First, the honest scope

SS Support Network is a business process outsourcing company, not a law firm or a certification body. There is no official "HIPAA certified" stamp any vendor can legitimately hold — so we don't claim one. What we can claim, and back up, is that every healthcare engagement runs on HIPAA-compliant processes: trained people, signed agreements, controlled access, and logged activity. If a prospective vendor tells you they're "HIPAA certified," ask them who issued the certificate.

What that looks like in practice

  • HIPAA-trained agents. Every agent completes HIPAA privacy and security training before joining a healthcare account, with refresher training thereafter — including the minimum-necessary rule for handling calls and records.
  • Business Associate Agreement. A BAA is available and expected on any engagement involving PHI. It's part of standard onboarding, not something you have to push for.
  • Role-based access. Agents get access only to the systems their role requires, under individual named credentials you control. Dispatchers don't see billing; billers don't see what they don't need.
  • Audit logging. Work happens inside your software, so every action is attributable to a named person and visible to you. We add our own QA reviews on top.
  • Secure connections. Access to your systems runs over secured, encrypted connections. Your data stays in your systems — we don't copy patient databases onto our own servers.
  • Offboarding discipline. When an agent rotates off your account, their credentials are removed the same day. Access reviews catch anything that lingers.

Why working inside your software matters

Most of our security posture comes from a structural decision: we work inside your platforms — dispatch software, billing system, phone system, broker portals — instead of pulling your data into ours. That means you keep ownership, you keep visibility of every trip and claim, and revoking access is as simple as disabling a login. It also means there's no second copy of your patient data sitting in a vendor's database waiting to become a problem.

Broker and payer expectations

Brokers like Modivcare, MTM, and Access2Care hold providers to documentation and privacy standards of their own, and our agents work with those requirements daily. We are an independent company and not affiliated with or endorsed by any broker or software vendor — we simply know their rules because we operate under them on behalf of clients every day.

This page describes our operating practices. It is not legal advice — for questions about your own obligations under HIPAA or state law, talk to a qualified healthcare attorney.