Skip to content

We are a business associate when we create, receive, maintain, or transmit PHI for a covered-entity practice. The BAA is signed first. The chart comes second.

Last updated2026-09-02

Why a BAA is required

Under HIPAA, a vendor that handles PHI for a provider is a business associate. Documentation specialists, medical coders, QA reviewers, and prior-authorization coordinators all sit in that category. A Business Associate Agreement is required before PHI is disclosed to us — not after the first chart, and not as a PDF attached to a welcome email once work has already started.

Most general virtual-assistant shops cannot sign a BAA. We provide one. Until it is executed, we will not take remote EMR access, file drops, or sample charts.

What the BAA is for

The BAA sets the permitted uses of PHI: performing the contracted documentation, coding, QA, and authorization work, and disclosures required by law. It requires safeguards aligned with the Security Rule, breach notification to the covered entity, downstream BAAs with any subcontractor that would see PHI, and return or destruction of PHI when the relationship ends.

This page is an explanation. It is not the BAA. The signed agreement controls.

How PHI is handled on the floor

Access is provisioned per practice, on a need-to-know basis, with multi-factor authentication. Specialists are matched to one specialty at a time. They sign confidentiality terms and complete HIPAA training. Devices used for the work follow our device-security requirements. We do not put PHI on this marketing site, in public email threads, or into tools that are not covered by a BAA.

If a security incident involves a practice’s PHI, we notify that practice as the BAA requires — not later than the HIPAA outer limit of 60 days from discovery, and faster when the agreement says so.

What not to send here

The contact form, the public inbox, and this website are not authorized channels for PHI. Do not paste notes, claims, patient identifiers, or screenshots of a chart. Ask for the security overview if you need the control list, where data sits, and who can reach it. Then we execute the BAA and open the contracted channel.