The one-sentence version

No agent touches protected health information until they are trained on HIPAA, a Business Associate Agreement is in place, and their access has been scoped to exactly what their role requires, and everything they do after that is attributable and reviewable.

Training: before access, not after

HIPAA training happens before an agent joins a healthcare account, full stop. It covers the privacy and security rules in working terms: what counts as PHI, the minimum-necessary standard, how to verify a caller before discussing patient details, what may and may not go into a text or chat message, and when to stop and escalate. Because our agents answer phones, work dispatch boards, and process claims, the training is scenario-based: real situations from real accounts, not a slideshow and a quiz. Refresher training recurs on a set schedule, and every new client engagement adds a layer: your protocols, your escalation contacts, your rules. Our agents aren't generalists dropped onto a healthcare account. They're experienced across NEMT, healthcare, and home care operations, and they communicate in clear, professional English.

The BAA: signed before PHI flows

A Business Associate Agreement defines what we're permitted to do with PHI, the safeguards we maintain, how subcontractors would be handled, and how quickly we notify you if anything is ever suspected. We sign yours or provide ours. Either way, it's in place before work begins, as a standard part of onboarding.

Access: least privilege, named accounts

Agents work inside your systems under individual credentials that you issue and can revoke at any time. Access is scoped by role: a dispatcher sees the dispatch board, a biller sees the billing system, and nobody gets a master login "just in case." When someone rotates off your account, their access is removed the same day, and periodic reviews catch anything that lingers. Shared team logins are not allowed on healthcare accounts, because an audit trail is only useful if every entry has a name on it.

Where the work happens, and where your PHI stays

SS Support Network is a US-registered company headquartered in Vancouver, Washington, and we staff accounts with a combined US and overseas delivery team. We say that plainly, because "is my patients' information going offshore?" is a fair question every healthcare buyer should ask. The honest answer is that the standard doesn't change with geography: every agent on your account, wherever they sit, works under the same Business Associate Agreement, the same signed confidentiality agreement, the same HIPAA training, and the same named, role-scoped credentials.

Where your PHI actually lives matters just as much. Because our agents work inside your systems (your EHR, your dispatch platform, your phone system, your billing software) protected health information stays in your systems of record. We don't migrate your data into a separate SS Support Network platform, and there's no parallel copy of your patient database on our side. Agents follow the minimum-necessary standard and your own handling rules, under your logins, so your own logs show every action. If a specific engagement requires tighter geographic limits, tell us during the audit and we scope the account to meet it.

Security, owned at the leadership level

Data protection isn't a box we tolerate at SS Support Network. It's a discipline our leadership owns directly. Our security approach is led by a founder with senior cybersecurity expertise, and that shapes how every account is run: least-privilege named access, disciplined credential handling, work performed inside your own systems and monitoring, and regular review of who can see what. For a healthcare business handing over patient information, it means the people setting our security standards treat protecting your data, and your patients' information, as a core competency, not a compliance afterthought.

If something ever goes wrong

Our incident process is contain, assess, notify, correct. The moment an agent suspects a privacy issue (a misdirected fax, a caller who couldn't be verified, an access anomaly) it escalates to our compliance lead, the access in question is contained, and we assess what information was involved. You're notified promptly under the BAA's terms with a written account, and the fix is documented: retraining, tightened access, or a changed procedure. You will never discover an issue before we've told you about it.

Subcontractors: the short answer is "your approval first"

Your account is delivered by our own trained team. HIPAA permits business associates to use subcontractors only under a downstream BAA; our own bar is higher. Any such arrangement would also require your written approval before it happens. In practice, that conversation almost never needs to occur, because the work stays in-house.

A necessary note: this page describes SS Support Network's operating practices and is not legal advice. Your own HIPAA obligations depend on your role, your state, and your contracts. For those questions, consult a qualified healthcare attorney.