Who does your work
Our own employees. Not a subcontracted agency.
The people who would handle your work are recruited, trained, employed and managed by us directly. There is no third-party staffing agency between us and the person doing the job, and nobody is subcontracted out. That is why we can promise you the same named coordinators every day rather than whoever is on shift.
Our clinical lead — a practicing physician — trains that team in person and writes the escalation rules herself. When a call turns clinical, the rule for what happens next was written by someone who has actually taken that call.
Before we start, we check your payer and EHR-vendor contracts for any terms that restrict how your data may be accessed and handled. If something in your agreements blocks how we work, we’ll tell you plainly and we won’t take the work.
In place
What binds from the day you sign.
- In placeBusiness Associate Agreement. Signed before we touch a single record. No exceptions, no pilots without one, no "we will paper it later."
- In placeNamed, unique logins. Every coordinator has their own credentials in your systems. No shared accounts, ever — it’s both a HIPAA audit-trail requirement and a term in most EHR vendor contracts.
- In placeMinimum necessary access. Role-based access to only the parts of your system the job requires. If we are running your fax queue we don’t need your billing module.
- In placeAnnual HIPAA workforce training. Every person who touches your work completes documented HIPAA training, and we retain the records. If your compliance officer asks for evidence, we can produce it.
- In placeNo clinical advice, ever. We never triage, never advise, never suggest a diagnosis or a billing code. Anything clinical goes back to your team the same minute it reaches us. This is a standing rule, not a preference.
- In placeWe never hold your money. Payments go to you. We invoice separately, and we never net a fee out of anything collected — no percentage of collections, no per-appointment fee.
- In placeDisclosed use of automation. Where software assists our coordinators, we tell you, and we default to disclosing it to patients.
Not yet — and we won’t pretend otherwise
We’re a new company. Here’s exactly what we’re still building.
Most vendors leave this list off their website. We think publishing it is the faster way to earn a conversation with someone whose job is to be careful. Everything below has an owner and a date internally, and we’ll show you the current state on a call.
- In progressSecurity Rule risk analysis. A formal written risk analysis is required before we touch a live record, and it will be complete and shared with you before your start date.
- In progressAttorney-reviewed agreements. Our BAA and service agreement templates are being drafted with healthcare counsel. You will see the final documents before you sign anything.
- In progressCyber liability and errors & omissions cover. Quotes are out to four markets. We will name the carrier and the limits before we sign with you, and you will get the certificate.
- In progressWritten escalation and supervision protocol. The documented chain for what a coordinator does when something is out of scope — being written now by our clinical lead.
- In progressWritten data-handling and access assessment. A formal written assessment of how and where your data is accessed by our team. Desk research is complete; the signed document is not.
- In progressIndependent security audit (SOC 2 Type II). Not started. It’s the right thing for a company at scale and we’re not there. Telling you that is better than implying otherwise.
One thing to watch for
Nobody is “HIPAA certified.” Including us.
The US Department of Health and Human Services doesn’t certify anyone as HIPAA compliant, and says so in writing — it doesn’t endorse or recognize private organizations’ certifications, and holding one doesn’t absolve a covered entity of anything.
So if a vendor puts a “HIPAA Certified” badge on their homepage, that badge means a member of their staff paid about thirty dollars for a course. The course is genuinely worth taking — ours do — but it is evidence of training, not a credential. What we say instead is the true version: our staff complete annual HIPAA training and we retain the records.
Send this page to your compliance person.
If they come back with questions we can’t answer, we would genuinely like to know. Call us or put them on the phone with us directly.