Security and Compliance

Compliance is not a badge here. It is the onboarding.

Every Velma placement is built around your practice's own security policy, documented at every checkpoint. Here is the model, in the order your compliance officer will ask about it.

1. Prevention

Access starts with your practice, not with us.

Client-owned provisioning

Your practice creates the accounts, sets the scope and revokes access. Every credential a VA uses is one you issued, with a documented revocation path on file.

Two-factor confirmed at onboarding

Multi-factor authentication is confirmed on your systems before the first shift, and the access grant is recorded with its scope.

HIPAA training through Accountable, certificate on file

Every VA completes HIPAA training through Accountable before placement. The dated certificate stays on file and is available to your compliance officer. Device-security attestations, endpoint protection, identity verification, background checks and credential review are recorded for every VA we place.

2. Containment

The work happens inside your environment.

No local storage

VAs work inside your EHR, your phone system and your tools. Patient data stays in your systems; Ask Velma keeps no copies of PHI. Our contractors access PHI only inside systems you provision, under a BAA.

Least-privilege access and visibility

Access is scoped to the role. Time tracking and activity visibility are available to you on every placement, whenever you want to look.

Your direction, always

VAs work under your team's direction and supervision, inside your systems and your policies. Practices that want network-level control can add a dedicated VPN per VA; your practice covers the cost and we handle installation and setup.

3. Recourse

You contract with a US company, under Texas law.

Ask Velma is a US-domiciled Texas entity headquartered in Houston. It carries commercial general liability, professional liability and cyber coverage. Your practice contracts with a US company under Texas law. You are not pursuing a remedy overseas.

A Business Associate Agreement is executed with the SOW, between your practice, your VA and Ask Velma as applicable, before day one. Not on request. By default.

Ask Velma runs its own HIPAA compliance program on Accountable, and the current attestation is available to your compliance team. There is no government HIPAA certification, and we do not claim one; we show you the training records and the program instead.

If your compliance team wants coverage detail, we provide a certificate of insurance for your broker to review.

What your compliance officer receives

AgreementsMSA, SOW and BAA
CoverageCertificate of insurance
TrainingAccountable HIPAA certificates
ProgramAccountable compliance attestation
DevicesSecurity attestations
AccessScope and revocation record
Get the Security and Compliance Packet
You own your systems, your policies and your oversight. Ask Velma confirms and documents compliance with them at defined checkpoints.

Have your compliance officer call ours.

We are happy to walk your team through the full security model, document by document.

Book a Discovery Call
Ask Velma
Book a CallCall (346) 361-0770