Skip to main content

HIPAA & Compliance Statement

This HIPAA compliance statement explains how MCM South Medical Billing Service handles protected health information (PHI) every day. It covers our role under the Health Insurance Portability and Accountability Act (HIPAA), how responsibility is shared with your practice, and who to contact with questions.

Last reviewed: January 2, 2026.

Our role: business associate

A business associate is a company that handles PHI on behalf of a healthcare provider. When a practice hires a billing service, the practice is the “covered entity” and the billing service is its business associate. MCM South acts as a business associate for the psychotherapy and psychiatry practices we serve.

Who we are and where we work

MCM South was founded in 2010 and works exclusively in mental and behavioral health billing. Our founder, Michael Williams, is based in Georgia, and we have team members in Georgia and Massachusetts. We currently serve practices in Georgia, Massachusetts, Connecticut, Texas, Florida, New York, Colorado, Tennessee, North Carolina and Illinois.

HIPAA is a federal law, so it applies in every state. We have also worked with practices in other states over the years, and we confirm each state’s rules before we work there.

HIPAA compliance statement: responsibility is shared

HIPAA compliance is a shared responsibility. Your practice, your electronic health record (EHR) or practice-management software, and your billing service each have duties.

WhoTypical responsibility
Your practice (covered entity)Decides who may see PHI, trains its own staff, keeps its own risk analysis
Your EHR / practice-management vendorSecures its own platform. Ask yours for its security documentation
MCM South (business associate)Uses PHI only for the billing work you ask us to do

We do not control your EHR vendor’s security, and your vendor does not control ours. Ask each vendor what it covers.

The minimum necessary standard

HIPAA expects PHI use to be limited to the minimum necessary for the task. For billing, that means the information needed to verify benefits, submit and follow up on claims, work denials and appeals, and handle credentialing paperwork.

Practice tip: before you send a record to any vendor, ask whether the task really needs it. Sending less lowers your risk and keeps your HIPAA compliance workload smaller.

If something goes wrong

HIPAA’s Breach Notification Rule requires covered entities, and business associates, to follow set notification steps after a breach of unsecured PHI. State breach laws may add requirements, and they differ from state to state. In Georgia, for example, state law applies alongside HIPAA.

Substance use disorder records

Some behavioral health records carry extra protection under 42 CFR Part 2, the federal rule on substance use disorder treatment records. Whether Part 2 applies depends on the program that created the record. If you think it applies to your practice, tell us before sending records so we handle them correctly.

State laws can be stricter

HIPAA sets a federal baseline. Some states add rules for mental health records, minors, or data privacy. Where state law is stricter, the stricter rule can apply. We do not assume one state’s rules fit another’s, and we recommend your practice confirm state-specific questions with its own attorney or compliance officer.

If your practice sees clients in more than one state, keep a short list of each state’s mental health record rules next to your HIPAA compliance policies, and review it every year.

What this page is not

We do not hold a “HIPAA certification”. No official HIPAA certification exists. This page is an operational compliance statement, not legal advice. For legal questions, talk to an attorney or your compliance officer.

Questions or concerns

Email our compliance contact:

To discuss your practice’s billing needs, Get a Free Quote or Schedule a Consultation.