Data handling

Your practice data, and how we hold it

We touch bank feeds, payroll, and financial records that sit alongside protected health information. Here is what we sign, where the data lives, and who can see it.

The short version

We are a business associate, and we contract like one

Accounting for a healthcare practice means handling records that can contain protected health information — remittance advice, payer correspondence, patient balances. HIPAA treats a service provider in that position as a business associate.

So we execute a Business Associate Agreement with every practice we serve, before we are given access to anything. If a prospective client does not raise it, we do.

Specifics

What that means day to day

Minimum necessary
We ask for the least data that lets us do the work. For most engagements that is transaction-level financial data, not clinical records. Where a report contains PHI, we request it de-identified when the work permits.
Access
Named team members on your engagement only. Access is granted per client, reviewed when staff change, and removed when an engagement ends.
Where it lives
Inside your own accounting, payroll and document systems wherever possible, so the record of authority stays with you. Where we hold copies, they sit in access-controlled cloud systems, not on local machines or personal email.
Transfer
Documents move through the client portal or your own system. Not email attachments, and not text messages.
Subcontractors
Any subcontractor who could touch practice data is bound by the same terms we are, in writing, before access.
If an engagement ends
You leave with your books, files and system access in usable form. We retain what professional standards and law require us to retain, and nothing beyond that purpose.
If something goes wrong
You hear it from us. Notification follows the terms of the Business Associate Agreement and applicable law, and we will tell you what happened rather than what is comfortable.

This page describes our practices. It is not a warranty, and it does not replace the Business Associate Agreement and engagement letter, which are the operative documents.

Questions

Send this to whoever handles compliance

If your practice has a privacy officer or outside counsel, we are happy to answer their questions directly before you engage us.

Ask a question