Leadership
Syed Shahzaib Shah
Founder and chief executive of SS Support Network LLC, and a cybersecurity researcher whose disclosure work has been covered by HackerNoon, Cybersecurity News, GBHackers and The Hack Post. He sets how this company handles other people's patient data, and he writes the compliance guides on this site.
Background
Syed Shahzaib Shah, who also publishes as Shahzaib Shah, founded SS Support Network LLC in 2020 and runs it as chief executive. He was born on 1 August 2000 and is Pakistani. Before the company existed he was already working in security research, and that came first in a way that still shows in how the business is built.
His field is coordinated vulnerability disclosure. In plain terms: find a flaw in a system you are allowed to test, report it privately to the people who own it, and give them time to fix it before anyone else hears about it. He has done that work against large technology platforms and against government systems, and it has been written up by five independent outlets.
It is a discipline that rewards one specific habit. Read the specification. Test what the system actually does rather than what its documentation claims. Report what you found, not what would sound better. That is an awkward habit in a sales conversation and a useful one in a company that handles protected health information for a living.
What that means for how this company runs
Most back offices treat security as a page on the website. Here it is the thing the founder does with the rest of his time, so the claims on this site are written to be checked rather than believed.
Every regulatory statement in our knowledge base links to the text of the rule at Cornell LII, the eCFR, the Federal Register, NIST or the OCR breach portal. A compliance reviewer can verify any of it in the time it takes to click. Where a rule is proposed rather than in force, the page says so, with the docket number and the projected date, because the difference matters and most vendor content blurs it.
The same standard applies to claims about us. SS Support Network holds no SOC 2 report and no HIPAA certification, and no HIPAA certification exists for anyone to hold; HHS has said so since 2003. Our trust center states both plainly, alongside the controls we do run and how you can verify them. If that changes we will publish the scope and the date. Not before.
Companies
What he leads
One operation, three registered companies. Knowing which entity does what is the difference between a contract that holds and one that doesn't.
SS Support Network LLC
The US company, registered in Vancouver, Washington. It holds the client contracts and signs the business associate agreement, so this is the entity a covered entity is contracting with and the one carrying direct liability under HIPAA. Founded 2020 by Shahzaib as CEO and Nimra Khalid as co-founder and COO.
SS Support Network Pvt Ltd
The Pakistan-registered back office, and where most of the delivery team sits. Registering the offshore side as a real company rather than running it as loose contractors is what makes the workforce clauses in a BAA enforceable: employment contracts, confidentiality terms and disciplinary process all attach to an entity that exists.
Transport BPO
A separate transportation-focused operation at transportbpo.com, serving NEMT providers and trucking dispatch. Shahzaib is CEO and Nimra Khalid is co-founder and COO there as well, which is why dispatch practice moves between the two companies quickly.
Independent coverage
Where his security work has been written about
Five pieces, none of them ours. We link them so you can read what other people said rather than what we would say about ourselves.
What a client actually gets from it
A founder with a security background is only worth something if it reaches the floor. These are the places it does.
- Access is scoped per account. An agent sees the client they are assigned to and nothing else, including no contact details for any other client.
- Nobody on the delivery floor can delete a record. Corrections are made by adding to the history, so the trail of what happened stays intact.
- Downloads are logged with the person, the file and the time, because "who took a copy of this" is the first question after any incident and the worst time to find out you can't answer it.
- Patient identifiers are encrypted in the database, not just behind a login, so a stolen backup isn't the same thing as a stolen record.
- Two-step verification is on by default for every account rather than offered as an option people decline.
- Our claims carry citations. Where we can't prove something, the page says we can't, which is the part most vendors leave out.
None of this is unusual for a company that takes security seriously. It is unusual for a back office priced like ours, and that is the actual point.
Written by him
Compliance guides by Syed Shahzaib Shah
What protected health information a healthcare and NEMT back office really touches, and what the rules require of the people handling it.
Credentialing & Compliance
NEMT Patient Data Security: What One Trip Record Exposes
A single trip record hits most of the 18 HIPAA identifiers at once. What is actually on a dispatch screen, and where it l…
Credentialing & Compliance
What a HIPAA BAA Actually Obligates, Clause by Clause
The ten clauses the regulation requires, what direct liability changed in 2013, and the nine questions to ask before sig…
Credentialing & Compliance
16 Security Questions to Ask a Healthcare BPO
Sixteen questions about PHI handling, each with the answer that should worry you and the answer that should reassure yo…
Credentialing & Compliance
How a Remote or Offshore Team Handles PHI Properly
HIPAA has no residency rule. CMS and several state Medicaid contracts do. Here is the control set either way.
Talk to us about your operation
Tell us what you run and what is breaking. You will get a straight answer about whether we are a fit, including when we aren't.