We expect you to check this.
You are handing patient data to a team outside your building. That should raise a question, and a vague answer should disqualify us. Here is the specific one.
Your practice remains the covered entity. We are a business associate, which means our obligations are legal, not merely contractual.
Nothing on this page is unusual — it is what HIPAA requires of any business associate. We publish it because most offshore vendors do not, and because the practices worth working with are the ones who ask.
We also work inside your system rather than exporting your data into ours. That is a meaningful architectural difference: there is no second copy of your patient database sitting on our infrastructure.
- We sign a Business Associate Agreement before any PHI is shared. Under HIPAA this is a requirement on your practice, not a courtesy from us, and no work starts without it.
- Your counsel is welcome to review and amend the BAA rather than accept a standard form.
- Defined data ownership: your data is yours, returned in a usable format on termination.
- Encryption in transit and at rest.
- Unique user identification for every agent — no shared logins, ever.
- Role-based access, scoped to the minimum each role needs to do the work.
- Audit logging on records accessed, retained and available for review.
- Automatic session termination on inactivity.
- Access revoked promptly on staff departure, as a documented step in offboarding.
- Documented policies and procedures covering PHI handling.
- Formal HIPAA training and certification for every team member before any access to patient data, with completion records retained.
- A named security officer accountable for the programme.
- A written breach notification procedure with defined timelines.
- Background screening as part of hiring.
- Controlled physical access to the operations floor.
- Clean-desk policy and restrictions on personal devices on the floor.
- Device and media controls, including secure disposal.
Questions any vendor should answer crisply
Use these on us and on anyone else you are evaluating. Vague answers are the signal, not the specifics.
- Will you sign our BAA, and can our counsel amend it?
- Is every user uniquely identified, and can you produce an access log for one patient record?
- How quickly is access revoked when someone leaves your team?
- What is your breach notification timeline, in writing?
- Has any third party assessed your controls?
- What happens to our data when we terminate?
Common questions
Is offshore dental billing HIPAA compliant?
It can be, and ours is built to be. HIPAA does not restrict geography — it restricts how protected health information is handled. A vendor with documented controls is safer than a domestic one without them. What offshore genuinely changes is that cross-border enforcement is harder, so contractual and technical controls carry more weight and deserve more scrutiny. We would rather you scrutinise them.
Will you sign our BAA?
Yes. We are happy to work from your agreement rather than insisting on ours, and your counsel is welcome to amend it.
Can you produce an access log for a specific patient record?
Yes. Audit logging is per-user and per-record, which is the point of not using shared logins.
Do you hold SOC 2 or another third-party certification?
No, and we would rather say so plainly than imply otherwise. We hold no SOC 2 report and no third-party security assessment today. What we do have is specific: every agent completes formal HIPAA training and certification before touching patient data, access is role-based and individually credentialed with no shared logins, work happens inside your own system rather than ours, and the premises are access-controlled. It is also worth knowing that no organisation is officially certified HIPAA compliant by the government — HHS neither endorses nor recognises any HIPAA certification scheme, so a vendor advertising one is describing a private course, not a regulatory status. Judge us on the controls and the BAA, and ask us to evidence any of them.
What happens to our data if we stop working together?
We work inside your practice management system, so your patient data never leaves your environment in the first place. Our access is revoked and any working records we hold are disposed of under the terms of the BAA.
Are calls recorded?
Where calls are recorded for quality scoring, it is disclosed at the start of the call. Several US states require all-party consent and we operate to that standard rather than the minimum.