Every clinic reaches the same point eventually. The front desk is drowning, prior authorizations are stacking up, and someone suggests outsourcing the administrative load.
Then the compliance question lands. The moment an outside person can see a chart, a schedule or an insurance record, your practice has taken on a business associate, and the paperwork behind that relationship is now part of your risk profile.
Here is the part most buyers get wrong. "HIPAA compliant" is a claim a vendor makes about itself. It is not, on its own, evidence of anything.
Key Takeaways
- HIPAA compliance is largely self-attested. Independent audits are what turn a claim into evidence.
- A signed Business Associate Agreement is mandatory, but it is a contract, not proof that controls work.
- SOC 2 Type II tests whether controls operated over months. Type I only checks how they looked on one day.
- ISO 27001 certification signals a documented, externally reviewed security programme rather than an improvised one.
- Ask for the audit documentation before the demo, not after the contract.
Why "HIPAA Compliant" Stopped Ending the Conversation
HIPAA sets the federal floor for protecting patient health information in the United States. Any vendor handling charts, scheduling, eligibility checks or claims has to sign a BAA and apply the Privacy, Security and Breach Notification Rules.
That part is not optional. It is also not verified by anyone unless the vendor submits to an outside audit.
A company can write policies, train staff and describe safeguards in a sales deck without a single third party ever checking whether those safeguards hold up on a Tuesday afternoon in month nine. That gap is exactly where compliance officers now focus their questions.
The useful shift is simple. Stop asking whether a vendor is HIPAA compliant and start asking what independent evidence they can produce, and when it expires.
The Three Layers Worth Understanding
The BAA. Required under the HIPAA rules, this contract defines permitted uses of patient data, required safeguards, breach notification timelines, subcontractor obligations and termination rights. A vendor who hesitates here has answered your question.
SOC 2. Developed by the AICPA, it evaluates a service organisation across five Trust Services Criteria: security, availability, processing integrity, confidentiality and privacy. Type I is a design snapshot taken on a single date. Type II tests whether those controls actually operated across a window of several months, with an auditor pulling logs, sampling access records and reviewing incidents.
ISO 27001. The international standard for an Information Security Management System, certified by an accredited body and reviewed on an ongoing basis. For a domestic clinic it may sound like an overseas concern, but it signals something practical: the security programme is documented, managed and inspected by someone who does not work there.
Seven Things to Ask For Before Granting Access
-
A BAA that covers the full delivery chain. Downstream contractors need agreements too. Ask the vendor to map who touches what.
-
A current SOC 2 report, with the type stated plainly. "In progress" and "we follow SOC 2 principles" are not the same thing as a report you can hand your auditor.
-
An ISO 27001 certificate with its scope attached. A certificate that excludes the service line you are buying will not help you during a review.
-
A description of where patient data lives and moves. Which systems the assistant touches, what they can view, what they can download and what persists afterwards.
-
Encryption specifics, in writing. At rest and in transit, with the standards named rather than gestured at.
-
Access logging and revocation process. Least privilege at the start, documented approval, and prompt removal when a role changes.
-
Continuity cover. What happens when your assistant is sick, on leave or leaves entirely. Compliance gaps often open during unplanned handovers.
A vendor that answers all seven with documents and dates is operating at the level you want. One that pivots back to "our staff are HIPAA trained" has not answered.
What Compliant Coverage Looks Like Day to Day
The evidence matters most when you can see it attached to real work rather than a landing page.
Take front desk coverage, which is usually the first thing a clinic hands over. Wing Assistant runs this as a managed virtual receptionist healthcare service, handling patient schedules, appointment confirmations and reschedule requests directly inside systems such as Epic, Athenahealth and Kareo.
The same assistant can extend into medical admin and EMR updates, intake form preparation, insurance claim processing, coverage verification, lab coordination, provider messages and visit notes. The point is not breadth for its own sake. It is that one trained person inside your workflow beats four partial handoffs.
Behind the assistant sits the layer that actually matters for compliance. The company publishes ISO 27001 compliance, SOC 2 certification and HIPAA compliance with a signed BAA on every healthcare engagement, and will provide SOC 2 and ISO 27001 documentation for vendor security reviews on request.
Data handling is specified rather than implied. Information is encrypted in transit using SSL with 2048-bit certificates and at rest using AES-256, device identity is authenticated on every request, and any access to identifiable information is logged and flagged for audit when behaviour looks unusual.
Practical structure rounds it out. Assistants are dedicated to your practice during the hours you choose, replacements are free, a Customer Success Manager owns the account, and NDAs plus tailored healthcare policies sit alongside the BAA.

What the Coverage Costs
Published pricing helps here, because vague quotes tend to hide scope problems.
The healthcare plans run at $1,099 a month for part-time cover at 80 hours and $1,799 a month for full-time at 160 hours. Both include a dedicated assistant, free replacement, a Customer Success Manager, quality control and supervision, and access to the Wing Workspace app.
The difference sits in the details. Full-time includes unlimited file sharing and storage, while the part-time tier caps storage at 10 GB. Billing terms are flexible, with monthly, annual or customised schedules available.
For most clinics the comparison is against a fully loaded domestic hire once salary, payroll taxes, benefits, recruitment and turnover are counted. The published claim is up to 80 percent lower monthly admin costs.
Documentation Discipline Pays Off Twice
Here is the benefit practices rarely anticipate. The habits that satisfy a security auditor also fix problems elsewhere in the practice.
Consistent EMR entry, complete intake records and reliable documentation are the same inputs that quality programmes depend on. Anyone who has rebuilt a year of evidence in the final weeks of a reporting period knows how expensive sloppy capture becomes, which is why MIPS reporting workflows reward clinics that document as they go rather than reconstructing after the fact.
A trained administrative assistant working to a defined process improves both at once. You get cleaner data for reporting and a cleaner audit trail for compliance, from the same hours you were already paying for.
The Line Nobody Should Cross
One boundary is worth stating plainly, because it protects patients as much as the practice.
A medical virtual assistant handles administration. Scheduling, intake coordination, insurance verification, claims support, records, referrals, reminders and documentation all sit comfortably inside that scope.
It does not assess symptoms, judge urgency, offer reassurance about a health concern or make any clinical decision. Those belong to your licensed clinicians without exception.
The usual failure is not carelessness. It is warmth. A helpful assistant wants to settle an anxious caller, and saying "that sounds like nothing to worry about" is a clinical statement. Make escalation the default and train the instinct out before anyone speaks to a patient.
Bringing It Together
Compliance in 2026 is not a checkbox on a vendor's homepage. It is a stack, and each layer answers a different question.
The BAA establishes obligations. SOC 2 Type II shows the controls worked over time. ISO 27001 shows the security programme is managed and inspected. Encryption, logging and least-privilege access show it reaches the actual desk where your patient data is handled.
Ask for the evidence early, read the scope, and check the dates. A partner with the full stack will send the package without friction. That response alone tells you most of what you need to know.
Frequently Asked Questions
Is HIPAA compliance alone enough when outsourcing patient data work?
HIPAA is mandatory and remains the legal floor, but it is largely self-attested. Independent evidence such as a SOC 2 report and an ISO 27001 certificate is what allows your compliance team to defend the decision later.
What is the difference between SOC 2 Type I and Type II?
Type I confirms controls were designed appropriately on one specific date. Type II tests whether those controls actually operated effectively across a monitoring window of several months, which is why it carries more weight for ongoing access to patient data.
Does ISO 27001 matter for a clinic that only operates in the United States?
It is not a legal requirement, but it indicates the vendor runs a documented, externally certified security programme that is reviewed on a schedule rather than maintained informally. That raises the baseline regardless of geography.
How much does a HIPAA-compliant medical virtual assistant cost?
It depends on hours and scope. As a live reference point, published healthcare plans run $1,099 a month for 80 hours and $1,799 a month for 160 hours, with a dedicated assistant, free replacement and account management included.
What can a medical virtual assistant not do?
It cannot triage symptoms, assess urgency, give clinical advice or make diagnostic and treatment decisions. Administrative work moves across, while every clinical judgment stays with your licensed clinicians.