Medical Billing Business Guide

How to Start a Medical Billing Business: HIPAA Compliance, NPI Registration, Anti-Kickback Statute, and Startup Costs (2026 Guide)

Medical billing is one of the most accessible healthcare businesses to start — you can operate from home with startup costs under $15,000. But HIPAA compliance is non-negotiable, the Anti-Kickback Statute and False Claims Act create serious federal liability, and the penalties for violations are severe. This guide covers the key federal regulations, certifications, state requirements, and operational steps from business formation to your first client contract.

Updated April 13, 2026 22 min read

Not legal advice. Requirements may change — always verify with your local government authority before applying. Last verified: .

Quick answer: what you need to start a medical billing business

  • 1HIPAA compliance program — Mandatory under 45 CFR Parts 160, 162, and 164. Implement Privacy Rule, Security Rule, and Breach Notification Rule requirements before handling any patient data.
  • 2Business Associate Agreement (BAA) — Required by 45 CFR § 164.504(e) before accessing any PHI. Execute a separate BAA with every client, clearinghouse, software vendor, and IT provider that can access patient data.
  • 3Professional certification — CPC (AAPC) or CMRS (AMBA) is not legally required but is practically essential for winning client contracts. Nearly all providers demand credentialed billing staff.
  • 4Clearinghouse enrollment — Enroll with Availity, Office Ally, or Change Healthcare to submit electronic claims in 837P/837I format and receive ERAs in 835 format as required by 45 CFR Part 162.
  • 5Federal fraud law compliance — Anti-Kickback Statute (42 U.S.C. § 1320a-7b), Stark Law (42 U.S.C. § 1395nn), and False Claims Act (31 U.S.C. § 3729) all apply to your billing operations. Violations carry felony-level consequences.
  • 6Cyber + E&O insurance — A single HIPAA breach can cost $50,000-$250,000+ in notification and legal costs. Both cyber liability and professional liability (E&O) insurance are essential before signing your first client.

1. How the medical billing regulatory framework works

A medical billing company submits healthcare claims to insurance companies (payers) on behalf of healthcare providers. You receive patient encounter data, translate it into standardized codes (CPT, ICD-10-CM, HCPCS), submit claims electronically through a clearinghouse, track adjudication, manage denials and appeals, and post payments. You handle protected health information (PHI) at every step.

Because you handle PHI, you are classified as a "business associate" under HIPAA (45 CFR § 160.103). This classification triggers compliance obligations under three separate HIPAA rules: the Privacy Rule (how PHI can be used and disclosed, 45 CFR Part 164 Subpart E), the Security Rule (technical and physical safeguards for electronic PHI, 45 CFR Part 164 Subpart C), and the Breach Notification Rule (what to do when PHI is compromised, 45 CFR Part 164 Subpart D). These obligations apply regardless of business size — a solo home-based biller has the same compliance requirements as a large billing company.

Beyond HIPAA, three federal fraud statutes create serious criminal and civil liability for billing companies: the Anti-Kickback Statute (42 U.S.C. § 1320a-7b), which prohibits fee arrangements that induce referrals; the Stark Law (42 U.S.C. § 1395nn), which prohibits physician self-referrals; and the False Claims Act (31 U.S.C. § 3729), which creates liability for submitting false or inaccurate claims to Medicare and Medicaid. Penalties under these statutes are severe — up to 10 years federal imprisonment under the AKS and FCA penalties of up to $27,894 per false claim plus treble damages.

HIPAA enforcement is handled by the HHS Office for Civil Rights (OCR). The OIG (Office of Inspector General) and DOJ enforce the AKS and FCA. In 2024, OCR received over 34,000 HIPAA complaints and the DOJ recovered $2.9 billion in healthcare fraud judgments — underscoring that enforcement is active and consequential for billing companies of all sizes.

2. Business formation: LLC, EIN, and general business licensing

Form an LLC before signing any client contract

Filed with: State Secretary of StateTypical cost: $50–$500Timeline: 1–2 weeks (expedited available)

An LLC (Limited Liability Company) provides essential personal liability protection. In a field where a single HIPAA breach or billing error can result in six-figure financial exposure, operating as a sole proprietor — with your personal assets at risk — is inadvisable. Your BAAs, insurance policies, clearinghouse contracts, and client agreements will all be in the LLC's name. Register with your state Secretary of State, then obtain an EIN from the IRS (free, immediate online). You also need a general business license from your city or county (typically $25-$200/year). Some states (e.g., California) charge an LLC franchise tax ($800/year minimum).

Professional certification: CPC or CMRS

Issued by: AAPC or AMBACost: $200–$1,500 (exam + study)Timeline: 2–6 months of preparation

No state or federal law mandates certification, but virtually all healthcare providers require credentialed billing staff before signing a contract. The CPC (Certified Professional Coder) from AAPC is the industry gold standard — it covers CPT, ICD-10-CM, HCPCS Level II, anatomy, and reimbursement methodology. The exam is 150 questions over 5 hours 40 minutes with a ~60-70% pass rate. Cost: $399 for AAPC members, $499 for non-members. Requires 2 years of professional experience (or earn CPC-A apprentice status immediately). The CMRS (Certified Medical Reimbursement Specialist) from AMBA focuses specifically on billing and reimbursement, is open-book, and is easier to obtain ($200-$300). Both require continuing education to maintain (AAPC: 36 CEUs per 2-year cycle).

HIPAA compliance program (45 CFR Parts 160, 162, 164)

Required by: HHS OCRCost: $500–$3,000 to establishTimeline: Ongoing obligation

You must implement a comprehensive HIPAA compliance program before handling any PHI. Required elements: (1) Written privacy and security policies and procedures; (2) Annual Security Risk Analysis — use the free HHS Security Risk Assessment Tool (healthit.gov/SRA); (3) Risk management plan addressing identified threats; (4) Workforce training on HIPAA — even if you are the sole employee; (5) Breach response plan with 60-day notification procedures; (6) Designated HIPAA Privacy and Security Officer (same person is permissible); (7) Documentation retained for minimum 6 years (45 CFR § 164.530(j)). Do not wait to build this program — OCR investigates complaints regardless of company size, and "I didn't know" is not a recognized defense.

3. Business Associate Agreements: the foundation of every client relationship

The Business Associate Agreement (BAA) is the most important legal document in your billing business. Under 45 CFR § 164.504(e), a covered entity cannot disclose PHI to a business associate without a written BAA — and you cannot handle PHI without one. This means: before your first client sends you a single patient record, a signed BAA must be in place. Before your clearinghouse receives your first claim, they must have a signed BAA with you. Before your billing software vendor hosts any of your data, they must sign a BAA.

The BAA must contain mandatory provisions specified at 45 CFR § 164.504(e)(2). At minimum, it must: specify permitted uses and disclosures of PHI; require the business associate to implement appropriate safeguards; require the business associate to report breaches within 60 days of discovery; require the business associate to ensure subcontractors agree to equivalent protections; provide for PHI return or destruction upon termination; and require the business associate to make internal practices available to HHS for compliance audits.

HHS provides sample BAA provisions at hhs.gov — but these are a starting point, not a finished document. Have a healthcare attorney customize your standard BAA. Expect to pay $500-$2,000 for a properly drafted BAA template that you can use for all client relationships.

Every vendor that touches PHI needs a BAA with you

This includes: billing software vendors, clearinghouses, cloud storage providers (Dropbox, Google Drive are not HIPAA-compliant without a BAA), encrypted email providers, HIPAA-compliant fax services, IT support companies who can access your systems, and shredding companies. If a vendor refuses to sign a BAA, you cannot use that vendor for any PHI-related activity. Standard Gmail, Dropbox, and most consumer fax apps cannot sign a BAA — replace them before starting operations.

4. Federal fraud laws: Anti-Kickback, Stark Law, and False Claims Act

Three federal statutes create significant criminal and civil liability for medical billing companies. Understanding them is not optional — violations can end your business and result in federal prosecution.

Anti-Kickback Statute (42 U.S.C. § 1320a-7b)

The AKS makes it a federal felony to offer, pay, solicit, or receive any remuneration to induce or reward referrals of items or services covered by federal healthcare programs. For billing companies, the primary risk is percentage-based billing fees — the OIG has scrutinized whether collecting a percentage of claims creates improper incentives. The OIG's guidance permits percentage billing arrangements as long as they are commercially reasonable, disclosed, and not tied to the volume or value of referrals that the billing company generates. The Personal Services and Management Contracts safe harbor (42 CFR § 1001.952(d)) protects properly structured billing arrangements.

Penalties: AKS violations are a felony — up to 10 years imprisonment per violation, $100,000 civil monetary penalty per violation, and mandatory exclusion from all federal healthcare programs. Exclusion means you cannot submit any claims to Medicare or Medicaid — effectively ending a medical billing operation.

Stark Law (42 U.S.C. § 1395nn, implemented at 42 CFR Part 411)

The Stark Law prohibits physicians from referring Medicare or Medicaid patients to entities with which the physician has a financial relationship unless a specific exception applies. Unlike the AKS, the Stark Law is strict liability — intent is irrelevant. Billing companies are indirectly implicated: if your client provider is violating the Stark Law and you bill for those services, you are submitting claims for non-reimbursable services. Include contractual representations from all clients that they are operating in compliance with applicable federal healthcare laws, and train billing staff to recognize red-flag referral patterns.

False Claims Act (31 U.S.C. §§ 3729-3733)

The FCA imposes civil liability of $13,946-$27,894 per false claim plus treble damages for knowingly submitting false or fraudulent claims to the government. "Knowingly" includes reckless disregard — if you submit claims without verifying the underlying documentation, you risk FCA liability. Upcoding (billing a higher-level service than documented), unbundling (billing component services separately instead of as a bundled code), and billing for services not rendered are classic FCA violations. The FCA's qui tam provision allows whistleblowers to file suit on behalf of the government and collect 15-30% of recoveries — meaning a disgruntled employee can trigger a federal investigation.

Compliance program — not optional

The OIG recommends that all medical billing companies adopt a formal compliance program including: written standards and policies; designated compliance officer; effective training; open lines of communication (compliance hotline); auditing and monitoring of claims; prompt response to detected violations; and disciplinary standards. The OIG's Compliance Program Guidance for Third-Party Medical Billing Companies (2000, updated via subsequent workplan items) provides the blueprint. A compliance program is also a mitigating factor in any federal investigation.

5. CPT, ICD-10-CM, and HCPCS coding requirements

Medical billing requires translating clinical services into standardized codes. HIPAA mandates use of standard code sets for all electronic healthcare transactions under 45 CFR § 162.1002. There are three code systems every medical billing company must master.

CPT Codes (Current Procedural Terminology)

Published and maintained by the AMA. CPT codes (00100–99607 for Category I) describe medical procedures and services. Usage requires an AMA license. CMS publishes Relative Value Units (RVUs) for each CPT code annually in the Medicare Physician Fee Schedule Final Rule (42 CFR Part 414), which determines Medicare reimbursement amounts. The CPC exam tests proficiency across the entire CPT code set — this is why certification matters operationally.

ICD-10-CM Diagnosis Codes

Maintained by the CDC National Center for Health Statistics. Mandated for all HIPAA-covered transactions under 45 CFR § 162.1002. The ICD-10-CM code set has approximately 72,000 codes updated annually on October 1 — billing companies must update their systems and encoder software each year. Codes must be reported to the highest level of specificity. Diagnosis codes drive medical necessity — an incorrect ICD-10-CM code that does not support medical necessity for the billed procedure is the leading cause of claim denials.

HCPCS Level II Codes

Maintained by CMS. Used for products, supplies, and services not covered by CPT codes — primarily durable medical equipment, drugs administered in office, ambulance services, and prosthetics/orthotics. Required for Medicare and Medicaid billing of covered items. Codes begin with A-V followed by four numbers. CMS updates HCPCS codes quarterly.

Electronic transaction standards

All electronic claims must be submitted in ASC X12 837P (professional claims) or 837I (institutional claims) format per 45 CFR § 162.1102. Electronic remittance advice is received in 835 format. Eligibility verification uses 270/271 transaction sets. These standards are maintained by the Workgroup for Electronic Data Interchange (WEDI) and required by HIPAA for all covered transactions. Your clearinghouse handles format conversion — but you must understand the underlying standards to troubleshoot rejections.

6. NPI registration, PECOS enrollment, and Medicare billing requirements

National Provider Identifier (NPI) — 45 CFR Part 162.410

Registered via: NPPES (nppes.cms.hhs.gov)Cost: FreeTimeline: Immediate online; 2–3 weeks by mail

Every covered healthcare provider must have an NPI under 45 CFR § 162.410. Individual providers receive Type 1 NPIs; organizations receive Type 2 NPIs. As a billing company, you do not obtain your own NPI — you submit claims under the provider's NPI. Professional claims (CMS-1500) require the billing provider NPI in Box 33a and rendering provider NPI in Box 24J. Missing or incorrect NPIs result in automatic claim denial. Verify your clients' NPIs against the NPPES registry before submitting your first claim.

PECOS enrollment for Medicare billing

Filed via: CMS PECOS portal or CMS-855BCost: FreeTimeline: 4–12 weeks

To bill Medicare on behalf of a provider, the provider must be enrolled in PECOS (Provider Enrollment, Chain, and Ownership System). As the billing agent, you typically need to be authorized in PECOS as the provider's billing agent. Some Medicare Administrative Contractors (MACs) also require the billing company itself to register. The CMS-855B is the Medicare enrollment application for billing agencies and independent diagnostic testing facilities. Medicaid enrollment requirements vary by state — check each state's Medicaid agency for billing company registration requirements before submitting Medicaid claims.

7. State-by-state licensing requirements for medical billing companies

Most states do not impose a specific license on medical billing companies — but several states have enacted additional requirements beyond HIPAA. The table below summarizes requirements for the largest states. Always verify current requirements with each state's licensing authority.

State Specific Billing License? Key Requirements Agency
California No dedicated license CMIA compliance (Cal. Civ. Code § 56); CCPA/CPRA if handling consumer data at scale; CA breach notification within 72 hours CA AG / Medical Board
Texas No dedicated license Texas Health & Safety Code Ch. 181 (medical privacy); TX breach notification required; general business license TX DHS / TX AG
Florida No dedicated license FL Statute § 395.301 (itemized billing); FL Statute § 817.505 (patient brokering prohibition); FL breach notification FL AHCA / FL AG
New York No dedicated license NY SHIELD Act (data security requirements); NY Public Health Law § 18 (patient record access); NY breach notification within 72 hours NY DOH / NY AG
New Jersey Registration required (some contexts) Third-party billing registration if billing consumers directly; NJ Identity Theft Prevention Act; NJ breach notification within 30 days NJ Division of Consumer Affairs
Illinois No dedicated license IL Personal Information Protection Act; IL breach notification; general business license from Secretary of State IL AG / SOS
Washington No dedicated license WA My Health MY Data Act (2023, strictest state health data law); WA breach notification within 30 days WA AG

Licensing requirements change frequently. Verify current requirements with each state's attorney general or health department before operating in that state.

Note on Washington's My Health MY Data Act: Washington enacted the most comprehensive state health data privacy law in 2023, effective March 31, 2024 (for large businesses) and June 30, 2024 (for small businesses). It applies to health data beyond HIPAA's scope — including location data, search history, and behavioral data that could identify health conditions. If you process any health data for Washington consumers, this law requires consumer rights obligations (access, deletion, consent) that exceed HIPAA requirements. Consult a healthcare privacy attorney before expanding to Washington.

8. Clearinghouse enrollment: Availity, Change Healthcare, Office Ally, and Trizetto

A healthcare clearinghouse is required infrastructure for electronic claims submission. Clearinghouses receive claims from your billing software, validate them for errors (missing NPI, invalid codes, incorrect payer IDs), convert them to HIPAA-compliant EDI format, and transmit them to payers. They receive electronic remittance advice (ERA, 835 format) from payers and route it back to your system. Every clearinghouse that handles PHI must sign a BAA with your billing company.

Choosing your primary clearinghouse

Clearinghouse Cost Best For Notes
Office Ally Free (837P); nominal for ERA Startups; solo billers No monthly fee; limited analytics
Availity Free to providers; billing co. fees vary All sizes; strong payer connectivity Largest payer network; preferred by Humana, Anthem
Change Healthcare (Optum) Per-transaction or monthly Mid-to-large billing companies 2024 cyberattack disrupted national billing; maintain backup clearinghouse
Trizetto (Cognizant) Contract-based RCM companies; enterprise Strong denial management analytics
Waystar Monthly subscription Modern cloud-native billing companies Strong real-time eligibility; good UX

Beyond clearinghouse enrollment, you must complete payer enrollment separately for each insurance company — registering to submit claims on behalf of your provider clients. Payer enrollment typically takes 2–8 weeks per payer and may require a CMS-855B (for Medicare) or payer-specific forms. ERA/EFT (electronic funds transfer) enrollment is a separate process. Build payer enrollment timelines into your client onboarding — new client revenue cannot flow until payer enrollment is complete.

9. Startup cost breakdown

Item Low High Notes
LLC formation (state filing fee)$50$500CA adds $800/yr franchise tax
EIN registration$0$0Free via IRS.gov
General business license$25$200City/county requirement
CPC or CMRS certification (exam + study materials)$200$1,500CPC: $399-$499 exam; CMRS: $200-$300
HIPAA compliance program (training + SRA + policies)$500$3,000SRA Tool is free (healthit.gov)
Healthcare attorney (BAA template + compliance review)$500$3,000One-time investment; essential
Medical billing software (year 1)$600$6,000Kareo, AdvancedMD, CollaborateMD: $50-$500/mo
Clearinghouse fees (year 1)$0$3,600Office Ally is free for 837P claims
Professional liability / E&O insurance (year 1)$500$2,500Required by most provider clients
Cyber liability insurance (year 1)$1,000$3,000Critical for PHI handling
General liability insurance (year 1)$400$1,200Standard business coverage
HIPAA-compliant computer (encrypted drive)$500$2,000Enable BitLocker/FileVault
HIPAA-compliant email, fax, phone (year 1)$240$1,200Paubox or Hushmail + eFax Business
Website and marketing materials$300$2,000One-time setup cost
Total startup range$4,815$29,700Most solo startups: $8,000–$15,000

Revenue model: Most billing companies charge 4-10% of collections. A solo biller handling 3-5 small practices with combined monthly collections of $75,000-$150,000 earns $3,000-$15,000/month. Specializing in high-reimbursement specialties (orthopedics, cardiology, pain management, anesthesia) increases per-claim revenue significantly. Cash flow stabilizes after 3-6 months as payer enrollment completes and claim volumes increase.

Form your business entity first

Most permits require a registered business entity (LLC or corporation). These services handle the state filing for you:

We may earn a commission if you sign up through these links, at no extra cost to you.

10. Insurance requirements for medical billing companies

Medical billing companies carry significant liability exposure from three distinct risk categories: HIPAA/data breaches, billing errors, and general business risks. Three types of insurance are essential before signing your first client.

Professional Liability (Errors & Omissions)

Covers claims arising from billing errors, coding mistakes, missed filing deadlines (timely filing limits are strict — Medicare requires claims within 12 months of service date), failure to follow up on denials, or other professional errors that cause financial loss to provider clients. Billing errors can cost a practice tens of thousands of dollars in lost revenue. Most healthcare providers require proof of E&O coverage ($1 million per claim / $2 million aggregate is a common minimum) before executing a billing contract. Annual cost for a solo billing company: $500-$2,500.

Cyber Liability Insurance

The most critical coverage for a business handling PHI. Covers: forensic investigation costs after a breach, HIPAA-required patient notification (written notice to each affected individual), media notification (if breach affects 500+ patients in a state), regulatory fines (verify your policy covers HIPAA penalties — some exclude government fines), legal defense costs for OCR investigations and private lawsuits, credit monitoring services for affected patients, and business interruption from cyberattack. The average healthcare data breach cost $9.77 million in 2024 (IBM Security). Even a small breach affecting 200 patients can cost $25,000-$100,000 in notification and remediation. Annual cost for a small billing company: $1,000-$3,000.

General Liability

Covers bodily injury and property damage. Required for commercial lease agreements. Provides baseline protection for client visits to your office. Annual cost: $400-$1,200. Consider a Business Owner's Policy (BOP) that bundles general liability with commercial property coverage — typically cheaper than buying separately.

11. Common mistakes that get medical billing companies in trouble

Mistake 1: Starting work without a signed BAA

Accessing PHI without a signed Business Associate Agreement is an immediate HIPAA violation — before you process a single claim. OCR can assess penalties of $100-$50,000 per violation. Never receive patient data from a new client until the BAA is fully executed and filed. This applies equally to your vendors: if your billing software or clearinghouse does not have a signed BAA with you, you are in violation the moment you use them with PHI.

Mistake 2: Skipping the HIPAA Security Risk Assessment

The #1 finding in OCR HIPAA audits — by a wide margin — is failure to conduct a thorough and documented Security Risk Analysis. The SRA is required by 45 CFR § 164.308(a)(1) and must be comprehensive: identify all ePHI in your environment, assess threats and vulnerabilities, evaluate current controls, determine the likelihood and potential impact of threats, and document the analysis. "I intended to do it" is not a defense. Use the free HHS Security Risk Assessment Tool (healthit.gov/SRA) and document everything.

Mistake 3: Using non-HIPAA-compliant tools

Standard Gmail is not HIPAA-compliant. Personal Dropbox is not HIPAA-compliant. Consumer fax apps are not HIPAA-compliant. WhatsApp, iMessage, and standard text messaging are not HIPAA-compliant. Every tool that touches PHI must: (a) have HIPAA-appropriate security features (encryption at rest and in transit) and (b) have a signed BAA with your company. Acceptable alternatives: Paubox or Hushmail for email; eFax Business or Updox for fax; ShareFile (Citrix) or Box (with BAA) for file storage; and a HIPAA-compliant practice management platform for billing software.

Mistake 4: Upcoding or submitting unsupported codes

Billing a higher-level E/M code than the clinical documentation supports (upcoding) is a False Claims Act violation that can result in $13,946-$27,894 per false claim plus treble damages. Some billing companies upcode to increase collections and percentage fees — this is fraud. Even inadvertent upcoding from poor training creates FCA exposure. Implement pre-submission claim auditing, require access to clinical documentation before billing, and establish a written coding accuracy policy. The OIG can initiate a qui tam investigation based on a complaint from a single disgruntled employee.

Mistake 5: Neglecting denial management

Insurance companies deny 5-20% of claims on first submission. New billing companies often process clean claims efficiently but fail to build systematic denial management workflows — meaning 10-20% of potential revenue is never collected. Missed filing deadlines for appeals (most payers give 60-180 days; Medicare gives 120 days) result in permanent revenue loss. Build denial tracking, categorization (clinical vs. administrative vs. eligibility vs. coding denials), and systematic appeal processes into your workflow from day one. Your provider clients will measure you on net collection rate — not gross billing volume.

Mistake 6: Ignoring the Anti-Kickback Statute in fee arrangements

Any billing arrangement that could appear to compensate for referrals — even unintentionally — creates AKS exposure. Do not offer free billing software as an inducement to sign with your company. Do not offer unusually low fees to high-volume referral-generating practices while charging higher rates to others. Structure all fee arrangements to be commercially reasonable, documented in writing, and not based on referral volume. Have a healthcare attorney review your standard client contract before using it.

12. Medical billing business launch checklist

  1. 1.Form your LLC and register with the state Secretary of State. Obtain EIN from IRS (free, online). Open a dedicated business bank account.
  2. 2.Obtain professional certification — Enroll in CPC (AAPC) or CMRS (AMBA) exam preparation. Schedule your exam date within 3-6 months.
  3. 3.Build your HIPAA compliance program — Conduct Security Risk Analysis (use HHS SRA Tool), write Privacy and Security policies, designate HIPAA Officer, establish breach response procedures, and document everything.
  4. 4.Secure HIPAA-compliant tools — Replace standard email with Paubox or Hushmail, standard fax with eFax Business or Updox, and personal cloud storage with a BAA-capable alternative (Box, ShareFile, or Google Workspace with a BAA). Enable full-disk encryption on all computers.
  5. 5.Have a healthcare attorney draft your standard BAA and client contract — These documents protect you legally and establish your professional credibility with providers.
  6. 6.Select and configure billing software — Choose a HIPAA-compliant platform (Kareo, AdvancedMD, CollaborateMD, or similar), execute a BAA with the vendor, and configure for your target specialties.
  7. 7.Enroll with a clearinghouse — Start with Office Ally (free) and Availity. Execute BAAs with both. Establish a secondary clearinghouse connection for business continuity.
  8. 8.Obtain insurance — Professional liability (E&O), cyber liability, and general liability. Ensure cyber policy covers HIPAA regulatory penalties. Get certificates of insurance ready for prospective clients.
  9. 9.Research state requirements in your target market — Check for billing-specific registration, state health data privacy laws beyond HIPAA, and breach notification timelines in each state where you will bill.
  10. 10.Sign first client, execute BAA, complete payer enrollment — Build a 6-8 week client onboarding timeline to account for payer enrollment delays. Verify the provider's NPI via NPPES before billing.

Frequently asked questions

Do you need a license to operate a medical billing business?
No specific federal license is required to operate a medical billing business. However, federal HIPAA law applies automatically — you are a "business associate" under 45 CFR § 160.103 the moment you handle protected health information (PHI) on behalf of a covered entity (healthcare provider, health plan, or clearinghouse). This classification triggers compliance obligations under three separate HIPAA rules: the Privacy Rule (45 CFR Part 164 Subpart E), the Security Rule (45 CFR Part 164 Subpart C), and the Breach Notification Rule (45 CFR Part 164 Subpart D). At the state level, requirements vary significantly: California: No dedicated medical billing license, but the Confidentiality of Medical Information Act (CMIA, Cal. Civ. Code § 56 et seq.) imposes requirements beyond HIPAA. Third-party billers must register with the Medical Board of California if billing for licensed physicians in certain contexts. California also has enhanced breach notification requirements under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA). New Jersey: Third-party medical billing companies must register with the New Jersey Division of Consumer Affairs under the New Jersey Consumer Fraud Act if billing consumers directly for unpaid amounts. New York: No specific state billing license, but all businesses handling health information must comply with NY SHIELD Act requirements. Florida: No specific medical billing license, but healthcare provider billing is subject to Florida Statute § 395.301 (itemized billing requirements) and Florida Statute § 817.505 (patient brokering — relevant to fee arrangements). Texas: No specific license, but the Texas Medical Disclosure Panel issues rules governing medical billing disclosures. Beyond state law, you must obtain a general business license from your city or county (typically $25-$200/year), register an LLC or corporation with the state Secretary of State, and obtain an EIN from the IRS. Professional certification (CPC from AAPC or CMRS from AMBA) is not legally required but is practically essential — virtually all healthcare providers require credentialed billing staff before signing a contract.
What is a HIPAA Business Associate Agreement and why is it mandatory?
A Business Associate Agreement (BAA) is a legally required contract under 45 CFR § 164.504(e) between a covered entity (the healthcare provider, health plan, or clearinghouse that is your client) and a business associate (your medical billing company). Without a signed BAA, you are prohibited from accessing or using any protected health information — and doing so constitutes a HIPAA violation before you process a single claim. The BAA must specify, at minimum: — Permitted uses and disclosures of PHI by the business associate (billing, submitting claims, collecting payments, managing denials) — Prohibition on using PHI for purposes not listed in the agreement — Obligation to implement appropriate administrative, physical, and technical safeguards (as required by 45 CFR § 164.308, 164.310, 164.312) — Obligation to report breaches to the covered entity within 60 days of discovery (45 CFR § 164.410) — Requirement to subcontract only with parties that agree to equivalent protections (your clearinghouse, cloud storage provider, IT support — all must have their own BAAs with you) — Return or destruction of PHI upon termination of the agreement — Obligation to make PHI available to HHS for compliance audits HHS provides sample BAA provisions at hhs.gov, but customization is advisable. Have a healthcare attorney review your standard BAA before using it. Penalties for BAA violations are severe. Civil penalties: $100-$50,000 per violation (tiered by culpability), up to $1.9 million per violation category per year. Criminal penalties: up to $250,000 and 10 years imprisonment for intentional misuse. HHS OCR investigates all substantial complaints and conducts random audits — business size provides no shield.
How does the Anti-Kickback Statute (42 U.S.C. § 1320a-7b) apply to medical billing companies?
The Anti-Kickback Statute (AKS), 42 U.S.C. § 1320a-7b(b), makes it a federal crime to knowingly and willfully offer, pay, solicit, or receive any remuneration (including kickbacks, bribes, or rebates) to induce or reward the referral of items or services covered by federal healthcare programs (Medicare, Medicaid, TRICARE, CHIP). Violations are a felony — up to 10 years imprisonment, $100,000 in fines per violation, and mandatory exclusion from federal healthcare programs. For medical billing companies, AKS creates several compliance obligations: 1. Fee-based billing arrangements: Billing companies that charge a percentage of collections — the most common pricing model — are potentially implicated under the AKS if the arrangement could be construed as compensation that influences referrals. The OIG has issued guidance clarifying that percentage-based billing fees are generally permissible as long as the percentage is reasonable, the arrangement is documented, and the billing company is not in a position to influence patient referrals to the provider. 2. Billing software or service discounts: If you offer free or discounted billing software to providers in exchange for their billing business, you may be creating AKS exposure. The OIG Personal Services and Management Contracts safe harbor (42 CFR § 1001.952(d)) provides protection for legitimate service arrangements that meet specific requirements: the arrangement must be in writing, must cover all services, compensation must be set in advance and not based on volume of referrals, and the term must be at least one year. 3. Referral arrangements: If a billing company receives compensation for referring patients or providers to other healthcare entities, that arrangement must be structured within an AKS safe harbor. 4. Consulting the OIG safe harbors: The OIG has established regulatory safe harbors at 42 CFR § 1001.952 that define arrangements that will not be prosecuted under the AKS. For billing companies, the most relevant are the Personal Services and Management Contracts safe harbor and the Electronic Health Records (EHR) safe harbor. Practical compliance: Document all fee arrangements in writing, ensure percentages are commercially reasonable, avoid any arrangement that could appear to be paying for referrals, and consult with an OIG-experienced healthcare attorney when structuring complex arrangements.
What is the Stark Law (42 U.S.C. § 1395nn) and does it apply to medical billing companies?
The Stark Law, formally the Physician Self-Referral Law (42 U.S.C. § 1395nn), prohibits physicians from referring Medicare or Medicaid patients to entities with which the physician (or an immediate family member) has a financial relationship — unless the relationship fits within a statutory or regulatory exception. Unlike the Anti-Kickback Statute, the Stark Law is a strict liability statute — intent is irrelevant. Violations result in refusal of Medicare/Medicaid payment, repayment of amounts received, and civil monetary penalties up to $26,125 per improper claim (adjusted annually for inflation). Direct applicability to billing companies: The Stark Law primarily governs physicians and the entities to which they refer, not billing companies themselves. However, billing companies become indirectly implicated in two ways: 1. Billing Stark Law violations: If your physician client is making self-referrals in violation of the Stark Law and you bill for those services, you may submit claims for services that are not reimbursable under Medicare. This exposes your client — and potentially your billing company — to False Claims Act liability. 2. Financial arrangements with physician-owners: If a billing company has physicians as investors or owners who also refer business to the billing company, the arrangement must be analyzed for Stark Law compliance. Practical steps for billing companies: — Include representations and warranties in your client contracts that the healthcare provider is operating in compliance with all applicable federal healthcare laws, including the Stark Law — Train billing staff to flag referral patterns that may indicate Stark Law issues — Conduct annual compliance reviews — If you discover a potential Stark Law violation by a client, consult a healthcare attorney immediately — the CMS Self-Disclosure Protocol may be relevant The CMS Physician Self-Referral exceptions at 42 CFR §§ 411.355-411.357 define permitted financial relationships. Familiarize yourself with these exceptions when reviewing client arrangements.
How does the False Claims Act (31 U.S.C. § 3729) create liability for medical billing companies?
The False Claims Act (FCA), 31 U.S.C. §§ 3729-3733, is the federal government's primary tool for combating fraud in government programs including Medicare and Medicaid. It imposes civil liability on any person who knowingly presents (or causes to be presented) a false or fraudulent claim to the government, or knowingly makes or uses a false statement material to a false claim. "Knowingly" includes deliberate ignorance and reckless disregard — you do not have to know a claim is false to be liable. FCA penalties: Civil penalties of $13,946-$27,894 per false claim (2024 adjusted amounts, adjusted annually) plus three times the amount of damages sustained by the government. FCA liability can be catastrophic — a billing company submitting tens of thousands of claims can face liability in the hundreds of millions of dollars. How FCA applies to medical billing companies specifically: 1. Submitting false codes: Upcoding (billing for a more expensive service than was provided, e.g., billing a Level 5 office visit when the documentation supports only a Level 3) is a classic FCA violation. As the billing company, you are responsible for the claims you submit. The FCA's "causes to be presented" language means you can be liable even though you are not the healthcare provider. 2. Unbundling: Billing separately for services that should be billed under a single bundled code (e.g., billing each component of a surgical package separately) can constitute false claims. 3. Billing for services not rendered: If your client's records indicate a service was performed but it was not, and you bill for it, you have submitted a false claim. 4. Qui tam provisions: The FCA allows private citizens (relators) to file lawsuits on behalf of the government and receive 15-30% of any recovery. Disgruntled employees, competitors, or even clients can file qui tam suits. These are known as "whistleblower" cases and are increasingly common in healthcare billing. Compliance measures: — Implement claim auditing — review a random sample of claims before submission — Maintain written coding policies that align with CMS and payer guidelines — Train billing staff on FCA liability annually — Establish a compliance hotline for staff to report concerns — Never submit a claim without corresponding clinical documentation in the client's chart
What CPT, ICD-10, and HCPCS coding requirements must a medical billing company follow?
Medical billing requires translating clinical services into standardized codes that payers can process. There are three coding systems, each with specific regulatory requirements: 1. CPT Codes (Current Procedural Terminology): Published and maintained by the American Medical Association (AMA). CPT codes describe medical procedures and services. Usage of CPT codes requires a license from the AMA. Categories: Category I (main medical procedures, 00100-99607), Category II (performance measurement), Category III (emerging technology). CMS publishes Relative Value Units (RVUs) for each CPT code annually in the Medicare Physician Fee Schedule Final Rule, which determines Medicare reimbursement. The 2026 Medicare Physician Fee Schedule is published at 42 CFR Part 414. 2. ICD-10-CM (International Classification of Diseases, 10th Revision, Clinical Modification): Maintained by the CDC National Center for Health Statistics and required for all HIPAA-covered transactions (45 CFR § 162.1002). ICD-10-CM codes are used for diagnosis codes on professional and institutional claims. The current code set has approximately 72,000 codes updated annually each October 1. Incorrect ICD-10-CM codes are a leading cause of claim denials. 3. HCPCS Level II (Healthcare Common Procedure Coding System): Maintained by CMS. Used for products, supplies, and services not covered by CPT codes — primarily durable medical equipment (DME), drugs, ambulance services, and other non-physician services. Codes begin with a letter (A-V) followed by four numbers. Required for billing Medicare and Medicaid for covered items and services. Transaction standards: All electronic claims must be submitted in ASC X12 837P (professional) or 837I (institutional) format (45 CFR § 162.1102). Electronic remittance advice is received in 835 format. These formats are part of the HIPAA Electronic Transaction Standards. Coding accuracy obligations: — Codes must match clinical documentation in the provider's medical records — Diagnosis codes must be coded to the highest level of specificity — Procedure codes must accurately reflect the actual service provided — Do not upcode, downcode, or unbundle — Use the most current code set — outdated codes result in automatic denials Certification requirement: The CPC exam tests proficiency in all three code sets. Medical billing companies should have at least one CPC-credentialed staff member.
What are the NPI registration requirements for a medical billing company?
The National Provider Identifier (NPI) is a unique 10-digit identifier assigned to healthcare providers under 45 CFR Part 162.410. NPI registration is required for covered healthcare providers under HIPAA — not for billing companies themselves. However, understanding NPI requirements is essential for running a billing operation. As a billing company, here is what you need to know: 1. Your clients (healthcare providers) must have NPIs: All individual healthcare providers (physicians, nurse practitioners, physician assistants, etc.) must have an individual NPI (Type 1). Healthcare organizations (medical groups, hospitals, clinics) must have an organizational NPI (Type 2). NPI registration is free through NPPES (National Plan and Provider Enumeration System) at nppes.cms.hhs.gov. 2. Claims must include the correct NPI: Professional claims (CMS-1500) must include the billing provider NPI in Box 33a and the rendering provider NPI in Box 24J. Institutional claims (UB-04) require NPIs in specific form locators. Submitting claims with incorrect or missing NPIs results in automatic denial. 3. Billing companies do NOT need their own NPI: The NPI standard (45 CFR § 162.410) does not require billing companies to obtain an NPI. You submit claims under your client provider's NPI. 4. PECOS enrollment for Medicare: If billing Medicare for a provider, the provider must be enrolled in PECOS (Provider Enrollment, Chain, and Ownership System). As the billing agent, you may need to be authorized as the provider's billing agent within PECOS. The CMS-855B form is the Medicare enrollment application for billing agencies. Some Medicare Administrative Contractors (MACs) require billing companies to register before submitting claims on behalf of enrolled providers. 5. Medicaid enrollment: Each state Medicaid program has its own enrollment requirements for billing companies. Many states require billing companies to be registered with the state Medicaid agency before submitting Medicaid claims. Check the relevant State Medicaid Agency for requirements in each state where you will submit Medicaid claims. 6. Taxonomy codes: Along with NPIs, claims require Provider Taxonomy Codes identifying the provider's specialty. These are maintained by the National Uniform Claim Committee (NUCC) and are regularly updated.
What are the HIPAA technical and physical safeguard requirements for a home-based medical billing business?
HIPAA applies equally whether you operate from an office building or a home office. The HIPAA Security Rule (45 CFR Part 164 Subpart C) requires covered entities and business associates to implement three categories of safeguards for electronic PHI (ePHI): 1. Administrative Safeguards (45 CFR § 164.308): — Security Management Process: Conduct a thorough risk analysis to identify threats to ePHI; implement risk management policies to reduce identified risks to reasonable levels — Assigned Security Responsibility: Designate a HIPAA Security Officer (can be yourself in a sole proprietorship) — Workforce Security: Implement procedures for authorizing and supervising workforce access to ePHI — Information Access Management: Implement policies for granting access to ePHI on a minimum-necessary basis — Security Awareness and Training: Train all workforce members (including yourself) on HIPAA security; conduct annual refresher training — Security Incident Procedures: Document how you respond to security incidents — Contingency Plan: Implement data backup and disaster recovery procedures — Evaluation: Conduct periodic technical and non-technical evaluations of your security program 2. Physical Safeguards (45 CFR § 164.310): — Facility Access Controls: If working from home, dedicate a room or area for billing work; use a locking door; restrict access to others in the household — Workstation Use: Position screens so PHI cannot be viewed by unauthorized persons (family members, visitors); use screen locks — Workstation Security: Store laptops securely when not in use — Device and Media Controls: Implement procedures for disposing of devices containing ePHI (use certified data destruction; do not simply discard); track all hardware and electronic media that store ePHI 3. Technical Safeguards (45 CFR § 164.312): — Access Control: Use unique user IDs; never share login credentials; implement automatic session timeout (15-minute idle lockout is common practice) — Audit Controls: Implement software that logs access to ePHI — who accessed what records and when — Integrity: Implement mechanisms to ensure ePHI is not improperly altered or destroyed — Transmission Security: Use encrypted transmission (TLS 1.2 or higher) for all electronic communications containing PHI; do not transmit unencrypted ePHI via standard email Specific tools: — Full-disk encryption on all computers (BitLocker for Windows, FileVault for Mac) — non-negotiable — HIPAA-compliant email (Paubox, Hushmail, or Microsoft 365 with BAA) — HIPAA-compliant fax (Updox, eFax Business, RingCentral Fax with BAA) — VPN for remote connections — Regular automated backups to encrypted cloud storage (with BAA) — Password manager for unique, complex credentials Documentation: Retain all HIPAA policies, risk assessments, training records, and incident reports for a minimum of 6 years from the date of creation or last effective date (45 CFR § 164.530(j)).
What clearinghouses does a medical billing company use, and what does enrollment require?
A healthcare clearinghouse is an entity that receives non-standard health information transactions and converts them to standard format (and vice versa). For billing companies, clearinghouses are the essential intermediary between your billing software and insurance payers. They validate claims, convert them to HIPAA-compliant EDI format, and transmit them to the correct payer. They also receive and translate electronic remittance advice (ERA/835) from payers. Clearinghouses are themselves covered entities under HIPAA (45 CFR § 160.103) — they must sign a Business Associate Agreement with you, and they operate under the same HIPAA transaction standards you do. Major clearinghouses and what to know about each: 1. Availity: The largest free-to-providers clearinghouse. Supports 837P/837I claim submission, real-time eligibility verification (270/271), and 835 ERA. Free to providers; billing companies pay per-transaction or monthly fees. Availity is the primary clearinghouse for many major payers including Humana, WellPoint, and Anthem. 2. Change Healthcare (now Optum): One of the largest commercial clearinghouses by volume. Processes billions of claims annually. After the February 2024 cyberattack that disrupted healthcare billing nationally for weeks, many billing companies now maintain backup clearinghouse connections as part of their business continuity planning. Change Healthcare charges transaction fees. 3. Trizetto (Cognizant): Enterprise-grade clearinghouse used by larger billing companies and revenue cycle management firms. Strong payer connections and denial management reporting. 4. Office Ally: Free professional claim submission for standard professional (837P) claims. Popular with small and startup billing companies due to no subscription cost. Limited advanced features compared to commercial clearinghouses. 5. Waystar: Cloud-based revenue cycle platform with clearinghouse functionality. Newer platform with strong analytics and denial management tools. Enrollment process: — Create a clearinghouse account (most offer online signup) — Complete payer enrollment for each insurance company: Most payers require separate enrollment before they will accept claims from a new clearinghouse/billing agent. Payer enrollment typically takes 2-8 weeks per payer and may require submitting a CMS-855B or equivalent form — Obtain ERA/EFT enrollment: Electronic remittance advice and electronic funds transfer require separate enrollment with each payer — Execute a BAA with the clearinghouse Pro tip: Use Office Ally as your primary clearinghouse for cost control during startup, and enroll with Availity or Change Healthcare as a backup — especially after the 2024 Change Healthcare outage demonstrated the systemic risk of single-clearinghouse dependency.
What insurance does a medical billing company need?
Medical billing companies face significant liability exposure from HIPAA breaches, billing errors, and coding mistakes. Three types of insurance are essential: 1. Professional Liability (Errors and Omissions / E&O): Covers claims arising from billing errors, coding mistakes, missed filing deadlines, failure to follow up on denials, or other professional errors that cause financial loss to your clients. A billing error that costs a medical practice $50,000 in lost revenue can easily exceed your annual revenue as a startup. Typical cost: $500-$2,500/year for a small billing company. Most healthcare providers require proof of E&O coverage before signing a billing contract. 2. Cyber Liability Insurance: The most important coverage for a medical billing company. Covers: — Data breach response costs (forensic investigation, notification to affected patients, credit monitoring) — Legal defense costs and settlements from HIPAA OCR investigations — Regulatory fines (note: not all cyber policies cover government fines; verify this specifically) — Business interruption from cyberattack (critical after the Change Healthcare incident) — Ransomware payment (controversial; verify coverage and consult a healthcare attorney) The average cost of a healthcare data breach in 2024 was $9.77 million per incident (IBM Cost of a Data Breach Report, 2024). Even a small breach affecting a few hundred patients can cost $50,000-$250,000 in notification, legal, and remediation costs. Cyber insurance for a small billing company typically costs $1,000-$3,000/year. 3. General Liability: Covers bodily injury and property damage claims. Required by many commercial leases. If a client visits your office and trips, general liability covers the claim. Cost: $400-$1,200/year. 4. Workers Compensation: Required in most states if you have employees (requirements vary — some states exempt very small employers). Check your state's Department of Labor. 5. Optional: Commercial property insurance (if you have office equipment worth protecting), business owner's policy (BOP combines general liability and property), and umbrella liability. Total annual insurance budget for a solo medical billing startup: $2,000-$6,700. For a small company with 2-5 employees: $5,000-$15,000. Verify that all insurance policies include coverage for HIPAA-specific regulatory actions and that your E&O policy covers errors in claim coding — some policies exclude coding errors specifically.

Find the exact registrations required for your medical billing business

State business license requirements and third-party billing regulations vary by jurisdiction. StartPermit's free permit finder shows you the exact agencies, fees, and application links for your location.

Find my medical billing permits

Official Sources

Related Guides

Know your permits before you open

The StartPermit Report lists the permits, licenses, and registrations we identify for your business — personalized to your business type, city, and structure, with fees, filing order, and official links.

One-time purchase — not a subscription Ready in about 60 seconds Secure checkout via Stripe