HIPAA Compliance at VirtualScrivener
There's no official government "HIPAA certified" seal — HHS doesn't issue one, and any badge claiming otherwise should raise a flag. What we can show you instead is exactly what our compliance program does, and why it matters for every service we provide.
What's actually in place
We're your HIPAA Business Associate — and we treat that seriously.
What that means for your practice
A HIPAA Business Associate is an organization that provides a service to a covered entity requiring it to create, store, or disclose Protected Health Information (PHI). VirtualScrivener is a Business Associate. HIPAA sets the standard for how that information must be kept private and secure by everyone who touches it within healthcare — and as a Business Associate, we're required to comply with the same rigor as the covered entities we serve.
Why this distinction gets missed
One of the main challenges with Business Associate compliance is that organizations aren't always aware they're considered a BA under the law. Covered entities have long been conscious of their HIPAA obligations, but business associates historically have not. We're held liable for breaches just the same — so we take every necessary step to guarantee compliance. Being demonstrably HIPAA compliant tells covered entities and patients that we can be trusted to protect their information carefully.
- We execute a valid Business Associate Agreement with every covered entity we work with
- We limit our use or disclosure of PHI strictly to purposes authorized by the covered entity
- We assist covered entities in responding to individual requests concerning their PHI
The eight practices behind every service we run
This is the same checklist we hold ourselves to internally — not marketing copy, but the actual operating discipline behind AI Scribe, Virtual Medical Scribe, Medical Transcription, and Records & Legal Document Support.
- Determine, execute, and comply with valid Business Associate Agreements. Every BAA requires us to maintain the privacy of PHI, limits our use or disclosure of it to purposes the covered entity has authorized, and commits us to helping covered entities respond to individual requests about their PHI.
- Comply with Privacy Rule requirements. We may not use, access, or disclose PHI without the individual's valid, HIPAA-compliant authorization unless an exception applies — and we consult the covered entity before any further operation involving their data.
- Perform Security Rule risk analysis with the HHS-developed SRA tool. We periodically review and update our risk analysis using the Security Risk Assessment tool developed by HHS.
- Implement Security Rule safeguards. We've put in place the specific administrative, technical, and physical safeguards the Security Rule requires, following a checklist built by our in-house HIPAA auditor.
- Maintain written Security Rule policies. As a business associate, we adopt and maintain the written policies the Security Rule requires. Our HIPAA auditor performs periodic checks and keeps records against those policies.
- Respond immediately to any violation or breach. We act at once on any real or potential violation to mitigate unauthorized access to PHI and reduce the risk of HIPAA penalties — prompt action minimizes the chance that data has actually been compromised.
- Report security incidents and breaches on time. We report breaches of unsecured PHI to the covered entity so they can notify individuals and HHS as required; we report any use or disclosure that violates our Business Associate Agreement; and we report security incidents — attempted or successful unauthorized access, use, disclosure, or modification of PHI, or interference with a PHI system.
- Maintain required documentation for six years. We keep the documentation the Security Rule requires for six years from each document's last effective date, and we document additional compliance efforts beyond what's strictly required.
More on HIPAA and AI scribing
Before you adopt any AI or virtual scribe service, HIPAA compliance must be your first question.
A full walkthrough of HIPAA compliance steps, from risk assessment to breach response.
Questions about our compliance program?
Ask to see our BAA template, our risk assessment process, or anything else before you sign up.