HIPAA Compliance

Last Updated: April 18, 2026

✓ HIPAA Compliant: GMB Billing Firm is fully committed to compliance with the Health Insurance Portability and Accountability Act (HIPAA) and maintains comprehensive privacy and security programs to protect Protected Health Information (PHI).

1. Overview

As a medical billing service provider, GMB Billing Firm functions as a Business Associate under HIPAA. We handle Protected Health Information (PHI) on behalf of healthcare providers (Covered Entities) and implement strict safeguards to ensure compliance with HIPAA Privacy, Security, and Breach Notification Rules.

2. Business Associate Agreement

Before providing services involving PHI, we execute a Business Associate Agreement (BAA) with each covered entity client that:

3. HIPAA Privacy Rule Compliance

3.1 Minimum Necessary Standard

We limit use and disclosure of PHI to the minimum necessary to accomplish the intended purpose:

3.2 Permitted Uses and Disclosures

We use and disclose PHI only for:

3.3 Individual Rights

We assist covered entities in fulfilling patient rights:

4. HIPAA Security Rule Compliance

4.1 Administrative Safeguards

Safeguard Implementation
Security Management Process Risk assessments, risk management, sanctions policy, information system activity review
Assigned Security Responsibility Designated Security Officer responsible for developing and implementing policies
Workforce Security Authorization procedures, supervision, termination procedures, clearance procedures
Information Access Management Access authorization, access establishment, access modification
Security Awareness & Training Security reminders, protection from malware, log-in monitoring, password management
Security Incident Procedures Response and reporting procedures
Contingency Plan Data backup, disaster recovery, emergency mode operations, testing procedures
Business Associate Contracts Written contracts with subcontractors handling PHI

4.2 Physical Safeguards

4.3 Technical Safeguards

5. Encryption Standards

5.1 Data at Rest

5.2 Data in Transit

6. AI Coding Platform - HIPAA Considerations

Important: The AI coding platform is designed for use with DE-IDENTIFIED data only.

6.1 De-Identification Requirements

Before using the AI platform, you must remove all 18 HIPAA identifiers:

  1. Names
  2. Geographic subdivisions smaller than state
  3. Dates (except year)
  4. Telephone numbers
  5. Fax numbers
  6. Email addresses
  7. Social Security numbers
  8. Medical record numbers
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate/license numbers
  12. Vehicle identifiers and serial numbers
  13. Device identifiers and serial numbers
  14. Web URLs
  15. IP addresses
  16. Biometric identifiers
  17. Full-face photos
  18. Any other unique identifying characteristic

6.2 PHI Detection

The platform includes automated PHI detection to:

6.3 Client-Side Processing

Where possible, processing occurs in your browser:

7. Breach Notification

7.1 Breach Assessment

We promptly investigate suspected breaches using the four-factor risk assessment:

  1. Nature and extent of PHI involved
  2. Unauthorized person who accessed PHI
  3. Whether PHI was actually acquired or viewed
  4. Extent to which risk has been mitigated

7.2 Notification Requirements

If we discover a breach affecting your patients' PHI:

8. Workforce Training

All GMB Billing Firm employees receive:

9. Risk Assessment

We conduct comprehensive risk assessments:

10. Incident Response

Our incident response procedures include:

11. Subcontractor Management

We ensure HIPAA compliance by subcontractors:

12. Audit and Monitoring

We maintain audit trails for:

Audit logs are:

13. Sanctions Policy

Employees who violate HIPAA or our security policies face:

14. Your HIPAA Responsibilities

As a covered entity, you must:

15. Compliance Certifications

GMB Billing Firm maintains:

16. Documentation

We maintain documentation of:

Documentation is retained for minimum 6 years from creation or last effective date.

17. Contact Our Compliance Team

For HIPAA-related questions:

HIPAA Compliance Officer
GMB Billing Firm
1921 NW N River Dr, #B107
Miami, FL 33125
Phone: (305) 482-1491
Email: support@gmbcoding.com

18. Filing Complaints

If you believe we have violated HIPAA:

We will not retaliate against anyone who files a good-faith complaint.

Related Policies:
Privacy Policy | Terms of Service | Cookie Policy

← Back to Home