Last updated: May 2026
Zedtreeo provides healthcare staffing in roles that may handle Protected Health Information (PHI): medical billers and coders, prior-authorization specialists, virtual medical assistants, healthcare RCM staff, and HIPAA compliance support. This page describes the operational controls we put in place for those engagements, the boundary between Zedtreeo’s responsibilities and the client’s, and the language we deliberately do not use in our marketing.
HIPAA is a U.S. federal regulation that applies to covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates. There is no central HIPAA certification body: the Department of Health and Human Services (HHS) does not issue HIPAA certificates, and no third-party body can grant a binding “HIPAA compliant” status that exempts a participant from enforcement.
For that reason, you will not see Zedtreeo describe itself as “HIPAA certified” or, without important qualification, “HIPAA compliant.” HIPAA compliance is a continuously maintained operational program tied to the specific PHI flows of a specific covered entity. We position our role as a HIPAA-aligned business associate that supports that program; the covered entity owns ultimate compliance responsibility under 45 CFR §§ 164.306, 164.308, 164.310, and 164.312.
Before any Zedtreeo professional accesses PHI, we execute a Business Associate Agreement with the client (or with the client’s designated covered entity). The BAA covers:
Clients who cannot or will not sign a BAA cannot route PHI to Zedtreeo professionals. We turn down those engagements rather than proceed informally.
Every Zedtreeo professional placed in a HIPAA-scoped engagement:
For roles that touch PHI, the standard technical baseline includes:
These are baseline controls. Specific engagements may require additional technical measures driven by the client’s Security Rule risk assessment under 45 CFR § 164.308(a)(1)(ii)(A).
We maintain a documented incident response plan covering detection, containment, eradication, recovery, and post-incident review. If Zedtreeo discovers an incident that may constitute a breach of unsecured PHI:
Where Zedtreeo engages subcontractors that may receive PHI (for example, infrastructure providers), we maintain executed BAAs and assess their security postures before onboarding. Material vendor changes that affect PHI handling are reviewed before they go live.
Zedtreeo’s responsibility:implement the business-associate-side controls described above; train and supervise placed professionals; honor BAA obligations; notify on suspected incidents; cooperate with the covered entity’s audits.
The covered entity’s responsibility:maintain the overall HIPAA compliance program (Privacy Rule, Security Rule, Breach Notification Rule); conduct and document the Security Rule risk analysis; configure access permissions inside client-controlled systems; oversee minimum-necessary use of PHI; report breaches to HHS, affected individuals, and (where required) media; and remediate findings from OCR investigations.
We deliberately do not market Zedtreeo as a substitute for the covered entity’s compliance program. We are part of the control environment, not the whole of it.
On request, in connection with an active engagement, we provide:
We do not publish detailed control documentation publicly because that documentation is itself security-sensitive. Active or prospective clients with a signed mutual NDA can review the full control set with our compliance contact.
This page is a description of operational practice, not a HIPAA certification. It is not a representation that any particular engagement will satisfy every requirement of the Privacy, Security, or Breach Notification Rules — that is a function of the specific engagement design, the covered entity’s program, and the controls implemented for the actual PHI flow. We update this page as our practices evolve.
Compliance questions, BAA requests, and incident reports relating to active engagements:
Zedtreeo LLC
1021 E Lincolnway, Suite #6596
Cheyenne, WY 82001, USA
Email: contact@zedtreeo.com
Phone: +1-725-977-3776
For background on the engagement model, see the hire remote medical staff page or healthcare & telemedicine industry overview.