HIPAA Notice

We are HIPAA-first by design. Here's how we protect patient privacy.

Last updated July 2026

Our commitment

MedAssist takes the privacy and security of protected health information (PHI) seriously. Every virtual assistant we place completes dedicated HIPAA training before working with a US practice, and compliance is reinforced throughout their placement.

No PHI on this platform

This platform does not collect, process, or store patient health information.

Our website and portals handle marketing content, VA applications, training materials, quiz scores, and client account details only. When a virtual assistant performs work involving patients, that work happens inside the client practice's own secure medical systems (such as their EHR) — never on our platform.

Business Associate Agreements

Where a client relationship requires it, we enter into a Business Associate Agreement (BAA) that defines how PHI is safeguarded within the client's systems and the obligations of everyone involved.

Training simulations use fictional data

Our capstone practice simulation uses entirely fictional patients and is clearly labeled "Simulation — Fictional Data" on every screen. No real patient information is ever used for training.

Safeguards

We apply role-based access controls, private file storage with time-limited signed links, and encrypted connections. VAs are trained on the minimum-necessary principle, secure communication, and proper escalation.

Questions

For HIPAA or compliance questions, email hello@medassist.co or call (000) 000-0000.