BIS Compliance Report
BIS holds ISO/IEC 27001:2022, ISO 9001:2015, and SOC 2 Type II certifications and maintains HIPAA compliance — a four-layer assurance that protects your healthcare data, guarantees service quality, and reduces vendor risk so you can outsource revenue-cycle work with confidence.
Compliance Certifications
We maintain the highest industry standards and regularly undergo rigorous third-party audits to ensure compliance across security, quality, operational trust, and healthcare data protection.
ISO/IEC 27001:2022
Information Security Management System — Last audit: January 2026
Internationally recognized ISMS certification proving BIS operates formal, audited security controls that protect ePHI and critical business data with repeatable processes, risk-based controls, and continual improvement.
Modernized for Today's Threats
The 2022 update modernized Annex A controls to address cloud governance, threat intelligence, and data masking — making our ISMS directly relevant to hybrid-cloud, outsourced healthcare workflows.
Key Benefits for Healthcare Clients
Demonstrable HIPAA Security Rule alignment, reduced vendor risk through independent accredited audits, streamlined regulatory overhead across HIPAA/NIST/SOC, and structured incident response that limits revenue impact.
RCM Impact
Role-based access and encryption protect PHI flows; formal supplier controls secure clearinghouse and EMR integrations; business continuity keeps billing and denial workflows running; standardized logs reduce audit burden.
ISO 9001:2015
Quality Management System — Active Certification
A formal, third-party attestation that our Quality Management System meets internationally recognized standards for consistent, repeatable, and measurable service delivery — quality and continual improvement built into everything we do.
What It Means for BIS
Documented, auditable processes for every service — from denial management and coding support to training and onboarding — with clear SLAs, performance metrics, and a formal corrective action loop measured and reported consistently.
Key Benefits for Healthcare Clients
Predictable outcomes with faster claim turnarounds and improved first-pass resolution; lower operational risk through process controls; transparent KPI dashboards; faster scale-up without sacrificing quality.
RCM Impact
Root-cause analysis reduces repeat denials; standardized checklists and peer reviews improve billing accuracy; documented training curricula raise agent accuracy; consistent data governance supports reliable trend reporting.
SOC 2 Type II
AICPA Trust Services Criteria — Audit period reported annually
Independent AICPA-aligned attestation confirming that BIS's controls for security, availability, and confidentiality operated effectively over a sustained audit period — not just at a single point in time — giving clients evidence-based assurance of day-to-day control performance.
Operating Effectiveness Over Time
Unlike a point-in-time review, a Type II report tests whether our security, availability, and confidentiality controls actually operated as designed across the full audit window, giving clients ongoing assurance rather than a single snapshot.
Key Benefits for Healthcare Clients
Independent AICPA-based attestation for vendor due diligence, cross-mapping with ISO 27001 and HIPAA safeguards to reduce duplicate audit effort, faster security questionnaires, and demonstrated commitment to sustained operational trust.
RCM Impact
Continuously tested access, monitoring, and availability controls protect claims and PHI systems; documented change-management and monitoring evidence supports payer/provider trust; sustained control performance reduces service disruption risk.
HIPAA Compliance
Privacy, Security & Breach Notification — Ongoing Program
BIS operates a mature HIPAA compliance program built around Privacy, Security, and Breach Notification requirements — translating them into day-to-day controls that protect patients, payers, and providers while preserving revenue flow. Note: HIPAA compliance is an ongoing program, not a one-time certification issued by HHS/OCR.
Administrative, Technical & Physical Safeguards
Formal risk assessments, role-based access, workforce training, MFA, encryption in transit and at rest, secure file transfer, secure office access, and workstation controls — all documented and auditable.
Key Benefits for Healthcare Clients
Signed BAAs with covered entities and subcontractors; lower vendor risk and faster due diligence; pre-defined breach response playbooks; regulatory confidence with auditors and OCR; patient trust and brand protection.
RCM Impact
Secure, auditable claims workflows reduce improper disclosures; secure API and SFTP practices protect payer/provider interfaces; standardized logs accelerate audit responses; continuity plans keep revenue operations uninterrupted.
What Our Certifications Signal
Four frameworks. One commitment — to security, quality, and your peace of mind.
Resource Library
Access our security documentation, quality policies, SOC 2 audit reports, HIPAA evidence packs, and compliance reports.
ISO 27001:2022 Certification Report
Accredited third-party certification report for our Information Security Management System
ISMS Policy Summary
Information Security Management System policy overview and control framework
Risk Assessment Extracts
Security risk assessment documentation (redacted) covering key control domains
HIPAA/SOC Control Mapping
Control-mapping to HIPAA/SOC frameworks demonstrating cross-framework alignment
Business Associate Agreement (BAA)
Standard contractual clauses aligned to ISO and HIPAA controls — available for covered entities
Management Review Minutes
Regular management-review minutes and evidence of corrective-action closure across all frameworks
ISO 9001:2015 Certification Report
Independent third-party audit report for our Quality Management System — available on request
Sample SLAs & KPI Dashboard
Documented SLAs and measurable KPIs tied to contractual outcomes — tailored to your RCM needs
SOC 2 Type II Report
Independent AICPA-based attestation report covering Security, Availability, and Confidentiality Trust Services Criteria — available under NDA
SOC 2 Trust Services Criteria Mapping
Control-mapping of SOC 2 Trust Services Criteria to ISO 27001 and HIPAA safeguards for streamlined vendor review
HIPAA Evidence Pack
Policy index, BAA summary, risk assessment executive summary, key audit logs — for vendor due diligence
Security & Quality Controls
Our comprehensive program includes controls across security (ISO 27001:2022), quality (ISO 9001:2015), operational trust (SOC 2 Type II), and privacy (HIPAA) domains to protect your data and guarantee service delivery.
Access Control & Authorization
LIVEData Protection & Privacy
LIVESOC 2 Trust Services Controls
LIVERisk & Incident Management
LIVECompliance & Governance
LIVEIT & Operational Security
LIVEQuality Management Controls
LIVESubprocessors Directory
We carefully select and monitor all third-party services that process data on our behalf, with formal supplier-security requirements and vendor onboarding controls.
Microsoft Azure
Cloud Infrastructure
AWS
Cloud Infrastructure & Platform Services
Clearinghouse Partners
Claims Processing
EMR Integration Partners
Healthcare Data Exchange
Identity Provider
Identity & Access Management
Security Monitoring
Security Operations
Frequently Asked Questions
ISO 27001 is not a legal HIPAA certification, but it provides a strong, auditable security program that aligns with many HIPAA Security Rule requirements and makes HIPAA compliance easier to demonstrate. Our certification gives covered entities and business associates clear, auditable evidence of proactive security governance.
Certification shows BIS uses risk assessments, access controls, incident response, and supplier governance — all verified by independent auditors — which materially lowers the likelihood and impact of data incidents.
No — the standard emphasizes secure, repeatable processes. In practice you'll see clearer handoffs, predictable SLAs, and fewer exceptions — not slower throughput.
Our certification ensures: Protected claims and PHI flows through role-based access and encryption; Safer provider/payer integrations with formal supplier-security requirements; Reliable uptime for revenue processes with business continuity controls; and Audit-ready evidence with standardized logs and documented control performance.
ISO 9001:2015 is a Quality Management System (QMS) standard focused on customer satisfaction, process consistency, and continual improvement of service delivery. ISO 27001:2022 is an Information Security Management System (ISMS) standard focused on protecting confidentiality, integrity, and availability of information. Together, they give healthcare clients confidence in both the quality and security of BIS's operations.
You'll see clearer SLAs, fewer exceptions, faster resolution times, consistent reporting formats, and proactive improvement suggestions from our engagement teams. Our ISO 9001 program means fewer repeat denials, more accurate billing, and documented training frameworks that maintain quality as your volumes scale.
We can share: Independent third-party audit reports on file and available on request; Documented SLAs and measurable KPIs tied to contractual outcomes; Regular management reviews and client performance reviews; and a formal change-management process for scope or workflow changes.
SOC 2 Type II is an AICPA-based attestation report that tests whether our Security, Availability, and Confidentiality controls operated effectively over an extended audit period, rather than certifying against a fixed standard like ISO. It complements ISO 27001:2022 and ISO 9001:2015 by giving clients evidence-based, auditor-tested proof of sustained day-to-day control performance.
A Type I report only confirms controls were suitably designed at a single point in time. Our Type II report tests those controls' operating effectiveness across a full audit window, giving healthcare clients stronger assurance that safeguards for claims, PHI, and system availability hold up in practice, not just on paper.
Yes — the SOC 2 Type II report is available to prospective and current clients under a mutual NDA, along with a Trust Services Criteria mapping that cross-references our ISO 27001 and HIPAA safeguards to simplify your vendor due diligence.
There is no official "HIPAA certification" issued by HHS/OCR — compliance is an ongoing program of policies, technical controls, risk management, and training assessed by audits and regulatory review. BIS's HIPAA program is designed to meet HIPAA requirements and produce auditable evidence during due diligence or enforcement reviews. Our ISO 27001:2022 and ISO 9001:2015 certifications reinforce and document this posture.
Yes — we execute BAAs with covered entities and require equivalent contract terms from our subcontractors to ensure PHI is handled lawfully and safely throughout the processing chain.
No — our controls are designed to protect PHI while preserving efficient RCM workflows. You get predictable SLAs, not bottlenecks. Pre-defined incident response and breach procedures are designed to minimize disruption to claim processing, denial management, and patient correspondence.
We can provide: Accredited ISO 27001:2022 and ISO 9001:2015 third-party certification reports; ISMS and QMS policy summaries and risk assessment extracts (redacted); SOC 2 Type II report and Trust Services Criteria mapping (under NDA); HIPAA evidence pack (policy index, BAA, risk assessment summary, key logs — under NDA); Control-mapping across HIPAA, SOC 2, and ISO frameworks; Standard BAA template and contractual commitments; and regular management-review minutes with evidence of corrective-action closure.
Partner with a Security-First, Quality-Driven RCM Vendor
For US healthcare organizations, partnering with a BIS certified to ISO 27001:2022, ISO 9001:2015, and SOC 2 Type II — and HIPAA-compliant — reduces compliance burden, strengthens data protection, guarantees service quality, and preserves the continuity of revenue operations.
5501 West Gray Street Tampa, FL 33609 | +1 800-592-6079 | contactus@thebisteam.com
