HIPAA & Privacy Compliance
Your clients' information is handled with the same care you give your clinical notes.
Therapist’s Assistant is built around one principle: your clients’ protected health information is never ours to use, share, or sell. Every engagement includes a signed Business Associate Agreement, HIPAA-conscious workflows, and access only to what we need to do our job — nothing more.
- BAA Included with Every Engagement
- Minimum Necessary Rule Applied
- Apple Valley, CA · Serving Therapists Nationwide

- 🔒 PHI handled under signed BAA
- 📋 HHS-aligned BAA language
- 🛡️ Minimum necessary access only
- ⚡ 5-business-day breach notification
Our Standard
What "HIPAA-conscious" means in practice
A lot of virtual assistants claim to be “HIPAA compliant.” Most aren’t — because compliance isn’t a label, it’s an operating standard. Here’s exactly what we mean when we say it.
We operate as your Business Associate
Under 45 C.F.R. §164.504(e), any third party that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate. That’s us. We sign a BAA before any work begins — no exceptions.
We apply the Minimum Necessary Rule
We only access the PHI required to perform the specific service you’ve engaged us for. We do not browse records, read clinical notes, or access anything beyond the administrative scope of the task.
We use HIPAA-conscious tools
Every platform we work in on your behalf — your EHR, scheduling system, inbox — we access through your credentials and within your security settings. We do not introduce third-party tools that touch PHI without your knowledge.
We do not subcontract without protections
If any subcontractor or tool would access PHI on our behalf, they are bound by equivalent BAA obligations before any work begins. Your PHI does not flow downstream unprotected.
We report incidents within 5 business days
If we discover a breach, security incident, or improper use of PHI, we notify you within 5 business days — giving you time to meet your own breach notification obligations under HIPAA.
We return or destroy PHI upon termination
When an engagement ends, we return or certifiably destroy all PHI in our possession. We retain no client records. If destruction isn’t feasible, we extend BAA protections indefinitely.
Transparency
What we access — and what we don't
This table answers the most common question we get from cautious clinicians. Your clients’ clinical content stays yours.
Data Type
We Access This?
Context / Limitation
Client name & contact info
Conditional
Only when needed for scheduling, intake, or correspondence — never retained separately
Appointment schedule
Yes
Core to scheduling and calendar management services
Insurance & billing info
Conditional
Only when engaged for insurance verification or follow-up services
Intake forms & questionnaires
Conditional
Only when engaged for intake coordination; forms collected and handed off to clinician
Clinical session notes
Never
Only when needed for scheduling, intake, or correspondence — never retained separately
Treatment plans & diagnoses
Never
Clinical content; outside our administrative scope entirely
Client email content (clinical)
Never
When managing inboxes, we triage administrative/logistical emails only; clinical communications are flagged and left for the clinician
EHR / practice management platform
Conditional
Only when engaged for EHR workflow support, via clinician-granted access, limited to administrative modules
How We Protect PHI
Three layers of safeguards — as HIPAA requires
HIPAA’s Security Rule (45 C.F.R. §164.308–164.312) requires Business Associates to implement administrative, physical, and technical safeguards for ePHI. Here is what we maintain under each category.
📋
Administrative Safeguards
Access to PHI restricted to the minimum necessary for each task. Workforce training on HIPAA requirements before any PHI access is granted. Documented policies for PHI use, disclosure, and incident response. BAA in place before work begins.
🏢
Physical Safeguards
PHI not stored on personal or shared devices. Work conducted on password-protected, business-dedicated equipment. No printing or physical storage of client records. Screen locks and session timeouts enforced.
🔐
Technical Safeguards
Access to your systems only through your clinician-managed credentials. No third-party tools introduced without clinician knowledge and consent. Secure, encrypted channels used for all communications involving PHI (e.g., no unencrypted email for PHI). Session access reviewed and revoked upon engagement end.
Regulatory References
- 45 C.F.R. §164.308 — Administrative Safeguards (Security Rule)Access controls, workforce training, incident response, contingency planning
- 45 C.F.R. §164.310 — Physical Safeguards (Security Rule)Workstation use, device and media controls
- 45 C.F.R. §164.312 — Technical Safeguards (Security Rule)Audit controls, integrity, transmission security
- 45 C.F.R. §164.504(e) — Business Associate ContractsRequired provisions in all BAAs between covered entities and business associates
- 45 C.F.R. §164.410 — Breach Notification by Business Associates
Business Associate Agreement
What our BAA covers — and what it means for your practice
Our Business Associate Agreement is modeled on HHS-recommended BAA language and includes all provisions required under 45 C.F.R. §164.504(e). It is provided as part of your onboarding packet alongside our Services Agreement — no separate legal negotiation required.
The BAA specifies exactly how we use and disclose PHI, which safeguards we maintain, how subcontractors are handled, what happens in the event of a breach, and how PHI is returned or destroyed at the end of the engagement. It gives your practice a documented compliance record that covers our entire working relationship.
Every service tier — Essential, Practice Support, and Full Support — includes a signed BAA. HIPAA compliance is not an add-on; it is the baseline.
📄
Review Our BAA
Request a sample of our BAA language before your consultation. Transparency is part of how we operate.
Our Commitments
What we never do — ever
These are hard lines, not preferences. No exceptions, no workarounds.
Sell client data
PHI is never sold, monetized, or shared with any third party for commercial purposes — under any circumstances.
Use PHI for marketing
Your clients' information is never used to market our services or anyone else's — no retargeting, no analytics, no data brokering.
Access clinical content
Session notes, treatment plans, diagnoses, and psychotherapy notes are outside our scope. We do not open, read, or interact with clinical documentation.
Store PHI after engagement ends
Upon termination of services, all PHI in our possession is returned or destroyed. We retain no records. Period.
Introduce unauthorized tools
We do not connect third-party apps to your systems without your explicit knowledge and consent — no integrations, no automations you haven't approved.
Subcontract PHI access without protections
Any subcontractor requiring PHI access must have a BAA in place. Your compliance chain does not have gaps.
Platforms & Tools
We work inside your systems — not ours
We do not require you to adopt new software. We operate within the HIPAA-conscious platforms you already use, via your credentialed access, under your security settings.
EHR / Practice Mgmt
SimplePractice
EHR / Practice Mgmt
TherapyNotes
EHR / Practice Mgmt
TheraNest
EHR / Practice Mgmt
Jane App
Scheduling
Acuity / Calendly
Communication
HIPAA-Compliant Email
Don’t see your platform? We work with most major EHRs and practice management systems. Bring your current stack to the consultation — we’ll confirm compatibility before any agreement is signed.
Common Questions
HIPAA questions therapists ask us
Is Therapist's Assistant HIPAA compliant?
Do I need a BAA with my virtual assistant?
Will my virtual assistant see my clients' clinical notes?
What happens to client information when I stop working with you?
What if there is a data breach?
Can I use a general virtual assistant for my therapy practice?
Does the BAA cover all of your services?
Are you required to respond to HHS audits?
Ready to work with an admin partner who takes compliance seriously?
Book a free 30-minute consultation. We’ll walk through your practice’s workflow, confirm how we handle your specific systems, and answer any compliance questions before you sign anything.