If a virtual assistant touches Protected Health Information (PHI), HHS treats them as a Business Associate, and you, the practice, remain the Covered Entity legally responsible for any breach. This checklist walks through every control you need to verify before granting EHR access.
1. Business Associate Agreement (BAA)
- Signed BAA in place before any PHI is shared
- BAA names every downstream subcontractor with PHI access
- BAA includes breach-notification SLA (typically 24-60 hours)
- BAA includes termination + data-destruction clause
2. Workforce Training
- All virtual assistants complete HIPAA training annually
- Training records auditable on demand
- Role-specific training for clinical vs. billing vs. scheduling roles
- Refresher training within 30 days of any regulatory change
3. Access Controls (45 CFR §164.312)
- Unique user accounts (no shared logins) in EHR + phone system
- Role-based access, VAs see only what their job requires
- MFA enforced on all PHI-bearing systems
- Auto-logoff configured (≤15 min idle)
- Account de-provisioning within 24 hrs of staff change
4. Endpoint & Network Security
- VA workstations use full-disk encryption (FileVault, BitLocker)
- Mobile/laptop devices managed (MDM)
- VPN or zero-trust connection for EHR access
- No PHI stored on local drives
- Screen privacy filters for home-office setups
5. Audit Logs
- EHR audit logs reviewed monthly
- Access patterns flagged for after-hours / mass-record access
- Logs retained ≥6 years (HIPAA minimum)
6. Communications
- PHI never sent over SMS or personal email
- Secure messaging platform (Spruce, Klara, EHR-internal)
- E-fax over HIPAA-compliant service
7. Breach Response
- Written incident response plan
- Vendor commits to breach notification within 24-60 hours
- Practice has a designated Privacy Officer
- Tabletop exercise run annually
8. Workstation Physical Security
- VA's work area private (no household members in view of screen)
- No paper PHI printed in home offices
- Background-check + signed confidentiality from each VA
Q&A
Q: Can I share my single EHR login with a virtual assistant? A: No. HIPAA requires unique user identifiers. Shared logins are an automatic finding in any OCR audit.
Q: Is a vendor BAA enough, or do I need one with each individual VA? A: Your BAA is with the vendor (the Business Associate). The vendor is responsible for binding its workforce. Confirm this is documented in the BAA.
Q: What's the cost of a HIPAA violation involving a VA? A: Tier 1 fines start at $137 per violation and scale to $2.13M annual maximum per category (2025 OCR adjustment). Willful neglect uncorrected is $68,928 minimum per violation.
Verify Before You Hire
Virtual Nurse Rx publishes our Security & Compliance overview and provides BAA, training records, and audit logs by default. Take the free risk assessment to surface compliance gaps in your current operation.
This article is general information, not legal advice. Consult qualified healthcare counsel for your practice's obligations.
Related Services
Available Nationwide
Our HIPAA-compliant virtual assistants serve healthcare practices across the United States.
Ready to Transform Your Practice?
Take our free Clinical Operations Risk Assessment™ and get personalized recommendations.
This content is for general information only, not medical, legal, or billing advice. Virtual Nurse Rx provides administrative support only; clinical decisions remain with licensed providers. Results described are individual experiences and are not guaranteed.