Planet Billing: Security & Compliance FAQ
1. Is Planet Billing HIPAA Compliant?
Yes. Planet Billing operates as a Business Associate under HIPAA regulations. We maintain a comprehensive compliance program that includes administrative, physical, and technical safeguards to protect your practice’s Protected Health Information (PHI). We provide a signed Business Associate Agreement (BAA) to every client before services begin.
2. How is our patient data protected?
We use industry-standard security protocols to ensure data integrity:
- Encryption: All data is encrypted using AES 256-bit encryption both at rest and during transmission.
- Access Control: We enforce Multi-Factor Authentication (MFA) on all platforms. Only authorized personnel have access to your records, based on the principle of “least privilege.”
- Secure Environment: Our team works within secure, encrypted cloud environments. We do not store PHI on local hard drives or unencrypted portable devices.
3. What happens in the event of a security incident?
While we maintain rigorous defenses, HIPAA requires a clear response plan. Planet Billing has a documented Incident Response Plan. Per our BAA, we will notify your practice within [5 business days] of any suspected or confirmed breach, providing full transparency and assistance in the mitigation process.
4. How do you handle remote work security?
As a modern billing service, we utilize secure remote protocols:
- Secure VPNs: All connections to your Practice Management Software are made via encrypted Virtual Private Networks.
- Screen Privacy: All workstations are equipped with physical privacy filters to prevent “shoulder surfing.”
- Annual Audits: We conduct an annual Security Risk Assessment (SRA) to identify and patch potential vulnerabilities in our remote workflows.
5. Are your staff trained in HIPAA?
Yes. Every member of the Planet Billing team undergoes mandatory Annual HIPAA Training. This covers the Privacy Rule, Security Rule, and the Breach Notification Rule. We maintain training logs and accountability records for all personnel.
6. Do you use subcontractors?
If we utilize third-party services (such as secure cloud storage or IT support), we ensure they are also HIPAA compliant. We maintain “downstream” BAAs with all subcontractors to ensure the Chain of Trust remains unbroken.
