Not legal advice. Requirements may change — always verify with your local government authority before applying. Last verified: .
Quick answer: what you need to start a medical billing business
- 1HIPAA compliance program — Mandatory under 45 CFR Parts 160, 162, and 164. Implement Privacy Rule, Security Rule, and Breach Notification Rule requirements before handling any patient data.
- 2Business Associate Agreement (BAA) — Required by 45 CFR § 164.504(e) before accessing any PHI. Execute a separate BAA with every client, clearinghouse, software vendor, and IT provider that can access patient data.
- 3Professional certification — CPC (AAPC) or CMRS (AMBA) is not legally required but is practically essential for winning client contracts. Nearly all providers demand credentialed billing staff.
- 4Clearinghouse enrollment — Enroll with Availity, Office Ally, or Change Healthcare to submit electronic claims in 837P/837I format and receive ERAs in 835 format as required by 45 CFR Part 162.
- 5Federal fraud law compliance — Anti-Kickback Statute (42 U.S.C. § 1320a-7b), Stark Law (42 U.S.C. § 1395nn), and False Claims Act (31 U.S.C. § 3729) all apply to your billing operations. Violations carry felony-level consequences.
- 6Cyber + E&O insurance — A single HIPAA breach can cost $50,000-$250,000+ in notification and legal costs. Both cyber liability and professional liability (E&O) insurance are essential before signing your first client.
1. How the medical billing regulatory framework works
A medical billing company submits healthcare claims to insurance companies (payers) on behalf of healthcare providers. You receive patient encounter data, translate it into standardized codes (CPT, ICD-10-CM, HCPCS), submit claims electronically through a clearinghouse, track adjudication, manage denials and appeals, and post payments. You handle protected health information (PHI) at every step.
Because you handle PHI, you are classified as a "business associate" under HIPAA (45 CFR § 160.103). This classification triggers compliance obligations under three separate HIPAA rules: the Privacy Rule (how PHI can be used and disclosed, 45 CFR Part 164 Subpart E), the Security Rule (technical and physical safeguards for electronic PHI, 45 CFR Part 164 Subpart C), and the Breach Notification Rule (what to do when PHI is compromised, 45 CFR Part 164 Subpart D). These obligations apply regardless of business size — a solo home-based biller has the same compliance requirements as a large billing company.
Beyond HIPAA, three federal fraud statutes create serious criminal and civil liability for billing companies: the Anti-Kickback Statute (42 U.S.C. § 1320a-7b), which prohibits fee arrangements that induce referrals; the Stark Law (42 U.S.C. § 1395nn), which prohibits physician self-referrals; and the False Claims Act (31 U.S.C. § 3729), which creates liability for submitting false or inaccurate claims to Medicare and Medicaid. Penalties under these statutes are severe — up to 10 years federal imprisonment under the AKS and FCA penalties of up to $27,894 per false claim plus treble damages.
HIPAA enforcement is handled by the HHS Office for Civil Rights (OCR). The OIG (Office of Inspector General) and DOJ enforce the AKS and FCA. In 2024, OCR received over 34,000 HIPAA complaints and the DOJ recovered $2.9 billion in healthcare fraud judgments — underscoring that enforcement is active and consequential for billing companies of all sizes.
2. Business formation: LLC, EIN, and general business licensing
Form an LLC before signing any client contract
An LLC (Limited Liability Company) provides essential personal liability protection. In a field where a single HIPAA breach or billing error can result in six-figure financial exposure, operating as a sole proprietor — with your personal assets at risk — is inadvisable. Your BAAs, insurance policies, clearinghouse contracts, and client agreements will all be in the LLC's name. Register with your state Secretary of State, then obtain an EIN from the IRS (free, immediate online). You also need a general business license from your city or county (typically $25-$200/year). Some states (e.g., California) charge an LLC franchise tax ($800/year minimum).
Professional certification: CPC or CMRS
No state or federal law mandates certification, but virtually all healthcare providers require credentialed billing staff before signing a contract. The CPC (Certified Professional Coder) from AAPC is the industry gold standard — it covers CPT, ICD-10-CM, HCPCS Level II, anatomy, and reimbursement methodology. The exam is 150 questions over 5 hours 40 minutes with a ~60-70% pass rate. Cost: $399 for AAPC members, $499 for non-members. Requires 2 years of professional experience (or earn CPC-A apprentice status immediately). The CMRS (Certified Medical Reimbursement Specialist) from AMBA focuses specifically on billing and reimbursement, is open-book, and is easier to obtain ($200-$300). Both require continuing education to maintain (AAPC: 36 CEUs per 2-year cycle).
HIPAA compliance program (45 CFR Parts 160, 162, 164)
You must implement a comprehensive HIPAA compliance program before handling any PHI. Required elements: (1) Written privacy and security policies and procedures; (2) Annual Security Risk Analysis — use the free HHS Security Risk Assessment Tool (healthit.gov/SRA); (3) Risk management plan addressing identified threats; (4) Workforce training on HIPAA — even if you are the sole employee; (5) Breach response plan with 60-day notification procedures; (6) Designated HIPAA Privacy and Security Officer (same person is permissible); (7) Documentation retained for minimum 6 years (45 CFR § 164.530(j)). Do not wait to build this program — OCR investigates complaints regardless of company size, and "I didn't know" is not a recognized defense.
3. Business Associate Agreements: the foundation of every client relationship
The Business Associate Agreement (BAA) is the most important legal document in your billing business. Under 45 CFR § 164.504(e), a covered entity cannot disclose PHI to a business associate without a written BAA — and you cannot handle PHI without one. This means: before your first client sends you a single patient record, a signed BAA must be in place. Before your clearinghouse receives your first claim, they must have a signed BAA with you. Before your billing software vendor hosts any of your data, they must sign a BAA.
The BAA must contain mandatory provisions specified at 45 CFR § 164.504(e)(2). At minimum, it must: specify permitted uses and disclosures of PHI; require the business associate to implement appropriate safeguards; require the business associate to report breaches within 60 days of discovery; require the business associate to ensure subcontractors agree to equivalent protections; provide for PHI return or destruction upon termination; and require the business associate to make internal practices available to HHS for compliance audits.
HHS provides sample BAA provisions at hhs.gov — but these are a starting point, not a finished document. Have a healthcare attorney customize your standard BAA. Expect to pay $500-$2,000 for a properly drafted BAA template that you can use for all client relationships.
Every vendor that touches PHI needs a BAA with you
This includes: billing software vendors, clearinghouses, cloud storage providers (Dropbox, Google Drive are not HIPAA-compliant without a BAA), encrypted email providers, HIPAA-compliant fax services, IT support companies who can access your systems, and shredding companies. If a vendor refuses to sign a BAA, you cannot use that vendor for any PHI-related activity. Standard Gmail, Dropbox, and most consumer fax apps cannot sign a BAA — replace them before starting operations.
4. Federal fraud laws: Anti-Kickback, Stark Law, and False Claims Act
Three federal statutes create significant criminal and civil liability for medical billing companies. Understanding them is not optional — violations can end your business and result in federal prosecution.
Anti-Kickback Statute (42 U.S.C. § 1320a-7b)
The AKS makes it a federal felony to offer, pay, solicit, or receive any remuneration to induce or reward referrals of items or services covered by federal healthcare programs. For billing companies, the primary risk is percentage-based billing fees — the OIG has scrutinized whether collecting a percentage of claims creates improper incentives. The OIG's guidance permits percentage billing arrangements as long as they are commercially reasonable, disclosed, and not tied to the volume or value of referrals that the billing company generates. The Personal Services and Management Contracts safe harbor (42 CFR § 1001.952(d)) protects properly structured billing arrangements.
Penalties: AKS violations are a felony — up to 10 years imprisonment per violation, $100,000 civil monetary penalty per violation, and mandatory exclusion from all federal healthcare programs. Exclusion means you cannot submit any claims to Medicare or Medicaid — effectively ending a medical billing operation.
Stark Law (42 U.S.C. § 1395nn, implemented at 42 CFR Part 411)
The Stark Law prohibits physicians from referring Medicare or Medicaid patients to entities with which the physician has a financial relationship unless a specific exception applies. Unlike the AKS, the Stark Law is strict liability — intent is irrelevant. Billing companies are indirectly implicated: if your client provider is violating the Stark Law and you bill for those services, you are submitting claims for non-reimbursable services. Include contractual representations from all clients that they are operating in compliance with applicable federal healthcare laws, and train billing staff to recognize red-flag referral patterns.
False Claims Act (31 U.S.C. §§ 3729-3733)
The FCA imposes civil liability of $13,946-$27,894 per false claim plus treble damages for knowingly submitting false or fraudulent claims to the government. "Knowingly" includes reckless disregard — if you submit claims without verifying the underlying documentation, you risk FCA liability. Upcoding (billing a higher-level service than documented), unbundling (billing component services separately instead of as a bundled code), and billing for services not rendered are classic FCA violations. The FCA's qui tam provision allows whistleblowers to file suit on behalf of the government and collect 15-30% of recoveries — meaning a disgruntled employee can trigger a federal investigation.
Compliance program — not optional
The OIG recommends that all medical billing companies adopt a formal compliance program including: written standards and policies; designated compliance officer; effective training; open lines of communication (compliance hotline); auditing and monitoring of claims; prompt response to detected violations; and disciplinary standards. The OIG's Compliance Program Guidance for Third-Party Medical Billing Companies (2000, updated via subsequent workplan items) provides the blueprint. A compliance program is also a mitigating factor in any federal investigation.
5. CPT, ICD-10-CM, and HCPCS coding requirements
Medical billing requires translating clinical services into standardized codes. HIPAA mandates use of standard code sets for all electronic healthcare transactions under 45 CFR § 162.1002. There are three code systems every medical billing company must master.
CPT Codes (Current Procedural Terminology)
Published and maintained by the AMA. CPT codes (00100–99607 for Category I) describe medical procedures and services. Usage requires an AMA license. CMS publishes Relative Value Units (RVUs) for each CPT code annually in the Medicare Physician Fee Schedule Final Rule (42 CFR Part 414), which determines Medicare reimbursement amounts. The CPC exam tests proficiency across the entire CPT code set — this is why certification matters operationally.
ICD-10-CM Diagnosis Codes
Maintained by the CDC National Center for Health Statistics. Mandated for all HIPAA-covered transactions under 45 CFR § 162.1002. The ICD-10-CM code set has approximately 72,000 codes updated annually on October 1 — billing companies must update their systems and encoder software each year. Codes must be reported to the highest level of specificity. Diagnosis codes drive medical necessity — an incorrect ICD-10-CM code that does not support medical necessity for the billed procedure is the leading cause of claim denials.
HCPCS Level II Codes
Maintained by CMS. Used for products, supplies, and services not covered by CPT codes — primarily durable medical equipment, drugs administered in office, ambulance services, and prosthetics/orthotics. Required for Medicare and Medicaid billing of covered items. Codes begin with A-V followed by four numbers. CMS updates HCPCS codes quarterly.
Electronic transaction standards
All electronic claims must be submitted in ASC X12 837P (professional claims) or 837I (institutional claims) format per 45 CFR § 162.1102. Electronic remittance advice is received in 835 format. Eligibility verification uses 270/271 transaction sets. These standards are maintained by the Workgroup for Electronic Data Interchange (WEDI) and required by HIPAA for all covered transactions. Your clearinghouse handles format conversion — but you must understand the underlying standards to troubleshoot rejections.
6. NPI registration, PECOS enrollment, and Medicare billing requirements
National Provider Identifier (NPI) — 45 CFR Part 162.410
Every covered healthcare provider must have an NPI under 45 CFR § 162.410. Individual providers receive Type 1 NPIs; organizations receive Type 2 NPIs. As a billing company, you do not obtain your own NPI — you submit claims under the provider's NPI. Professional claims (CMS-1500) require the billing provider NPI in Box 33a and rendering provider NPI in Box 24J. Missing or incorrect NPIs result in automatic claim denial. Verify your clients' NPIs against the NPPES registry before submitting your first claim.
PECOS enrollment for Medicare billing
To bill Medicare on behalf of a provider, the provider must be enrolled in PECOS (Provider Enrollment, Chain, and Ownership System). As the billing agent, you typically need to be authorized in PECOS as the provider's billing agent. Some Medicare Administrative Contractors (MACs) also require the billing company itself to register. The CMS-855B is the Medicare enrollment application for billing agencies and independent diagnostic testing facilities. Medicaid enrollment requirements vary by state — check each state's Medicaid agency for billing company registration requirements before submitting Medicaid claims.
7. State-by-state licensing requirements for medical billing companies
Most states do not impose a specific license on medical billing companies — but several states have enacted additional requirements beyond HIPAA. The table below summarizes requirements for the largest states. Always verify current requirements with each state's licensing authority.
| State | Specific Billing License? | Key Requirements | Agency |
|---|---|---|---|
| California | No dedicated license | CMIA compliance (Cal. Civ. Code § 56); CCPA/CPRA if handling consumer data at scale; CA breach notification within 72 hours | CA AG / Medical Board |
| Texas | No dedicated license | Texas Health & Safety Code Ch. 181 (medical privacy); TX breach notification required; general business license | TX DHS / TX AG |
| Florida | No dedicated license | FL Statute § 395.301 (itemized billing); FL Statute § 817.505 (patient brokering prohibition); FL breach notification | FL AHCA / FL AG |
| New York | No dedicated license | NY SHIELD Act (data security requirements); NY Public Health Law § 18 (patient record access); NY breach notification within 72 hours | NY DOH / NY AG |
| New Jersey | Registration required (some contexts) | Third-party billing registration if billing consumers directly; NJ Identity Theft Prevention Act; NJ breach notification within 30 days | NJ Division of Consumer Affairs |
| Illinois | No dedicated license | IL Personal Information Protection Act; IL breach notification; general business license from Secretary of State | IL AG / SOS |
| Washington | No dedicated license | WA My Health MY Data Act (2023, strictest state health data law); WA breach notification within 30 days | WA AG |
Licensing requirements change frequently. Verify current requirements with each state's attorney general or health department before operating in that state.
Note on Washington's My Health MY Data Act: Washington enacted the most comprehensive state health data privacy law in 2023, effective March 31, 2024 (for large businesses) and June 30, 2024 (for small businesses). It applies to health data beyond HIPAA's scope — including location data, search history, and behavioral data that could identify health conditions. If you process any health data for Washington consumers, this law requires consumer rights obligations (access, deletion, consent) that exceed HIPAA requirements. Consult a healthcare privacy attorney before expanding to Washington.
8. Clearinghouse enrollment: Availity, Change Healthcare, Office Ally, and Trizetto
A healthcare clearinghouse is required infrastructure for electronic claims submission. Clearinghouses receive claims from your billing software, validate them for errors (missing NPI, invalid codes, incorrect payer IDs), convert them to HIPAA-compliant EDI format, and transmit them to payers. They receive electronic remittance advice (ERA, 835 format) from payers and route it back to your system. Every clearinghouse that handles PHI must sign a BAA with your billing company.
Choosing your primary clearinghouse
| Clearinghouse | Cost | Best For | Notes |
|---|---|---|---|
| Office Ally | Free (837P); nominal for ERA | Startups; solo billers | No monthly fee; limited analytics |
| Availity | Free to providers; billing co. fees vary | All sizes; strong payer connectivity | Largest payer network; preferred by Humana, Anthem |
| Change Healthcare (Optum) | Per-transaction or monthly | Mid-to-large billing companies | 2024 cyberattack disrupted national billing; maintain backup clearinghouse |
| Trizetto (Cognizant) | Contract-based | RCM companies; enterprise | Strong denial management analytics |
| Waystar | Monthly subscription | Modern cloud-native billing companies | Strong real-time eligibility; good UX |
Beyond clearinghouse enrollment, you must complete payer enrollment separately for each insurance company — registering to submit claims on behalf of your provider clients. Payer enrollment typically takes 2–8 weeks per payer and may require a CMS-855B (for Medicare) or payer-specific forms. ERA/EFT (electronic funds transfer) enrollment is a separate process. Build payer enrollment timelines into your client onboarding — new client revenue cannot flow until payer enrollment is complete.
9. Startup cost breakdown
| Item | Low | High | Notes |
|---|---|---|---|
| LLC formation (state filing fee) | $50 | $500 | CA adds $800/yr franchise tax |
| EIN registration | $0 | $0 | Free via IRS.gov |
| General business license | $25 | $200 | City/county requirement |
| CPC or CMRS certification (exam + study materials) | $200 | $1,500 | CPC: $399-$499 exam; CMRS: $200-$300 |
| HIPAA compliance program (training + SRA + policies) | $500 | $3,000 | SRA Tool is free (healthit.gov) |
| Healthcare attorney (BAA template + compliance review) | $500 | $3,000 | One-time investment; essential |
| Medical billing software (year 1) | $600 | $6,000 | Kareo, AdvancedMD, CollaborateMD: $50-$500/mo |
| Clearinghouse fees (year 1) | $0 | $3,600 | Office Ally is free for 837P claims |
| Professional liability / E&O insurance (year 1) | $500 | $2,500 | Required by most provider clients |
| Cyber liability insurance (year 1) | $1,000 | $3,000 | Critical for PHI handling |
| General liability insurance (year 1) | $400 | $1,200 | Standard business coverage |
| HIPAA-compliant computer (encrypted drive) | $500 | $2,000 | Enable BitLocker/FileVault |
| HIPAA-compliant email, fax, phone (year 1) | $240 | $1,200 | Paubox or Hushmail + eFax Business |
| Website and marketing materials | $300 | $2,000 | One-time setup cost |
| Total startup range | $4,815 | $29,700 | Most solo startups: $8,000–$15,000 |
Revenue model: Most billing companies charge 4-10% of collections. A solo biller handling 3-5 small practices with combined monthly collections of $75,000-$150,000 earns $3,000-$15,000/month. Specializing in high-reimbursement specialties (orthopedics, cardiology, pain management, anesthesia) increases per-claim revenue significantly. Cash flow stabilizes after 3-6 months as payer enrollment completes and claim volumes increase.
Form your business entity first
Most permits require a registered business entity (LLC or corporation). These services handle the state filing for you:
- ZenBusiness $0 + state fees, guided LLC formation
- Northwest Registered Agent $39 + state fees, includes a year of registered agent service
- LegalZoom best-known brand, optional attorney add-ons
We may earn a commission if you sign up through these links, at no extra cost to you.
10. Insurance requirements for medical billing companies
Medical billing companies carry significant liability exposure from three distinct risk categories: HIPAA/data breaches, billing errors, and general business risks. Three types of insurance are essential before signing your first client.
Professional Liability (Errors & Omissions)
Covers claims arising from billing errors, coding mistakes, missed filing deadlines (timely filing limits are strict — Medicare requires claims within 12 months of service date), failure to follow up on denials, or other professional errors that cause financial loss to provider clients. Billing errors can cost a practice tens of thousands of dollars in lost revenue. Most healthcare providers require proof of E&O coverage ($1 million per claim / $2 million aggregate is a common minimum) before executing a billing contract. Annual cost for a solo billing company: $500-$2,500.
Cyber Liability Insurance
The most critical coverage for a business handling PHI. Covers: forensic investigation costs after a breach, HIPAA-required patient notification (written notice to each affected individual), media notification (if breach affects 500+ patients in a state), regulatory fines (verify your policy covers HIPAA penalties — some exclude government fines), legal defense costs for OCR investigations and private lawsuits, credit monitoring services for affected patients, and business interruption from cyberattack. The average healthcare data breach cost $9.77 million in 2024 (IBM Security). Even a small breach affecting 200 patients can cost $25,000-$100,000 in notification and remediation. Annual cost for a small billing company: $1,000-$3,000.
General Liability
Covers bodily injury and property damage. Required for commercial lease agreements. Provides baseline protection for client visits to your office. Annual cost: $400-$1,200. Consider a Business Owner's Policy (BOP) that bundles general liability with commercial property coverage — typically cheaper than buying separately.
11. Common mistakes that get medical billing companies in trouble
Mistake 1: Starting work without a signed BAA
Accessing PHI without a signed Business Associate Agreement is an immediate HIPAA violation — before you process a single claim. OCR can assess penalties of $100-$50,000 per violation. Never receive patient data from a new client until the BAA is fully executed and filed. This applies equally to your vendors: if your billing software or clearinghouse does not have a signed BAA with you, you are in violation the moment you use them with PHI.
Mistake 2: Skipping the HIPAA Security Risk Assessment
The #1 finding in OCR HIPAA audits — by a wide margin — is failure to conduct a thorough and documented Security Risk Analysis. The SRA is required by 45 CFR § 164.308(a)(1) and must be comprehensive: identify all ePHI in your environment, assess threats and vulnerabilities, evaluate current controls, determine the likelihood and potential impact of threats, and document the analysis. "I intended to do it" is not a defense. Use the free HHS Security Risk Assessment Tool (healthit.gov/SRA) and document everything.
Mistake 3: Using non-HIPAA-compliant tools
Standard Gmail is not HIPAA-compliant. Personal Dropbox is not HIPAA-compliant. Consumer fax apps are not HIPAA-compliant. WhatsApp, iMessage, and standard text messaging are not HIPAA-compliant. Every tool that touches PHI must: (a) have HIPAA-appropriate security features (encryption at rest and in transit) and (b) have a signed BAA with your company. Acceptable alternatives: Paubox or Hushmail for email; eFax Business or Updox for fax; ShareFile (Citrix) or Box (with BAA) for file storage; and a HIPAA-compliant practice management platform for billing software.
Mistake 4: Upcoding or submitting unsupported codes
Billing a higher-level E/M code than the clinical documentation supports (upcoding) is a False Claims Act violation that can result in $13,946-$27,894 per false claim plus treble damages. Some billing companies upcode to increase collections and percentage fees — this is fraud. Even inadvertent upcoding from poor training creates FCA exposure. Implement pre-submission claim auditing, require access to clinical documentation before billing, and establish a written coding accuracy policy. The OIG can initiate a qui tam investigation based on a complaint from a single disgruntled employee.
Mistake 5: Neglecting denial management
Insurance companies deny 5-20% of claims on first submission. New billing companies often process clean claims efficiently but fail to build systematic denial management workflows — meaning 10-20% of potential revenue is never collected. Missed filing deadlines for appeals (most payers give 60-180 days; Medicare gives 120 days) result in permanent revenue loss. Build denial tracking, categorization (clinical vs. administrative vs. eligibility vs. coding denials), and systematic appeal processes into your workflow from day one. Your provider clients will measure you on net collection rate — not gross billing volume.
Mistake 6: Ignoring the Anti-Kickback Statute in fee arrangements
Any billing arrangement that could appear to compensate for referrals — even unintentionally — creates AKS exposure. Do not offer free billing software as an inducement to sign with your company. Do not offer unusually low fees to high-volume referral-generating practices while charging higher rates to others. Structure all fee arrangements to be commercially reasonable, documented in writing, and not based on referral volume. Have a healthcare attorney review your standard client contract before using it.
12. Medical billing business launch checklist
- 1.Form your LLC and register with the state Secretary of State. Obtain EIN from IRS (free, online). Open a dedicated business bank account.
- 2.Obtain professional certification — Enroll in CPC (AAPC) or CMRS (AMBA) exam preparation. Schedule your exam date within 3-6 months.
- 3.Build your HIPAA compliance program — Conduct Security Risk Analysis (use HHS SRA Tool), write Privacy and Security policies, designate HIPAA Officer, establish breach response procedures, and document everything.
- 4.Secure HIPAA-compliant tools — Replace standard email with Paubox or Hushmail, standard fax with eFax Business or Updox, and personal cloud storage with a BAA-capable alternative (Box, ShareFile, or Google Workspace with a BAA). Enable full-disk encryption on all computers.
- 5.Have a healthcare attorney draft your standard BAA and client contract — These documents protect you legally and establish your professional credibility with providers.
- 6.Select and configure billing software — Choose a HIPAA-compliant platform (Kareo, AdvancedMD, CollaborateMD, or similar), execute a BAA with the vendor, and configure for your target specialties.
- 7.Enroll with a clearinghouse — Start with Office Ally (free) and Availity. Execute BAAs with both. Establish a secondary clearinghouse connection for business continuity.
- 8.Obtain insurance — Professional liability (E&O), cyber liability, and general liability. Ensure cyber policy covers HIPAA regulatory penalties. Get certificates of insurance ready for prospective clients.
- 9.Research state requirements in your target market — Check for billing-specific registration, state health data privacy laws beyond HIPAA, and breach notification timelines in each state where you will bill.
- 10.Sign first client, execute BAA, complete payer enrollment — Build a 6-8 week client onboarding timeline to account for payer enrollment delays. Verify the provider's NPI via NPPES before billing.
Frequently asked questions
Do you need a license to operate a medical billing business?
What is a HIPAA Business Associate Agreement and why is it mandatory?
How does the Anti-Kickback Statute (42 U.S.C. § 1320a-7b) apply to medical billing companies?
What is the Stark Law (42 U.S.C. § 1395nn) and does it apply to medical billing companies?
How does the False Claims Act (31 U.S.C. § 3729) create liability for medical billing companies?
What CPT, ICD-10, and HCPCS coding requirements must a medical billing company follow?
What are the NPI registration requirements for a medical billing company?
What are the HIPAA technical and physical safeguard requirements for a home-based medical billing business?
What clearinghouses does a medical billing company use, and what does enrollment require?
What insurance does a medical billing company need?
Find the exact registrations required for your medical billing business
State business license requirements and third-party billing regulations vary by jurisdiction. StartPermit's free permit finder shows you the exact agencies, fees, and application links for your location.
Find my medical billing permitsOfficial Sources
- HHS: HIPAA Privacy Rule (45 CFR Part 164 Subpart E)
- HHS: HIPAA Security Rule (45 CFR Part 164 Subpart C)
- HHS: HIPAA Breach Notification Rule (45 CFR Part 164 Subpart D)
- HHS: Sample Business Associate Agreement Provisions
- CMS: National Provider Identifier Standard (45 CFR Part 162.410)
- CMS: Medicare Provider Enrollment (PECOS)
- OIG: Anti-Kickback Statute (42 U.S.C. § 1320a-7b)
- CMS: Physician Self-Referral (Stark Law, 42 U.S.C. § 1395nn)
- DOJ: False Claims Act (31 U.S.C. §§ 3729–3733)
- AAPC: CPC Certification Requirements
- AMBA: Certified Medical Reimbursement Specialist (CMRS)
- HHS: Security Risk Assessment Tool
- SBA: Apply for Licenses and Permits
- IRS: Apply for an EIN Online
- CMS: HIPAA Transactions and Code Sets (45 CFR Part 162)
Related Guides
- How to Start a Medical Courier Service — HIPAA-compliant transport, DOT requirements, and healthcare logistics licensing
- How to Start a Home Health Care Business — state licensing, Medicare certification (CoPs), and CMS provider enrollment
- How to Start a Collection Agency — FDCPA, Regulation F, state licensing, and surety bond requirements for debt collectors
- How to Start a Bookkeeping Business — another home-based professional service with low startup costs
- How to Start an LLC — protect your billing business with the right entity structure before signing your first client
- Business License vs. Permit — understand the difference before you apply