HIPAA, PHI, and Business Associate Agreements
Summary
PayerVista processes Protected Health Information (PHI) and acts as a Business Associate under HIPAA. A Business Associate Agreement (BAA) is required, and PayerVista makes one available to every customer.
An earlier version of this statement described PayerVista as working exclusively with de-identified data and asserted that no BAA was required. That description did not match how the platform actually operates and has been corrected. This document explains our current position for customers and their compliance teams.
Why PayerVista is a Business Associate
PayerVista ingests EDI 835 electronic remittance advice files, and optionally EDI 837 claim files, on behalf of healthcare providers. These files contain individually identifiable health information — including patient names and health plan member or medical record identifiers carried in the NM1 segments, along with claim identifiers, dates of service, procedure codes, and payment and adjustment detail tied to identified individuals.
PayerVista receives, maintains, and processes that information in order to provide revenue cycle analytics to the provider. Under 45 CFR § 160.103, an entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity in the performance of a function or service is a Business Associate. PayerVista meets that definition.
Accordingly:
- A BAA is required before a covered entity transmits PHI to the Service.
- PayerVista is directly liable for compliance with the applicable provisions of the HIPAA Security Rule and for the Privacy Rule obligations set out in its BAA.
- Data submitted to the Service is not de-identified, and customers should not assume it is.
Getting a BAA in place
Contact support@payervista.com to request a Business Associate Agreement. A BAA should be executed before you upload remittance or claim files containing PHI.
If you have already begun uploading files and no BAA is in place, contact us and we will prioritise executing one.
Safeguards
PayerVista maintains administrative, technical, and physical safeguards for PHI, including:
- Encryption. PHI is encrypted in transit and at rest.
- Tenant isolation. A multi-tenant architecture with row-level security and cross-tenant isolation testing keeps each customer's data logically separated.
- Access controls. Role-based access within each workspace, with separate administrator and member roles, and session controls including one-time-password email verification.
- Audit logging. Security-relevant actions are recorded.
- Incident response. A documented process for identifying, investigating, and reporting security incidents, including the breach notification obligations set out in the BAA.
- Minimum necessary. The Service requests only the remittance and claim data required to produce revenue cycle analytics.
Subprocessors
PayerVista uses third-party providers to operate the Service. Our position on each depends on whether it handles PHI:
- Cloud hosting and database — Amazon Web Services (AWS). PHI is stored and processed on AWS. An AWS Business Associate Addendum is executed and in effect, and production PHI is kept on HIPAA-eligible AWS services covered by that agreement.
- Payment processing — Stripe. Handles subscription billing only. Stripe does not receive PHI.
- Transactional email — Resend. Used for account, verification, security, and service notifications only. Email content is restricted by policy to account and security workflow information and must not contain patient, claim, remittance, or member-identifier data. Resend does not receive PHI.
- Error monitoring — Sentry. Configured to minimise the risk of capturing PHI: session replay is disabled, default personally identifiable information capture is disabled, and an event scrubber is applied before events are transmitted.
Customer responsibilities
HIPAA compliance is shared. Your organization is responsible for:
- Executing a BAA with PayerVista before transmitting PHI.
- Ensuring your workforce members who access the Service are authorised to access PHI, and promptly removing access when they should no longer have it.
- Managing user accounts, roles, and credentials within your workspace, including offboarding.
- Meeting your own obligations as a covered entity, including notices of privacy practices and individual rights requests.
- Not transmitting PHI to PayerVista through channels not intended for it, such as support messages or file names.
Individual rights requests
Because PayerVista holds PHI as a Business Associate rather than as the covered entity, requests from individuals exercising HIPAA rights — access, amendment, accounting of disclosures — should be directed to your organization. PayerVista will assist you in responding to such requests as provided in the BAA.
Questions
For questions from your compliance or legal team, contact support@payervista.com.
This statement is provided for informational purposes, describes PayerVista's practices as of the date above, and is not legal advice. Your organization should review it with your own counsel.