Date: 3 September 2026
Why This Belongs in Your Vendor Risk Register
Think about what a remote medical assistant can actually reach. Full patient records, appointment histories, insurance details, payment data and in many cases the practice management system itself.
That is deeper access than most software vendors get. Yet the same practice that would run a security review on a new EHR will onboard an assistant on the strength of a discovery call.
Two complications stack on top of the usual supply chain picture. Jurisdiction, because your contract and your breach remedies now cross legal systems that treat both differently. And visibility, because verifying claims about screening and device management is genuinely harder when the team sits eight time zones away.
Neither is a reason to avoid the model. Both are reasons to assess it properly, and the same discipline that applies to offshore vendor risk in software development applies almost unchanged when the offshore team is handling patient data instead of source code.
What to Actually Check Before You Sign
Who signs the BAA, and at what level? A company-level Business Associate Agreement covering the provider is materially stronger than a per-assistant arrangement or, worse, a contractor who signs nothing.
What does the certification actually cover? SOC 2 and ISO 27001 are only meaningful once you have read the scope statement and confirmed it covers the operation your assistant sits in.
Who controls the workstation? Company-managed devices with disk encryption and MDM are a different proposition to a personal laptop on home broadband. Ask which one you are getting.
How is access scoped? Named individual accounts, no shared credentials and access limited to what the role genuinely requires. The HIPAA minimum-necessary standard is a useful yardstick even for UK practices working to UK GDPR.
What happens when someone leaves? Attrition is a security event, not just a delivery problem. Agree in writing how quickly you get told when an assistant departs your account.
Is any of this subcontracted? Silent subcontracting is one of the fastest ways offshore risk multiplies without anybody noticing.
What is retained outside the EHR? Assistants accumulate context in shared drives, notes apps and messaging tools. Ask what is stored, in which jurisdiction and how it is destroyed at the end.
How fast is breach notification? Vague promises to notify you promptly give you nothing enforceable. You want a number in the contract, measured in hours.
Will they join a cyber tabletop exercise? A provider willing to rehearse a compromised-account scenario alongside your team is demonstrating something no questionnaire captures.
Six Providers Assessed Against That Checklist
1. Wing Assistant
Wing Assistant is the strongest option here on documented security posture, which is the deciding factor when the work involves patient data. Its healthcare virtual assistant service pairs HIPAA-trained assistants with certifications that most competitors in this category simply do not hold.
The compliance stack is unusually complete. Wing is SOC 2 certified, ISO 27001 compliant, HIPAA-compliant and GDPR-compliant, which matters if you operate in the UK or EU and need a lawful basis for processing that survives scrutiny.
On the checklist's first question, Wing answers at company level. It signs a Business Associate Agreement with healthcare clients before any patient data is accessed, and every assistant handling PHI works under it. That is the arrangement described above as materially stronger than a per-assistant signature.
Contractual protection is handled properly too. Wing provides comprehensive NDAs alongside custom healthcare policies that can be aligned to your practice's own compliance standards rather than imposed as a fixed template.
On the work itself, assistants handle patient scheduling, EMR updates, intake forms, insurance claims processing, coverage verification, lab coordination and visit notes. The provider cites EMR experience including Epic, Athenahealth and Kareo.
Oversight is structured rather than assumed. Every account gets a dedicated Customer Success Manager, assistants are supervised by Team Captains and Supervisors and work runs through the Wing Workspace App with real-time task visibility, documented workflows and structured handoffs.
Pricing is published, which is rarer than it should be. Full-time is $1,799 per month for 160 hours, part-time is $1,099 per month for 80 hours, both including free replacements.
Wing reports supporting more than 10,000 companies across 20 or more countries, screening over 2 million applicants annually. Its Provida Family Medicine case study reports 50% faster admin operations, 35% fewer billing errors and 25% faster claims.
Best for: Practices that need auditable compliance evidence, and any organisation whose own security review will ask for certification scope rather than a badge.

2. Hello Rache
Hello Rache was founded in 2017 by Dr Mark Carnett, a physician who built it for his own Arizona practice first. Assistants are licensed nurses and healthcare professionals based in the Philippines.
Pricing is a flat $9.50 per hour with no contracts, no setup fees and no minimum commitment, which suits practices needing only a few hours a week.
On compliance, every assistant completes Hello Rache's internal HIPAA training programme and is certified on completion, and placements go through licensing checks before touching a workflow. The specialisation is clinical documentation. Live virtual in-room charting, medical scribing, EMR documentation and transcription across medical, dental, optometry and veterinary practices.
Best for: Solo and small practices wanting clinically trained scribes at low hourly cost, where the primary need is documentation rather than a broad admin function.

3. MyOutDesk
MyOutDesk brings the longest track record here, citing 17 or more years in operation and 8,500 or more businesses served. Operations are SOC 2 certified, with HIPAA and PCI-DSS compliance maintained for regulated clients.
Its security model is worth understanding because it is genuinely different. A BAA is signed as standard, and the provider coordinates equipment procurement so your own IT team controls and locks down the assistant's workstation.
Access follows the HIPAA minimum-necessary standard, with VPN, multi-factor authentication and no shared credentials. BAA samples, SOC 2 reports and security documentation are available on request through a public trust centre.
The trade-off is that HIPAA training is coordinated with your practice rather than delivered wholesale. Baseline training is available, but the provider recommends running assistants through your own compliance process as well. That suits practices with a mature programme and burdens those without one.
Best for: Practices with an existing compliance function and an IT team willing to own device management.

4. HelpSquad
HelpSquad Health starts from $8 per hour and places assistants live in roughly two weeks, with a US-based account team running onboarding and weekly quality assurance.
The technical controls are the most specific of any provider reviewed. Assistants work under a company-level BAA on a secure virtual desktop, through encrypted channels, with copying, pasting and downloading of PHI blocked outright.
Access logs are audited and HIPAA training is continuous rather than one-off. Assistants are trained on Epic, Cerner and Athena, and candidates clear a five-dimension assessment before reaching your interview stage.
Best for: Practices that want technical PHI controls spelled out in advance rather than negotiated after signing.

5. Virtual Nurse Rx
Virtual Nurse Rx staffs its assistants with Registered Nurses and doctors, which puts it at the clinical end of this market rather than the administrative end.
The specialism is mental health practices and multi-provider group practices, and the team is HIPAA-trained. Clinically technical work such as chart review and prior authorisation sits comfortably within scope.
Pricing is not published, so budget comparison requires a direct conversation. That is worth factoring in if you are running a procurement process against fixed quotes.
Best for: Mental health and group practices needing genuine clinical judgement rather than admin throughput.

6. Care VMA Health
Care VMA Health offers fully managed HIPAA-compliant virtual medical assistants from $9 per hour, with onboarding advertised in under 48 hours.
Coverage spans virtual medical receptionists, remote patient monitoring, chronic care management, billing and patient care coordination, with assistants trained on major EHR platforms.
The rapid onboarding is the draw and also the thing to probe. Ask what security verification fits inside a 48-hour window, and what is deferred until afterwards.
Best for: Practices needing coverage at short notice, provided you run your own due diligence in parallel.

How to Choose
If your own security review will demand certification evidence, start with the provider that already holds it. Retrofitting compliance documentation onto a cheap hourly arrangement is a painful way to learn this lesson.
If you have a mature compliance function and want to own the controls yourself, a provider that hands you device management is an advantage rather than a gap.
If cost per hour is genuinely the deciding factor, go in with your eyes open about what you are taking on. The saving is real, and so is the accountability that comes with it.
Whichever way you go, put the provider in your incident response plan before you need it. Name their security contacts, agree escalation paths in both directions and decide in advance who has authority to revoke access at three in the morning.
Then test it. One tabletop exercise built around a compromised assistant account will teach you more than a year of questionnaires.
Frequently Asked Questions
1. Is a healthcare virtual assistant a business associate under HIPAA?
In almost all cases, yes. If the assistant creates, receives, maintains or transmits protected health information on your behalf, a Business Associate Agreement is required. Confirm whether the BAA is signed at company level or per individual, because the difference matters when something goes wrong.
2. Does hiring offshore break HIPAA?
No. HIPAA does not prohibit offshore processing, and there is no geographic restriction in the rule itself. What it does require is that appropriate safeguards and a BAA are in place, and offshore arrangements make verifying those safeguards harder rather than impossible.
3. What about UK and EU practices under GDPR?
Different framework, similar discipline. You need a lawful basis, a data processing agreement and a valid transfer mechanism for personal data leaving the UK or EEA. Providers holding GDPR compliance alongside their healthcare credentials will save you considerable work here.
4. How do I verify a provider's security claims?
Ask for evidence rather than assertions. Request the SOC 2 report and the ISO 27001 scope statement, confirm which entity and which location they cover then ask how workstations are managed. A provider that welcomes the scrutiny is telling you something useful, and so is one that resists it.
5. What should be in the contract?
Breach notification measured in hours rather than vague language about promptness, no subcontracting without written consent, a right to audit and an offboarding notification service level so access revocation on your side keeps pace with staffing changes on theirs.
.webp)
.webp)

.webp)