What “HIPAA compliant coding” should mean
HIPAA does not certify software. HHS sets Privacy, Security, and Breach Notification Rules. A coding product is HIPAA-oriented when it can operate under a BAA, apply Security Rule safeguards to ePHI, and support your covered-entity policies. Marketing that only says “HIPAA compliant” without BAA and audit detail is incomplete.
- Execute a BAA before production PHI is processed
- Encrypt data in transit and at rest
- Restrict access by role and log coding activity
How HealthCoder handles ePHI in coding
Charts enter through EHR integration or controlled upload. Suggestions, overrides, and exports are attributable. That supports both privacy (who saw the note) and coding compliance (why this ICD-10-CM was accepted).
Not a substitute for your Notice of Privacy Practices
Covered entities still maintain NPP, workforce training, and incident response. HealthCoder is a business associate in that model—details live on the Security & Compliance page.
AI training and PHI
Enterprise customers should contractually confirm whether production PHI is used to train shared models. Demand this in the BAA and DPA; do not assume consumer LLM defaults.
Frequently asked questions
Does HHS certify HealthCoder as HIPAA compliant?+
HHS does not certify electronic health software as “HIPAA compliant.” Compliance is a shared program: your policies plus vendor safeguards and a BAA. See HHS guidance for professionals.
Where do I read control details (encryption, logging, reports)?+
The Security & Compliance page documents HIPAA BAA, access control, encryption, and audit logging. Ask for current SOC or ISO reports during security review if you require them.