
Anastasiya Novikava
Copywriter
Anastasiya believes cybersecurity should be easy to understand. She is particularly interested in studying nation-state cyber-attacks. Outside of work, she enjoys history, 1930s screwball comedies, and Eurodance music.
Case studies
Summary: MediBillMD specializes in revenue cycle management for healthcare providers. Their teams work from South Asia, yet they must securely access PHI based in the U.S.
MediBillMD is a service-based company that provides end-to-end revenue cycle management for clinics and healthcare providers. They manage the billing of claims and the reimbursement process. They also handle:
Here’s a simplified version of the revenue cycle they manage:
MediBillMD handles the billing and collection tasks, so clinics can focus on patient care. They are experts at ensuring providers get paid for services rendered.
Alex Walker, Assistant VP Business Development and Sales, explains:
“We work with protected health information, so we must comply with HIPAA guidelines. We also need secure remote access to electronic medical records (EMRs) for our providers. We can’t do this without a dedicated U.S. IP address, and that’s where NordLayer helps us run operations smoothly.”
MediBillMD’s main office is in Dallas, Texas. Their operations team works primarily overseas. They needed:
They turned to NordLayer to fulfill these requirements.
MediBillMD had tried another solution that didn’t work well. They switched to NordLayer because of user-friendly management, strong support, and familiarity with Nord’s products.
“Nord is well-known. The support is good, and the prices are competitive. I was already using NordVPN personally, so I recommended NordLayer. We want to become an enterprise soon, and NordLayer fits those plans.”
Deployment was straightforward:
“Everything takes 2 or 3 minutes.”
MediBillMD’s teams must access U.S.-based websites and EMRs from other regions. Some websites block non-U.S. traffic. The dedicated U.S. IP solves that.
When employees begin work, they automatically connect to the NordLayer VPN to reach EMRs and billing websites. Without the VPN, they can’t access any resources at all.
MediBillMD also has a Business Associate Agreement (BAA) with each clinic. This ensures that PHI can be accessed without storing data locally. By using the dedicated IP, each clinic knows exactly where MediBillMD’s requests come from, and no PHI gets saved on local systems.
MediBillMD enforces an Always On VPN policy:
“There’s an option that only allows the internet connection when the VPN is on.”
This approach eliminates accidental data exposure and keeps PHI protected at all times.
MediBillMD blocks certain sites by using DNS filtering. They can tailor these policies to ensure employees don’t accidentally access risky domains.
“We can also explore other NordLayer solutions, like network segmentation, as we grow.”
MediBillMD values an all-in-one cybersecurity solution. They don’t want multiple vendors for separate tasks. NordLayer meets those needs:
They plan to add more dashboards for HIPAA audits in the future. For now, they focus on a smaller volume of analytics. As they expand, they’ll integrate more features.
Organizations handling PHI must follow strict security rules to stay HIPAA-compliant. These practices help prevent breaches and block unauthorized access. While designed for healthcare, they also benefit other industries managing sensitive data.
Alex Walker, Assistant VP Business Development and Sales @MediBillMD
MediBillMD needs a dedicated U.S. IP to serve their remote workforce and U.S. clients. Here’s what they did:
For healthcare companies like MediBillMD, an all-in-one solution helps maintain compliance, boost security, and simplify IT.
A Server with a dedicated IP starts at $40 per month. Other security features come in the Core NordLayer plan.
Subscribe to our blog updates for in-depth perspectives on cybersecurity.