A biller gave two weeks' notice and the practice manager sat down to remove her access. She found the practice management system and the EHR quickly. Then she started on the payer portals: Availity, the UnitedHealthcare provider portal, the Medicare contractor's portal, two state Medicaid portals, three regional plans, a workers' compensation network, the clearinghouse, CAQH. Some accounts were in the biller's name. Some were in a former biller's name with a shared password. One was the physician's own login, which the biller had been using for four years.

This is normal, and it is a problem. Payer portals are where a billing team checks eligibility, reads claim status, downloads remittances, submits authorizations and files appeals. They hold protected health information on every patient the practice has billed. They are also the least managed systems in most practices, because nobody bought them, nobody installed them, and they accumulated one login at a time.

Here is how we run portal access for the billing teams we manage. None of it is complicated. All of it depends on somebody owning it.

Key takeaways

  • Keep one access inventory: every portal, every user, their role, the administrator, the MFA status and the last review date. Passwords live in a password manager, not in the spreadsheet.
  • Every person gets their own login with the smallest set of functions their job needs. Shared logins have no audit trail and cannot be revoked for one person.
  • Onboarding and offboarding run from the same checklist, and departures are handled the same day, including reassignment of any administrator or authorized official role.
  • Batch portal work into four fixed passes a day; anything that needs a portal more than four times a day belongs in the practice management system or clearinghouse instead.
  • Review the user lists quarterly against the staff list and record the review.

Start with an inventory

Build one spreadsheet, kept somewhere access-controlled, with a row for every portal the practice uses. For each row record the portal name and address, the payers it covers, the practice's organization or account identifier, the named administrator, every user with access and their role, whether multi-factor authentication is turned on, the date access was last reviewed, and the portal's own rule for inactivity (many lock accounts after 60 or 90 days without a login). Passwords do not go in the spreadsheet. They go in a password manager with shared vaults per role.

The first time a practice builds this list it usually finds three things: accounts belonging to people who left, at least one shared login, and a portal nobody can get into because the administrator was a former employee. Fix those before anything else. Picture a three-physician internal medicine practice that counts 34 portal accounts across a billing team of three and a front desk of two. Eleven belonged to people who no longer worked there. Two portals had no living administrator, and getting one reinstated took a notarized letter and three weeks. That is the cost of not having the list.

Use the portal's own administrator model

Almost every major portal supports an organization account with one or more administrators who create, modify and remove individual users. Availity calls this the administrator role and lets an administrator assign specific functions to each user. The UnitedHealthcare portal, the Medicare contractor portals and most Blue plans have an equivalent. CMS's Identity and Access Management System, which controls access to PECOS and NPPES, uses a similar structure: an authorized official for the organization, access managers who can approve staff, staff end users, and surrogates such as an outside billing company acting on the practice's behalf.

The rule we use: every person has their own login, in their own name, with the smallest set of functions their job needs. The front desk gets eligibility and authorization status; the poster gets remittance download; the follow-up biller gets claim status and appeals; nobody outside the practice manager and one backup gets administrator rights. A practice that shares one login "because it is easier" has no way to know who looked at what, and cannot remove one person's access without changing everyone's.

The HIPAA Security Rule expects unique user identification and procedures for ending access when employment ends. We are not lawyers and this is not legal advice, but we can say that a shared payer portal login is hard to defend on either point, and that the fix costs nothing.

Always have two administrators. One is not enough: the day the only administrator is on leave is the day a new hire needs an account, or the day a locked account has to be reset before an appeal deadline. The backup should be the practice manager or owner, not another biller, so that the role survives turnover on the billing team.

Onboarding and offboarding on the same checklist

EventSame dayWithin a week
New hireCreate individual accounts on the portals the role needs; enroll their MFA device; record them in the inventoryConfirm they can complete each daily task; remove any function they do not use
Role changeAdjust functions on each portal; update inventoryReview for leftover access from the old role
DepartureRemove or deactivate every account on the inventory; rotate any credential the person could have known; reassign administrator roles if they held oneConfirm no login activity since departure; document the completion date
Physician or owner departureReassign authorized official roles in CMS systems and CAQH before the last day, not afterVerify PECOS and portal ownership transferred
Billing vendor changeRemove the old vendor's surrogate and user accounts; add the new vendor's under the practice's organization, never under the vendor's ownConfirm remittances and claim status still route to the practice's accounts

The physician row matters more than it looks. When a departing physician was the authorized official for PECOS or the administrator of a portal, the practice can lose the ability to manage its own enrollment records until the role is reassigned, and reassignment after the person has left takes far longer than a signature before.

The vendor row is the one practices forget. When a billing company sets up portal access under its own organization account instead of the practice's, the practice does not own its access. Changing vendors then means starting over on every portal. Insist that every account is created under the practice's organization with the vendor's staff added as users or surrogates, so that access can be removed with a click when the relationship ends.

Multi-factor authentication and inactivity

Turn on multi-factor authentication everywhere it is offered. Register the second factor to a work device or an authenticator app, not to a personal phone number that leaves with the employee. Many portals now require it, and the ones that do not will. Then deal with inactivity locks: a portal used only for occasional appeals will lock the account between uses. Assign one person to log into every low-use portal on the first business day of each month. It takes ten minutes and prevents the two-day scramble to re-verify an account on the day an appeal is due.

Which portal tasks to batch, and when

Portal work expands to fill the day if it is done reactively. We batch it:

  1. Before 9 a.m.: download every remittance that did not arrive electronically, and check the clearinghouse for rejections. One person, one pass, every portal in a fixed order.
  2. Mid-morning: claim status for anything over 30 days with no remittance, by payer, from the follow-up work list. Record status codes in the practice management system, not in the head.
  3. Early afternoon: eligibility for the next two business days of appointments, unless the practice management system runs it automatically; authorization status for pending requests past their expected decision date.
  4. End of day: appeals and reconsiderations uploaded, with confirmation numbers logged.

Any portal that needs to be opened more than four times a day is a sign that a task belongs in the practice management system or the clearinghouse instead. Eligibility (the 270/271 transaction), claim status (276/277) and remittances (835) can all run electronically for most payers; the portal is the fallback, not the workflow.

Quarterly access review

Once a quarter, the administrator prints the user list from each portal and compares it to the inventory and the current staff list. Every difference is a finding: a user who left, a role that grew, a portal that was added without being recorded. Fix, date, and initial the review. Practices that outsource billing should ask their partner to show them this review; Revelrex runs it for the practices whose billing we handle, and we think any partner should be able to produce the list on request.

Questions we hear

The physician wants to keep using the same login for everything. Is that a problem?

Yes, for two reasons. If staff use it, the audit trail says the physician did everything. If the physician alone uses it, nobody else can act when they are unavailable. Give the physician their own account with the functions they use, and give staff theirs.

How many portals should a practice really have?

Fewer than it does. Consolidate through a multi-payer portal where the payers support it, run eligibility and claim status through the clearinghouse, and keep direct portals only for payers that offer nothing else or for appeals. A shorter list is easier to secure and easier to review. If your billing technology has grown by accretion, our RCM audit includes an access and tooling review that produces the inventory for you.

Our billing company set up all the portals. Do we still need our own inventory?

Yes. The practice is the covered entity and the portals hold its patients' data. Ask the vendor for the list of portals and users it maintains on your behalf, check that the accounts sit under your organization, and keep a copy of the list. If the vendor cannot produce it in a day, that tells you something about how the access is being managed.

What to do this week

  1. Open a spreadsheet and list every portal the practice uses, with the administrator and every user. Ask each biller and the front desk to add what you missed.
  2. Remove every account belonging to someone who no longer works there, and change any shared password today.
  3. Name a second administrator on each portal, preferably the practice manager or owner.
  4. Turn on multi-factor authentication on every portal that offers it, tied to work devices.
  5. Put the first business day of the month on the calendar for low-use portal logins, and the first week of each quarter for the access review.