Security & Compliance

Security your IT team can sign off on

Handling U.S. patient and practice data is a responsibility we treat as core to the service — not an afterthought. This page summarizes how ERG protects your data and what we can provide for your security review.

How we protect your data

Controls across the whole workflow

HIPAA-compliant processes applied end to end — from the moment we receive data to every claim, appeal and report.

Signed BAA with every client

We enter a Business Associate Agreement before any protected health information is exchanged, defining permitted uses, safeguards and breach obligations.

Access on a need-to-know basis

PHI is limited to the authorized staff working your account, with unique logins and least-privilege access rather than shared, blanket access.

Encryption & secure systems

Data is handled through secure, access-controlled systems and transmitted over encrypted connections — never over unsecured or personal channels.

Workforce confidentiality & training

Every team member signs a HIPAA confidentiality and non-disclosure agreement and is trained on privacy, data handling and their obligations.

No PHI on personal devices

Company policy prohibits downloading, copying or storing patient or client data on personal devices — data stays inside controlled systems.

Incident response & reporting

Any suspected data incident must be reported immediately and handled under our defined process, including client notification in line with HIPAA.

Data handling principles

How your data is treated

  • All patient and client data is treated as strictly confidential.
  • Data is used only to perform the billing and RCM services you engage us for.
  • Access is restricted to the assigned, authorized team — not the whole company.
  • No sharing, downloading or storing of client data on personal devices.
  • Certified coders work to AAPC and AHIMA standards on your account.

“HIPAA-compliant” describes our ongoing operational practices and safeguards. It is not a certification claim — we do not describe ERG as “HIPAA certified.”

For your security review

What we can provide

Evaluating ERG? We're glad to support your due diligence with:

  • A signed Business Associate Agreement (BAA)
  • A written security & data-handling overview
  • Completion of your vendor security questionnaire
  • A summary of access, confidentiality and incident-response controls
  • A named point of contact for security questions

Request documentation →

Related

More on how we work

About ERG

The certified team and leadership behind your account.

Bring your security questions to the call

We'll walk your team through our controls, provide a BAA, and answer anything your review needs — before you commit.

Book a strategy call
Book a strategy call