Compliance & Security

Data Security Questions to Ask Any RCM Vendor

Before trusting an RCM vendor with PHI, confirm: they will sign a BAA, data is encrypted in transit and at rest, access is least-privilege, every action is logged, data is stored in the US, they do not sell or train public models on your data, and they can describe their breach-notification process.

Choosing an RCM vendor means handing over patient data, so security due diligence matters. Here is a practical checklist to run through with any vendor before you sign.

Compliance basics

Will you sign a Business Associate Agreement (BAA)? Are you HIPAA compliant, and are your controls aligned to SOC 2 Type II? These are table stakes for handling PHI.

Data handling

Where is PHI stored, and is it in the US? Is it encrypted in transit and at rest? Who and what can access it, and is access least-privilege? Do you sell data or use it to train public models (the answer should be no)?

Accountability and incidents

Is every action, including AI agent actions, logged and auditable? What is your breach-notification process and timeline? How do you handle our data if we stop working together?

For AI vendors specifically

How do AI agents access PHI, and are their actions supervised and escalated to humans on exceptions? A good AI RCM vendor can explain exactly how the agents stay within HIPAA-standard handling.

How MedXFlow AI agents handle this

MedXFlow handles this to HIPAA standards with a signed BAA, SOC 2-aligned controls, US data residency, encryption in transit and at rest, and full audit logging - so the automation meets the bar enterprise buyers require.

Related resources

Frequently asked questions

What security questions should I ask an RCM vendor?

Ask whether they will sign a BAA, whether data is encrypted and stored in the US, who can access PHI, whether every action is logged, whether they sell or train models on your data, and what their breach-notification process is.

What is the most important security question?

Whether the vendor will sign a Business Associate Agreement (BAA). Without one, sharing PHI is a HIPAA violation, regardless of their other assurances.