Clutch 2026 Top Virtual Assistant Company · Top Medical Billing Company · Managed Virtual Medical Assistants

HIPAA-Trained Is Not HIPAA-Compliant: The BAA Loophole That Leaves You Exposed

Published: By:
Healthcare administrator reviewing a Business Associate Agreement contract at a desk, with a HIPAA compliance folder and medical records visible

If the virtual assistant agency you're evaluating told you their staff is "HIPAA-trained," that's encouraging - but it is not the protection your practice actually needs. The real protection comes from a Business Associate Agreement signed at the company level. The critical detail most practices miss is who the BAA actually names: the agency as a legal entity, or the individual contractor assigned to your account? That distinction separates meaningful legal recourse from a credential that offers comfort without accountability. In this article, I walk through the specific loophole that leaves practices exposed, the real-world stakes of signing a BAA with an offshore individual rather than a US company, and the five questions every practice owner should ask before signing any staffing contract.

  • Is "HIPAA-trained" the same as HIPAA-compliant?
  • Who should sign the BAA - the individual virtual assistant or the agency?
  • What five questions should I ask any healthcare staffing agency before signing a contract?

No. "HIPAA-trained" means a person completed a training course; "HIPAA-compliant" means a signed Business Associate Agreement (BAA) makes a legal, insured company accountable. These are not interchangeable, and treating them as equivalent is how practices end up holding liability that should have belonged to the vendor.

In my role leading marketing at HelpSquad, I watch this confusion surface constantly. Our CEO, Jason O'Neill, addresses it almost every week on calls with practice owners who are shopping for virtual assistant support. His warning is direct: "The agency is going to have you sign the BAA with the individual virtual assistant, and I'd caution you: that's a terrible idea." Most practices don't recognize the trap until they're already in a contract - or already dealing with a breach.

My background informs why I take this seriously. Before HelpSquad, I spent years at UnitedHealth Group (Optum) managing claims, policy inquiries, and dense volumes of protected health information every day. Handling PHI at that scale leaves you with no illusions about what exposure costs - not just financially, but in patient trust and regulatory standing. A training certificate is not a substitute for a signed agreement with a company that can be held accountable under US law.

What follows is a buyer-beware guide. I'll cover the training-versus-compliance distinction, the liability structure that puts your practice at risk, and the five questions you should ask any agency before you sign a single document.

Is "HIPAA-Trained" the Same as HIPAA-Compliant?

No - and understanding why requires separating two things that agencies often present as a package.

HIPAA training is an educational activity. An individual completes a course - sometimes a 30-minute online module, sometimes a more structured multi-day certification - and receives documentation confirming they understand privacy rules, PHI handling requirements, and the general principles of the Health Insurance Portability and Accountability Act. That documentation tells you what the person has learned. It says nothing about who is legally accountable when something goes wrong, as of .

HIPAA compliance in a vendor relationship is a contractual obligation. It is established through a signed Business Associate Agreement. Under HIPAA, a vendor who requires access to PHI to provide their services - but is not your employee and is not a covered entity themselves - qualifies as a business associate and must have a BAA in place. That BAA has specific, enforceable requirements: it must describe the permitted uses of PHI, state that the business associate will not use PHI beyond what is permitted under the agreement, and require the business associate to implement adequate safeguards to protect patient information. The BAA is what makes accountability real.

Here is the distinction that matters most: a training certificate belongs to an individual. A BAA belongs to a legal entity. When an agency tells you their staff is "HIPAA-trained," they are describing their team's education. The relevant question - one that most practices forget to ask - is: who is the named signatory on your BAA? The company, or the individual contractor?

It's worth noting that formal compliance certification does not guarantee actual security. A HIPAA/HITRUST compliance auditor conducting professional examinations across healthcare organizations confirmed in a well-circulated discussion that gaps can persist even for organizations that check every compliance box. The same principle applies to BAA structure: an agency can hold every internal certification, train every member of their staff rigorously, and still route the BAA to the individual contractor assigned to your account. Their organizational compliance is a separate instrument from the BAA governing your specific vendor relationship.

I've watched this play out with practices that genuinely did their homework. They asked about HIPAA. They reviewed training records. They felt confident. The question they didn't ask - "Who is the named signatory on our BAA?" - was the one that would have changed the outcome entirely.

The Office for Civil Rights resolved 1,185 HIPAA cases with corrective action and technical assistance in 2023 alone. When OCR investigates a breach, they are not asking whether the individual who mishandled data was trained. They are asking whether the covered entity had an enforceable agreement in place with an accountable business associate. A training certificate has never satisfied that standard.

Consider what this means in practice. A patient's data is exposed through a routine workflow error - a file shared in an unencrypted format, a login credential sent over email. OCR opens an investigation. You provide your BAA. The BAA names an individual - an offshore contractor, not the agency. The agency's position is clean: the signed agreement is between you and that individual, and they are not party to the enforcement action. You are left negotiating with a foreign national who has no US legal standing, no liability insurance, and no obligation to cooperate. You hold the liability. They do not.

In summary: training describes what a person knows. A company-signed BAA describes who is accountable. They are not the same document, and they do not create the same protection.

Side-by-side comparison showing two documents: one labeled 'Individual VA BAA' marked with a red X, and one labeled 'Company BAA' marked with a green checkmark

Who Is Actually Liable When a Breach Occurs?

This is the question every practice owner should lead with when evaluating a virtual assistant agency - and most don't ask it until it's too late.

The answer depends entirely on who signed your BAA. If the BAA names the agency - a US-incorporated company with errors-and-omissions and cyber liability insurance - then when a breach occurs, the accountability chain runs through that company. They are required by contract to cooperate with your breach response, notify you within 60 days of discovering the breach, and accept OCR's enforcement jurisdiction. They carry insurance that provides financial recourse. You have legal standing against a named US entity.

If the BAA names an individual - specifically, an offshore contractor - the chain breaks immediately. An individual residing outside the United States has no meaningful exposure to OCR enforcement. They may carry no insurance whatsoever. They cannot be compelled to appear in US legal proceedings. And the agency that placed them? They are not party to your agreement and have no formal obligation to assist you.

My years at Optum gave me a direct view into what PHI liability looks like when it falls on an organization. A single misdirected fax, a login credential shared by mistake, an unencrypted file left in a shared folder - these are the moments that trigger investigations. The stakes are steep regardless of breach scale. A malicious insider breach at Montefiore Medical Center - involving only 12,517 patient records - resulted in a $4.75 million HIPAA penalty from OCR, a penalty that by itself exceeded OCR's total enforcement collections for all of 2023. That cost does not distribute evenly. When your BAA points to an individual who is unreachable, it falls entirely on you.

To make this concrete, compare the two arrangements side by side:

Factor BAA with Offshore Individual BAA with US Company
Legal jurisdiction None / foreign - outside OCR enforcement authority US-incorporated - fully subject to OCR jurisdiction
Liability in event of breach Falls almost entirely on the practice Shared with the business associate company
Insurance coverage Individual may carry no coverage whatsoever Company carries E&O and/or cyber liability insurance
Recourse after breach Extremely limited - individual may be unreachable Contractual remedies against a named US entity
60-day breach notification Unclear - individual may not comply with the legal requirement Company is legally required to notify you within 60 days of discovery
Audit rights Functionally unenforceable against a foreign national Enforceable - company must cooperate with audits
OCR cooperation No obligation to participate in US investigations Required by law to cooperate with OCR

The table above is not hypothetical. These are the real differences between two document structures that look almost identical at the surface level. Both say "BAA." Both have a signature at the bottom. The difference is in who - or what - that signature represents, and whether that entity can be held accountable under US law when it matters most.

It's important to note that practices sometimes discover this structure mid-engagement. They receive a BAA template from the agency, sign it without examining the named parties, and only realize the individual contractor is the signatory when they return to the document for an unrelated reason. By that point, they're in a live vendor relationship with the wrong legal structure in place.

The fix is simple if you catch it before signing: ask who the named signatory will be. The answer must be the agency itself - a legal entity with a US business address and verifiable insurance. If the answer is the individual, that is a red flag worth acting on before you commit to anything.

How Do I Vet a Healthcare Staffing Agency Before Signing Any Contract?

The good news is that identifying the right vendor structure is not complicated. It requires asking five specific questions and being willing to walk away if you don't receive direct, documented answers to all of them.

I've developed this checklist through direct observation - watching our sales and operations teams field these exact questions from practices, and watching how competing vendors respond when practices push for specifics. The questions are simple. The responses tell you everything. It's also worth noting that most HIPAA violations stem from internal carelessness or partial adherence rather than sophisticated external attacks - which means a well-structured vendor relationship with clear, documented obligations is your primary protection.

The 5-Question Vendor-Vetting Checklist

  1. "Who is the named signatory on the BAA - your company or the individual virtual assistant?"

    This is the most important question on the list. Clarity = KEY here: the answer must be the agency itself, named as a US legal entity. If the agency asks you to sign the BAA directly with the individual VA, or if their response is vague or deflecting, treat that as a disqualifying answer. There is no defensible reason for a compliant agency to push the BAA to the individual.

  2. "Does your company carry cyber liability and errors-and-omissions insurance? Can you provide a certificate of insurance?"

    A compliant agency should produce a COI on request without hesitation. If they cannot, their HIPAA compliance promises are uninsured assertions. In the event of a breach, there is no financial backstop available to your practice. Ask for the certificate before the conversation advances. If they stall or redirect, move on.

  3. "Where are your virtual assistants located, and are they employed directly by your company or engaged as independent contractors?"

    Employment structure matters considerably. A company-employed VA is a fundamentally different arrangement than an independent contractor operating through a staffing broker. The former means the agency bears HR, training, and compliance responsibility directly. The latter means the contractor is effectively self-employed - and when you sign a BAA directly with them, you are signing with someone who has no institutional backing from the agency placing them.

  4. "What internal agreement do you hold with the virtual assistant that mirrors the obligations in our BAA?"

    A reputable agency signs the BAA with you at the company level and then holds a separate, internal agreement with the VA that passes down the same HIPAA obligations. Under HIPAA, BAAs must describe permitted uses of PHI, state that PHI will not be used beyond those permitted uses, and require adequate safeguards to protect patient information. Ask how the agency passes those same obligations down to the individual VA. If they have no internal compliance document governing the individual's behavior, the company-level BAA is less protective than it appears.

  5. "What happens to our BAA and our data access if the individual VA assigned to my account leaves your agency?"

    This question tests the continuity of your compliance structure. If the BAA is with the company, the agreement survives staff turnover intact. If the BAA is with the individual, their departure may create a compliance gap - or leave you in a situation where a former contractor still holds access credentials under a now-defunct agreement. The answer should make clear that your legal protection is tied to the company, not to a specific individual.

A legitimate, compliant agency will answer all five of these questions directly, without redirection. They will provide documentation when asked. They will not treat these questions as obstacles - they will recognize them as exactly the right questions to ask.

If an agency becomes defensive, vague, or attempts to redirect you to training certifications as the primary evidence of compliance, that response is itself informative. An agency that has structured itself correctly has no reason to avoid these questions. The evasion tells you what the documentation would have revealed.

These five questions are how you find out which situation you're in before you sign a single document - not after.

What Will Matter Most in HIPAA Compliance Over the Next 12-24 Months?

The regulatory environment for healthcare PHI is tightening, and the growth of offshore virtual assistant staffing means the BAA structure question is going to become more visible - not less - in the near future.

OCR enforcement has shifted toward a higher-intensity posture. A single malicious insider breach at Montefiore Medical Center recently generated a $4.75 million HIPAA penalty - a penalty that, by itself, exceeded OCR's total enforcement collections for all of 2023. That is not a number that comes from a relaxed regulatory agency. It reflects an OCR increasingly willing to make enforcement examples regardless of breach scale, and a posture that will only intensify as the volume of vendor-managed PHI grows.

In 2023, OCR received 47,017 HIPAA complaints - the highest annual total on record. That volume represents an activated patient population and a regulatory body that has publicly committed to following through on complaints. For practices using third-party vendors with non-standard BAA structures, this is a meaningful shift in risk profile. Small practices are not shielded from enforcement by their size - the HIPAA Security Rule applies at every scale, and regulators are increasingly aware of the vendor-structure loopholes created by the rapid growth of offshore staffing arrangements.

The offshore staffing market for healthcare support roles is growing rapidly. Virtual assistants, medical billing specialists, prior authorization coordinators, and patient intake specialists are increasingly sourced from the Philippines, India, and Latin America. This is not inherently a compliance problem - international staff can be trained rigorously and managed under fully compliant structures. The problem emerges when cost-focused agencies use the offshore model as cover for routing individual contractors, rather than the company itself, as the named business associate in your BAA.

What I expect to see over the next 12 to 24 months is increased OCR scrutiny of vendor agreements in practices that have experienced breaches. As more practices adopt remote and offshore support, the question of who signed the BAA will surface in more enforcement actions. Practices that hold company-level BAAs with insured, US-accountable vendors will be in a defensible position. Those with individual-level BAAs will not.

The practical implication is straightforward: if you currently use a virtual assistant service, now is the right time to pull your BAA and check the named signatory. If it names an individual rather than the company, that is a correctable problem - but it needs to be corrected before a breach forces the conversation under far more difficult circumstances.

It's important to note that this fix is not complicated or expensive. The right BAA structure is table stakes for any reputable healthcare staffing agency. The challenge is awareness - most practices don't know to look for the distinction until they've had a conversation like the one our CEO Jason O'Neill has every week with practices evaluating HelpSquad. Raising that awareness is the whole point of this article.

In the next two years, practices that require company-level accountability from their vendors will be measurably better protected than those that don't. The regulations have not changed - but OCR's capacity and willingness to enforce them has increased significantly, and vendor structure will be a primary focal point when it does.

Forecast window: 12-24 months

Where HIPAA Compliance Enforcement Heads Next

Three evidence-based forecasts on how HIPAA enforcement, vendor BAAs, and outsourced healthcare staffing will shift over the next two years.

26 sources analyzed7 community discussions3 industry publications3 newsletters2 video sources
A

Forecasts For BAA-Backed Compliance

Use these forecasts to gauge which compliance signals, not just training claims, will matter most when vetting healthcare vendors.

69/100
Medium confidence 12-24 months

More SaaS and scheduling platforms will follow Microsoft 365, Google Workspace, Mindbody, Acuity Scheduling, and WellnessLiving in bundling signed BAAs into specific paid tiers over the next 12-24 months, making BAA availability a direct purchasing filter for healthcare buyers rather than a separate negotiation.

48/100
Medium confidence 12-24 months

Over the next 12-24 months, OCR will keep issuing high-dollar HIPAA penalties tied to insider access and BAA gaps even when the number of affected individuals is small, following the pattern set by Montefiore Medical Center's $4.75 million penalty for a malicious insider incident touching just 12,517 records.

Early indicators on the radar: Montefiore's $4.75 million penalty exceeded OCR's total 2023 HIPAA enforcement collections despite affecting far fewer people than the 2021 Excellus Health Plan breach, which involved 9.35 million records and a $5.1 million penalty. Community practitioners note there is no such thing as a formal 'HIPAA compliant' certification comparable to PCI, while buyers are actively asking for HIPAA compliant call centers and outsourced medical receptionists without a clear standard to reference. Microsoft 365 HIPAA compliance already requires specific tiers such as Business Premium or E5 plus a signed BAA, and Google Workspace offers a self-service five-step BAA acceptance flow inside its admin console.

B

Evidence For And Against Each Forecast

Each forecast lists the supporting and countervailing sources drawn from enforcement actions, vendor policies, and practitioner discussion.

Platforms increasingly bundle signed BAAs into paid tiers 69
Supporting evidence
Counter-signals
C

What Could Change These Forecasts

These scenarios describe the regulatory or market shifts that would push the forecasts in a different direction.

Read this with care

No forecast here is a sure thing. Even the strongest signal (71/100) has evidence pushing against it, and the contrarian read (71/100) exists because sources genuinely disagree.

  • If regulators or buyers move in the opposite direction, The vendor market stays fragmented without a formal compliance seal would weaken first.
  • If the source mix shifts toward stronger contrary evidence, The vendor market stays fragmented without a formal compliance seal could become the more durable forecast.
Methodology Every signal carries a 0-100 score reflecting the authority, freshness, and balance of the sources behind it.

The core problem here is not complicated: practices sign documents without examining who they're actually signing with. The agency facilitates this by presenting the training credential and the BAA as equivalent evidence of compliance. They are not.

HelpSquad's approach is straightforward. We sign the BAA at the company level - company-to-company, not company-to-individual. We then hold a separate, internal compliance agreement with the virtual assistant that passes down the same HIPAA obligations, ensuring the VA is bound to the same standards we are contractually required to maintain on your behalf. The accountability chain runs from your practice to our company to the individual supporting your account. There is no gap in that chain.

I'm not writing this to close a sale. I'm writing this because the practices that end up in the most difficult breach situations are often the ones that did the most diligence. They confirmed training. They reviewed certificates. They felt confident. The one question they didn't ask - "Who is the named signatory on this BAA?" - was the question that would have changed everything.

Bring the five-question checklist to your next vendor conversation. The answers will tell you everything you need to know about whether a vendor's compliance posture is real or rhetorical - and they'll tell you before you've committed to anything.

Written by

Maria Rush

Marketing Team Lead, HelpSquad

Maria De Jesus-Rush is Marketing Team Lead at HelpSquad, a healthcare business process outsourcing company, with a background in content development, digital marketing, and project management.

Connect on LinkedIn

Not Sure Your Current BAA Structure Is Right?

If you're evaluating virtual assistant agencies for your healthcare practice, HelpSquad's team can walk you through how we structure our BAAs and what company-level accountability looks like in practice. No pressure - just a direct conversation about compliance structure before you sign anything.

Talk to Our Team

Frequently Asked Questions

What is the difference between HIPAA training and HIPAA compliance?

HIPAA training is an educational activity that produces a certificate for an individual. HIPAA compliance in a vendor relationship is a legal obligation established through a signed Business Associate Agreement (BAA) with a named legal entity. Training confirms what someone knows; a BAA with a company creates enforceable accountability - the business associate must describe permitted PHI uses, restrict use to those purposes, and implement adequate safeguards.

Should a BAA be signed with the virtual assistant or the staffing agency?

The BAA must be signed with the staffing agency - the legal entity - not with the individual virtual assistant. A company-signed BAA gives your practice recourse against a US-incorporated organization that carries insurance and is subject to OCR jurisdiction. An individual-signed BAA gives you recourse against a contractor who may have no US legal presence, no insurance, and no obligation to cooperate with an investigation.

What happens if my BAA is signed with an offshore individual and a breach occurs?

Your practice absorbs the liability. An offshore individual contractor is outside OCR's enforcement jurisdiction, likely carries no liability insurance, and has no legal obligation to cooperate with a US investigation. The staffing agency that placed them is not party to your agreement. The full burden of the breach falls on your practice, with no meaningful recourse against the individual who caused it.

Does a HIPAA training certificate mean a virtual assistant is HIPAA-compliant?

No. A HIPAA training certificate confirms that an individual has been educated on HIPAA principles. It does not create a legal obligation, does not constitute a BAA, and does not transfer liability away from your practice. OCR enforces compliance through Business Associate Agreements with legal entities - training records have never satisfied that standard.

What five questions should I ask a virtual assistant agency about their HIPAA BAA structure?

Ask: (1) Who is the named signatory on the BAA - the company or the individual VA? (2) Does the company carry cyber liability insurance, and can they provide a certificate of insurance? (3) Where are VAs located, and are they direct employees or independent contractors? (4) Does the agency hold a separate internal compliance agreement with each VA? (5) What happens to the BAA structure if the assigned VA leaves the agency?

Can an offshore virtual assistant be part of a HIPAA-compliant vendor arrangement?

Yes - if the structure is correct. The BAA must be signed with the US-incorporated agency, not with the offshore individual. The agency must then hold a separate internal agreement with the VA that passes down the same HIPAA obligations. The VA's physical location matters less than who is legally accountable under the agreement governing your vendor relationship.

Tags
  • hipaa
  • healthcare
  • outsourcing-strategy
  • team-management
  • cybersecurity
Let's talk

Let's talk about what your practice actually needs.

A 30-minute call. No sales pressure. We'll tell you honestly whether we're a fit.

877-775-3667 · info@helpsquad.com · Doylestown, PA