HIPAA Compliance North Carolina 2026: What the FastMed Ruling Changed

hipaa compliance north carolina

North Carolina practices face privacy liability that goes beyond HIPAA. The vendor or virtual assistant you hire is part of that exposure. A recent Business Court ruling confirmed that meeting every federal HIPAA requirement doesn’t shield you from state-level negligence claims.

HIPAA Laws in North Carolina

North Carolina healthcare practices operate under three stacked legal obligations. Most practices only account for one. 

Federal HIPAA sets the floor. Every covered entity and business associate must implement administrative, physical, and technical safeguards to protect PHI.  

North Carolina’s Identity Theft Protection Act (N.C. Gen. Stat. § 75-60) adds state breach notification requirements on top. Amendments enacted between 2023 and 2025 tightened those timelines beyond HIPAA’s 60-day window. 

The third layer is where most practices have a blind spot: NC common law. The FastMed ruling confirmed that courts will hold healthcare providers to a negligence standard for patient data handling, independent of HIPAA compliance. That’s the layer with the most vendor and staffing exposure. 

What the FastMed Ruling Actually Said

The FastMed HIPAA ruling confirmed that NC healthcare providers have a common law duty to protect patient information. In Rodriguez v. FastMed Urgent Care, Inc. (2025 NCBC 15), the North Carolina Business Court ruled that healthcare providers have a common law duty to protect patient information. 

FastMed had embedded Meta tracking tools in its patient portal without patient consent. Those tools transmitted PHI to Meta, where it was linked to Facebook accounts and used for ad targeting. FastMed moved to dismiss the case. The court refused, allowing three NC state law claims to move forward. 

The court was explicit: HIPAA standards are the benchmark for reasonable care in state negligence claims. 

A provider that meets every federal HIPAA requirement is not automatically shielded from NC state liability. It means healthcare providers should choose vendors and virtual medical assistant providers with strong privacy and security measures.

Why this applies to more than just patient portals

The FastMed case involved website tracking technology; its impact can go beyond patient portals. 

According to Parker Poe’s analysis of the decision, the court’s reasoning is not limited to o covered entities or to web-based tracking technology. 

It means any organization that creates, maintains, or transmits patient information may carry state-law exposure. It includes remote contractors, third-party vendors, and virtual medical assistants. 

Any agency that handles protected health information (PHI) must have strong privacy, proper training, and security measures.

How North Carolina’s Privacy Framework Layers on Top of HIPAA

Most HIPAA explainers think that this is the only law that protects patient information. For NC practices, it is only the starting point. Healthcare providers must follow state laws that add extra responsibilities to protect patient information. 

Federal HIPAA as the compliance floor

HIPAA applies to covered entities including healthcare providers, health plans, and clearinghouses and their business associates. It requires administrative, physical, and technical safeguards to protect ePHI. That’s the entry requirement. Every other obligation in North Carolina builds on top of it. 

NC state statutes that add requirements

  1. The North Carolina Identity Theft Protection Act (N.C. Gen. Stat. Section 75-60):

    This is a North Carolina law about protecting personal information. It requires practitioners to notify affected patients and the NC Attorney General’s office after a data breach. State amendments between 2023 and 2025 made those deadlines stricter than HIPAA’s 60-day window.

  2. NC Medical Board records rules (21 NCAC 32):

    These rules require patient records to be kept for at least 11 years. HIPAA only required 6 years of documentation. If a virtual medical assistant manages your records, their retention process must meet the NC standard.

  3. DHSR licensure rules:

    These rules apply to hospitals, surgery centers, nursing homes, and home health providers. They cover how patient information is handled at the facility level, as well as how those requirements extend to any remote staff.

Common law duty and what the FastMed ruling reinforced

NC courts recognize that healthcare providers must protect patient information. The FastMed ruling made the consequences clear. Even if a practice meets every HIPAA requirement can still face an NC state negligence claim if the court decides they didn’t take reasonable steps to protect patient data. 

State claims can include damages such as emotional distress or financial harm. This is why choosing vendors and staffing partners needs proper attention. 

What This Means When You Hire a Virtual Medical Assistant in North Carolina

Before hiring a virtual assistant into your practice, you must know their way of handling patient information. Look for trained staff, secure systems, and proper access controls. A HIPAA-trained virtual medical assistant can help manage administrative tasks while following privacy and security practices to protect PHI. 

What to verify before signing a contract

Before signing a contract with a virtual medical assistant or a staffing company, every healthcare provider needs to verify five critical compliance areas:

Business Associate Agreement scope. The BAA must cover not just the staffing agency but any subcontractors the agency uses. 

HIPAA training documentation. Ask when staff were trained, who delivered the training, and how often it is updated. Annual training with documented completion records is the standard the 2026 Security Rule assumes. 

Role-based access controls. A virtual medical assistant should only access the PHI required for their specific job. Confirm the agency uses role-based access controls (RBAC) to limit PHI access by job function. Each VMA operates under a unique user account, and multi-factor authentication (MFA) is required on every system that touches patient data.

Encryption standards. Under the 2026 HIPAA Security Rule, encryption is mandatory. Verify the vendor uses AES-256 encryption for data stored on any device and TLS 1.2 or higher for data moving between systems. 

Subcontractor flow-down. If the staffing agency uses subcontractors, BAA obligations and HIPAA requirements must apply to those subcontractors explicitly. Ask for documentation. 

Why a virtual staffing agency’s compliance posture matters as much as the individual hire’s

A virtual staffing agency’s compliance posture matters as much as an individual hire. Because it protects your business from legal liability, financial loss, and operational disruption. Under NC common law, a principal’s duty doesn’t stop at getting a signature on BAA. The healthcare practice is responsible for evaluating any third party that will handle protected health information (PHI). 

If a virtual staffing agency has weak security or poor HIPAA compliance, your practice may still be liable for a data breach or privacy violation. Choosing compliant partners helps reduce this risk. So, vetting a staffing agency’s compliance program is quite important.

The 2026 Federal Updates That Changed the Compliance Baseline

As of 2026, HIPAA’s security rules require mandatory encryption and multi-factor authentication. These requirements apply to every system responsible for handling ePHI. It also includes those systems used by remote staff. 

  • Mandatory encryption for ePHI at rest and in transit: Every device, computer, cloud platform, and software application your virtual medical assistant uses must be encrypted. It includes data stored on a device (at rest) and data being sent between systems (in transit)

  • Mandatory MFA on every ePHI-accessing system: Every system that allows access to electronic protected health information (ePHI) should require multi-factor authentication. Users must verify their identity using at least two methods, such as a password and a one-time code sent to their phone or generated by an authentication app. 
  • Annual penetration testing and biannual vulnerability scanning: Verify that the vendor performs annual penetration tests to simulate cyberattacks and biannual vulnerability scans to identify and fix security weaknesses before they can be exploited. 
  • 72-hour breach reporting to OCR for 500+ patient breaches: Inquire if the vendor has a process to report breaches affecting 500 or more individuals within 72 hours to the Office for Civil Rights (OCR) and to notify your practice promptly. 
  • Written asset inventory tied to risk analysis: Verify that the vendor maintains an up-to-date record of all devices and systems that handle ePHI and uses it to conduct regular risk assessments and address potential security risks. 

What NC Practices Should Do Now

The FastMed ruling didn’t create a new law. The ruling confirmed that healthcare practices remain responsible for protecting patient information. This applies even when staffing agencies or virtual medical assistants handle the data. Practices must show they took reasonable steps to choose a staffing partner that follows HIPAA compliance standards.

Under North Carolina common law, your responsibility does not end with your own practice. It also extends to any third party that handles patient information on your behalf, including virtual medical assistants.

That means hiring a virtual medical assistant is more than a staffing decision. You should take the time to carefully review the staffing agency’s compliance practices, training, and security measures. If a vendor is not properly vetted or does not have strong safeguards in place, your practice could still face legal claims, financial losses, and damaged reputation if patient information is compromised.

Most Frequently Asked Questions

What did the FastMed ruling mean for North Carolina healthcare providers?

The FastMed ruling confirmed that North Carolina healthcare providers are responsible for protecting patient information. A provider that meets all federal HIPAA requirements can still face state negligence liability if a court finds its data protection measures were unreasonable. HIPAA standards now function as a benchmark for reasonable care in NC state law claims.  

North Carolina practices operate under a three-tiered framework: Federal HIPAA covers compliance, the North Carolina Identity Theft Protection Act (ITPA) adds breach notification requirements with strict timelines than HIPAA’s 60-day window, and common law duty of care imposes negligence duty to protect patient data. All three must apply simultaneously. 

Yes. A virtual medical assistant who handles patient information is considered a business associate under HIPAA. They must have a signed BAA before accessing protected health information. Skipping this step can lead to federal compliance risk and state liability. 

Yes. The FastMed ruling made clear that a non-covered entity can still be held responsible for mishandling the patient information. Even if an organization is not directly covered by HIPAA, NC courts may use HIPAA to decide whether it took reasonable steps to protect patient information or not. 

Look for a staffing provider that signs a BAA agreement before giving virtual medical assistants access to patient information. The provider should also offer documented HIPAA training, role-based access controls, and secure, encrypted communication. It should have a clear process for reporting data breaches and be able to provide HIPAA compliance documentation on request. 

The 2026 HIPAA Security Rule updates require virtual medical assistant systems to use encryption and multi-factor authentication to protect patient information. They also require regular security checks and faster reporting if a major data breach occurs. 

Subscribe to Our Newsletter
Receive occasional updates, hiring insights, and practical tips on building reliable remote teams, sent only when it’s useful.

Build Your Expert Remote Team in Less Than 10 Days.
Hiring top-tier talent is simple, fast, and reliable through Remote Scouts. 100% risk-free virtual assistant staffing with top 3% vetted candidates across multiple industries and regions. No more work delays.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Begin Your Risk-Free Hiring Process
Looking for a job? View Our Current Openings.