EyeCareWorks is built exclusively for optometry and ophthalmology practices. Every virtual assistant we place completes formal HIPAA training, holds an active third-party HIPAA certification, and signs a Business Associate Agreement directly with your practice. Your VA works inside your systems, under your permissions, with every access logged.
HIPAA compliance at EyeCareWorks is not a feature we advertise. It is the operating system our entire service runs on. Before a virtual assistant ever logs into a practice's systems, three things have already happened: they have completed formal HIPAA training and earned an active third-party certification, they have signed confidentiality agreements covering all PHI handling, and they have signed a Business Associate Agreement (BAA) directly with your practice. From that point forward, the safeguards required under the HIPAA Security Rule, administrative, physical, and technical, are actively maintained, documented, and available for your review.
Our VAs are trained on optometry and ophthalmology workflows before placement: vision plans versus medical insurance, refraction data, OCT imaging, and recall protocols. PHI is handled by people who understand exactly what it is.
You work with the same assistant every day. No rotating pool, no shared logins, no unknown hands on your patient data. The result is a smaller attack surface and a cleaner audit trail.
Third-party HIPAA certification, signed confidentiality agreements, secured workstations, and documented incident response procedures, all in place before day one, not bolted on afterward.
A flat $10/hour includes every safeguard described on this page. There is no "security package" upsell, because compliance is not optional equipment. Your practice stays secure, efficient, and focused on patient care.
The HIPAA Security Rule organizes a business associate's obligations into three categories of safeguards. Here is how EyeCareWorks and every assistant we place implement each one, not as policy language, but as daily practice.
Workforce screening, formal HIPAA training, and third-party certification before placement. Signed confidentiality agreements covering all PHI handling, documented policies and procedures, a zero-tolerance sanction policy for mishandling, and incident response procedures written down before they are ever needed.
Secured, dedicated workstations on hardwired internet connections. No personal devices in the workspace, locked screens when unattended, and restricted local storage so patient data never leaves your systems. The workstation environment is part of the compliance program, not an afterthought.
Encrypted remote sessions, multi-factor authentication on assistant accounts, role-based access built on least privilege, and automatic session timeouts on every workstation. All work happens inside your systems under permissions you control, so every access lands in your own audit trail, backed by secure time and activity tracking.
If you are evaluating remote staffing for your practice, ours or anyone's, these are the questions a diligent practice administrator should ask before signing anything. Here is where EyeCareWorks stands on each.
Yes. Your assistant signs a BAA directly with your practice before any PHI access begins, and we make sure it is executed as part of onboarding. A provider who hesitates on this question has already answered it.
Formal HIPAA training plus an active, third-party HIPAA certification before placement, kept current throughout the engagement. Ask any vendor who issues their certification, and when it expires.
In your systems, full stop. Our VAs work inside your EMR under permissions you control. PHI is never downloaded, exported, or stored on the assistant's workstation.
Secured workstations, hardwired connections, multi-factor authentication, encrypted sessions, automatic timeouts, and activity logs available for your review.
Documented incident response procedures, prompt notification to your practice, and a zero-tolerance policy for PHI mishandling: enforced, not aspirational.
Yes. Compliance documentation, including training records, certification status, and security protocols, is available to your practice on request, before and during the engagement.
No contracts. No setup fees. Cancel anytime.