HIPAA & Privacy Compliance

Your clients' information is handled with the same care you give your clinical notes.

Therapist’s Assistant is built around one principle: your clients’ protected health information is never ours to use, share, or sell. Every engagement includes a signed Business Associate Agreement, HIPAA-conscious workflows, and access only to what we need to do our job — nothing more.

 

Our Standard

What "HIPAA-conscious" means in practice

A lot of virtual assistants claim to be “HIPAA compliant.” Most aren’t — because compliance isn’t a label, it’s an operating standard. Here’s exactly what we mean when we say it.

 

We operate as your Business Associate

Under 45 C.F.R. §164.504(e), any third party that creates, receives, maintains, or transmits PHI on your behalf is a Business Associate. That’s us. We sign a BAA before any work begins — no exceptions.

 

We apply the Minimum Necessary Rule

We only access the PHI required to perform the specific service you’ve engaged us for. We do not browse records, read clinical notes, or access anything beyond the administrative scope of the task.

 
 

We use HIPAA-conscious tools

Every platform we work in on your behalf — your EHR, scheduling system, inbox — we access through your credentials and within your security settings. We do not introduce third-party tools that touch PHI without your knowledge.

 
 
 

We do not subcontract without protections

If any subcontractor or tool would access PHI on our behalf, they are bound by equivalent BAA obligations before any work begins. Your PHI does not flow downstream unprotected.

 
 
 

We report incidents within 5 business days

If we discover a breach, security incident, or improper use of PHI, we notify you within 5 business days — giving you time to meet your own breach notification obligations under HIPAA.

 
 
 
 

We return or destroy PHI upon termination

When an engagement ends, we return or certifiably destroy all PHI in our possession. We retain no client records. If destruction isn’t feasible, we extend BAA protections indefinitely.

 
 
 
 
 

Transparency

What we access — and what we don't

This table answers the most common question we get from cautious clinicians. Your clients’ clinical content stays yours.

Data Type

We Access This?

Context / Limitation

Client name & contact info

Conditional

Only when needed for scheduling, intake, or correspondence — never retained separately

Appointment schedule

Yes

Core to scheduling and calendar management services

Insurance & billing info

Conditional

Only when engaged for insurance verification or follow-up services

Intake forms & questionnaires

Conditional

Only when engaged for intake coordination; forms collected and handed off to clinician

Clinical session notes

Never

Only when needed for scheduling, intake, or correspondence — never retained separately

Treatment plans & diagnoses

Never

Clinical content; outside our administrative scope entirely

Client email content (clinical)

Never

When managing inboxes, we triage administrative/logistical emails only; clinical communications are flagged and left for the clinician

EHR / practice management platform

Conditional

Only when engaged for EHR workflow support, via clinician-granted access, limited to administrative modules

How We Protect PHI

Three layers of safeguards — as HIPAA requires

HIPAA’s Security Rule (45 C.F.R. §164.308–164.312) requires Business Associates to implement administrative, physical, and technical safeguards for ePHI. Here is what we maintain under each category.

 

📋

Administrative Safeguards

Access to PHI restricted to the minimum necessary for each task. Workforce training on HIPAA requirements before any PHI access is granted. Documented policies for PHI use, disclosure, and incident response. BAA in place before work begins.

 

🏢

Physical Safeguards

PHI not stored on personal or shared devices. Work conducted on password-protected, business-dedicated equipment. No printing or physical storage of client records. Screen locks and session timeouts enforced.

 
 

🔐

Technical Safeguards

Access to your systems only through your clinician-managed credentials. No third-party tools introduced without clinician knowledge and consent. Secure, encrypted channels used for all communications involving PHI (e.g., no unencrypted email for PHI). Session access reviewed and revoked upon engagement end.

 
 

Regulatory References

  • 45 C.F.R. §164.308 — Administrative Safeguards (Security Rule)Access controls, workforce training, incident response, contingency planning
  • 45 C.F.R. §164.310 — Physical Safeguards (Security Rule)Workstation use, device and media controls
  • 45 C.F.R. §164.312 — Technical Safeguards (Security Rule)Audit controls, integrity, transmission security
  • 45 C.F.R. §164.504(e) — Business Associate ContractsRequired provisions in all BAAs between covered entities and business associates
  • 45 C.F.R. §164.410 — Breach Notification by Business Associates

Business Associate Agreement

What our BAA covers — and what it means for your practice

Our Business Associate Agreement is modeled on HHS-recommended BAA language and includes all provisions required under 45 C.F.R. §164.504(e). It is provided as part of your onboarding packet alongside our Services Agreement — no separate legal negotiation required.

 

The BAA specifies exactly how we use and disclose PHI, which safeguards we maintain, how subcontractors are handled, what happens in the event of a breach, and how PHI is returned or destroyed at the end of the engagement. It gives your practice a documented compliance record that covers our entire working relationship.

 

Every service tier — Essential, Practice Support, and Full Support — includes a signed BAA. HIPAA compliance is not an add-on; it is the baseline.

📄

Review Our BAA

Request a sample of our BAA language before your consultation. Transparency is part of how we operate.

Our Commitments

What we never do — ever

These are hard lines, not preferences. No exceptions, no workarounds.

 

Sell client data

PHI is never sold, monetized, or shared with any third party for commercial purposes — under any circumstances.

Use PHI for marketing

Your clients' information is never used to market our services or anyone else's — no retargeting, no analytics, no data brokering.

Access clinical content

Session notes, treatment plans, diagnoses, and psychotherapy notes are outside our scope. We do not open, read, or interact with clinical documentation.

Store PHI after engagement ends

Upon termination of services, all PHI in our possession is returned or destroyed. We retain no records. Period.

Introduce unauthorized tools

We do not connect third-party apps to your systems without your explicit knowledge and consent — no integrations, no automations you haven't approved.

Subcontract PHI access without protections

Any subcontractor requiring PHI access must have a BAA in place. Your compliance chain does not have gaps.

Platforms & Tools

We work inside your systems — not ours

We do not require you to adopt new software. We operate within the HIPAA-conscious platforms you already use, via your credentialed access, under your security settings.

 

EHR / Practice Mgmt

SimplePractice

Scheduling, intake forms, documentation workflow support
 

EHR / Practice Mgmt

TherapyNotes

Client records, billing, scheduling, clinical documentation
 
 

EHR / Practice Mgmt

TheraNest

Practice management, billing, scheduling workflows
 
 

EHR / Practice Mgmt

Jane App

Scheduling, intake, billing coordination
 
 

Scheduling

Acuity / Calendly

Client-facing appointment booking with BAA where applicable
 
 

Communication

HIPAA-Compliant Email

Hushmail, Google Workspace (with BAA), or your existing platform
 

Don’t see your platform? We work with most major EHRs and practice management systems. Bring your current stack to the consultation — we’ll confirm compatibility before any agreement is signed.

Common Questions

HIPAA questions therapists ask us

Is Therapist's Assistant HIPAA compliant?
Therapist’s Assistant operates as a Business Associate under HIPAA, meaning we are legally required to comply with HIPAA’s Privacy, Security, and Breach Notification Rules wherever we handle PHI. We sign a Business Associate Agreement with every client before any work begins, and we apply HIPAA-conscious workflows to every service we deliver.
 
Yes. If your virtual assistant creates, receives, maintains, or transmits protected health information on your behalf — including scheduling, intake, or inbox management — they are a Business Associate under 45 C.F.R. §160.103 and a BAA is legally required. Therapist’s Assistant includes a signed BAA with every engagement.
 
 
No. Clinical session notes, treatment plans, diagnoses, and psychotherapy notes are entirely outside the scope of our administrative services. We do not access, read, or interact with clinical content under any circumstances. Our access is limited to the administrative information required to perform the specific service engaged.
 
 
Upon termination of our engagement, we return or certifiably destroy all PHI in our possession. We retain no client records after the relationship ends. If return or destruction is not feasible for a specific reason, we extend BAA-level protections to any retained PHI indefinitely.
 
 
We are required under our BAA and HIPAA’s Breach Notification Rule (45 C.F.R. §164.410) to notify you of any breach or security incident without unreasonable delay. Our internal standard is within 5 business days of discovery — well ahead of HIPAA’s 60-day maximum — so you have time to meet your own notification obligations to affected individuals.
 
 
Technically yes, but it creates real compliance risk. General VAs rarely have HIPAA training, typically won’t sign a BAA, and may use tools that are not appropriate for PHI. If they access scheduling systems, intake forms, or client emails — even incidentally — they are a Business Associate. Without a BAA, you are out of compliance and your practice bears the liability.
 
 
Yes. The BAA covers all services Therapist’s Assistant provides — inbox management, scheduling, client intake coordination, insurance follow-up, EHR workflow support, and practice consulting — to the extent those services involve PHI. It applies regardless of which service tier you are on.
 
 
Yes. As a Business Associate, Therapist’s Assistant is required under 45 C.F.R. §164.504(e) to make its practices, books, and records available to the Secretary of HHS for compliance audits. Covered Entities can request this access, and regulators can require it directly.
 
 

Ready to work with an admin partner who takes compliance seriously?

Book a free 30-minute consultation. We’ll walk through your practice’s workflow, confirm how we handle your specific systems, and answer any compliance questions before you sign anything.