HIPAA & GDPR Statement
Our approach to protected health information and UK/EU data protection, stated plainly, without overclaiming.
Where we stand
Nessar Health is not a covered entity under HIPAA, and this page is not a claim of formal HIPAA certification: no such personal or agency certification exists under US law. What we do commit to is HIPAA-aware training and practice for every assistant, applied consistently across engagements.
HIPAA-informed workflows
- All Remote Care Coordinators complete HIPAA best-practice training before starting any engagement
- Most engagements begin with non-PHI administrative tasks
- Where a role expands to include protected health information, a formal Business Associate Agreement (BAA), provided by your practice as required under HIPAA, is put in place before that work begins
- Secure password management and confidentiality agreements are standard practice, not add-ons
GDPR awareness (UK/EU practices)
For practices operating under UK or EU data protection law, assistants are trained in GDPR-aware handling of personal data, including data minimization and secure handling principles. As with HIPAA, formal data processing terms are set out in the specific engagement agreement, not assumed by default.
Why we phrase it this way
We'd rather be precise than impressive. "Trained in best practices" is accurate. Claims of blanket "compliance" or "certification" that don't exist would put both your practice and ours at legal risk, so we don't make them.
Questions before you commit
If your practice has specific compliance requirements, we're glad to walk through exactly how a given role would be structured before any PHI is involved. Reach out and we'll talk it through.