1, 2025, CMS says a practice has identified an overpayment when it knowingly receives or retains one, using the False Claims Act definition, with a 6-year lookback and a 60-day deadline to report and return. And the OIG’s Compliance Program Guidance for Third-Party Medical Billing Companies, published in 1998 and still the only guidance written for billing vendors, lists seven elements a billing company should run: written policies, a compliance officer, training, a hotline, discipline, audits and monitoring, and correction of systemic problems, including a policy against employing sanctioned people.

So the evaluation question is not whether a vendor says it is compliant. It is whether it can show you each of those seven elements, and whether you can see enough of your own data to catch a problem before it becomes an overpayment you knowingly kept.

Who is liable if your billing company upcodes?

Both of you can be, and the practice is the easier target because it received the money. The OIG guidance names the risk areas it expects billing companies to police, including billing for services not documented, unbundling, upcoding, duplicate billing, failure to use modifiers correctly and inadequate resolution of overpayments. It also warns that percentage billing arrangements may increase the risk of upcoding. A clause saying the vendor indemnifies you helps with cost, not with exposure: the payer still recoups from your practice.

The stakes are specific. HIPAA penalties in tiers 1 to 3 reach $73,011 per violation, each False Claims Act claim carries $14,308 to $28,619 plus three times the damages, and contracting with an excluded person or keeping a known overpayment each carry $25,595 per item.

Maximum federal penalty per violation, 2026 Maximum federal penalty per violation, 2026. HIPAA, tiers 1 to 3: $73,011; False Claims Act claim: $28,619; Hiring excluded staff: $25,595; Kept overpayment: $25,595. Source: HHS 91 FR, Jan 28, 2026; DOJ 28 CFR 85.5. Maximum federal penalty per violation, 2026 HIPAA, tiers 1 to 3 $73,011 False Claims Actclaim $28,619 Hiring excludedstaff $25,595 Kept overpayment $25,595 Source: HHS 91 FR, Jan 28, 2026; DOJ 28 CFR 85.5
Source: HHS 91 FR, Jan 28, 2026; DOJ 28 CFR 85.5

How do you evaluate a billing company for compliance, step by step?

Evaluate a billing company by asking for documents and access, then checking them yourself. This order works in about two weeks of calls and document review:

  1. Read their business associate agreement before your own counsel does. Check it against the required elements in 45 CFR 164.504(e), listed below.
  2. Ask for the latest HIPAA security risk analysis and a third-party report. A SOC 2 Type 2 report or a HITRUST i1 or r2 certification, dated within the last year for SOC 2 and i1.
  3. Ask for the compliance program. The name of the compliance officer, the written policies, the training log and the last internal audit, mapped to the OIG’s seven elements.
  4. Ask how often they screen staff against the OIG exclusion list. The OIG updates the list monthly and recommends that providers screen billing or coding contractors, so monthly screening of every person on your account is the standard.
  5. Check coder credentials by name. Coders should hold an AAPC CPC or AHIMA CCS, and an outside coding audit should run at least once a year.
  6. Map where the money lands. Payer deposits and ERAs should go to an account and a clearinghouse enrollment you own.
  7. Ask who else touches your data. Every subcontractor and offshore team, in writing, with the BAA that covers them.
  8. Read the overpayment and write-off policy. Who approves an adjustment, and how fast the vendor tells you about an overpayment.
  9. Confirm audit rights and exit terms. Your right to audit their work on your claims, and a full data export in a usable format when you leave.

What should a HIPAA compliant medical billing company put in writing?

A HIPAA compliant medical billing company signs a BAA that covers every element in 45 CFR 164.504(e): permitted uses only, appropriate safeguards and compliance with the Security Rule, reporting of any non-permitted use including breaches, the same terms flowed down to subcontractors, support for patient access, amendment and accounting of disclosures, books open to HHS, and return or destruction of all PHI at termination. HHS lists billing as business associate work, so there is no exception for small vendors.

Two more lines matter in practice. The vendor must notify you of a breach without unreasonable delay and in no case later than 60 calendar days after discovery. And the vendor must run its own risk analysis under 45 CFR 164.308. A SOC 2 Type 2 report shows its controls operated over a period; it is not a HIPAA certification, because no such federal certification exists.

Is a percentage-of-collections fee compliant?

Usually yes, when payer money goes into the practice’s own account. When Medicare pays a billing agent directly, 42 CFR 424.73 and 424.80 require that the agent’s pay is not related in any way to the dollar amounts billed or collected, and Medicaid’s rule at 42 CFR 447.10 says the same. Most percentage contracts stay outside those rules because the payer deposits to the practice and the vendor invoices separately. The fee shape still matters: 44% could not name the fee basis in their current billing contract, which means they cannot tell whether the vendor is paid on charges, collections or net collections. For how fee models compare on cost, see our guide on what billing companies charge and how to compare them.

What does medical billing transparency look like after you sign?

Medical billing transparency means you can see your raw data without asking the vendor to pull it. Reports summarize; raw access lets you check the summary. The minimum is a read-only login to your clearinghouse, every 835 ERA, a write-off and adjustment log showing who approved each entry, a denial report by CARC reason code, and an underpayment report against your contracted rates.

This is where vendors differ most. The top three denial reasons accounted for 58% of denied dollars in the average practice we reviewed, yet 63% could not name their top three denial reasons. 52% of practices that switched billing vendors cited missing denial reporting as the main reason. A vendor that reports denials by reason, with dollars and the fix owned by a named person, is doing the part most practices never see. Our denial and AR recovery work starts from that report.

In the Luxen claim audit of 61,400 claims, eligibility and coverage errors caused 24% of denials, coding and modifier errors 21%, missing or invalid prior authorization 17%, duplicate claims 9% and timely filing 6%, leaving 23% for all other causes.

What caused denials in our claim audit What caused denials in our claim audit. Eligibility and coverage: 24%; Coding and modifiers: 21%; Prior authorization: 17%; Duplicate claims: 9%; Timely filing: 6%; All other causes: 23%. Source: Luxen claim audit, 61,400 claims, Jan 2025 to Jun 2026. What caused denials in our claim audit 24% 21% 17% 9% 6% 23% 100% Eligibility andcoverage 24% (24%) Coding andmodifiers 21% (21%) Priorauthorization 17% (17%) Duplicate claims 9% (9%) Timely filing 6% (6%) All other causes 23% (23%) Source: Luxen claim audit, 61,400 claims, Jan 2025 to Jun 2026
Source: Luxen claim audit, 61,400 claims, Jan 2025 to Jun 2026

Duplicates and timely filing are the two causes that point straight at vendor process. Duplicates come mostly from resubmitting instead of correcting. Timely filing losses are nearly permanent: Medicare’s limit is one calendar year from the date of service, and only 4% of timely filing denials were recovered.

How do you run a medical billing audit on your current billing company?

A medical billing audit of your vendor takes one staff day a quarter and a sample of your own claims. Do it this way:

  1. Pull 30 random paid claims, 20 denied claims and every write-off over $250 from the last 90 days.
  2. For the paid claims, compare each CPT code and modifier with the visit note. Send any disagreement to an outside coder, or to a certified coding review.
  3. Match each 835 ERA to what was posted. Check allowed amounts against your fee schedule for the top five payers.
  4. For each denial, check the date it was worked and whether it was corrected, appealed or written off, and who approved the write-off.
  5. Ask for the exclusion screening log for everyone who touched those claims.

Underpayments against contracted rates appeared on 7.8% of paid claims in our audit, and the average underpaid claim was short by $38. Most practices never see either number because nobody compares the ERA with the contract.

What does weak billing transparency cost? A worked example

Take a practice with 3 providers collecting $90,000 a month on 800 paid claims, an average of $112.50 a claim. At 7.8% underpaid and $38 short each, 62.4 claims a month lose $2,371, or $28,454 a year. At the 14.2% first-pass denial rate our client practices started with, 113.6 claims a month are denied. If 19% of those are never reworked, 21.6 claims a month at $112.50 is $2,428, or $29,138 a year.

That is $57,592 a year of leakage against a vendor fee of $54,000 at 5% of collections. The chart shows the vendor fee at $54,000, underpaid claims at $28,454 and denials never reworked at $29,138 a year.

Yearly cost vs hidden leakage, $90,000 a month Yearly cost vs hidden leakage, $90,000 a month. Vendor fee at 5%: $54,000; Underpaid claims: $28,454; Denials never reworked: $29,138. Source: Luxen claim audit and Luxen billing reviews, Jan 2025 to Jun 2026, applied to the worked example. Yearly cost vs hidden leakage, $90,000 a month Worked example, 3-provider practice Vendor fee at 5% $54,000 Underpaid claims $28,454 Denials neverreworked $29,138 Source: Luxen claim audit and Luxen billing reviews, Jan 2025 to Jun 2026, applied to the worked example
Source: Luxen claim audit and Luxen billing reviews, Jan 2025 to Jun 2026, applied to the worked example

The compliance side of the same practice is worse. If an outside audit finds 60 claims upcoded, the False Claims Act minimum of $14,308 per claim is $858,480 before treble damages. That is why the audit rights and the monthly raw data matter more than the fee.

What compliance mistakes do practices make with billing vendors?

  • Signing the vendor’s BAA unread. Missing subcontractor flow-down and PHI return at termination are the common gaps.
  • Treating a SOC 2 logo as HIPAA compliance. Ask for the report itself and read the exceptions section.
  • Letting the vendor write off without approval. Set a dollar threshold above which you sign off.
  • Not asking about offshore work. Medicare Advantage plans must report offshore subcontractors that handle beneficiary PHI to CMS, and many pass an offshore attestation down to providers in their contracts.
  • Nobody owning the vendor relationship. 42% of practice managers said nobody owns denial follow-up full time, so nobody reads the vendor’s reports either.
  • Checking AR only when cash drops. Practices that reviewed AR ageing monthly carried 12 fewer days in AR.

Should you keep billing in-house or outsource for compliance?

Compliance duties are the same either way; what changes is who runs them and what they cost. Fully loaded in-house billing cost 7.9% of collections for practices under $2M, across 96 practices that shared payroll data, against 3% to 6% of collections for an outsourced service. In-house, you still need the seven elements, a risk analysis and exclusion screening for your own staff, and 34% of practice managers replaced a biller in the past two years, which resets training and access control each time.

Outsourcing makes sense when the vendor can show every document in the checklist above and gives you raw access. Keep billing in-house when you already have a certified coder, a compliance lead and someone who reads denials weekly. If you are comparing vendors now, our comparison of medical billing companies covers the market, and how the full revenue cycle works shows where a vendor’s work starts and stops. A full-service billing arrangement should include every step above. To see where your own claims stand, book a free billing review and send your AR ageing report.

Want to know how this applies to your practice? We will review your AR and denials, free, in 30 minutes.

Book the review

Which compliance documents should a billing company show you?

Ask for each of these before you sign, and read what each one does not prove. No single document covers HIPAA, OIG and coding risk together.

DocumentWhat it provesWhat it does not proveWhat to check
Business associate agreementLegal duty to protect PHI and report breachesThat safeguards existAll 164.504(e) elements, 60-day breach notice, subcontractor flow-down
HIPAA security risk analysisThe vendor assessed its own ePHI risksThat risks were fixedDate within 12 months, remediation plan
SOC 2 Type 2 reportControls operated over a review periodHIPAA compliance or coding accuracyPeriod covered, exceptions section, scope includes billing systems
HITRUST i1 or r2 certificationControls tested against a healthcare frameworkCoding accuracyLevel and expiry: i1 is valid 1 year, r2 is valid 2 years
Compliance programOIG seven elements in placeThat the program is followedNamed officer, training log, last internal audit
OIG exclusion screening logStaff checked against the LEIEScreening frequency, unless datedMonthly dates, every person on your account
Coder credentials and outside auditCoding skill and accuracy on a sampleAccuracy on your specialtyCPC or CCS by name, audit sample from your claims
Subcontractor and offshore listWho touches your dataTheir safeguardsA BAA for each, location of each team

How the answer changes by specialty

Dental

Dental billing runs on CDT codes and the ADA claim form, but the compliance checks are the same: a BAA, a risk analysis and screened staff. The transparency test is PPO fee checking. 12% of paid PPO dental claims came in below the contracted fee, and dental practices wrote off a median $23,400 a year in restorative claims denied for missing narratives or X-rays. Ask the vendor for a PPO underpayment report and a list of denied restorative claims by reason. In our dental practice case study, reworking old claims recovered $86,000.

Physical therapy

Therapy billing carries Medicare rules a vendor must track per patient: the 8-minute rule for timed units, the KX modifier past the annual threshold and plan of care certification. The KX modifier was missing on 21% of Medicare therapy claims past the threshold, and 8-minute rule unit errors appeared on 9% of therapy claims. Ask the vendor how it tracks each patient’s threshold and who checks units against minutes before submission. See our physical therapy billing page for the full rule set.

Behavioral health

Behavioral health adds two compliance layers. Substance use disorder records fall under 42 CFR Part 2, and the HHS final rule of February 8, 2024 set a compliance date of February 16, 2026, allowing a single patient consent for treatment, payment and operations. A vendor handling those records must follow Part 2, not just HIPAA. The coding risk is time: 18% of 90837 claims had documented session time under 53 minutes, and claims sent to the medical plan instead of the behavioral health carve-out caused 12% of behavioral health denials. More on psychiatry billing.

Ambulance

Ambulance billing compliance turns on documentation the crew and the facility produce, not the biller. Physician Certification Statements were missing or unsigned on 18% of non-emergency transports, and ambulance agencies carried 37% of AR past 90 days. Ask the vendor how it holds a claim until the PCS is signed and how it reports aged transports by payer. In our King-American Ambulance case study, days in AR went from 71 to 38.

Primary care

Primary care compliance risk sits in modifiers and time-based services. Problem-oriented visits billed with an annual wellness visit lacked modifier 25 on 12% of claims, and chronic care management time went uncaptured for 58% of eligible patients. A vendor should show you both numbers each quarter, because one is a denial risk and the other is revenue you earned but never billed. See our primary care billing page for code-level detail.

Frequently asked questions

What happens if my billing company has a data breach?

The billing company must tell you without unreasonable delay and no later than 60 calendar days after it discovers the breach. Your practice, as the covered entity, then owns notifying patients and HHS. Your BAA should name a shorter notice window, a contact person and who pays for notification and credit monitoring.

How often should a billing company check the OIG exclusion list?

Monthly. The OIG updates its exclusion list every month and recommends screening billing and coding contractors, and contracting with an excluded person can bring a civil penalty for each item billed. Ask for a dated screening log that covers every person who touches your claims, including subcontractors and offshore staff.

Does a SOC 2 report mean a billing company is HIPAA compliant?

No. A SOC 2 Type 2 report shows that a vendor’s security controls worked over a review period, as tested by an outside auditor. It does not check HIPAA’s specific rules, the BAA or coding accuracy. There is no federal HIPAA certification, so you still need the BAA, the risk analysis and a coding audit.

Can my billing company write off balances without my approval?

Only if your contract lets it. Set a dollar threshold in writing above which every adjustment needs your approval, and ask for a monthly adjustment log that shows the reason code and the person who approved each write-off. Unexplained small-balance and timely filing write-offs are the first place to look in an audit.

Who has to return an overpayment that the billing company finds?

Your practice does, because the payer paid you. Once you knowingly have an overpayment, you have 60 days to report and return it, with a 6-year lookback. Your contract should require the vendor to tell you about any overpayment it finds within a set number of days so you can meet that deadline.

How often should I audit my billing company?

Run a small internal sample every quarter, such as 30 paid claims, 20 denials and all large write-offs, and an outside coding audit once a year. The quarterly check catches underpayments and unworked denials, and the annual audit tests coding accuracy against documentation by a certified coder who does not work for the vendor.

Sources

Shivam Pujara
About the author
Shivam Pujara
Founder, Luxen Talent|Leads Luxen's billing and revenue cycle team

Shivam founded Luxen to run the revenue cycle for independent medical practices, from eligibility checks to zero balance, inside the systems they already use. He writes from what the team sees in client AR, denials and billing reviews every week.

LinkedIn profile

Get a straight answer for your practice

A free 30 minute review of your AR ageing and denial reasons. We tell you what is recoverable and what it would take. No deck, no commitment, no fee.

Book a free billing review