HIPAA Compliance for Accounting Firms Serving Healthcare
Essential guide to protecting healthcare financial information and patient data
Quick Answer
Accounting firms serving healthcare organizations frequently access Protected Health Information (PHI) during financial audits, tax preparation, and consulting engagements. HIPAA compliance requires executing Business Associate Agreements, limiting access to minimum necessary financial information, implementing data security controls, maintaining audit logs, obtaining SOC 2 Type II certification, securing financial records containing healthcare data, and establishing procedures preventing unauthorized PHI disclosure or use.
Why Accounting Firms Need HIPAA Compliance
Accounting firms may access PHI during work with healthcare organizations:
- Financial audits accessing revenue cycle systems containing patient billing data
- Tax preparation reviewing healthcare revenue, patient insurance, and billing information
- Consulting engagements advising on reimbursement and compliance matters
- Cost allocation studies examining patient care costs
- Compliance assessments reviewing healthcare billing practices
- Business valuations accessing patient census and revenue data
- Due diligence for healthcare mergers/acquisitions examining patient records and revenue
When accounting firms access this information, they become business associates under HIPAA and must comply with privacy, security, and breach notification requirements.
10 Critical HIPAA Compliance Requirements for Accounting Firms
Obtain signed BAAs before any healthcare client work involving access to PHI. BAA must specify: scope of authorized PHI access, permitted uses (financial audit, tax preparation, etc.), security safeguards, breach notification procedures, and audit rights. The BAA clarifies that accounting firm is business associate, not covered entity. Document all BAAs with healthcare clients. Without BAA, do not access any patient data.
Restrict audit team access to financial data required for specific engagement—not all patient records or complete EHR systems. For example: revenue cycle audits need billing/insurance data but not clinical treatment information. Tax preparation requires revenue and deduction data but not detailed patient identities. Document access restrictions in engagement letters. Implement role-based controls limiting each team member to assigned data. Review access regularly ensuring no overly broad permissions.
Use encrypted channels (SFTP, HTTPS, or encrypted email with password protection) for transferring healthcare client data. Store downloaded files on encrypted devices with access controls. Never email unencrypted PHI. Implement secure file sharing systems with authentication and audit logging instead of email attachments. Delete downloaded data from local devices after engagement completion using secure deletion methods. Maintain secure servers for storing client data during engagements with automatic backup and encryption.
Establish firm-wide policies requiring all staff to maintain confidentiality of healthcare client information. Include confidentiality clauses in engagement letters and employment agreements with specific HIPAA provisions. Restrict discussion of healthcare clients to authorized team members only. Prevent social media posts about healthcare clients or patient data (even anonymized). Train staff on HIPAA confidentiality requirements. Establish disciplinary procedures for confidentiality violations. Consider requiring NDA (Non-Disclosure Agreements) for all staff with healthcare client access.
Store audit workpapers and client documents in secure locations with access controls. Encrypt workpapers containing PHI both in storage and in transit. Use password-protected files or containers for sensitive documentation. Implement file sharing controls preventing accidental sharing of client data outside firm. Maintain separate folders for different clients preventing cross-client data exposure. After engagement conclusion, securely delete all downloaded client data from local devices and personal cloud storage. Retain only required copies per professional standards.
Log all access to healthcare client data including: team member name, files accessed, timestamp, and type of access (read, download, modification). Implement file download tracking preventing bulk unauthorized downloads. Alert on suspicious patterns (after-hours access, downloads of unrelated files, access by unauthorized personnel). Retain logs for minimum 6 years per healthcare record retention requirements. Provide logs to healthcare clients for compliance audits and breach investigations. Use logs to detect and investigate any data security incidents.
Achieve SOC 2 Type II certification demonstrating effective data security controls and compliance with professional standards. SOC 2 covers: security, availability, processing integrity, confidentiality, and privacy. Annual independent audits verify control effectiveness. SOC 2 certification provides healthcare clients assurance that accounting firm maintains adequate security. Include SOC 2 reports in RFP responses when competing for healthcare engagements. Remediate any SOC 2 exceptions and maintain current certification continuously.
Require all professionals working with healthcare clients to complete HIPAA training before client engagement. Document training completion. Conduct annual refresher training covering: confidentiality obligations, minimum necessary principle, proper data handling, engagement restrictions, and consequences of violations. Address common issues: inadvertent PHI disclosure, inappropriate discussions with non-engagement staff, and careless data handling. Make training mandatory, not optional. Provide specialized training for partners/managers overseeing healthcare client work.
Develop documented procedures for detecting and responding to potential data breaches involving healthcare client information. Define who should be notified if data is inadvertently disclosed (sent to wrong email recipient, shared with unauthorized firm staff, lost laptop containing healthcare data). Notify affected healthcare clients within 24 hours of discovering unauthorized access or data loss. Conduct investigation determining: what data was involved, who accessed it, why unauthorized access occurred, and steps to prevent recurrence. Maintain documentation of all incidents and responses.
Require all devices (laptops, tablets, phones) accessing healthcare data to be encrypted, password-protected, and equipped with antivirus/security software. Implement Mobile Device Management (MDM) for remote devices with remote wipe capability. Establish VPN requirements for connecting to firm networks from remote locations. Prohibit unsecured public WiFi when accessing healthcare data. Implement firewall and intrusion detection on firm networks. Require clean desk policies preventing visible PHI. Prohibit printing healthcare documents without business justification and requiring immediate destruction after use.
Types of Healthcare Accounting Engagements and PHI Access
Financial Audits
- Typical PHI Accessed: Patient billing data, insurance information, revenue cycle details, patient volume statistics
- Minimum Necessary: Limited to financial data needed to audit revenue and receivables—not clinical data
- Data Handling: Downloaded data should be deleted from workstations after audit completion
- Confidentiality: Audit reports should not disclose specific patient names or detailed billing information
Tax Preparation and Planning
- Typical PHI Accessed: Revenue by service type, patient volume, insurance revenue, charity care data
- Minimum Necessary: Revenue and deduction information—not patient identification details
- Data Handling: Maintain copies only of necessary tax documents, securely destroy original client data
- Confidentiality: Tax returns should not disclose specific patient revenue breakdowns
Consulting Engagements
- Typical PHI Accessed: Reimbursement data, patient volume trends, cost analysis by patient type
- Minimum Necessary: Limited to data required for specific consulting project—not unrestricted data access
- Data Handling: Delete consulting data after project completion unless client specifically requests retention
- Confidentiality: Consulting reports should use aggregated data without specific patient information
Mergers, Acquisitions, and Valuations
- Typical PHI Accessed: Patient census, revenue data, service mix, operational metrics
- Minimum Necessary: Financial and operational data needed for valuation—restricted due diligence access
- Data Handling: Data room access with logging, physical controls, and NDAs for all parties
- Confidentiality: Due diligence documents strictly confidential, not shared beyond transaction parties
Special Considerations: Balancing Professional Requirements and HIPAA
Audit Standards and HIPAA
- AICPA Standards: Generally Accepted Auditing Standards (GAAS) require sufficient audit evidence. However, this does not override HIPAA minimum necessary principle.
- Balancing Act: Auditors should obtain sufficient evidence using HIPAA-compliant methods. Request summary data/reports rather than individual patient records when possible.
- Documentation: Audit documentation should not include unnecessary PHI. Use patient identifiers (number, not name) and avoid clinical details in workpapers.
- Engagement Letters: Clarify in engagement letters that audit will be conducted within HIPAA constraints and client must provide necessary summary data
Tax Return Confidentiality
- Tax Return Privilege: Tax returns prepared by tax professionals may have attorney-client privilege protection
- HIPAA vs. Tax: HIPAA and tax confidentiality have different scopes. Both must be maintained.
- Working Papers: Contain PHI and must be handled per both HIPAA and tax professional standards
Regulatory and Compliance Access
- Subpoenas: If subpoenaed for litigation or investigations, maintain confidentiality while complying with legal orders
- Regulatory Requests: CMS, HHS, and state regulators may request accounting records. Limit disclosure to required information.
- Professional Liability Claims: If sued by healthcare client, maintain confidentiality of other clients' data in defense
Common HIPAA Violations by Accounting Firms
- No BAA in Place: Accepting healthcare clients and accessing PHI without executed Business Associate Agreements.
- Excessive Access: Downloading entire patient databases when only summary revenue data is needed for audit.
- Inadequate Data Security: Storing healthcare data on unencrypted laptops or emailing unencrypted PHI attachments.
- Data Retained Indefinitely: Keeping downloaded healthcare data on firm servers years after engagement completion.
- Inadequate Staff Training: Staff unfamiliar with HIPAA requirements, minimum necessary principle, and confidentiality obligations.
- Inappropriate Disclosure: Discussing healthcare client data with non-engagement staff or in public/shared spaces.
- No Access Controls: All firm personnel able to access healthcare client data regardless of role/engagement.
- Lost or Stolen Data: Unencrypted healthcare data on lost laptop or stolen backup drive exposing patient information.
- Slow Breach Response: Discovering unauthorized healthcare data access but delaying client notification.
- No Audit Logs: Unable to detect or investigate unauthorized data access due to lack of file access logging.
Due Diligence Checklist for Healthcare Accounting Engagements
Before accepting healthcare client work, verify:
- BAA has been executed with healthcare client
- Client has authorized scope of PHI access for engagement
- Engagement letter clearly documents data handling requirements and restrictions
- Engagement team staff have completed HIPAA training
- Secure data transfer method established (SFTP, encrypted email, secure file sharing)
- Devices for engagement team are encrypted and equipped with security software
- VPN or secure network access configured for remote team members
- File storage for client data on encrypted firm servers, not personal computers
- Data deletion procedures established for engagement conclusion
- Backup and disaster recovery procedures in place for client data
Frequently Asked Questions
Do accounting firms need BAAs with all healthcare clients or only those with substantial PHI access?
Healthcare firms should assume BAAs are needed for any healthcare client work where PHI may be accessed, even indirectly. This includes: financial audits (revenue cycle systems contain patient billing data), tax preparation (healthcare revenue contains patient information), and consulting (operational metrics often tied to patient data). If there's any possibility of accessing identifiable healthcare data, execute a BAA. It's better to err on the side of compliance. Some accounting firms standardize BAA language for all healthcare clients to simplify the process.
How should we handle downloaded healthcare data from client servers after engagement completion?
Delete all downloaded healthcare data from firm devices and servers after engagement conclusion. Use secure deletion methods (overwriting with random data, not simple file deletion that allows recovery). Document deletion dates and methods. If regulatory retention is required (e.g., for tax purposes), maintain data in encrypted storage for the minimum required period, then securely delete. Do not retain indefinitely "just in case" it's needed later—this increases breach risk. Delete copies from backups after retention period expires. Obtain written confirmation from healthcare clients authorizing data deletion.
Can we email healthcare client data to team members working on engagement?
Only if email is encrypted end-to-end and recipients are authenticated team members with legitimate access to the data for their engagement role. Never email unencrypted PHI. Better practice: use secure file sharing systems (Tresorit, Virtru encrypted email, OneDrive with password-protected links) enabling access control and tracking. Document which team members accessed files and when. For sensitive data, consider secure download from healthcare client servers rather than email. Include confidentiality warnings in any email transmission.
What should our audit workpapers contain regarding PHI?
Audit workpapers should contain only information necessary to document audit evidence and conclusions. Avoid including: patient names, full addresses, social security numbers, or detailed clinical information. Use patient ID numbers instead of names when necessary for audit traceability. Summarize healthcare data rather than including complete records. For example: "Reviewed sample of 25 patient accounts totaling $X in revenue" is better than listing all 25 patients' names and insurance details. Document the audit procedures and results; the supporting PHI details can be referenced as "available for review at client site" rather than copied into workpapers.
Take Action on Accounting Firm HIPAA Compliance
Ensure your healthcare client engagements maintain HIPAA compliance. Our security risk analysis evaluates your data handling procedures, staff training, and client controls:
Schedule Your Security Risk Analysis