How to Choose a Bad Debt Recovery Agency With HIPAA-Compliant Workflows
Learn how to evaluate healthcare bad debt recovery agencies based on collection performance, HIPAA considerations, data security, reporting, and vendor fit.
Healthcare organizations choosing a bad debt recovery agency should evaluate two areas together: collection performance and protection of patient information. If the agency will create, receive, maintain, or transmit protected health information (PHI) on behalf of the provider, the organization should determine whether the agency is a HIPAA business associate and review the applicable Business Associate Agreement (BAA).
The evaluation should cover permitted uses of PHI, security safeguards, breach reporting, subcontractors, patient information requests, data retention, and what happens to PHI when the relationship ends.
HHS states that a business associate agreement should establish permitted and required uses and disclosures of PHI and require appropriate safeguards.
1. Start With the Agency's Healthcare Collection Experience
Bad debt recovery for hospitals and healthcare providers involves more than collecting unpaid balances. Agencies may receive information connected to patient accounts, billing records, payment history, insurance information, and other PHI.
Ask potential agencies:
- How much healthcare collection experience do you have?
- Do you work with hospitals, health systems, or physician groups?
- What types of patient accounts do you recover?
- How are disputed accounts handled?
- What reporting is provided to the healthcare organization?
Healthcare experience is important because the agency needs to fit into the provider's existing revenue cycle and patient communication processes.
2. Determine Whether the Agency Is a HIPAA Business Associate
Do not simply ask whether a company is "HIPAA compliant."
First determine whether its role makes it a business associate.
HHS generally defines a business associate as an organization performing certain services for a covered entity that involve creating, receiving, maintaining, or transmitting PHI. HHS specifically lists functions such as billing and claims processing as examples of activities that can create a business associate relationship when PHI is involved.
For a bad debt recovery agency, the healthcare organization should therefore determine exactly what patient information the agency will access and why.
3. Review the Business Associate Agreement
This is where the vendor evaluation can become much more specific.
HHS provides sample Business Associate Agreement provisions that healthcare organizations can use as a reference when reviewing contractual requirements.
The HHS sample provisions address several areas that are useful when evaluating a bad debt recovery agency.
Permitted Uses and Disclosures
The agreement should clearly establish what the agency may do with PHI.
For a recovery agency, the provider should understand:
- What patient information the agency receives
- Why the information is needed
- Which collection activities are permitted
- Whether information can be used for any additional purpose
- Whether minimum necessary policies apply
HHS's sample provisions state that a business associate may only use or disclose PHI as permitted or required by the agreement or applicable law.
Security Safeguards
The agreement should address safeguards designed to prevent unauthorized use or disclosure of PHI.
Ask the agency about:
- Employee access controls
- Authentication procedures
- Encryption and secure transmission
- System monitoring
- Security incident procedures
- Employee training
- Access to electronic PHI
HHS's sample provisions specifically address appropriate safeguards and compliance with applicable Security Rule requirements for electronic PHI.
Breach and Security Incident Reporting
A strong vendor evaluation should also examine what happens when something goes wrong.
The BAA should address reporting of unauthorized uses or disclosures, breaches of unsecured PHI, and security incidents. HHS's sample provisions specifically include these responsibilities.
Ask:
How quickly will the agency notify us of a suspected security incident?
Also ask who is responsible for investigating, documenting, and communicating the incident.
4. Check Subcontractor Access
This is an area that is easy to overlook.
A collection agency may use technology providers, call center vendors, mailing services, payment processors, or other subcontractors.
HHS's sample BAA provisions state that applicable subcontractors with access to PHI should be subject to the same relevant restrictions and conditions.
Therefore, ask:
- Does the agency use subcontractors?
- Which subcontractors can access PHI?
- Are they covered by appropriate agreements?
- How is subcontractor access monitored?
5. Ask What Happens When the Contract Ends
Data handling should not stop being a concern when the collection agreement expires.
HHS's sample provisions address return or destruction of PHI after termination, subject to applicable circumstances, and also address safeguards for information that must be retained.
Ask the agency:
- Will patient information be returned?
- Will it be destroyed?
- How is destruction documented?
- What information must be retained?
- How is retained PHI protected?
This gives procurement and compliance teams a much clearer picture of the vendor's complete data lifecycle.
6. Evaluate Patient Communication and Collection Practices
HIPAA is only one part of vendor selection.
The agency should also have collection practices that fit the healthcare organization's patient communication standards.
Review how it handles:
- Patient calls
- Written collection notices
- Payment arrangements
- Disputed balances
- Financial hardship situations
- Patient complaints
- Requests for account information
- Escalation procedures
The objective is to recover appropriate outstanding balances without creating unnecessary patient experience or compliance problems.
7. Compare Recovery Performance
Finally, evaluate whether the agency can actually improve bad debt recovery.
Request information about:
| Evaluation Area | What to Review |
|---|---|
| Healthcare experience | Similar providers and account types |
| Recovery rate | Historical collection performance |
| Account aging | Early and aged bad debt capabilities |
| Reporting | Account-level and portfolio reporting |
| Patient communication | Contact and escalation processes |
| HIPAA | PHI safeguards and applicable BAA |
| Subcontractors | Third-party access to PHI |
| Security incidents | Notification and response procedures |
| Data termination | Return, destruction, and retention |
| Pricing | Fees and recovery structure |
Where to Find Potential Healthcare Partners
Once the requirements are established, healthcare organizations can use industry resources and specialized vendor directories to identify potential providers.
For example, RCR|HUB's HIPAA Compliance Services category can be used as one vendor research resource when organizations are looking for healthcare-focused business partners. Its directory also separates revenue cycle categories such as bad debt recovery and collection services, allowing organizations to research providers based on their specific needs.
The important distinction is that a directory can help create a vendor shortlist, while the healthcare organization remains responsible for evaluating the agency's actual security practices, contract terms, references, and compliance requirements.
Final Thoughts
Choosing a bad debt recovery agency with HIPAA-conscious workflows requires more than finding a company that advertises "HIPAA compliance."
Healthcare organizations should examine what PHI the agency receives, how it may use that information, what safeguards are in place, how incidents are reported, whether subcontractors have access, and how PHI is handled when the relationship ends.
The HHS sample BAA provisions are particularly useful because they provide a more concrete framework for these questions. HHS also cautions that the sample provisions are not mandatory language and do not replace legal review or other contractual requirements.
That makes the article more useful than a generic "HIPAA compliance checklist." It directly answers how to choose the agency, while giving the reader specific BAA and workflow questions to investigate.


