Our approach to protected health information and UK/EU data protection, stated plainly, without overclaiming.
MedBridge Health is not a covered entity under HIPAA, and this page is not a claim of formal HIPAA certification: no such personal or agency certification exists under US law. What we do commit to is HIPAA-aware training and practice for every assistant, applied consistently across engagements.
For practices operating under UK or EU data protection law, assistants are trained in GDPR-aware handling of personal data, including data minimization and secure handling principles. As with HIPAA, formal data processing terms are set out in the specific engagement agreement, not assumed by default.
We'd rather be precise than impressive. "Trained in best practices" is accurate. Claims of blanket "compliance" or "certification" that don't exist would put both your practice and ours at legal risk, so we don't make them.
If your practice has specific compliance requirements, we're glad to walk through exactly how a given role would be structured before any PHI is involved. Reach out and we'll talk it through.