Healthcare · Guide

HIPAA and virtual assistants: what a medical practice must put in place

By Issabela Masters · · Reviewed by Nimra Khalid

8 min read · 1,696 words

HIPAA and virtual assistants: what a medical practice must put in place: AssistBPO guide cover

A HIPAA virtual assistant is not a special category of person, it is a normal administrative assistant working under a signed business associate agreement with role-based access, documented training and audit logging. Your practice stays the covered entity. Get those four controls in place before the first login is issued and the rest follows.

This is a plain-language summary, not legal advice.

Who is the covered entity and who is the business associate?

HIPAA splits the world into two roles, and mixing them up is where most trouble starts.

You are the covered entity. Health plans, health care clearinghouses and providers who transmit health information electronically in connection with covered transactions are covered entities. A dental practice billing insurance electronically is one. A solo therapist submitting claims is one.

A virtual assistant company is a business associate. HHS defines a business associate as a person or entity that creates, receives, maintains or transmits protected health information on behalf of a covered entity. Scheduling, eligibility verification, prior authorization follow-up, referral coordination, patient calls and billing support all qualify.

Subcontractors are business associates too. If your assistant company uses a transcription vendor, a cloud storage provider or a telephony platform that touches PHI, each of those needs its own agreement in the chain. Ask the question directly: who else touches this data, and do you hold a BAA with them?

One thing the rules do not care about is geography. HIPAA imposes no US-only staffing requirement. What it requires is the agreement, the safeguards, the training and the ability to show who accessed what. A practice that cannot produce an access log for its in-house front desk is in a weaker position than one that can produce it for a remote team.

What has to be in the business associate agreement?

The BAA is signed before access, not after. HHS publishes sample provisions you can start from. At minimum it should nail down the following.

ClauseWhat it should sayWhy it matters
Permitted uses and disclosuresThe exact functions: scheduling, eligibility, referrals, patient messaging, billing supportAn open-ended clause gives you nothing to enforce
SafeguardsAdministrative, physical and technical safeguards required by the Security RuleThis is the hook for MFA, device control and encryption
SubcontractorsEvery subcontractor that touches PHI is bound by equivalent termsCloses the chain below your vendor
ReportingSecurity incidents and breaches reported to you, with a stated deadlineThe 60-day legal outer limit is too slow for an operational response
Access, amendment, accountingCooperation with patient rights requests within set timeframesPatients ask, and the clock runs on you
Minimum necessaryAccess limited by role, reviewed on a scheduleMakes least privilege contractual, not aspirational
Termination and return of PHIData returned or destroyed, access revoked, certificate providedOffboarding is where records quietly linger
Audit and evidenceYou can request training records, access logs and the risk analysis summaryTurns claims into artifacts

Add two practical clauses that are not required but save arguments later: a named point of contact on both sides for incidents, and a same-day access revocation commitment when a staff member leaves the account.

What does minimum necessary look like for a remote front desk?

The minimum necessary standard asks you to limit uses, disclosures and requests to what the job actually needs. In a practice management system that means building a role, not handing over a copy of the doctor’s login.

A workable scheduling and intake role:

  • Full access: appointment book, patient demographics, contact preferences, insurance carrier and plan fields, recall and continuing care lists, referral tracking.
  • Read only: treatment plan line items where scheduling or eligibility depends on the procedure code.
  • No access: clinical notes, imaging, lab results, medication history, anything outside the administrative workflow.
  • Never: shared logins, exported spreadsheets of patient data, screenshots in chat, PHI in email subject lines, full card numbers anywhere outside your payment portal.

The standard has exceptions. It does not apply to disclosures to a provider for treatment, to the individual, made under a valid authorization, or required by law. Most administrative work sits outside those exceptions, so build to the tighter rule.

What training is required, and how do you prove it?

Two separate requirements, both explicit.

The Privacy Rule requires training on your policies and procedures for every workforce member, as necessary and appropriate for their functions, plus retraining when policies change materially. The Security Rule separately requires a security awareness and training program covering malicious software, login monitoring and password management.

What proof looks like:

  • A named curriculum with a version and a date.
  • A roster of who completed it, with completion dates and an assessment score.
  • A signed confidentiality acknowledgment per person, per client account.
  • Refresher cadence written down, usually annual, plus event-driven training after a policy change or an incident.
  • Role-specific modules, because a scheduler and a billing assistant handle different risks.

When you evaluate a provider, ask for the roster for the people who would work on your account, not a generic certificate. Names, dates, module versions. If that does not exist, the training probably does not either.

How do you log and review access?

The Security Rule is specific here, and it is the part practices most often skip.

  • Unique user identification. Every person gets their own login in the practice management system. Shared credentials break the audit trail and end the conversation.
  • Audit controls. Hardware, software or procedural mechanisms that record and examine activity in systems containing PHI.
  • Information system activity review. Someone actually reads the logs on a schedule. Access reports, audit logs, security incident tracking.
  • Automatic logoff and session limits. Particularly for remote desks.
  • Authentication. Multi-factor authentication is the baseline expectation in 2026; CISA’s guidance is a good plain-English reference, and HHS has proposed making explicit technical controls of this kind mandatory in an update to the Security Rule.
  • Risk analysis. A documented, accurate assessment of risks to the confidentiality, integrity and availability of PHI, refreshed when things change. HHS’s risk analysis guidance sets out what a real one contains.

A monthly review takes about twenty minutes: pull the access report for each remote user, check volume against expected workload, look for after-hours access and bulk exports, and file the result. Twenty minutes a month is also the evidence that you were monitoring.

Why can nobody be HIPAA certified?

Because there is no certifying authority. HHS does not endorse or recognize certifications issued by private organizations, and no federal program certifies a company as HIPAA compliant. Compliance is an ongoing state that depends on your policies, your controls and what actually happens day to day. A vendor can complete a course, pass a private audit or hold a SOC 2 report, and those can be useful. None of them is a HIPAA certificate, because that is not a real credential.

So when a provider offers a HIPAA certified badge, replace it with a document request:

  1. The signed BAA, unredacted.
  2. The training roster for the assigned staff.
  3. A summary of the most recent risk analysis and remediation status.
  4. The access control model they will apply in your system.
  5. The incident response runbook with named contacts and timelines.
  6. The subcontractor list for anything touching PHI.

AssistBPO staffs healthcare desks with HIPAA-trained staff and a BAA, with per-user logins, least-privilege roles set in your system and no PHI stored on local devices. Assistants are employed, managed staff working your hours. Plans depend on hours, desks and coverage. Get a staffing plan within 1 business day.

What happens when something goes wrong?

Assume it will, and rehearse it. Under the Breach Notification Rule, a business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovery. You then notify affected individuals within 60 days, notify HHS, and notify media where 500 or more residents of a state are affected.

Sixty days is the legal ceiling. Your operational deadline should be much shorter. A practical runbook:

  • Hour 0: the assistant reports the incident to the team lead and to your named contact. Access suspended if needed.
  • Hour 4: scope established. Which records, which users, which window, what was viewed or sent.
  • Day 1: written incident summary to the practice. Preservation of logs and recordings.
  • Day 3: risk assessment on whether the incident is a reportable breach under the four-factor test.
  • Day 10: remediation confirmed, policy or access change made, training refreshed where relevant.

A go-live checklist before the first login

Work through this in order. Nothing below the line starts until everything above it is done.

  • BAA signed by both parties, countersigned copy filed.
  • Subcontractor chain confirmed, with agreements in place.
  • Risk analysis reviewed or refreshed to cover remote administrative access.
  • Role built in the practice management system with minimum necessary permissions.
  • Unique login created per assistant, MFA enforced, no shared credentials.
  • Session timeout and automatic logoff configured.
  • Training roster received, with names, dates and module versions.
  • Confidentiality acknowledgment signed per assistant for your account.
  • Communication channels agreed: where PHI may and may not appear, never in chat or email subject lines.
  • Call recording notice set, and patient identity verified before any detail is discussed.
  • Monthly access review scheduled with a named reviewer at the practice.
  • Incident contacts exchanged on both sides, with phone numbers.
  • Offboarding process agreed: same-day revocation, return or destruction of any data, written confirmation.

Print it, tick it, file it. That file is the answer to almost every question an auditor or a worried patient will ask, and it takes an afternoon to build.

Frequently asked questions

Can a virtual assistant legally access patient records?

Yes, with the paperwork and controls in place first. A virtual assistant company handling scheduling, eligibility, referrals or billing support is a business associate under HIPAA, which means a signed business associate agreement before any access, role-based permissions that follow the minimum necessary standard, documented workforce training, unique logins and audit logging. The rule is not about where the person sits. It is about what is agreed, what they can reach, and whether you can show who looked at what.

Is HIPAA certification a real credential for a virtual assistant company?

No such credential exists. HHS has said plainly that it does not endorse or recognize certifications issued by private organizations, and no federal body certifies a company as HIPAA compliant, so HIPAA certified is not a real status. What you can verify is concrete: a signed BAA, a completed risk analysis, a training record with dates and names, documented access controls, and a breach notification process with defined timelines. Ask for those artifacts instead of a badge.

What is the minimum necessary standard in practice?

It means limiting uses, disclosures and requests for protected health information to the least needed for the job. For a remote front desk that usually looks like this: full access to the appointment book, demographics and insurance fields, read-only access to the treatment plan where scheduling depends on it, and no access to clinical notes, imaging or the wider chart. The standard has exceptions, including disclosures for treatment and disclosures to the patient, but it governs most administrative access.

How quickly must a breach be reported?

A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovering a breach. The covered entity then notifies affected individuals without unreasonable delay and no later than 60 days, notifies HHS, and notifies media where a breach affects 500 or more residents of a state or jurisdiction. Sixty days is the outer limit, not the target. Write a shorter internal deadline into the BAA and name the person who gets the call.

Does a signed BAA make my practice safe if the assistant makes a mistake?

It defines responsibilities and remedies. It does not transfer your obligations. You remain the covered entity, and you are still expected to have done a risk analysis, granted least-privilege access, trained your own workforce and monitored activity. A BAA is one control among several. Think of it as the contract that makes the other controls enforceable: what the business associate must do, what it must report, how fast, and what happens if it does not.

Sources

  1. HHS, HIPAA for Professionals
  2. HHS, Business Associates guidance
  3. HHS, Sample Business Associate Agreement Provisions
  4. HHS, Minimum Necessary Requirement
  5. HHS, HIPAA Security Rule
  6. HHS, Guidance on Risk Analysis
  7. HHS, Breach Notification Rule
  8. CISA, More than a password (multi-factor authentication)

Ask an AI assistant to summarize this page

Related guides

Picked from the same pillar and subject as this one, not from whatever was published last.

Next step

Your desk, staffed. Wherever you are.

Tell us what is overloaded. A named person replies within 1 business day with a staffing plan, and we propose your assistant within 72 hours.

Get a staffing plan Book a 20-minute call

Or call +1-657-777-0006 during US, UK or Australian business hours, or hear our demo receptionist.

  • A named assistant proposed within 72 hours
  • Employed, screened and managed staff, never freelancers
  • Your hours, your tools, your data
Call WhatsApp Staffing plan