(888) 216-2197VMA Staffing From $9.99/hr — Specialized, Trained & Committed Staff.Get a FREE Website
Trust & Compliance

Security, Privacy, and Access Controls

How access, permissions, and data handling actually work - explained plainly, without overstating what's certified or guaranteed.

Virtual Medical Assistant limits system access to client-approved roles and permissions defined in each practice's scope and access agreement, and staff follow documented privacy and security procedures. Our workflows are designed to support HIPAA-aligned practices - this is not the same as a formal HIPAA certification, because no such certification exists for a vendor to hold. A Business Associate Agreement may be executed when applicable to your engagement.

How Access and Permissions Work

No VMA is granted broad or default access to any system. Access is scoped, in writing, as part of your scope and access agreement - before onboarding training begins, not after.

  • Your practice defines which systems (EHR, practice-management software, phone system, shared inbox, scheduling calendar) a VMA needs to touch for the specific service you've engaged
  • Permissions are set at the role level your practice approves
  • Access is tied to the service scope agreed during onboarding; if scope changes, access is reviewed and adjusted
  • Your practice retains control over system-level permission settings; we work within the access your administrators configure

What "HIPAA-Aligned" Means in Practice

We use the phrase "designed to support HIPAA-aligned workflows" deliberately, and we want to be direct about what it does and doesn't mean.

What it means: our processes - access limitation by role, documented privacy and security procedures, conditional BAA availability, and a no-PHI-in-public-materials policy - are built with HIPAA's administrative safeguards in mind.

What it doesn't mean: there is no such thing as a company being "HIPAA certified," because HIPAA does not have an official government certification program for vendors or business associates. We don't use that phrase, and we'd encourage you to be cautious of any vendor that does.

What stays your responsibility: as a covered entity, your practice retains its own HIPAA compliance obligations regardless of which vendors you work with.

Business Associate Agreements

A Business Associate Agreement may be executed when applicable to your engagement. Whether a BAA is required, and its specific terms, depends on the scope of services agreed and the nature of any protected health information involved. We recommend raising it explicitly during your assessment call.

Staff Training and Procedures

Staff are trained on documented privacy and security procedures as part of onboarding for every engagement. We describe this as "documented," not "certified" - we do not claim staff hold third-party security certifications unless that is factually true. Procedures cover, at minimum: role-based access limits, secure handling of any information encountered while performing approved tasks, escalation rules for anything outside approved scope, and expectations around never storing or transmitting information outside client-approved systems.

No PHI in Public-Facing Materials

We do not request, collect, or display patient health information in public-facing website forms, marketing materials, case examples, or blog content, or any communication before a scope and access agreement is signed. If your practice is ever asked for PHI through a form on this site, that's a mistake - please flag it to us directly rather than submitting it.

Data Handling Boundaries

  • VMAs work inside your systems using the access your practice grants - we do not export, replicate, or maintain a separate copy of your patient data outside your approved systems as standard practice
  • Any information encountered while performing an approved task is handled according to the documented procedures described above
  • Access is reviewed against the scope agreed for your engagement; it is not expanded without your approval
  • If your practice terminates an engagement, access is revoked according to the offboarding terms in your agreement

What to Ask Before You Share Any Access

  1. What specific access does this task require, and can it be scoped narrower than "full system access"?
  2. Who at the vendor has visibility into what we share, and is that documented anywhere?
  3. Is a Business Associate Agreement available, and what does it actually cover for this engagement?
  4. What happens to our access and any data touched if we end the engagement?
  5. Can the vendor show us, in writing, what "HIPAA-aligned" or "HIPAA compliant" specifically means in their own workflows?
FAQ

Security & Privacy FAQs

We don't make that claim as a bare statement, because HIPAA compliance is a shared obligation between covered entities and their business associates, not a one-time certification a vendor can hold. Our workflows are designed to support HIPAA-aligned practices: access is limited by client-approved roles and permissions, staff follow documented privacy and security procedures, and a Business Associate Agreement may be executed when applicable.

No, and no legitimate vendor can be - there is no official HIPAA certification program. We avoid this phrase because it misrepresents how HIPAA works.

A Business Associate Agreement may be executed when applicable to your engagement. This is discussed as part of your scope and access agreement.

Only the access your practice defines and approves as part of your scope and access agreement, scoped to the specific service you've engaged.

As standard practice, VMAs work inside your systems using the access you grant, rather than exporting or maintaining a separate copy of your data.

Access is revoked according to the offboarding terms in your agreement.

Bring Your Access Questions to Your Assessment Call

No PHI required for the initial conversation.

Free front-desk workflow reviewBook Free Consultation
VMA AssistantAsk about services, pricing, HIPAA, or book a call