Answer first: VAConnect is a managed agency using South African professionals. US security: NDA, POPIA, client-owned cloud and systems, and LastPass (or equivalent). Medical and dental practice admin is on the books. We are not HIPAA-certified and will not overclaim.
Access is yours to grant and revoke; data stays in your cloud. Founded 2008; managed; month-to-month.
Controls
- NDA: Every VA signs one; you may add yours.
- POPIA: We are POPIA compliant; no invented certifications.
- Cloud: Keep files in your Drive, SharePoint, Dropbox, or similar.
- Passwords: Use LastPass or equivalent; raw passwords stay hidden.
- Ownership: You own CRM/EHR, email alias, US number, dialler data, and records.
HIPAA: honest
We can discuss medical admin and practice support. We are not HIPAA-certified or HIPAA-compliant. BAA, training, or no-PHI scope belongs in discovery. Not legal advice.
FAQ
Do VAs sign an NDA?
Yes, plus you may add yours.
Can you handle medical practices?
Yes, but we are not HIPAA-certified.
Who owns systems and the US number?
You do; accounts, cloud, CRM/EHR, number, data, and records stay yours.
How should we share passwords?
Use your cloud and LastPass or equivalent.
Are you GDPR or US-state privacy certified?
We are POPIA compliant and do not claim those certifications.