How to choose a medical billing company: The complete outsourcing buyer's guide

A medical billing company manages your revenue cycle starting at scheduling, well before a single claim is ever created: eligibility checks (often run days or weeks ahead of the visit, then re-verified again at submission), coding validation, claim submission, denial management, payment posting, patient billing, and reporting. The real decision hiding inside "which vendor" is actually "which model," and it comes down to incentive alignment as much as capability. A company you pay to appeal denials makes more money when you generate more denials, the same way a body shop needs you to need more bodies. Pay people to clean up claims after they break, or pay for a system built to keep them from breaking in the first place.
What you're actually buying
A full-service billing company handles eligibility verification, coding validation, claim submission, denial management and appeals, payment posting, patient billing, and financial reporting. If a vendor only touches submission and leaves denials, appeals, and A/R follow-up to your staff, you haven't outsourced the revenue cycle. You've outsourced data entry and kept the expensive part in-house.
Revenue cycle consultants are a different service entirely. They assess your workflows, identify revenue leakage, and recommend process or technology changes, but they don't process a single claim themselves. Hiring a consultant when you need an execution partner, or the reverse, is one of the more common and costly mismatches practices make during vendor selection.
This list isn't exhaustive, and every vendor will describe their scope a little differently. The question that cuts through the marketing is simple: ask a vendor to walk you through the last denial they personally appealed and won, not just a claim they submitted. If all they can point to is submission and reporting, they're not carrying revenue-cycle risk, your staff still is. The vendors worth shortlisting are the ones who own the full loop end to end, including the outcome, and who can show you how few claims reach the appeals stage in the first place because of how they're built.
Six things that separate good vendors from bad ones
Weigh these six factors before you sign anything:
Scalability: Can the vendor support you on a single platform instance as you add locations, providers, or claim volume, or does growth force a re-implementation, a new contract tier, or a migration to their "enterprise" product? Ask specifically how their rules and automation scale with volume, not just how fast they can hire more staff.
Technology and integration across your full stack: EHR integration is table stakes. Ask what else the platform connects to: clearinghouses, patient estimation and payment tools, credentialing systems, and analytics or BI tools. A vendor that only integrates with your EHR still leaves you stitching everything else together by hand. Ask for a live look at the reporting dashboard, not a slide deck built for the sales call.
Compliance and security depth: A signed Business Associate Agreement is table stakes and should exist before any patient data moves, but it doesn't tell you much. Push further: ask which SOC report they hold (SOC 1 vs SOC 2), what scope and time period the audit actually covers, how often it's renewed, and whether they'll produce the auditor's report itself rather than a compliance summary page. Also ask for their written encryption and access-control policies and a documented breach-response plan.
Pricing structure: Most firms charge a percentage of net collections, commonly 4% to 10% depending on specialty and volume, a flat fee per claim, or a hybrid of both.
Performance metrics in writing: Clean claim rate, touchless claim rate (TCR), days in A/R, denial rate, denial overturn rate, and net collection rate belong in the contract, not the sales deck.
Transition support: Ask how they'll handle your legacy A/R, whether you get a named account manager, and whether they'll run parallel with your current process before full cutover.
Before you talk to a single vendor, pull your own baseline numbers: current clean claim rate, days in A/R, denial rate, and collection percentage. Every improvement claim a vendor makes should be measured against those numbers, not against an industry average that has nothing to do with your payer mix.
Automation-first billing vs legacy BPO outsourcing
Legacy BPO outsourcing is a labor model. Offshore or nearshore teams manually process claims, work denials, and file appeals, and quality depends on headcount and the skill of whoever happens to be staffed on your account that quarter. Scaling means hiring more people, which means your cost structure grows roughly in line with your claim volume, not faster than it.
Automation-first billing is a different approach. Instead of paying more people to fix claims after a payer rejects them, the platform uses rules and automation to catch problems before the claim ever leaves the building: incorrect patient demographics, missing credentialing links, coding errors against payer-specific requirements. Candid Health's rules engine checks claim data against coding guidelines and payer requirements pre-submission, and correctly configuring provider credentialing and contract terms prevents many denials and rejections from happening at all, rather than generating work to appeal them later.
That distinction shows up most clearly in how each model treats denial management. A legacy vendor that leads with the size of its denial-management team is often describing a workaround for a high error rate at submission, not a fix for it. The metric worth asking about is touchless claim rate, the share of claims that get from submission to resolution without a single manual touch. A vendor proud of how many people it takes to appeal denials is telling you something about how many claims are breaking upstream.
Candid Health is used by more than 200 healthcare organizations and completed a Type 1 SOC 1 examination with a clean auditor opinion, the kind of third-party verification worth requesting from any vendor regardless of which model they run.
Red flags worth walking away from
A vendor that won't share denial and collection metrics before you sign isn't going to share them after. Treat that hesitation as an answer, not an oversight.
Other warning signs: vague fee language that never quite specifies gross versus net, no signed BAA, staff turnover high enough that nobody can name your account manager, and a service model that can't flex as your volume or specialty mix changes. Outsourced billing can be HIPAA compliant, but only with a signed BAA and documented security controls in place, not a verbal assurance on a sales call.
The actual choice
Every buyer's guide tells you to check references and compare pricing tables. Do that. The more important question is whether you're hiring a bigger team to fix claims after they break, or a system built to stop them from breaking in the first place. Ask every vendor on your shortlist which one they're selling you, and hold them to the metrics that prove it.