🇮🇳 India 🇺🇸 US
Healthcare SEO AI search (AIO) Local SEO & Google Business Profile Content marketing Performance marketing Google Ads Meta Ads Email & SMS marketing Reputation management Website design Branding YouTube & video Marketing consulting
Dental practices Pediatric practices Primary care Med spas Dermatology IVF & fertility Dallas (HQ) Houston New York All US cities and specialties
US healthcare marketing statistics Med spa consumer behavior report Dental patient experience report Google benchmarks: 9 specialties Free tools All US research US case studies
Software
Healthcare practices Pharma Medical devices
About Ichelon Consulting US How we work Santosh Reddy, Director Ravi Kumarraju, Partner & Director
Book a call with the US team Call +1 (724) 612-3694
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · HIPAA by practice size

HIPAA compliance as you scale: what changes from one office to a platform

The HIPAA rules are the same for a solo dentist and a 60-location dermatology platform. What changes as you grow is how many people, systems, vendors and legal entities touch patient information. A program that lives in one owner’s head works for one office. At five offices it needs named owners and written processes. At a platform level it needs an inventory, an audit trail and a diligence routine for every acquisition.

Guide for US practice owners · Published October 4, 2026

TL;DR
  • The core obligations do not change with size: risk analysis, risk management, a privacy official and a security official, training, policies, BAAs and breach notification apply at every stage.
  • What changes is how often you reassess, who owns each control and how you prove it. Every new location, system or acquisition is a change that should trigger a risk analysis update.
  • Multi-location groups need role-based access, one vendor and BAA inventory, and one rule for who may add tools to the website.
  • MSOs and PE platforms add entity structure questions (who is the covered entity, who is the business associate) and M&A diligence: inherited BAAs, legacy systems, breach history and old tracking pixels.
  • State laws stack on top of HIPAA: Texas Health and Safety Code Chapter 181, Texas SB 1188, Washington’s My Health My Data Act and California’s CMIA and CCPA are the common ones for growing groups.
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Ichelon Consulting US
  • Dallas, Texas LLC
  • 10-person US client team · Central Time (CST)
  • 25+ US healthcare clients
  • BAA signed with every client
  • HIPAA compliance training across client and delivery teams
  • Contracts and invoices in USD
How we work with US practices →
Trusted by US practices · case studies → 25+ US clients · 8 shown · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
The short answer

What stays the same and what changes

Short answer: the obligations stay the same at every size, and the way you meet them has to change. A solo practice can meet HIPAA with one owner who knows every system and vendor. A group with ten offices, a central phone team and three marketing vendors cannot. It needs written policies that everyone follows, named owners for each control and records that prove the work was done.

These obligations apply to every covered health care provider, whatever its size:

  • Risk analysis and risk management under 45 CFR 164.308(a)(1)(ii)(A) and (B): an accurate and thorough assessment of risks to electronic PHI, and security measures that reduce those risks to a reasonable and appropriate level.
  • A security official under 164.308(a)(2) and a privacy official plus a contact person for complaints under 164.530(a).
  • Workforce training under 164.530(b) and a security awareness program under 164.308(a)(5), covering everyone including management.
  • Policies and procedures, a sanctions policy for staff who break them, and a periodic evaluation of whether the program still fits (164.308(a)(8)).
  • Business associate agreements with every vendor that creates, receives, maintains or transmits PHI for you (164.308(b) and 164.504(e)).
  • Breach notification to affected individuals, to HHS and, for breaches affecting more than 500 residents of a state, to the media (164.400 to 164.414). Breaches affecting fewer than 500 people are reported to HHS within 60 days after the end of the calendar year; larger ones are reported at the same time as individual notice.
  • Documentation kept for six years from creation or the date it was last in effect, whichever is later (164.316(b)(2) and 164.530(j)).

The table below shows how the same obligations look at four common stages. Each stage has its own guide: solo practice, multi-location practice, MSO or management company and private-equity-backed platform.

Size tier × controls

How each control changes by size

ControlSolo practiceMulti-location groupMSO / management companyPE-backed platform
Risk analysisAnnual review plus updates when systems change; owner and one advisor can run itOne enterprise analysis with a walkthrough of each location; update on every opening or system changeCovers the MSO’s own shared systems; supports each client practice’s analysisEnterprise analysis plus a pre-close assessment of every target and a post-close update
Privacy and security officersOwner or office manager holds both rolesOne accountable officer; privacy liaison at each locationMSO names its own officers; each practice still designates its ownDedicated compliance function; officers report to leadership or the board
PoliciesShort written set adapted to the officeOne group-wide set with location addenda; version controlMSO policies plus a clear split of duties in each BAAStandard policy set adopted by each acquired practice within a fixed window after close
TrainingAt hire and when policies change; sign-in sheet or certificate keptRole-based modules; tracked in a learning systemMSO staff trained as business associate workforce; role-basedCentral learning system; new acquisitions onboarded on a schedule
Vendor and BAA inventoryA list of perhaps 10 to 20 vendors with signed BAAs on fileOne central inventory; locations cannot add vendors on their ownBAAs up to each practice and down to subcontractorsInherited BAAs reviewed for assignment, expiry and overlap; consolidated after close
Access controlUnique logins; no shared passwordsRole-based access by location; central teams get cross-location access by roleAccess to each practice’s data limited to the services in its BAAIdentity management across entities; quarterly access reviews
Marketing dataNo PHI to ad platforms; BAAs with forms, phone and texting vendorsOne tag inventory per website; central approval for new toolsMSO often runs marketing for all practices; governs tracking and CRM centrallyWebsite and tracking audit for every acquired brand; legacy pixels removed
State law overlayHome state onlyEvery state with a location or patientsEvery state of every client practiceMapped per state at diligence; transaction notice laws in some states
Risk analysis

Risk analysis cadence: when to reassess

Short answer: reassess fully once a year and update the analysis every time something material changes. Growth is a series of material changes.

The Security Rule requires "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information" (164.308(a)(1)(ii)(A)). It does not say "annually". It does require the analysis to reflect your real environment, and HHS has made risk analysis a specific enforcement focus through its Risk Analysis Initiative, which has produced a string of settlements with organizations of every size, including software vendors and accounting firms acting as business associates.

Events that should trigger an update in a growing organization:

  • Opening or acquiring a location, or moving an office.
  • Changing EHR, practice management, phone, texting, CRM or scheduling systems.
  • Setting up a central call center or moving staff to remote work.
  • Adding a marketing vendor that will handle call recordings, form data or patient lists.
  • Any security incident, even one that turns out not to be a reportable breach.

Two developments are worth tracking. First, HHS published a proposed update to the Security Rule on January 6, 2025 (90 FR 898). Among other changes, it would require a written technology asset inventory and network map, make most addressable specifications required, and require regular review of the risk analysis. It is a proposal, not a final rule, at the time of writing. Groups that are growing anyway can build the inventory now, because it makes every later step easier. Second, a 2021 amendment to the HITECH Act (Public Law 116-321) requires HHS to consider whether an organization had recognized security practices, such as the NIST Cybersecurity Framework or the HHS 405(d) Health Industry Cybersecurity Practices, in place for the previous 12 months when it decides on fines and remedies. A documented program that has been running for a year counts for something if you ever face an investigation.

People

Privacy and security officers at each stage

Short answer: every covered entity must name both officers. As you grow, the question shifts from "who" to "with what authority and how much time".

  • Solo: the owner or office manager usually holds both roles. That is allowed. Write the designation down and keep it with your policies.
  • Multi-location: one accountable privacy officer and one security officer (often your IT lead or managed IT provider’s named contact), with a privacy liaison at each office who takes questions, collects incident reports and runs local training sign-offs.
  • MSO: the MSO names officers for its own workforce and systems. Each practice it serves is still a covered entity and must designate its own officials, even if the person filling the role is supplied by the MSO under contract. Write that arrangement into the services agreement and the BAA.
  • PE platform: a compliance function with a budget, reporting lines to senior leadership or the board, and a plan for each acquired practice’s officers during integration.

Legally separate covered entities under common ownership or control can designate themselves as a single affiliated covered entity under 45 CFR 164.105(b), documented in writing and kept for six years. That lets a group of commonly owned practices run one HIPAA program. Many physician groups owned through an MSO and affiliated professional corporations do not have common ownership in the legal sense, because of state corporate practice of medicine rules, so ask counsel whether the designation is available to you before relying on it.

Policies and training

Policies and training that survive growth

Short answer: one policy set, with location addenda where offices genuinely differ, and role-based training tracked in one place.

A common failure in growing groups is policy drift. Each acquired or newly opened office keeps its own binder, and nobody knows which version is current. Fix it with a single, version-controlled policy set, a short addendum for each location covering what is truly local (the layout of the front desk, the local phone setup, which state laws apply), and an annual review date.

HIPAA requires training for each new workforce member "within a reasonable period of time" after joining, and again after material policy changes (164.530(b)). Texas adds its own rules for anyone operating there: under Texas Health and Safety Code 181.101, employees must be trained on state and federal PHI law within 90 days of hire, must sign a statement confirming the training, the covered entity must keep those statements for six years, and staff must be retrained within a year of a material change in the law. Growing groups usually move to role-based training: front desk and call center staff need different scenarios than billing, clinical or marketing staff. Our HIPAA compliance by role guide breaks this down by job.

Vendors

The vendor and BAA inventory

Short answer: keep one list of every vendor that touches PHI, with the signed BAA, what data it holds, where that data is stored and who can approve a new one.

A solo practice might have a dozen vendors with access to PHI. A ten-location group can easily have fifty once you count the EHR, clearinghouse, phone system, call recording, texting, online scheduling, intake forms, review requests, CRM, IT provider, shredding service, answering service and marketing agency. Useful fields for each entry:

  • Vendor, service and the internal owner of the relationship.
  • Types of PHI it touches (demographics, appointment data, call audio, clinical notes, payment data).
  • BAA signed date, version and renewal or termination terms; the subcontractors it uses.
  • Where data is stored. Texas SB 1188 requires covered entities to keep electronic health records of Texas residents physically in the United States or a US territory for records stored on or after January 1, 2026.
  • How data is returned or destroyed when the contract ends.

Remember the vendors that will not sign a BAA. Google states that it "makes no representations that Google Analytics satisfies HIPAA requirements and does not offer Business Associate Agreements in connection with this service." Meta’s Business Tools Terms prohibit sending health information. The rule for those tools is simple: configure them so PHI never reaches them. HHS guidance also treats a cloud provider that stores electronic PHI as a business associate even when the data is encrypted and the provider has no key. Our guide to choosing a marketing vendor that signs a BAA lists the questions to ask.

Access

Centralized vs location-level access

Short answer: centralize the systems, not the access. Give each person the minimum access their role needs, and give central teams cross-location access by role, with an audit trail.

Growth usually brings centralization: one EHR instance, one phone system, a central scheduling team. That is good for patients and for security, as long as access follows the minimum necessary standard (164.502(b) and 164.514(d)) and the Security Rule’s access control and audit control standards (164.312(a) and (b)). Texas SB 1188 adds a state rule that electronic health record information of Texas residents be accessible to people who need it for treatment, payment or health care operations duties.

  • Unique user IDs for everyone. Shared front-desk logins destroy the audit trail you need after an incident.
  • Role templates. Front desk at location A sees location A’s schedule. The central call team sees every schedule but not clinical notes. Marketing staff see lead and booking data, not charts.
  • Quarterly access reviews and same-day removal when someone leaves. Staff turnover across many offices is where stale accounts pile up.
  • Information system activity review (164.308(a)(1)(ii)(D)): someone actually looks at the logs on a schedule.
Acquisitions

M&A diligence: what you inherit

Short answer: when you buy a practice, you inherit its HIPAA history. Diligence should find the problems before close and the integration plan should fix them within a set window after.

A practical diligence request list:

  1. The most recent risk analysis, risk management plan and evidence of remediation.
  2. The breach and incident log for at least six years, including small breaches reported to HHS in annual submissions, and any OCR complaints, investigations or state attorney general inquiries.
  3. Every BAA, with assignment and change-of-control clauses checked. Some cannot be assigned without consent.
  4. Systems inventory, including end-of-life software and servers that cannot be patched, and the plan for migrating or retiring them, including how long legacy records must be kept.
  5. Every website and landing page the practice has run, with the tracking pixels and session recording tools on them, current and historical.
  6. Patient contact lists used for marketing, with records of consent for texts and calls.
  7. Call recording practices and disclosures, especially for calls with patients in all-party consent states.
  8. Workforce training records and signed Texas training statements where applicable.

Transaction rules are also tightening at the state level. Oregon requires notice to the Oregon Health Authority of material change transactions at least 180 days before the proposed effective date, and California requires notice of certain transactions to its Office of Health Care Affordability. These are not HIPAA requirements, but they change deal timelines and the diligence record you will want to show.

Marketing data

Marketing data governance across locations

Short answer: marketing is where growing groups leak PHI most often, because every location manager wants their own tools. Put tracking, call recording and CRM under one set of rules.

Tracking technologies

HHS published guidance on online tracking technologies in December 2022 and updated it in March 2024. In June 2024, in American Hospital Association v. Becerra, a federal court in Texas vacated the part of that guidance that treated a combination of an IP address and a visit to an unauthenticated public page about a health condition as PHI. The rest of the picture is unchanged: tracking on patient portals, booking flows and intake forms can disclose PHI, and sending it to a vendor without a BAA is a problem. Keep one tag inventory per domain, one consent configuration, and a rule that no one adds a pixel without approval. Our HIPAA-safe website tracking guide covers the setup.

Call recordings

Call recordings contain names, dates of birth and reasons for visit, so the recording vendor needs a BAA. State recording laws vary: California, Florida and Washington, for example, require consent from all parties, while Texas requires the consent of one party. A central call team taking calls from several states should use the stricter rule and announce recording on every call.

CRM and patient communications

A CRM that stores appointment or treatment information is holding PHI. It needs a BAA and role-based access. Keep treatment and appointment communications separate from marketing campaigns: under 164.501 and 164.508(a)(3), many communications about your own services are not "marketing", but a communication paid for by a third party is, and that needs patient authorization. Text campaigns also need consent under the Telephone Consumer Protection Act; see our TCPA guide for healthcare SMS.

Ad platforms

Google’s personalized advertising policy treats health as a sensitive category and restricts how advertisers can target it. Meta filters data it categorizes as potentially sensitive health information from its ad systems and its terms prohibit sending it. Build campaigns around location and broad interest audiences, measure bookings in your own systems, and send ad platforms aggregated or de-identified conversion signals. See Google Ads healthcare policy for detail.

State laws

State privacy laws that stack on HIPAA

Short answer: HIPAA sets a floor. As you add states, you add laws that either cover health data HIPAA does not, or add duties for data it does.

  • Washington, My Health My Data Act (RCW 19.373): covers "consumer health data" that is not HIPAA PHI, such as data from website visitors who are not yet patients. It requires consent to collect and share that data, a separate signed authorization to sell it, and a published consumer health data privacy policy. It bans geofences within 2,000 feet of an in-person health care location used to track people or send them ads. Most obligations applied from March 31, 2024 (June 30, 2024 for small businesses), and consumers can sue under the state Consumer Protection Act.
  • Nevada and Connecticut passed consumer health data laws in 2023 with similar consent requirements. Nevada’s has no private right of action.
  • Texas, Health and Safety Code Chapter 181: defines "covered entity" more broadly than HIPAA, including anyone who comes into possession of PHI. It adds the training rules above and requires notice to patients that their PHI may be disclosed electronically (181.154).
  • Texas SB 1188 (2025): electronic health records of Texas residents must be physically stored in the US for records stored on or after January 1, 2026, with access limited to treatment, payment and operations duties. It also requires practitioners who use AI for diagnostic purposes to disclose it to patients.
  • Texas Data Privacy and Security Act: in force since July 1, 2024; it exempts HIPAA covered entities and business associates, so it matters mainly for non-HIPAA affiliates such as a wellness brand or retail arm.
  • California: the Confidentiality of Medical Information Act applies to providers alongside HIPAA. The CCPA, as amended by the CPRA, exempts PHI and CMIA medical information but treats other personal information "collected and analyzed concerning a consumer’s health" as sensitive personal information, which can include marketing and website data a larger group collects.

If you advertise in these states, our state guides cover the advertising side: Texas, Washington and California.

Marketing partners

What to expect from a marketing partner as you scale

A marketing partner for a growing group touches call recordings, form submissions, booking data and sometimes the CRM. Expect a BAA before any data moves, HIPAA-trained staff, a written list of the tools it will put on your websites, and reporting built on bookings measured inside your systems rather than on data sent to ad platforms.

Ichelon Consulting US is the US practice of Ichelon Consulting Group, a healthcare-only marketing agency since 2018. We sign a BAA with every US client, our client-facing and delivery teams hold HIPAA compliance training certificates, and our 10-person US client team in Dallas works Central Time. Read how we work, see our US research, or ask for a free practice visibility audit.

HIPAA by practice size

Find the guide for your size and structure

Solo practice

One office, one owner, a handful of staff and a short vendor list.

Multi-location practice

Several offices, shared systems, a central phone team and location managers.

MSO or management company

A management company serving affiliated practices, usually as a business associate.

Private-equity-backed platform

Acquisitions every quarter, inherited systems and diligence on every deal.

HIPAA compliance by role

What owners, practice managers, front desk and marketing staff each need to do.

Sources

Sources

  1. 45 CFR 164.308, administrative safeguards (risk analysis, risk management, security official, training, evaluation, BAAs).
  2. 45 CFR 164.530, administrative requirements (privacy official, training, documentation retention).
  3. 45 CFR 164.408, notification to the Secretary; 164.406, notification to the media.
  4. 45 CFR 164.105, affiliated covered entities.
  5. 45 CFR 164.312, technical safeguards; 164.514(d), minimum necessary; 164.508, authorizations.
  6. HIPAA Security Rule proposed rule, 90 FR 898 (Federal Register, January 6, 2025).
  7. HHS OCR settlement announcements under the Risk Analysis Initiative (HHS press room).
  8. Recognized security practices, HITECH Act section 13412 (HHS).
  9. Guidance on HIPAA and cloud computing (HHS).
  10. Texas Health and Safety Code 181.101, training; 181.001, definitions; 181.154, notice of electronic disclosure.
  11. Texas SB 1188, enrolled text (89th Legislature, 2025).
  12. Texas Data Privacy and Security Act (Texas State Law Library).
  13. Chapter 19.373 RCW, Washington My Health My Data Act; Washington Attorney General guidance.
  14. Nevada and Connecticut consumer health data laws (McDermott Will & Emery summary).
  15. California Civil Code 1798.140, sensitive personal information (CCPA as amended).
  16. Oregon Health Care Market Oversight FAQ (Oregon Health Authority).
  17. Portions of OCR’s tracking technologies bulletin vacated (summary of AHA v. Becerra, June 20, 2024).
  18. HIPAA and Google Analytics (Google); Personalized advertising policy (Google).
  19. About sensitive health information and Meta Business Tools Terms (Meta).

Not legal advice: this guide explains how HIPAA programs typically change as healthcare organizations grow. It is not legal advice. Laws and guidance change, and entity structures differ, so confirm your obligations with healthcare counsel.

Keep reading

Related pages from the US team

HIPAA compliance by role

What owners, managers, front desk and marketing staff each need to do.

HIPAA-compliant healthcare marketing

Marketing under HIPAA: authorizations, tracking and BAAs.

HIPAA-safe website tracking

How to measure a healthcare website without sending PHI to ad platforms.

Choosing a marketing vendor that signs a BAA

What to ask before a vendor touches patient data.

Agency vs all-in-one automation platform

A criteria-based comparison for practice owners.

All US guides

Marketing and compliance guides for US practices.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

Do HIPAA requirements change as a practice gets bigger?

The rules themselves do not. The Privacy, Security and Breach Notification Rules apply the same way to a solo office and a large group. What changes is scale: more workforce members to train, more systems to assess, more vendors needing business associate agreements, and more legal entities whose roles must be documented.

How often should a growing practice update its HIPAA risk analysis?

HIPAA does not set a fixed frequency. It requires an accurate and thorough risk analysis that is kept current. In practice that means a full review at least once a year and an update whenever something material changes, such as opening a location, switching EHR or phone systems, adding a call center or closing an acquisition.

Can one privacy officer cover several locations?

Yes. HIPAA requires each covered entity to designate a privacy official and a security official, and one person can hold both roles. Groups with several offices usually keep one accountable officer and name a privacy liaison at each location who handles day-to-day questions and escalates incidents.

Is a management services organization a covered entity or a business associate?

Usually a business associate. An MSO that provides billing, IT, marketing or administrative services to affiliated practices handles PHI on their behalf, so it signs BAAs with each practice. The practices remain the covered entities. Your counsel should confirm this for your structure.

What HIPAA issues come up in healthcare acquisitions?

The common ones are an out-of-date or missing risk analysis, unreported or poorly documented breaches, BAAs that cannot be assigned or have expired, legacy systems that cannot be patched, tracking pixels on old websites and marketing lists without documented consent.

Do state privacy laws apply if we already comply with HIPAA?

Often, yes. Several state laws exempt HIPAA-protected health information but still cover other health data, such as website visitor data that is not PHI. Texas also has its own medical privacy law with a broader definition of covered entity and its own training rules.

Does a marketing agency need a BAA with a multi-location practice?

If the agency will create, receive, maintain or transmit PHI, such as call recordings, form submissions tied to appointments or CRM records, it is a business associate and needs a BAA. Ichelon Consulting US signs a BAA with every US client.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Growing to more locations?

A 30-minute call with the US team. We will review how patient data moves through your marketing, from website forms to call recordings and your CRM, and show you what we would change first.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership