Before sending PHI to a claim-follow-up vendor
The first conversation with a claim-follow-up vendor does not need a real claim. You can explain the backlog, review a synthetic result, and discuss the proposed work before sharing protected health information, or PHI.
Use that time to resolve a more important question: what will govern the information once it leaves your organization?
A security page helps you start the review. It does not replace the agreements, evidence, and operating decisions needed for your particular engagement. The questions below are a starting point for an RCM team's privacy, security, and legal reviewers—not a complete compliance assessment or legal advice.
Establish the contractual relationship
An RCM company may already act as a business associate for its practice clients. A vendor handling PHI on its behalf may be a business associate subcontractor. HHS identifies billing and claims administration among business-associate activities and explains that appropriate downstream business associate agreements are required before PHI is disclosed to a subcontractor. Have your reviewer confirm the roles and required agreements for the arrangement. HHS: Business Associates.
Ask who the contracting entity is, what work it is authorized to perform, and whether your existing client agreements impose additional conditions. Make sure the contract covers the service you intend to use, rather than a different offering from the same vendor.
Review what the vendor may do with the information
Ask how the agreement addresses permitted uses, disclosures, reporting obligations, and subcontractors. HHS's sample business associate provisions cover these subjects, but HHS also cautions that its sample is not a substitute for legal review or sufficient on its own for every contract. HHS: Business Associate Contracts.
For services involving AI, ask specifically whether information is used only to perform the contracted work or may also be used for model training, evaluation, or product improvement. Request answers for the vendor and its relevant subprocessors. Do not infer the answer from an “AI-powered” label or a general statement about encryption.
These are diligence questions about the proposed use. They are not an assertion that every AI-related use has the same legal treatment.
Agree what information the inquiry actually needs
HHS explains that the Privacy Rule generally calls for reasonable steps to limit PHI uses, disclosures, and requests to what is needed for the purpose, subject to specified exceptions. The appropriate scope depends on the activity and applicable requirements; “send everything just in case” is not a useful intake design. HHS: Minimum Necessary Requirement.
Ask for a field-level intake specification. Which fields are required for this inquiry? When is supporting documentation needed? Who decides whether additional information should be supplied?
Separate a public sales inquiry from the approved claim-intake process. Use synthetic examples for demonstrations whenever possible. Simply removing a name from a real record should not be treated as proof that it is safe to share publicly; HIPAA de-identification has specific requirements. HHS: De-identification Guidance.
Ask how access works in practice
The HIPAA Security Rule addresses administrative, physical, and technical safeguards for electronic PHI. HHS's summary includes workforce authorization, role-appropriate access, training, and risk assessment. A review should therefore examine operating practices as well as software controls. HHS: Summary of the Security Rule.
Ask the vendor to explain who can access a batch during ordinary work, support, and incident response. For an RCM company serving multiple practices, request a demonstration using synthetic data of how practice-level access is assigned and removed.
Ask what activity is recorded and how your organization can obtain relevant evidence. A list of controls is more useful when the reviewer can connect it to a specific workflow.
Identify the other organizations and locations involved
Request the relevant subprocessor list and a plain-language account of where information is stored, processed, and accessed. Ask separately about backups, support access, and any subcontracted operators.
These are distinct questions. A storage-region answer does not necessarily explain where a person can access the data or where another service processes it. The point is to compare the actual arrangement with your agreements and requirements, not to treat one location label as a complete security review.
Ask how changes to the arrangement are communicated and who in your organization will review them.
Plan for problems and for the end of the work
Ask for the incident contact, escalation route, contractual reporting obligations, and the information you would receive to support your own response. Agree who owns this relationship before the pilot starts.
Also ask how information is returned, retained, or destroyed when the engagement ends. HHS's sample provisions address return or destruction at termination where feasible, and continuing protections where it is not. Your contract and review should address the specific arrangement, including backups and retained records. HHS: Business Associate Contracts.
Avoid leaving exit questions until the team has already decided to stop. Find out which records you receive, which formats are available, and who confirms the agreed steps were completed.
Leave the review with decisions, not just documents
Before releasing a live batch, confirm with the appropriate reviewers that:
- The service scope and contractual roles are understood.
- Required agreements are executed and proposed uses are acceptable.
- The approved intake process and necessary information are defined.
- Access, subcontractors, locations, and safeguards have been reviewed.
- Incident reporting and escalation responsibilities are understood.
- Retention and exit arrangements are documented.
- Someone has explicitly approved moving from synthetic examples to PHI.
A signed agreement matters. So does knowing how its commitments are carried out. The strongest review connects the two to the actual work being purchased.
Reviewing Halcora? Start with security and data handling, or tell us what your review requires. Do not include PHI in the contact form or ordinary email.