Playbook
Why Your Agency's Virtual Assistant Never Signed a HIPAA BAA
Your VA touches client health information most days of the week. Almost nobody checks whether the company that supplied them is even allowed to sign the agreement that makes that legal.
A virtual assistant who handles client health information on your behalf is, in HIPAA's own terms, a business associate, and 45 CFR 160.103 says so directly: creating, receiving, maintaining, or transmitting PHI for billing, benefit management, or practice management triggers the status1. Business associates are named in a rising share of reported healthcare breaches, up to 43 percent in the first half of 2026 from a 34 percent average over the prior eight years3, and OCR treats a missing business associate agreement as evidence of a systemic failure, not a paperwork gap. Most VA staffing arrangements were never built to sign one.
Your VA is touching more than data entry
You hired a virtual assistant to get the CRM cleaned up. Maybe it was a marketplace hire, ten to twenty dollars an hour, found through a staffing site or a Facebook group of other agents swapping recommendations. The job description sounded administrative: update contact records, schedule appointments, follow up on renewal reminders, maybe answer routine emails. Nothing about it sounded like handling protected health information, because nobody framed it that way to you when you signed up, and you did not think to ask.
Look at what that VA actually does in a normal week on a Medicare or ACA book. They open a CRM record that shows which plan a client is enrolled in. They read a note from last month's call describing a client's specific health condition, entered by you or a producer so the next conversation would not have to start from zero. They send a text confirming a doctor's appointment tied to a Medicare Advantage referral. They pull up a benefit summary to answer a client's question about a prescription tier. None of that reads like "data entry" from the outside. From the inside of federal privacy law, every one of those actions is exactly the kind of thing that turns a contractor into something with a specific legal name.
This is not a hypothetical edge case that only applies to a large call center. It is the ordinary, daily texture of running a Medicare or ACA book with any help at all, and it applies whether the VA is one person you found on a freelance marketplace or a managed team from an offshore staffing company with a sales deck and a logo. The question this article answers is not whether your VA is allowed to do this work. It is whether anyone, on either side of that hiring decision, ever put in writing what happens to the health information your VA sees every day.
Before you keep reading
If you want a straight answer on where your own site and workflow stand on HIPAA safe tracking, the free Audit checks it in about a minute. strategicaiarchitects.com/audit
What actually makes a VA a business associate
HIPAA does not leave this to interpretation. The regulation defining the term sits at 45 CFR 160.103, and it names the triggering activities directly rather than leaving agents to guess. A business associate is a person who, on behalf of a covered entity, "creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities, billing, benefit management, practice management, and repricing"1. Read that list against the VA task list in the last section. Benefit management and practice management are not obscure legal terms. They are what a VA does when they touch a client's plan details or manage the operational side of your book.
The regulation goes one step further than most agents expect, and it is the step that actually matters for how VA arrangements get staffed. A subcontractor of a business associate is itself a business associate, in the regulation's own words, whenever that subcontractor "creates, receives, maintains, or transmits protected health information on behalf of the business associate"1. Staffing companies frequently layer subcontractors: the company you signed a contract with is not always the company whose employee is actually logging into your CRM. Each layer in that chain inherits the same obligation. Nobody gets a pass by being one step removed from the agent who hired the VA in the first place.
| Regulation's function | What it looks like on a real VA's task list |
|---|---|
| Benefit management | Pulling up plan details, formulary tiers, or coverage specifics to answer a client question |
| Practice management | Scheduling appointments, managing the CRM pipeline, running renewal reminder sequences |
| Claims processing or administration | Following up on a claim status, submitting documentation on a client's behalf |
| Billing | Reconciling premium payments, chasing a lapsed autopay, updating billing records |
| Data analysis or administration | Cleaning up CRM fields, tagging records, running a book review that touches health status notes |
Notice what is not on that list, because it matters just as much. A VA who only ever touches life insurance leads, annuity paperwork, or property and casualty policies is not handling protected health information in the HIPAA sense, since PHI is specifically health information tied to an identifiable person. That distinction shows up again later in this article, because it changes the entire calculus for an agent who does not write Medicare, ACA, or group health business at all.
The Medicare layer most agents forget
If you sell Medicare Advantage or Part D, there is a second regulatory layer sitting on top of HIPAA that most agents have never heard named. CMS's own definitions at 42 CFR 422.2 describe a chain of entities tied to every MA contract. A first tier entity is "any party that enters into a written arrangement, acceptable to CMS, with an MA organization or applicant to provide administrative services or health care services for a Medicare eligible individual under the MA program"2. A downstream entity sits one level below that: "any party that enters into a written arrangement, acceptable to CMS, with persons or entities involved with the MA benefit, below the level of the arrangement between an MA organization (or applicant) and a first tier entity"2.
Read your own agent agreement against that language. An independent agent contracted to sell Medicare Advantage for a carrier is, in the ordinary case, either a first tier entity or a downstream entity under that carrier's MA contract, depending on exactly how the brokerage layers are structured. The carrier is the HIPAA covered entity, a health plan. You are the party CMS's own regulation places directly beneath it. That status is not something you opted into. It comes from the shape of your agent contract, whether or not anyone at the carrier ever used the phrase "downstream entity" when you signed it.
Here is where the chain most often breaks. Your carrier almost certainly required you, the agent, to attest to compliance obligations, complete annual certification training, and in many cases sign something establishing your status as a business associate or downstream entity before you were allowed to sell their plans. That paperwork exists because the carrier's own compliance program requires it of every party beneath them in the chain. What almost never happens next is you doing the same thing to the VA you hired. The obligation that flowed down to you from the carrier does not evaporate just because you handed the actual PHI-touching work to someone else. It is supposed to flow down again, to your VA, the same way it flowed down to you. Most agencies never take that second step, because nobody at the carrier is positioned to check whether you did, and nobody at the VA marketplace is asking either.
Why this does not apply the same way to a pure life or P&C book
42 CFR 422.2's downstream entity definition is written specifically around the Medicare Advantage benefit2. An agent who writes only life insurance, final expense, or property and casualty is not operating inside that Medicare regulatory chain at all, and is not handling PHI in the HIPAA sense either. The mechanism in this article is real, but it is scoped to Medicare, ACA, and group health business specifically, not to every line an agency might carry.
What an unsigned BAA actually costs
It is easy to treat a missing signature as a paperwork gap that would only matter if regulators went looking for it. The breach data says the opposite: business associates are already the mechanism through which a rising share of healthcare data actually gets exposed, whether or not anyone was looking.
HIPAA Journal's own compiled breach analysis, tracking every large breach reported to HHS OCR, found that business associate involvement averaged 20 percent of reported healthcare data breaches from 2009 through 2017, then rose to a 34 percent average from 2018 through 20263. In just the first six months of 2026, that share climbed further, to 43 percent3. The same analysis found an even sharper shift in how many people each breach actually touches: business associate involvement accounted for only 5 percent of individuals affected by healthcare breaches in 2015, and 65 percent of individuals affected in 20253. Two of the breaches behind that shift, the Change Healthcare incident in 2024 and the Conduent Business Services incident in 2025, combined for almost 255 million affected individuals between them3, which is most of why the percentage of people affected moved so much further than the percentage of incidents.
None of that data specifically names insurance agency virtual assistants as a category, and it would be dishonest to claim otherwise. What it does establish, with real numbers rather than a guess, is that the business associate layer of the healthcare data chain is where breach exposure is concentrating, year over year, at both the incident level and the people-affected level. A VA who never signed a business associate agreement is operating inside that exact layer with none of the paper trail, training requirement, or safeguard obligation that a signed agreement would have required.
The consequence when something goes wrong runs in two directions at once. HHS OCR treats a missing or deficient business associate agreement as evidence of a systemic compliance failure on the covered entity's side, not a minor oversight, and OCR's enforcement actions against business associates themselves have produced real financial penalties in cases where PHI moved through an unauthorized party. Separately, and often faster than any federal investigation, a carrier that discovers an agent let an unvetted third party handle PHI without the required agreement can terminate that agent's appointment for cause under the same downstream entity chain described in the last section. Losing an appointment over a paperwork failure that had nothing to do with how well you actually sold the plan is a genuinely avoidable outcome.
Check what your own VA setup is actually doing
You do not need to guess which side of this line your own agency sits on. Pull up whatever contract or onboarding paperwork you signed with your VA, whether that was a staffing agency, a marketplace listing, or a direct hire, and look for three specific things.
First, is there a business associate agreement at all, under that name or a close equivalent, separate from the general services contract or non-disclosure agreement. A standard NDA is not a substitute. An NDA protects confidential business information generally. A business associate agreement has to establish the specific permitted uses and disclosures of PHI, require appropriate safeguards, require reporting of breaches and security incidents back to you, and bind the business associate's own subcontractors to the same terms, per the structure HIPAA's own regulations require of the agreement.
Second, does the contract or the vendor's own marketing ever use the words HIPAA, PHI, or business associate at all. A staffing marketplace or freelance listing that never mentions health information in its terms is telling you, indirectly, that health information handling was never part of what they built their compliance posture around, whatever their salespeople say on a call.
Third, ask the vendor directly whether their own staff receive HIPAA-specific training, separate from general customer service training, and whether they can name who their own subcontractors are. If your VA works through a team lead who reports to an offshore agency that itself contracts individual VAs, each layer in that chain is a business associate of the one above it under 45 CFR 160.103's subcontractor language1, and a vendor who cannot describe their own subcontracting structure cannot honestly tell you who else has touched your clients' information.
It helps to know exactly what a real business associate agreement is supposed to require, since that is the checklist to hold a vendor's paperwork against. 45 CFR 164.504(e) spells out the specific obligations: the contract has to establish the permitted and required uses and disclosures of PHI, require the business associate to use appropriate safeguards, require the business associate to report back any use or disclosure not provided for by the contract, including breaches of unsecured PHI, require the business associate to ensure its own subcontractors agree to those same restrictions, and require the business associate to return or destroy all PHI it holds once the contract ends6. A one-page confidentiality clause folded into a general services agreement does not cover any of that. If a vendor hands you something calling itself a BAA that skips the subcontractor flow-down clause or the breach reporting requirement, it is missing exactly the pieces this article is about.
Separate from the contract itself, HIPAA's Security Rule requires every covered entity and business associate to "implement a security awareness and training program for all members of its workforce (including management)"7. A signed BAA with no actual training behind it is a document, not a safeguard. Ask whether the vendor can show you what that training covers and how often it runs, not just whether the contract mentions it.
Consider what this looks like on an ordinary Medicare book. An agency hires one VA through a general marketplace to manage the CRM and handle renewal outreach. That same VA, through the marketplace's own staffing model, is also working part-time for two other insurance agencies in the same city, unrelated to your carrier relationship, because that is how the marketplace's pricing works and nobody on the agency side asked about exclusivity. Nothing about that arrangement is unusual or malicious. It does mean a single individual is handling PHI on behalf of multiple, unrelated covered entities' downstream chains at once, with a single generic contract standing in for what should be a specific business associate agreement with each one. That is exactly the kind of arrangement a carrier's own FDR audit is built to catch, and exactly the kind of arrangement most agencies have never once thought to ask their VA about.
A pattern worth checking for specifically
Many general VA marketplaces built for e-commerce, real estate, or general executive assistance never designed their onboarding, contracts, or infosec practices around health information at all, because most of their client base does not need it. That is not a knock on the platform. It means an insurance agency hiring through one of those general marketplaces is very likely the first client that vendor has ever needed a real business associate agreement from, which is exactly the situation where the paperwork gets skipped by default rather than by anyone's deliberate choice.
The state layer HIPAA doesn't cover
HIPAA is not the only rule in play, and treating it as the whole picture misses a second obligation that applies even to agencies that write no health business at all. The NAIC's Insurance Data Security Model Law requires a licensee to "exercise due diligence in selecting its Third-Party Service Provider and shall require a Third-Party Service Provider to implement appropriate administrative, technical, and physical measures to protect and secure the Information Systems and Nonpublic Information" the provider can access4. As of the NAIC's own August 2025 government affairs brief, 28 of the NAIC's 56 U.S. jurisdictions had adopted the model in some form4, which means a licensed agent in one of those states carries this due diligence duty regardless of whether the VA ever touches a single piece of protected health information.
"Nonpublic information" under the model law is a broader category than PHI. It covers personal identifying information tied to any line of business, life and annuity included, not just health lines. An agent operating in an adopting state who hands CRM access, client contact records, or policy details to a VA vendor without any documented evaluation of that vendor's security practices is exposed under this model even on a book with zero Medicare or ACA business. This is the piece that makes the topic bigger than HIPAA alone: a life-only agency in an NAIC Model 668 state still owes its clients a documented due diligence process for any third party touching their data, VAs included.
| Rule | Triggers on | Applies to |
|---|---|---|
| HIPAA business associate rule (45 CFR 160.103) | PHI specifically: health status, plan, claims, or benefit details tied to an identifiable person | Medicare, ACA, and group health business, nationwide |
| NAIC Insurance Data Security Model Law due diligence duty | Nonpublic information generally: any personal or business data a third party can access | Any line of business, in the 28 of 56 jurisdictions that have adopted the model |
How to actually fix this
None of this requires expensive tooling to start correcting, and most of the fix is a documentation and vetting exercise you can run this month. The order matters, because each step narrows what you actually need to worry about.
Inventory what your VA actually touches, task by task. Write down every recurring task on your VA's plate and check it against the business associate trigger list earlier in this article. Some tasks, like managing a purely life or P&C pipeline, will not touch PHI at all. Others, like anything involving a Medicare or ACA client's plan or health details, will.
Get a real business associate agreement in place for anyone touching PHI. If your current VA vendor cannot sign one, that is your answer about whether they are the right vendor for that specific task, not a reason to skip the requirement. A vendor built for HIPAA-adjacent work should be able to produce a BAA template without you having to draft one yourself.
Ask about the subcontractor layer explicitly, and get it in writing. A signed agreement with the company at the top of the chain does not automatically bind a subcontractor two layers down unless the agreement says so. Confirm the flow-down language exists before you assume it does.
Document a due diligence review of the vendor, separate from the BAA itself, in NAIC Model 668 states. Even a simple written record, what you asked, what they answered, when you checked, satisfies the due diligence expectation far better than an undocumented gut check, and it is the artifact a state examiner or a carrier audit would actually ask to see.
Limit what a VA can see in the first place. Role-based CRM permissions that hide health status notes and plan details from a VA whose job does not require them shrink the entire problem before any paperwork question comes up. A VA who schedules appointments does not need to see the reason for the appointment. Most CRMs already support this level of field permission; most agencies have simply never turned it on.
You can do the inventory and vetting steps yourself
None of the first four steps above require a developer or a new platform. An afternoon spent listing your VA's actual tasks, pulling your current contract, and emailing your vendor three direct questions gets you most of the way to knowing where you stand. Where agencies usually stall is the CRM permissions step, since most people have never opened that settings menu, and the ongoing discipline of re-checking the vendor relationship every time the VA's job changes.
How we build this correctly
Our own VA + AI support is built around removing the guesswork described above rather than asking an agency to trust a staffing vendor's paperwork on faith. Anything that touches real client data on a build we run passes through Ambrose first, which masks protected health information before any AI model without a signed business associate agreement ever sees it, then re-hydrates the record afterward for the person who actually needs it5. That keeps the PHI exposure question answered at the infrastructure layer, once, rather than depending on every VA and every AI tool in a workflow having its own current agreement in place.
Paired with that, we provide trained virtual assistants who handle the insurance-specific administrative work agencies actually need done, CRM hygiene, pipeline and task management, website updates, and the routine back-office work that eats a producer's selling hours, working inside that same PHI-aware architecture instead of a generic marketplace hire with no health-information posture at all. Custom builds, including this kind of PHI-safe VA and automation setup, are scoped and priced on a call rather than sold as one fixed package, since what a Medicare-heavy agency needs masked and gated looks different from what a life-only agency needs at all.
The point of pairing a trained VA with automation, rather than leaving a VA to work a raw CRM login all day, is that the automation is doing the part of the job that should never have depended on a person's paperwork in the first place. Database reactivation, renewal reminders, and pipeline task management can run through workflows that never expose the underlying health detail to a human at all, with a VA stepping in for the judgment calls a workflow cannot make. That shrinks the actual surface area of PHI a VA vendor's own compliance posture has to cover, instead of asking one general-purpose contractor to be the safeguard for everything at once.
What you get
Concretely, an agency that works through this gets a documented answer to a question that almost never comes up until a carrier audit, a state examination, or a breach forces it, which is who exactly is allowed to see a client's health information and what they signed before they were allowed to see it. It gets CRM permissions that actually match who needs to see what, instead of every VA having the same blanket access a producer has. And for agencies that route PHI-adjacent work through a masked, gated architecture instead of a raw CRM login, it gets a setup where the compliance question is answered once at the infrastructure level rather than re-litigated every time a VA vendor's own paperwork lapses. None of that is a promise that a breach becomes impossible, and we are not going to pretend it is. It is the difference between an unanswered question sitting in your workflow and a documented one.
When this isn't your problem
If your book is entirely life insurance, final expense, or property and casualty, with no Medicare, ACA, or group health business at all, the specific HIPAA business associate mechanism in this article does not apply to you, because there is no protected health information for your VA to touch in the first place. Depending on your state, the NAIC due diligence duty covering nonpublic information more broadly may still apply, which is worth checking once rather than assuming away entirely. And if you have no VA at all, and every task in your agency runs through you or a W-2 employee under your own direct supervision, the business associate question described here largely does not arise, since the regulation is specifically about arrangements with outside parties, not internal staff acting under your own direct control.
Questions agents ask
Does a virtual assistant need to sign a HIPAA business associate agreement?
Yes, if the VA creates, receives, maintains, or transmits protected health information on behalf of a covered entity, or on behalf of an agent acting as a business associate of one. HIPAA's own definition at 45 CFR 160.103 lists the triggering functions directly: claims processing, billing, benefit management, practice management, and similar work performed with PHI. If a VA does any of that for a Medicare, ACA, or group health book, a signed business associate agreement is a legal requirement, not a best practice.
Can an independent contractor virtual assistant even sign a BAA?
Nothing in HIPAA blocks an individual contractor from signing one. A business associate agreement is a contract between whoever is disclosing PHI and whoever is receiving it, and 45 CFR 160.103 does not condition that status on employment classification. What actually stops many VA arrangements is that the staffing marketplace or agency supplying the VA was never built with a compliance program, a signed BAA template, breach reporting procedures, or subcontractor oversight in place, so nobody on their side is prepared to countersign one even though nothing in the law prevents it.
Is my insurance agency itself a HIPAA covered entity?
Usually not directly. HIPAA's covered entities are health plans, health care providers who transmit certain information electronically, and health care clearinghouses. An independent agent is typically neither. What pulls an agent into HIPAA's chain is acting as a business associate of a carrier, which is a covered entity, whenever the agent creates, receives, or handles PHI on that carrier's behalf, such as enrollment assistance, benefit verification, or renewal follow-up involving plan and health details.
What is a downstream entity, and does it apply to me as an agent?
Under 42 CFR 422.2, CMS defines a downstream entity as any party with a written arrangement below the level of the agreement between a Medicare Advantage organization and a first tier entity, providing administrative or health care services related to the MA benefit. An independent agent selling Medicare Advantage or Part D for a carrier typically fits that definition, since the agent's contract sits below the carrier's own direct agreement with CMS.
What actually happens if my VA has a data breach and never signed a BAA?
The covered entity, meaning the carrier whose PHI was exposed, and the agent who let an unauthorized party handle it, both carry exposure. HHS OCR investigates business associate involvement in breaches regardless of whether a BAA existed, a missing agreement is treated as evidence of a systemic compliance failure rather than a paperwork gap, and OCR's own enforcement actions against business associates have produced financial penalties for exactly this pattern. Separately, a carrier that discovers an unauthorized downstream party handling PHI without a BAA can terminate the agent's appointment for cause.
Does the NAIC Insurance Data Security Model Law apply even if HIPAA doesn't?
It can. The NAIC's Insurance Data Security Model Law, adopted in some form in 28 of the NAIC's 56 U.S. jurisdictions as of the NAIC's own August 2025 count, requires a licensee to exercise due diligence in selecting a third-party service provider and to require that provider to implement administrative, technical, and physical safeguards for nonpublic information, a category broader than HIPAA's protected health information and one that covers life, annuity, and property lines too, in states that have adopted the model.
What should I actually ask a VA vendor before hiring them?
Ask directly whether they will sign a business associate agreement, ask to see their own written information security policy, ask whether their staff receive HIPAA-specific training, and ask what happens contractually if their own subcontractor causes a breach, since 45 CFR 160.103 makes a business associate's subcontractor a business associate in its own right. A vendor that cannot answer these plainly, or treats the question as unusual, is telling you something important before you sign anything.
How does Ambrose avoid this problem?
Our own build routes anything touching real client data through Ambrose first, which masks protected health information before any AI model without a signed BAA ever sees it, then re-hydrates the record afterward for the person who actually needs it. That keeps the masking and access control at the infrastructure layer instead of depending on every VA vendor's own paperwork being current.
What specifically has to be in a real HIPAA business associate agreement?
45 CFR 164.504(e) spells it out: the contract must establish the permitted and required uses and disclosures of PHI, require the business associate to use appropriate safeguards, require it to report back any use or disclosure outside the contract, including breaches of unsecured PHI, require it to bind its own subcontractors to the same restrictions, and require it to return or destroy all PHI once the contract ends. A generic confidentiality clause or non-disclosure agreement covers none of that specifically.
Sources
- Legal Information Institute, Cornell Law School, mirroring 45 CFR 160.103: definition of "business associate," listing claims processing, data analysis, billing, benefit management, practice management, and repricing as triggering functions, and providing that a subcontractor of a business associate that creates, receives, maintains, or transmits PHI on the business associate's behalf is itself a business associate. Verified live 2026-09-15. law.cornell.edu.
- Legal Information Institute, Cornell Law School, mirroring 42 CFR 422.2: definitions of "first tier entity" and "downstream entity" under the Medicare Advantage program, describing the written-arrangement chain below an MA organization's direct CMS contract. Verified live 2026-09-15. law.cornell.edu.
- HIPAA Journal (Steve Alder). "Business Associates Face Increased Regulatory Scrutiny as Vendor Breaches Soar," published June 15, 2026: business associate involvement averaged 20% of reported healthcare data breaches 2009 to 2017, rose to a 34% average 2018 to 2026, and reached 43% in the first six months of 2026; individuals affected by business-associate-involved breaches rose from 5% in 2015 to 65% in 2025; Change Healthcare (2024) and Conduent Business Services (2025) combined for nearly 255 million affected individuals. Verified live 2026-09-15. hipaajournal.com.
- National Association of Insurance Commissioners. "The NAIC Insurance Data Security Model Law," government affairs brief, August 2025: 28 of the NAIC's 56 U.S. jurisdictions had adopted Model #668 as of this brief; the model requires a licensee to exercise due diligence in selecting a third-party service provider and to require that provider to implement administrative, technical, and physical safeguards for information systems and nonpublic information. Verified live 2026-09-15. content.naic.org.
- Strategic AI Architects. AI Expert / custom build service page: "Anything that touches real client data runs through Ambrose, which masks protected health information before any non-BAA AI model ever sees it, then re-hydrates it for you." Verified live 2026-09-15. strategicaiarchitects.com/ai-expert.
- Legal Information Institute, Cornell Law School, mirroring 45 CFR 164.504(e): required contents of a business associate contract, including permitted and required uses and disclosures, safeguards, reporting of breaches and security incidents, subcontractor flow-down of the same restrictions, and return or destruction of PHI at termination. Verified live 2026-09-15. law.cornell.edu.
- Legal Information Institute, Cornell Law School, mirroring 45 CFR 164.308(a)(5): security awareness and training standard requiring a security awareness and training program for all members of a covered entity's or business associate's workforce, including management. Verified live 2026-09-15. law.cornell.edu.
Talk it through
Want a second pair of eyes on it?
Free 30 minutes. Bring what you found, or bring nothing and we will look together at how AI engines read your site and which fixes move first.
See what your own site and workflow are actually doing
Run the free Audit, a live AEO Audit plus a HIPAA tracking scan of your site, in under a minute.
Related reading: why your agency's virtual assistant isn't working · why your GoHighLevel BAA doesn't make your funnel HIPAA safe · is pasting a client's info into ChatGPT a HIPAA violation