HIPAA Compliance Guide

HIPAA Compliant File Sharing
for Healthcare Billing

Protect PHI during billing workflows, claims processing, and revenue cycle management. Encrypted file exchange that meets HIPAA Technical Safeguard requirements -- and self-destructs when the job is done.

HIPAA Requirements for File Sharing

Understanding what the law actually requires when you share Protected Health Information electronically.

What Counts as PHI

Protected Health Information (PHI) is any individually identifiable health information held or transmitted by a covered entity or business associate. In billing, this includes:

  • Patient names, dates of birth, Social Security numbers
  • Insurance ID numbers and policy details
  • Diagnosis codes (ICD-10) and procedure codes (CPT)
  • Explanation of Benefits (EOBs) and remittance advice
  • Claims data, billing records, and account numbers
  • Any document that links health information to an individual

HIPAA Security Rule Technical Safeguards

The Security Rule (45 CFR Part 164) mandates specific technical safeguards for any system that stores, processes, or transmits electronic PHI (ePHI):

  • Encryption & decryption of ePHI at rest
  • Access controls with unique user identification
  • Audit controls logging all ePHI access
  • Transmission security for data in transit
  • Integrity controls to prevent unauthorized alteration
  • Automatic logoff and session management

Penalties for Violations

The HHS Office for Civil Rights (OCR) enforces HIPAA with a tiered penalty structure:

Tier 1 (Unknowing)$100 - $50,000 per violation
Tier 2 (Reasonable cause)$1,000 - $50,000 per violation
Tier 3 (Willful neglect, corrected)$10,000 - $50,000 per violation
Tier 4 (Willful neglect, not corrected)$50,000 per violation

Annual maximum of $1.5 million per identical provision. State attorneys general can pursue additional penalties. Criminal penalties apply for knowing violations.

Business Associate Agreements

If you're a healthcare billing company or RCM firm, you are a Business Associate under HIPAA. This means:

  • You must sign a BAA with every covered entity you serve
  • Any subcontractor or vendor handling PHI on your behalf also needs a BAA
  • Your file sharing tools are part of this chain -- no BAA means no compliance
  • You are directly liable for breaches under the HITECH Act

Common HIPAA Violations in File Sharing

These happen every day in billing offices. Each one is a reportable breach waiting to happen.

Emailing EOBs and Claims with PHI

Standard email is unencrypted in transit and stored indefinitely on mail servers. Sending Explanation of Benefits, claims data, or patient identifiers via email violates the Transmission Security standard.

Consumer Cloud Tools Without BAAs

Google Drive, Dropbox, and WeTransfer are not HIPAA-compliant out of the box. Using them without a signed Business Associate Agreement exposes your organization to breach liability.

No Encryption at Rest

Storing claims files, patient records, or billing data on unencrypted drives or servers violates the Encryption and Decryption implementation specification under the Security Rule.

No Audit Trail of Access

HIPAA requires audit controls that record who accessed PHI, when, and what they did. Sharing files without logging access events is a direct violation of 45 CFR 164.312(b).

What HIPAA-Compliant File Sharing Requires

Any tool you use to share PHI must meet these technical requirements at a minimum.

AES-256 encryption at rest

All PHI must be encrypted when stored, using NIST-approved algorithms.

TLS 1.2+ encryption in transit

Data transmitted over networks must be protected with transport layer security.

Role-based access controls

Only authorized personnel should access PHI, with unique user identification.

Comprehensive audit logging

Every access, modification, and transmission of PHI must be logged and reviewable.

Automatic data destruction

PHI should not persist beyond its required retention period. Disposal must be verifiable.

Business Associate Agreement (BAA)

Any third-party service handling PHI must sign a BAA accepting HIPAA obligations.

Technical Safeguard Alignment

How DeadVault Meets These Requirements

A direct mapping of HIPAA Technical Safeguards to DeadVault's architecture.

HIPAA Safeguard

Encryption & Decryption (164.312(a)(2)(iv))

Encrypt ePHI at rest

DeadVault Implementation

AES-256-GCM encryption with per-file keys. Each file gets its own encryption key, wrapped with a master key and stored separately from file data.

HIPAA Safeguard

Transmission Security (164.312(e)(1))

Protect ePHI in transit

DeadVault Implementation

All data transmitted over TLS 1.2+. Secure links for client access with no unencrypted fallback.

HIPAA Safeguard

Access Controls (164.312(a)(1))

Limit ePHI access to authorized users

DeadVault Implementation

Unique secure links per recipient. Optional PIN protection for two-factor file access. No shared credentials.

HIPAA Safeguard

Audit Controls (164.312(b))

Record ePHI access activity

DeadVault Implementation

Complete audit trail with timestamps, IP addresses, and access events. Export-ready logs for compliance reviews and breach investigations.

HIPAA Safeguard

Integrity Controls (164.312(c)(1))

Protect ePHI from unauthorized alteration

DeadVault Implementation

AES-256-GCM provides authenticated encryption, detecting any tampering with file data. Immutable audit logs prevent retroactive changes.

HIPAA Safeguard

Automatic Logoff / Disposal

Terminate sessions and dispose of ePHI

DeadVault Implementation

Cryptographic erasure at deadline: encryption keys are permanently destroyed, rendering file data mathematically unrecoverable. Nothing lingers.

About BAAs and HIPAA Compliance

HIPAA compliance is an organizational process, not a product certification -- there is no such thing as "HIPAA certified." DeadVault's architecture aligns with HIPAA Technical Safeguard requirements. Business Associate Agreements (BAAs) are available on our Enterprise plan for covered entities and business associates that require them as part of their compliance program.

Frequently Asked Questions

Common questions about HIPAA-compliant file sharing for billing and RCM.

There is no such thing as "HIPAA certified" -- HIPAA compliance is an organizational process, not a product certification. What we can say: DeadVault's architecture aligns with HIPAA Technical Safeguard requirements including encryption at rest (AES-256-GCM), transmission security (TLS 1.2+), access controls, and audit logging. Business Associate Agreements (BAAs) are available on our Enterprise plan for organizations that require them.
EHR systems are designed for clinical workflows, not secure external file exchange with billing partners, clearinghouses, or payers. DeadVault complements your EHR by providing a dedicated, encrypted channel for sharing billing-specific documents like EOBs, claims, remittance advice, and appeals -- with automatic destruction after the engagement ends.
No. Clients receive a simple secure link and can upload or download files immediately. No accounts, no software, no training. The security controls -- encryption, access logging, automatic destruction -- happen automatically in the background. Your clients interact with a clean, branded portal.
The encryption keys are permanently destroyed through cryptographic erasure. Without the key, the encrypted file data is mathematically unrecoverable -- even by us. The secure link returns a clean expiration notice with no file previews, metadata, or evidence of what was shared. Your audit trail is preserved in your dashboard for compliance documentation.
DeadVault is purpose-built for ephemeral transfers -- sending and receiving documents that should not persist indefinitely. If you need long-term document storage, keep your existing solution. If you need secure, time-limited exchange of billing documents, claims, and PHI with external parties, DeadVault is a stronger fit because files do not accumulate as a breach liability.

Stop emailing PHI. Start encrypting it.

Secure file exchange for healthcare billing that meets HIPAA Technical Safeguard requirements -- with automatic destruction so PHI never lingers past its purpose.

BAAs available on Enterprise plans. No credit card required for trial.