HIPAA & Business Associate Commitment
Last updated: August 20, 2026
VisitOpts is built to help home-care agencies handle Protected Health Information (PHI) responsibly. When we process PHI on an agency’s behalf, we act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA), and we sign a Business Associate Agreement (BAA) with each agency we serve.
Our role
Home-care agencies are “covered entities” (or business associates of payers) under HIPAA. When an agency uses VisitOpts to schedule visits, verify care, and submit Medicaid claims, VisitOpts stores and processes PHI — such as client names, Medicaid identifiers, addresses, service authorizations, and visit records — on the agency’s behalf. That makes VisitOpts a Business Associate, and our use and disclosure of PHI is limited to what the BAA and HIPAA permit.
Safeguards we maintain
Consistent with the HIPAA Security Rule, we maintain administrative, technical, and physical safeguards, including:
- Encryption of PHI in transit (TLS 1.2+) and at rest.
- Tenant isolation — each agency’s data is logically separated so one agency cannot access another’s records.
- Role-based access controls and unique user accounts, so staff only see what their role allows.
- Audit logging of privileged and security-relevant actions.
- Minimum necessary — we access and disclose only the PHI needed to provide the Services.
- HIPAA-eligible hosting on Amazon Web Services, under a Business Associate Addendum with AWS, using encrypted, access-controlled infrastructure.
Subcontractors
Where we use subcontractors that may handle PHI to provide the Services (for example, cloud hosting), we require them to provide safeguards and agree to obligations at least as protective as those we owe to agencies, as required by HIPAA.
Breach notification
If we discover a breach of unsecured PHI, we will notify the affected agency without unreasonable delay and in the timeframe required by HIPAA and the applicable BAA, and cooperate with the agency’s response.
What we do not do
We do not sell PHI, use PHI for advertising, or use or disclose PHI except as permitted by the BAA, HIPAA, or as required by law.
Request a Business Associate Agreement
Before your agency puts real client information into VisitOpts, we will execute a BAA with you. To request our standard BAA — or to send us yours for review — contact info@visitopts.com and we’ll get it in place.
This page describes our commitments and is provided for information; it does not by itself create a Business Associate relationship. The executed BAA governs the parties’ HIPAA obligations.
Contact
VisitOpts
151 Silver Lake Rd, Unit 2, New Brighton, MN 55112
Email: info@visitopts.com
Phone: +1 (612) 366-0002