Estimated reading time: 7 minutes.
Summarize with ChatGPT
TL;DR:
Table of contents
Insurance changes rarely announce themselves. A long-term client switches jobs in March, signs new HR paperwork, and doesn't realize they also need to update you. You find out in May, when their claim comes back denied, while you're catching up on Friday billing.
Now you're looking at weeks of sessions billed to an inactive plan, a list of resubmissions, and the awkward choice between writing off the balance, paying a biller to clean it up, or making the calls yourself.
In a 2017 CommonWealth Beacon piece, a Massachusetts clinician shared the story of a private practice colleague who was asked to repay $27,000 after insurance claims were reversed months later. While unusual, this case shows how insurance issues can snowball when coverage changes go unnoticed.
You can't prevent every insurance issue. But a consistent process for collecting and updating insurance information makes problems easier to catch before they turn into weeks of denied claims.
Under HIPAA, insurance information is considered protected health information (PHI), which means practices need a secure way to collect, send, and store it.
What helps here is just having a process in place. You need a secure way to collect insurance details, a small set of moments to proactively check in, and a habit of resending the form whenever a client's coverage changes.
"Insurance information might feel like billing data, but under HIPAA, it's PHI. Member IDs, group numbers, card images, and plan details are all tied to a person seeking care. That's exactly the kind of information HIPAA was written to protect."
Steven O. Youngman, VP of Legal and Compliance at Hushmail
Yes, and not just the policy number.
Under HIPAA, PHI is any individually identifiable health information held or transmitted by a covered entity. That covers a lot more than chart notes. When you collect a member ID, a group number, a plan name, or a photo of an insurance card, you're holding information that ties a specific person to a specific health benefit. That's PHI.
For a deeper breakdown of what does and doesn't count, see our post on what counts as PHI.
Why card images require extra care
Insurance card photos often bundle several pieces of sensitive information in a single upload, including names, member IDs, group numbers, and plan details. That's one reason practices should collect and store them through secure, organized workflows.
Accurate insurance information does real work. When a claim comes back denied, it's often the first place to check.
A few specific reasons it matters:
Insurance changes don't always get mentioned right away. Clients may not realize a coverage change can affect therapy billing unless they're asked directly.
The changes themselves are pretty predictable. They tend to cluster around a small handful of moments:
Sometimes the first sign that something changed is a denied claim. By then, sessions may already have been billed under outdated coverage, creating extra follow-up and administrative work.
This is why most of the work is on the front end. Build a few moments into your workflow where you ask the client directly, and you’re more likely to catch changes before they create problems.
Most billing problems don't come from one big mistake. They usually come from a few small shortcuts that pile up over time.
How it usually happens:
Each shortcut feels efficient at the moment. Stacked together, they create three patterns that quietly cost you time and money:
💡 Hushmail tip: A secure form gives clients one encrypted place to upload insurance details and card photos, instead of sending them across multiple emails or text messages. You're more likely to receive complete information the first time, and your client doesn't have to think about what they forgot to attach.
HIPAA doesn't mandate a specific form builder, app, or email provider. It asks you to implement "reasonable safeguards" to protect PHI.
For insurance information specifically, that translates to a few practical principles:
"HIPAA doesn't tell you which form builder or email service to use. It asks you to protect PHI during transmission and ensure only the right people can access it. For insurance information, that usually comes down to one question: is the tool you're using secure and covered by a BAA?"
Steven O. Youngman, VP of Legal and Compliance at Hushmail
HIPAA gives practices flexibility in how they handle insurance information. But it's still your responsibility to choose tools and workflows that protect PHI.
The workflow itself doesn't have to be complicated. The harder part is being proactive about when you ask, not what you ask.
Instead of spreading insurance details across a string of emails, send one secure intake form that captures everything you need in a single submission:
When it all arrives together, you don't have to track down what's missing, and your client doesn't have to remember what they still owe you.
The first few weeks of January are when many new insurance plans and benefit changes take effect. Build the "has your insurance changed?" message into your calendar so it actually happens, not just in theory. If you also see private-pay clients, you can pair this with the year-start work you're already doing for them, like sending Good Faith Estimates or rate change notices. That way, the entire annual refresh becomes a single routine instead of a separate task.
If a client mentions a new job, a divorce, a baby, or a return to therapy after a break, that's the moment to resend the form. You don't have to wait for a denied claim to find out something changed.
Wherever you store client information, the goal is a single secure location with access controls. Not scattered across email, paper, and sticky notes.
💡 Hushmail tip: Hushmail's Insurance Information form template covers the fields most insurance-based practices need, including secure uploads for the front and back of a client's card. Your client completes the form from any device, and submissions land directly in your secure inbox.
You don't have to overhaul your whole intake process to make insurance collection easier. Pick one of these:
Both moves take less than an hour to set up and can save you admin headaches by catching an insurance change before it creates billing delays or claim issues.
For the client, the experience is simple. They get a notification with a link, complete the form on their phone or laptop, upload card photos, and they're done. No app to install, no special software to set up.
If you want to step back and look at your whole compliance picture, our HIPAA compliance checklist is a useful place to start.
"A secure, consistent process for collecting and updating insurance information helps you catch changes earlier, before they turn into billing delays or denied claims. That's where compliance and good practice start to overlap."
Steven O. Youngman, VP of Legal and Compliance at Hushmail
Ready to collect insurance information securely?
Hushmail gives clients a secure way to submit insurance details and card photos via an encrypted channel, with everything delivered to your secure inbox.
Reviewed by: Steven O. Youngman, VP of Legal and Compliance, Hushmail.