Compliance is not a badge here. It is the onboarding.
Every Velma placement is built around your practice's own security policy, documented at every checkpoint. Here is the model, in the order your compliance officer will ask about it.
Access starts with your practice, not with us.
Client-owned provisioning
Your practice creates the accounts, sets the scope and revokes access. Every credential a VA uses is one you issued, with a documented revocation path on file.
Two-factor confirmed at onboarding
Multi-factor authentication is confirmed on your systems before the first shift, and the access grant is recorded with its scope.
HIPAA training through Accountable, certificate on file
Every VA completes HIPAA training through Accountable before placement. The dated certificate stays on file and is available to your compliance officer. Device-security attestations, endpoint protection, identity verification, background checks and credential review are recorded for every VA we place.
The work happens inside your environment.
No local storage
VAs work inside your EHR, your phone system and your tools. Patient data stays in your systems; Ask Velma keeps no copies of PHI. Our contractors access PHI only inside systems you provision, under a BAA.
Least-privilege access and visibility
Access is scoped to the role. Time tracking and activity visibility are available to you on every placement, whenever you want to look.
Your direction, always
VAs work under your team's direction and supervision, inside your systems and your policies. Practices that want network-level control can add a dedicated VPN per VA; your practice covers the cost and we handle installation and setup.
You contract with a US company, under Texas law.
Ask Velma is a US-domiciled Texas entity headquartered in Houston. It carries commercial general liability, professional liability and cyber coverage. Your practice contracts with a US company under Texas law. You are not pursuing a remedy overseas.
A Business Associate Agreement is executed with the SOW, between your practice, your VA and Ask Velma as applicable, before day one. Not on request. By default.
Ask Velma runs its own HIPAA compliance program on Accountable, and the current attestation is available to your compliance team. There is no government HIPAA certification, and we do not claim one; we show you the training records and the program instead.
If your compliance team wants coverage detail, we provide a certificate of insurance for your broker to review.
What your compliance officer receives
Have your compliance officer call ours.
We are happy to walk your team through the full security model, document by document.
Book a Discovery Call