01
A BAA before any access.
We sign a Business Associate Agreement before any access is granted. No signed agreement, no credentials — in that order, every time.
Regulatory affairs, medical writing, biostatistics, HEOR (health economics and outcomes research) and device QA/RA (quality assurance / regulatory affairs) work from submission documents, aggregate tables, de-identified datasets and quality records. They do not access patient records.
No protected health information (PHI) means no business associate agreement (BAA) and no offshore-data review.
For billing, prior authorisation and administrative roles that do touch patient data:
01
We sign a Business Associate Agreement before any access is granted. No signed agreement, no credentials — in that order, every time.
02
Access is through your systems only — no local storage, no printing, no personal devices. Nothing leaves your environment.
03
Minimum-necessary access, reviewed annually. Each person sees only what the role requires, and we check that it stays that way.
04
Suspected breach notified within 24 hours. You hear it from us first, with what we know and what we are doing about it.
We will ask whether you hold Medicaid or Medicare Advantage contracts, and whether any payer agreement restricts offshore access to PHI. Several US states — including Wisconsin, Texas and Arizona — restrict offshore handling of patient data in some programmes.
We would rather find that out on the first call than at contract stage.
Fifteen minutes is enough to know whether PHI is involved and what that means for the paperwork.