HIPAA Notice
We are HIPAA-first by design. Here's how we protect patient privacy.
Last updated July 2026
Our commitment
MedAssist takes the privacy and security of protected health information (PHI) seriously. Every virtual assistant we place completes dedicated HIPAA training before working with a US practice, and compliance is reinforced throughout their placement.
No PHI on this platform
This platform does not collect, process, or store patient health information.
Our website and portals handle marketing content, VA applications, training materials, quiz scores, and client account details only. When a virtual assistant performs work involving patients, that work happens inside the client practice's own secure medical systems (such as their EHR) — never on our platform.
Business Associate Agreements
Where a client relationship requires it, we enter into a Business Associate Agreement (BAA) that defines how PHI is safeguarded within the client's systems and the obligations of everyone involved.
Training simulations use fictional data
Our capstone practice simulation uses entirely fictional patients and is clearly labeled "Simulation — Fictional Data" on every screen. No real patient information is ever used for training.
Safeguards
We apply role-based access controls, private file storage with time-limited signed links, and encrypted connections. VAs are trained on the minimum-necessary principle, secure communication, and proper escalation.
Questions
For HIPAA or compliance questions, email hello@medassist.co or call (000) 000-0000.