Executed before access is granted
We enter into a Business Associate Agreement with your practice before your dedicated employee is given access to any system that contains PHI.
Adding remote staff shouldn't mean loosening how you protect patient data. Here is exactly how Nivia handles PHI, what we put in writing, and the oversight that sits behind every person we place — so you can verify it, not just take our word for it.
Under HIPAA, a workforce that handles protected health information on your behalf is your business associate. Nivia treats a signed Business Associate Agreement as the starting line of every engagement, not a formality negotiated later.
We enter into a Business Associate Agreement with your practice before your dedicated employee is given access to any system that contains PHI.
The BAA covers permitted uses and disclosures, safeguards, breach notification, and return or destruction of PHI at the end of the engagement.
Already have a BAA template your compliance team prefers? We'll review and sign yours. Otherwise we provide one for your counsel to examine.
Your dedicated employee logs into your EMR and works inside the systems you already trust. Patient data stays in your environment; Nivia's role is access, not custody.
Works from an endpoint Nivia provides and controls, with access scoped to the systems you authorise.
Each employee works from an email address and phone number Nivia provides and fully controls — so the channels PHI can move through are ones we can oversee.
One employee per practice, with access scoped to the specific systems you explicitly authorize — no shared pools and no standing access to anything you didn't approve.
Every Nivia employee completes HIPAA training before they are placed with a practice, on top of role-specific programs that build the judgment to handle patient information correctly.
HIPAA training is completed before anyone is placed, alongside strict vetting and thorough background checks during hiring.
Four months built around real-time charting, medical terminology and anatomy, and direct shadowing of real providers — so handling clinical documentation is second nature.
An eight-month program covering coding across CPT and ICD-10, the full claim lifecycle, denials and appeals, and live billing in real practices.
We keep full control and access over every tool our employees use — so oversight is built in, not promised.
HIPAA compliance is a partnership. A few things stay on your side so access is scoped correctly and revoked cleanly.
Provision your employee with their own EMR and system logins, scoped to the tasks their role actually requires — no shared or admin accounts.
Sign the Business Associate Agreement before access begins, and route it through your own counsel or compliance team.
Let us know about role changes, coverage changes, or offboarding so credentials can be updated or revoked promptly.
Your privacy policies, acceptable channels for PHI, and any practice-specific rules — so your employee follows your standards from day one.
The questions compliance-minded practices ask before they let anyone near their EMR.
Yes. Nivia treats a signed BAA as a prerequisite for the engagement and executes it before your employee is granted access to any system that contains PHI. You can sign our template or your own.
In your systems. Your dedicated employee logs into your EMR, phone system, and portals and works there — the same environment your in-office staff use. Nivia does not maintain a separate copy of your patients' records.
One employee is assigned to one practice, using credentials you provision, scoped to the systems you explicitly grant. Their Nivia-issued email and phone are fully controlled by us, and a dedicated department monitors those channels on an ongoing basis.
Every Nivia employee completes HIPAA training before placement — operators, scribes, and billers alike — on top of role-specific programs (four months for scribes, eight months for billers).
Access to your systems is revoked, and the return or destruction of any PHI is handled under the terms of the BAA. The exact offboarding and data-handling steps are specified in that agreement.
We don't claim certifications we can't substantiate here. What we can put in writing today is a signed BAA, dedicated staff who access your EMR without storing records locally, company-controlled and monitored communication channels, and HIPAA training before placement. Any formal audit or certification status should be confirmed directly with us.
We'll walk your team through our BAA, how PHI is accessed, and the controls behind every placement — before you commit to anything.