Trust Center
How We Protect Your Data — Stated Plainly
Healthcare and payment data raise the stakes. This page lays out exactly what we do to protect it, what agreements we sign, and what we honestly can and cannot claim. If a compliance reviewer needs it, everything here is designed to be forwarded.
The controls
What's in place before we touch anything
HIPAA-trained agents
Every agent completes HIPAA training before touching client work, and we follow HIPAA-compliant processes for handling protected health information.
Signed BAA
A Business Associate Agreement is signed with every healthcare client, defining safeguards, permitted uses, and breach-notification duties before any PHI is handled.
Role-based, logged access
Agents access only what their role requires, inside your systems, with activity logged. We work in your platforms rather than copying data into a parallel one.
Documented incident process
Contain, assess, notify your contact promptly, and support your BAA's breach-notification timeline. We never conceal an incident.
AI used honestly
Automation is disclosed, never makes clinical decisions, and PHI is not fed to third-party AI tools without your written approval and a compliant data path.
Reviewable by your team
We provide a one-page trust summary and complete reasonable security questionnaires as part of your due diligence. Ask and we'll send it.
An honest note on certifications. You will see competitors advertise a "HIPAA certified" badge. There is no official HIPAA certification for BPO vendors, so that claim is marketing, not a credential. We would rather show you the actual controls above and sign a BAA than wave a badge that does not exist. If a specific attestation (such as SOC 2) becomes part of our program, we will state it here with its scope and date, never before.
Compliance questions
What your reviewer will ask
Yes. We sign a BAA with every healthcare client before any protected health information is handled. The BAA defines permitted uses, safeguards, breach-notification duties, and subcontractor obligations under HIPAA.
No vendor can be, because there is no official HIPAA certification program for BPO companies. Any company claiming a "HIPAA certified" stamp is overstating. What we can show is real: HIPAA training for every agent, HIPAA-compliant processes, a signed BAA, and role-based access with logging.
Your data stays inside your own systems; we work in them under role-based, logged access rather than copying data into a parallel platform. SS Support Network is a US-registered company with a 24/7 global delivery team, and every agent is HIPAA-trained before touching client work.
We follow a documented incident process: contain, assess scope, notify your designated contact promptly, and support the breach-notification timeline your BAA requires. We never conceal an incident.
Any automation we use is disclosed and never makes clinical decisions. Protected health information is not fed into third-party AI tools without your written approval and a compliant data path. Humans handle judgment; tools handle repetition.
Yes. Ask for our one-page trust summary covering controls, training, access, and escalation, and we will complete a reasonable security questionnaire as part of your due diligence.
Need something specific for procurement? Request our trust summary or call +1 (657) 777-0006.