Protecting Practice Information Through Controlled Operations
Our approach is built around controlled access, workforce accountability, secure working procedures and clearly defined responsibilities for every client engagement.
Discuss Security RequirementsControls Should Match the Work Being Performed
Medical billing may involve access to protected health information. User access, communication methods, working devices and escalation procedures therefore need to be controlled and documented.
Core Controls Across People, Access and Technology
The exact control environment is confirmed during onboarding.
Role-based access
Permissions are limited to the functions each authorized team member needs to perform.
Individual user accounts
Unique accounts improve accountability and reduce risks created by shared credentials.
Secure authentication
Multi-factor authentication is used where supported and required by the client system or policy.
Workforce controls
Confidentiality obligations, access expectations and security awareness are established for authorized personnel.
Controlled devices
Access occurs through approved devices and working environments consistent with agreed requirements.
Access review
User status, account access and operational concerns are reviewed according to established procedures.
Security Expectations Are Clarified During Onboarding
Each engagement identifies which systems will be used, what information may be accessed, who authorizes access and how concerns will be reported.
Contractual Safeguards for Services Involving PHI
Where applicable, the working relationship should include an appropriate Business Associate Agreement that defines permitted use, safeguards, reporting and related responsibilities.
- BAA review before access to PHI
- Defined permitted uses and disclosures
- Applicable subcontractor obligations
- Incident-notification responsibilities
- Return or destruction requirements where applicable
This Website Is Not Intended to Receive Patient Information
The public form is designed for business enquiries. Visitors should not submit patient names, medical details, account numbers, insurance information or other protected health information.
A Clear Path From Identification to Client Communication
Record the concern
Document the affected system, users and known circumstances.
Restrict exposure
Limit inappropriate access and preserve information required for review.
Review responsibilities
Evaluate the event against contractual, operational and legal requirements.
Escalate appropriately
Notify the designated client contact according to agreed procedures.
Important Security Statement
This page describes the intended operating approach of GI Practice Revenue. It does not replace a client agreement, Business Associate Agreement, security assessment or legal advice. Controls and responsibilities should be confirmed for each engagement before access is provided. GI Practice Revenue does not describe itself as “HIPAA certified.”
Discuss Your Practice’s Security Requirements
Tell us about the systems, workflows and revenue-cycle support your practice is considering.
