Mental-Health Billing Vendor Selection: Questions That Test Denial Prevention, Privacy, and Reporting
How to evaluate a mental-health billing vendor on 42 CFR Part 2, denial prevention, HIPAA security, and pricing. Includes the questions to ask.

Choose a mental-health billing vendor by testing 4 capabilities: Part 2 compliance for SUD records, HIPAA security evidence, denial prevention measured by CARC code, and a transition plan that protects cash. If a vendor can't answer specifically on all 4, walk away.
Most practices evaluate billing companies on price and turnaround time. Those are the two things a vendor controls least. Price is a formula everyone publishes. Turnaround depends on payer behavior nobody controls.
What separates a good behavioral health billing partner from a bad one shows up in questions about privacy, denial cause, and who does the work when something breaks. Below are the questions that force a real answer, with the numbers you should hold in your head while you ask them.
Key takeaways
- 42 CFR Part 2 has been enforceable since February 16, 2026. OCR made Part 2 noncompliance an enforcement priority and now accepts breach notification complaints under the rule.
- Healthcare data breaches cost $6.64 million on average in 2026, the 13th consecutive year as the costliest industry (IBM and Ponemon Institute).
- Mental-health billing typically prices at 4% to 8% of collections. Residential, PHP, IOP, and SUD programs price at the higher end for documented reasons.
- Practices that switch billing companies lose 6% to 14% of revenue during the transition when the handoff is structured poorly.
- A blended denial rate under 5% can still hide one payer denying 15% of claims. Always break denials out by payer and CARC code.
What questions should you ask a mental-health billing company?
Ask what they'll show you, not what they'll tell you.
The questions below are ordered by how quickly a weak vendor gives itself away. The Part 2 question filters fastest.
Ask for a named security contact, a sample denial report from a comparable behavioral health practice, and the specific CARC codes they see most. A general billing company will answer all three with a brochure.
Can the vendor handle 42 CFR Part 2 records?
This is where most mental-health vendor evaluations stop short, and where the most regulatory exposure sits.
42 CFR Part 2 carries stricter confidentiality rules for substance use disorder records than HIPAA does. The 2024 final rule took effect April 16, 2024, with a compliance date of February 16, 2026. From that date, the HHS Office for Civil Rights began accepting complaints alleging Part 2 violations and breach notification failures. OCR has named Part 2 noncompliance an enforcement priority.
Penalties now align with HIPAA. In 2025 those ranged from 2.1 million per violation tier, with criminal penalties also possible.
Ask your vendor four specific questions:
- Which Part 2 provisions does your BAA cover?
- Who at your company has completed Part 2 training, and when?
- How is single TPO consent handled in your submission workflow?
- Which systems hold SUD counseling notes, and who has access?
A vendor that treats Part 2 as a checkbox on the BAA has not read the rule. Our 42 CFR Part 2 compliance guide covers what single TPO consent changes operationally, and our SUD counseling notes documentation playbook covers the disclosure scope questions.
What security evidence should a billing vendor show you?
HIPAA compliance is the baseline, not the differentiator. Ask for evidence beyond the BAA.
IBM and the Ponemon Institute put the average healthcare data breach at 4.99 million, and the US average ran $11.5 million.
Evidence to request | What it proves |
|---|---|
Current SOC 2 Type II report | Controls operated effectively over 6 to 12 months |
HITRUST or ISO 27001 certification | Healthcare-specific security program |
BAA with subcontractors | Your data chain is covered end to end |
Breach notification timeline in contract | You know when you'll be told |
Named security officer | There's a person, not a policy document |
A signed BAA establishes a framework. It doesn't prove the vendor's controls work. SOC 2 assesses long-duration control operation; the HIPAA Security Risk Analysis is a separate exercise, and a vendor should be willing to discuss both.
One more question: where does work physically happen? Data location and cross-border transfer rules add a compliance layer that most practices never ask about. If your vendor uses offshore staff, ask specifically which data they can access.

What should you know about AI in a vendor's workflow?
Every RCM vendor now claims to use AI. Very few will tell you where a human still signs off.
CAQH's 2025 Index found more than 50% of health plans and 25% of provider organizations now use AI tools in administrative workflows. The same report put the remaining savings opportunity from fully automating manual transactions at 258 billion already avoided in 2024.
That's real adoption, which is exactly why you need to ask about oversight rather than capability.
Three questions:
- Which actions require human approval before they leave your practice?
- Who reviews AI-flagged denials, and what are their credentials?
- Can you see an audit log showing which system touched a claim?
Black Book's 2026 State of Hospital and Health System RCM Technology and Services Report found 69% of organizations require human-in-the-loop controls before allowing AI to take claim, appeal, coding, or patient-contact actions. You're in the majority if you want that too.
The same report found 70% of organizations want to reduce or rationalize their number of RCM vendors, and 66% say their current RCM analytics are insufficient for CFO-level revenue predictability. Ask what reporting you actually receive, and how many clicks it takes to get a denial breakdown by CARC code.
Our guide to AI governance controls in denial management covers model validation, PHI handling, and measuring false-positive denial flags.
How do you test a vendor's denial prevention ability?
Ask to see a denial breakdown by CARC code from a comparable practice. If they show you a single blended denial rate, they aren't tracking root cause.
Behavioral health denials cluster in predictable places: authorization (CO-197), missing claim data (CO-16), and medical necessity (CO-50). A vendor who works behavioral health regularly will name those codes without checking notes.
The number that should concern you is the appeal win rate. Insurance appeal data has been public since March 31, 2026, and KFF's analysis of 2025 insurer filings found substantial overturn rates:
Market | Standard PA denial rate | Overturned on appeal |
|---|---|---|
Medicare Advantage | 12% | 67% |
Medicaid managed care | 14% | 47% |
ACA Marketplace | 18% | 43% |
Overturn rates varied enormously by insurer. In Medicare Advantage they ran from 40% at Kaiser Permanente to 93% at Centene. Ask which payers your vendor appeals successfully. The answer tells you whether they've done the work.
Our psychiatry claims denial analytics approach breaks denials into dashboards by reason code with a named owner for each, and our behavioral health prior authorization workflow covers the prevention side.
How do you compare pricing models for behavioral health billing?
Percentage of collections is the most common model for full outsourcing, typically 4% to 8% for behavioral health. More complex programs, including residential, PHP, IOP, and SUD treatment, price toward the higher end.
Per-claim pricing, flat monthly fees, and hybrid models also exist. Here's the practical difference:
Model | Best for | Watch out for |
|---|---|---|
Percentage of collections | Practices that want aligned incentives | Cost rises as collections rise |
Per claim | Predictable claim volume | Punishes long complex claims |
Flat monthly | Small practices with steady volume | Doesn't flex with growth |
Hybrid | Mixed service lines | Harder to compare across vendors |
Ask what's included at the quoted rate. Software licensing, portal access, credentialing, and patient statements sometimes sit inside the percentage and sometimes stack on top. A 5% quote with software billed separately isn't a 5% quote.
Behavioral health practices running higher-acuity programs should expect the higher end of the range. See behavioral health billing services pricing for how providers structure by service line.
How should the transition plan work?
Ask for a written transition timeline with named deliverables and dates before you sign anything.
Practices that switch billing companies lose 6% to 14% of revenue during the transition when the handoff is structured badly. The loss comes from aged claims nobody owns during the gap, not from the new vendor performing worse.
Three things should be in the contract:
- A claims-in-flight inventory handed over before your first payment
- Submission of all claims outstanding as of the cutover date
- Defined ownership of pre-cutover denials for at least 90 days
If a vendor won't commit to those in writing, assume you'll absorb the gap.

When is outsourcing the right call?
Outsource when you have volume the work demands but not the staff to do it. Keep it in-house when the clinical relationship drives revenue and you have someone who can own the detail.
The clearest signal is documentation drift. When coding errors trace back to where notes get recorded rather than to the clinicians writing them, an outside team can fix the configuration faster than an exhausted biller can.
Ask for references from comparable practices. Same specialty, similar claim volume, similar payer mix. A vendor's best reference usually isn't their best client.
If you operate across state lines, check state coverage separately. Our New York medical billing guide covers what changes when your enrollment footprint crosses a border, which is where multi-state vendors tend to get vague.
Our medical billing audit covers whether your current setup has a fixable problem before you commit to a full outsourcing relationship.
