Patient Billing. Resolved.

Legal & Compliance

Compliance & Security

What Patriot Pay is responsible for, what stays your responsibility, and the documentation your security review will ask for.

HIPAA

Patriot Pay operates as a Business Associate under HIPAA. We process Protected Health Information (PHI) on behalf of covered entities strictly under the terms of a signed Business Associate Agreement, and we do not use PHI for any purpose beyond delivering the contracted service.

    What this means in practice:

  • A BAA is signed before any patient data moves
  • Only the fields needed to reach a patient and present a balance leave your EHR or PM system
  • PHI is encrypted in transit and at rest
  • Access is role-based and logged
  • AI models are trained on de-identified or synthetic data only, never on client PHI

Patient-facing messages reference a balance, not the nature of care. For behavioral health and substance use treatment providers with obligations under 42 CFR Part 2, message content can be configured so that nothing about the type of care is disclosed.

Data security and PCI-DSS

Card data is handled to PCI-DSS standards and is processed by our payment partners rather than stored on your systems or ours. Removing cardholder data from your environment is one of the more direct ways to reduce your own PCI scope.

    Controls:

  • TLS encryption for all data in transit
  • Encryption at rest for stored patient and balance data
  • Role-based access control with least-privilege defaults
  • Tokenized payment methods, so a stored card is a token rather than a number
  • Segregated client environments

Patients never create an account or set a password to pay, which removes a whole category of credential risk from the process.

Section 504 and accessible patient billing

Patriot Pay conforms to Section 504 of the Rehabilitation Act as it applies to patient billing communication. Section 504 prohibits discrimination on the basis of disability by programs receiving federal financial assistance, which includes most healthcare providers, and it requires that communication with patients who have disabilities be as effective as communication with anyone else.

Billing is communication. A statement a patient cannot read, or a payment process they cannot complete, is an access problem rather than a collections problem.

    How the platform supports accessible billing:

  • No portal account, password, or app download is required to view or pay a balance, removing steps that commonly block patients with cognitive or motor disabilities
  • Balances are delivered by SMS with a direct link, which works with screen readers and with the assistive settings a patient has already configured on their own device
  • AI billing agents explain charges in plain language on request, so understanding a bill does not depend on reading dense statement formatting
  • Support for 100+ languages, addressing the overlap between Section 504 and Title VI language-access obligations
  • Patients can reach a human on your team at any point, with the full conversation history attached

Shared responsibility: Patriot Pay is responsible for the accessibility of the billing communication and payment experience it delivers. Your obligations as a covered provider extend more broadly, including physical access and clinical communication, and are not discharged by your choice of billing vendor.

SOC 2 and TCPA

SOC 2: Patriot Pay maintains SOC 2 controls covering security, availability, and confidentiality. Security reviewers can request the current report through the contact below.

TCPA: Patient outreach happens by SMS, which puts it under the Telephone Consumer Protection Act. That shapes how the platform behaves:

  • Outreach runs on the contact details and consent status held in your system of record
  • Opt-out language is carried on messages, and a patient who opts out stops receiving them immediately
  • Opt-out status is written back so it is honoured across every future cycle
  • Sending windows respect the patient's local time zone
  • Message frequency is capped, and configurable below the cap

Consent is a shared responsibility. Patriot Pay honours the consent status your system holds; capturing valid consent at registration remains yours.

Audit trail and reporting

Every outreach message, patient interaction, and payment is logged with a timestamp, so the full history of an account can be reconstructed.

    Available for review:

  • What was sent to a patient, when, and through which channel
  • What the AI billing agent said, in full
  • When a balance was viewed, disputed, or escalated to your team
  • Every payment, partial payment, and plan, with posting status back to your system

This matters for internal audit, for payer and regulator questions, and for the ordinary case of a patient calling to say they were never contacted.

Compliance questions and documentation

Security reviews, BAA requests, vendor questionnaires, and accessibility documentation all go to the same place.

Email Mike@patriotpay.ai or use the contact form, and tell us which documents your review requires. We would rather answer a long questionnaire properly than have you discover a gap after signing.

This page describes how the Patriot Pay platform is built and operated. It is not legal advice, and it does not replace your own compliance obligations as a covered entity. See our Privacy Policy and Terms of Service.