ClaimOps

ClaimOps  /  HIPAA and data protection

Section 06

Protected health information, and the obligations that travel with it

Everything your team touches on this process is protected health information under the United States Health Insurance Portability and Accountability Act. The client is a covered entity. Akontec and the service provider are business associates, and the obligations flow down in full.

Physical floor

  • A dedicated, access-controlled bay. No shared floor with any other account.
  • Badge or biometric entry, logged, reviewed monthly.
  • CCTV covering all entry points and the bay, 90-day retention.
  • No personal mobile phones, cameras, smart watches or recording devices inside the bay.
  • No paper, no notebooks, no pens. No printer on the floor.
  • Clean-desk verification at every shift close, logged.

Technical

  • Access to client systems only through the agreed secure channel.
  • USB mass storage, optical media and local writes blocked at the endpoint.
  • Internet access restricted to a whitelist: payer portals, clearinghouse, client system.
  • Personal email, messaging, file sharing and cloud storage blocked.
  • Screenshot and clipboard-to-host controls enforced.
  • Unique named accounts. No shared logins, ever, for any reason.
  • Access revoked within 4 hours of an agent leaving the process.

People

RequirementApplies toEvidence held
Background verification — identity, address, education, employment, criminal recordEvery person with access, without exceptionReport on file before day one of access
HIPAA privacy and security trainingEvery person with accessCompletion record, annual refresh
Individual confidentiality undertakingEvery person with accessSigned, retained for the term plus 6 years
Sanctions screeningEvery person with accessChecked at onboarding and annually
Named security officer and privacy officerService provider organisationAppointment letter, contact on file
Breach obligation. Any suspected or actual unauthorised access, disclosure or loss of protected health information must be reported to Akontec within 24 hours of discovery, in writing, whether or not it has been confirmed. Late reporting is treated more seriously than the incident itself. There is no internal-investigation grace period.
Honesty on controls

What we claim, and what we do not

Akontec does not claim any certification it does not hold, and will not permit a service provider to represent Akontec as holding one. Where a control is implemented but not independently certified, it is described as implemented — not certified.

We will not agree to a control waiver on the basis that a client is willing to accept the risk. The obligations here are statutory, not commercial. And we will not accept a floor that is not ready in order to hold a go-live date.

The detailed control set is in the Data Protection and HIPAA Annexure that accompanies the contracting pack. Everything above is the headline requirement, and every item is checked at the readiness audit and again quarterly.

A single up-coded claim does more damage to this account than a month of slow production. Speed is negotiable. Coding integrity is not.

Next step

Security posture is an eligibility criterion, not a preference.

ISO/IEC 27001 certification, or a written commitment to implement the equivalent control set within 90 days, is checked at the readiness audit before any seat is released to live data.

See the eligibility bar Read the quality framework