Glossary
HIPAA
U.S. federal rules that set standards for protecting health information and certain electronic transactions.
Also called: Health Insurance Portability and Accountability Act
In plain English
HIPAA covers privacy, security and breach notification for covered entities and their business associates, plus standard electronic transactions such as 837 claims and 270/271 eligibility.
Saying software is "HIPAA certified" is often misleading — HIPAA does not run a product certification program the way people mean it in marketing.
Why it matters
Buyers need honest language: what controls exist today, what documentation you can review, and what remains your organization's responsibility.
A billing company signs a BAA, limits staff access by role, and keeps an audit trail of who approved each claim.
We design for PHI workloads and share compliance documentation on request; we do not claim "HIPAA certified" or "SOC 2 certified" on this site unless those programs are completed.
Related features
Related terms
Protected health information (PHI)
Individually identifiable health information protected under U.S. HIPAA rules.
Business associate agreement (BAA)
A contract that allows a vendor to handle PHI for a covered entity under HIPAA.
837P claim
The electronic format for professional (physician and clinician) claims.
Browse all 21 terms in the billing glossary.
See it in MEDBIXDeep dive
What Hipaa means in daily ops.
Practical context for Hipaa: how teams use it, where it sits in the loop, and what to ask in a demo.
- Tied to how billing work actually splits
- Clear on human vs machine responsibility
- Links into related MEDBIX areas

Practice
Where this shows up on a busy day.
From morning eligibility checks to end-of-day posting, Hipaa connects to the queues your team already lives in.
- Morning coverage and claim build
- Midday scrub and approval
- Afternoon denials and patient pay

Control
Keep a person on the send button.
Whatever page you're on, MEDBIX keeps AI in a propose role. Approvals, posting and rule activation stay human.
- Named approvals
- Visible AI proposals
- Immutable audit trail


Next
See related features in a demo
Bring your payer mix and the friction you feel today. We'll map it onto sample data in thirty minutes.
- Sample data only
- Your questions drive the agenda
- Written follow-up after
Common questions
Is MEDBIX an EHR?
No. MEDBIX is a revenue cycle and medical billing platform. It can take in billing-relevant data from EHRs, but it doesn't do clinical charting, prescriptions or labs.
Does the AI submit claims automatically?
No. AI agents suggest codes, explain scrub findings and propose denial fixes. A person on your team has to review and approve every claim before it goes to the clearinghouse.
Who can see our data?
Your billing company is the tenant. Practices under you are separated by permissions, and other billing companies can't see your data at all, because PostgreSQL row-level security enforces it.
Can a solo practice use it?
Yes. A solo practice onboards as its own tenant, with the provider or office manager as the tenant admin.
Which clearinghouse do you use?
Stedi, a modern JSON clearinghouse API, for eligibility (270/271), claims (837) and remittance (835).
Want to walk MEDBIX against your real claim mix?
Thirty minutes with sample data. We'll follow one claim through the gate, then talk about your payers, practices and where the rework hurts today.
Notes from the billing floor
Occasional, practical writing on denials, A/R and running a billing company. No spam, unsubscribe any time.
