How access, permissions, and data handling actually work - explained plainly, without overstating what's certified or guaranteed.
Virtual Medical Assistant limits system access to client-approved roles and permissions defined in each practice's scope and access agreement, and staff follow documented privacy and security procedures. Our workflows are designed to support HIPAA-aligned practices - this is not the same as a formal HIPAA certification, because no such certification exists for a vendor to hold. A Business Associate Agreement may be executed when applicable to your engagement.
No VMA is granted broad or default access to any system. Access is scoped, in writing, as part of your scope and access agreement - before onboarding training begins, not after.
We use the phrase "designed to support HIPAA-aligned workflows" deliberately, and we want to be direct about what it does and doesn't mean.
What it means: our processes - access limitation by role, documented privacy and security procedures, conditional BAA availability, and a no-PHI-in-public-materials policy - are built with HIPAA's administrative safeguards in mind.
What it doesn't mean: there is no such thing as a company being "HIPAA certified," because HIPAA does not have an official government certification program for vendors or business associates. We don't use that phrase, and we'd encourage you to be cautious of any vendor that does.
What stays your responsibility: as a covered entity, your practice retains its own HIPAA compliance obligations regardless of which vendors you work with.
A Business Associate Agreement may be executed when applicable to your engagement. Whether a BAA is required, and its specific terms, depends on the scope of services agreed and the nature of any protected health information involved. We recommend raising it explicitly during your assessment call.
Staff are trained on documented privacy and security procedures as part of onboarding for every engagement. We describe this as "documented," not "certified" - we do not claim staff hold third-party security certifications unless that is factually true. Procedures cover, at minimum: role-based access limits, secure handling of any information encountered while performing approved tasks, escalation rules for anything outside approved scope, and expectations around never storing or transmitting information outside client-approved systems.
We do not request, collect, or display patient health information in public-facing website forms, marketing materials, case examples, or blog content, or any communication before a scope and access agreement is signed. If your practice is ever asked for PHI through a form on this site, that's a mistake - please flag it to us directly rather than submitting it.
We don't make that claim as a bare statement, because HIPAA compliance is a shared obligation between covered entities and their business associates, not a one-time certification a vendor can hold. Our workflows are designed to support HIPAA-aligned practices: access is limited by client-approved roles and permissions, staff follow documented privacy and security procedures, and a Business Associate Agreement may be executed when applicable.
No, and no legitimate vendor can be - there is no official HIPAA certification program. We avoid this phrase because it misrepresents how HIPAA works.
A Business Associate Agreement may be executed when applicable to your engagement. This is discussed as part of your scope and access agreement.
Only the access your practice defines and approves as part of your scope and access agreement, scoped to the specific service you've engaged.
As standard practice, VMAs work inside your systems using the access you grant, rather than exporting or maintaining a separate copy of your data.
Access is revoked according to the offboarding terms in your agreement.
No PHI required for the initial conversation.
Tell us about your front-desk and admin workload - we reply within one business hour.