🇮🇳 India 🇺🇸 US
Healthcare SEO AI search (AIO) Local SEO & Google Business Profile Content marketing Performance marketing Google Ads Meta Ads Email & SMS marketing Reputation management Website design Branding YouTube & video Marketing consulting
Dental practices Pediatric practices Primary care Med spas Dermatology IVF & fertility Dallas (HQ) Houston New York All US cities and specialties
US healthcare marketing statistics Med spa consumer behavior report Dental patient experience report Google benchmarks: 9 specialties Free tools All US research US case studies
Software
Healthcare practices Pharma Medical devices
About Ichelon Consulting US How we work Santosh Reddy, Director Ravi Kumarraju, Partner & Director
Book a call with the US team Call +1 (724) 612-3694
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · HIPAA compliance guide

HIPAA compliance by role: a four-stage framework for every person and vendor in your practice

To keep a practice HIPAA compliant, put every person and company that touches patient information through the same four stages: Onboard (train, clear and sign), Access (give each role the minimum it needs), Operate (handle PHI the same safe way every day) and Offboard (remove access, recover devices, return or destroy data). What changes from role to role is the detail inside each stage, not the stages themselves. This guide maps those details for the roles a med spa, dental office, primary care clinic or specialty group actually has, inside the building and outside it.

Guide for US practice owners · Published October 4, 2026

TL;DR
  • HIPAA requires you to train every workforce member on your privacy policies as needed for their job (45 CFR 164.530(b)) and to run a security awareness program that includes management (164.308(a)(5)).
  • Access should follow the minimum necessary standard (164.502(b)) and the Security Rule's access controls: unique user IDs, emergency access, audit controls and authentication (164.312).
  • Any outside company that creates, receives, maintains or transmits PHI for you needs a Business Associate Agreement before it gets data (164.502(e), 164.504(e)). Your marketing agency is on that list if it handles PHI.
  • Offboarding is where small practices slip. OCR has settled cases where a former employee kept login access and where PHI went to a vendor with no BAA.
  • A 2024 federal court ruling narrowed part of OCR's tracking-technology guidance for public web pages. The rest of the guidance stands, so ad pixels still stay off booking, portal and form pages.
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Ichelon Consulting US
  • Dallas, Texas LLC
  • 10-person US client team · Central Time (CST)
  • 25+ US healthcare clients
  • BAA signed with every client
  • HIPAA compliance training across client and delivery teams
  • Contracts and invoices in USD
How we work with US practices →
Trusted by US practices · case studies → 25+ US clients · 8 shown · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
The framework

Four stages, every role, inside and outside the practice

Short answer: HIPAA compliance fails at handoffs. A new hire starts before training is done. A vendor gets a patient list before anyone signs a BAA. A former coordinator still has the booking app on her phone. The four-stage model closes those gaps by asking the same four questions about every person and every company that touches protected health information (PHI).

Stage 1

Onboard

Check the person or vendor before PHI changes hands. Background check where your state and policy allow, role-based training, signed confidentiality agreement for staff, signed Business Associate Agreement (BAA) for vendors.

Stage 2

Access

Give each role the least access it needs. Unique logins, role-based permissions, multi-factor authentication (MFA), device rules, audit logs that someone actually reviews.

Stage 3

Operate

Handle PHI the same way every day: front desk, phones, texting, email, social media, online reviews, marketing data, and a clear path for reporting incidents fast.

Stage 4

Offboard

End access on the last day. Recover keys, badges and devices. For vendors, terminate the BAA properly and get PHI returned or destroyed, with written confirmation.

The stages come straight from the regulations. Stage 1 maps to the Privacy Rule training standard (45 CFR 164.530(b)), the Security Rule workforce clearance procedure (164.308(a)(3)(ii)(B)) and the business associate contract rules (164.502(e) and 164.504(e)). Stage 2 maps to information access management (164.308(a)(4)), technical access controls (164.312) and the minimum necessary standard (164.502(b)). Stage 3 maps to Privacy Rule safeguards (164.530(c)), security incident procedures (164.308(a)(6)) and breach notification (164.400–414). Stage 4 maps to termination procedures (164.308(a)(3)(ii)(C)) and the requirement that a BAA end with PHI returned or destroyed where feasible (164.504(e)(2)(ii)(J)).

If you want the broader marketing picture first (authorizations, testimonials, ads), start with our HIPAA-compliant healthcare marketing guide and come back here for the people side.

Who is covered

Who counts as "workforce" and who counts as a "business associate"

Short answer: if you direct how someone works, they are workforce, paid or not. If an outside company handles PHI on your behalf, it is a business associate. The two groups get different paperwork but the same four stages.

HIPAA defines workforce as employees, volunteers, trainees and other people whose conduct, in the performance of work for a covered entity, is under the covered entity's direct control, whether or not they are paid (45 CFR 160.103). That pulls in a lot of people practices forget: the student shadowing a provider, the part-time aesthetician paid per treatment, the office manager's relative who helps with filing on Saturdays, and often a locum provider working under your policies.

A business associate is a person or company that creates, receives, maintains or transmits PHI on your behalf to perform a function or service for you. Typical examples in a practice: your EHR and practice management vendor, online booking, patient texting and email tools, call tracking and call recording, a CRM that stores leads, a review-request tool fed with patient contact details, an IT managed service provider with admin access, a billing company, a shredding company, and a marketing agency that touches any of this. Subcontractors of business associates that handle your PHI are business associates too, and your vendor must have its own BAA with them (164.502(e)(1)(ii)).

Two categories sit outside the BAA requirement. Other health care providers receiving PHI for treatment are not your business associates (160.103). And HHS says a BAA is not required with people such as janitorial staff or electricians whose work does not involve PHI, where any exposure is incidental and reasonable safeguards are in place. Pure transmission services like the postal service fall under the narrow "conduit" exception, which does not cover companies that store PHI or access it regularly.

The roles this guide covers

  • Internal: front desk and patient coordinators; providers (MD, DO, NP, PA, RN, aestheticians); practice manager or owner; marketing staff; billing staff.
  • External: marketing agency; software vendors (EHR, booking, CRM, call tracking, review tools); IT or managed service provider; contractors and locum providers; cleaning and facilities.
The matrix

Roles × stages: what each stage means for each role

Short answer: print this table, put a name next to each row and review it every quarter. Each row links to a deeper page where we have one.

Role1 · Onboard2 · Access3 · Operate4 · Offboard
Front desk / patient coordinatorsBackground check per policy; training before first shift; signed confidentiality agreementScheduling, demographics, insurance, check-in; no clinical notes unless the job needs them; MFA on EHR and booking appSign-in sheets, phone verification, appointment reminders, texting rules, overheard conversations, wrong-recipient emailsDisable EHR, booking, phone system, shared inboxes and texting app on the last day; collect keys and badge
Providers (MD, NP, PA, RN, aestheticians)Credential and license check; training that covers photos and personal devices; confidentiality agreementClinical access for their patients; treatment disclosures are exempt from minimum necessary, but chart browsing is not allowedBefore-and-after photos, personal phones, social media, talking to media, curbside consults by textRemove EHR and e-prescribing access; delete PHI and photos from personal devices; confirm in writing
Practice manager / ownerDesignated privacy and security official (164.530(a), 164.308(a)(2)); deeper trainingAdmin rights with a second admin account for emergencies; reviews access logsRisk analysis, policies, vendor file, sanctions, breach decisions, documentation kept six yearsHand over admin credentials and vendor list; rotate shared passwords; transfer privacy/security official role
Marketing staffTraining on PHI in marketing, authorizations, tracking tech; confidentiality agreementDe-identified or aggregate reports by default; lead and CRM data only if the role requires itReviews, testimonials, photos, email lists, ad audiences, pixels, call recordingsRemove ad accounts, CRM, social logins, website admin; transfer ownership of business accounts
Billing staffBackground check per policy; training on payment data and patient requestsBilling, claims and payment screens; clinical detail limited to what coding needsStatements, collections calls, payer portals, faxing, verifying identity on the phoneDisable payer portals, clearinghouse, payment processor and EHR; rotate any shared payer logins
Marketing agencyBAA signed before any PHI; proof of staff training; data-flow mapNamed users on your accounts; agency never shares logins; PHI scoped to the workPHI kept out of ad platforms; forms and call tracking on BAA-covered tools; breach notice termsReturn or destroy PHI; transfer ad, analytics and website ownership back to the practice
Software vendors (EHR, booking, CRM, call tracking, reviews)BAA; security questionnaire; subcontractor listRole-based permissions configured by you; MFA enforced; audit logs availablePatch and uptime notices; breach notice within the BAA's timeline (60 days at the outside under 164.410)Export your data; confirm deletion or extend protections where deletion is not feasible
IT / managed service providerBAA; background checks on technicians with admin rightsNamed admin accounts, MFA, remote-access logging; no shared "admin" loginBackups, patching, encryption, device inventory, incident response with youRotate every admin and service password; revoke remote tools; collect documentation
Contractors and locum providersDecide: workforce (under your direct control) or separate provider; train and sign accordinglyTime-limited accounts with an end date set at creationYour policies apply while they work under your directionAccounts expire automatically; confirm no PHI left on personal devices
Cleaning and facilitiesUsually no BAA (incidental access); confidentiality clause in the service contractNo system access; after-hours access to areas without exposed PHILocked records rooms, locked shred bins, screens off or locked at nightCollect keys and alarm codes; change codes
Stage 1

Stage 1 · Onboard: check, train and sign before PHI changes hands

Short answer: nobody, inside or outside, should see PHI until three things are done: you have checked them, they have been trained for their role, and the right agreement is signed.

Background and clearance

The Security Rule asks you to have a workforce clearance procedure, so you can determine that a person's access to electronic PHI is appropriate (164.308(a)(3)(ii)(B)). It is an "addressable" specification, which means you must implement it if it is reasonable and appropriate for your practice, or document why not and what you do instead. HIPAA does not require criminal background checks by name. Many practices run them for anyone with system access, subject to state law and any employment rules that apply to you. Providers also need license verification, which you are doing for credentialing anyway.

Role-based training

The Privacy Rule requires you to train all workforce members on your PHI policies "as necessary and appropriate" for their functions, to train new members within a reasonable period after they join, to retrain people whose jobs are affected by a material policy change, and to document the training (164.530(b)). Separately, the Security Rule requires a security awareness and training program for all workforce members, including management, with addressable pieces on security reminders, malware, log-in monitoring and password management (164.308(a)(5)).

"Role-based" is the part most practices skip. A generic video satisfies nobody. A front desk coordinator needs to rehearse identity checks on the phone and what to say when a spouse calls. An aesthetician needs the photo rules. A marketing coordinator needs to know why a review reply cannot confirm someone is a patient. We give role scripts on each role page in this series.

Signed agreements

  • Staff: a confidentiality agreement and acknowledgment of your policies, signed on day one. HIPAA does not mandate a specific form, but it gives you a record and supports sanctions if needed.
  • Vendors: a Business Associate Agreement before any PHI moves. The BAA must spell out permitted uses, require safeguards, require breach reporting, flow requirements down to subcontractors, give HHS access to relevant records and require return or destruction of PHI at the end (164.504(e)(2)). HHS publishes sample BAA provisions you can compare a vendor's paper against.
  • Locums and contractors: decide whether they work under your direct control. If yes, treat them as workforce: train them and have them sign your confidentiality agreement. If they are a separate provider treating your patients, treatment disclosures do not need a BAA, but you still control what system access they get.
OCR case: a vendor with no BAA. Raleigh Orthopaedic Clinic in North Carolina paid $750,000 after handing x-ray films and related PHI for about 17,300 patients to a company that offered to digitize them, without a BAA in place. The corrective plan required a process for deciding who is a business associate and a named person responsible for getting BAAs signed before disclosure.
Stage 2

Stage 2 · Access: the minimum each role needs, and proof of who did what

Short answer: set permissions by role, give everyone their own login with MFA, and review access logs often enough that snooping gets caught.

Minimum necessary

When you use or disclose PHI, you must make reasonable efforts to limit it to the minimum necessary for the purpose (164.502(b)). For your own staff, that means identifying which roles need which categories of PHI and limiting access to match (164.514(d)). There are exceptions, most importantly disclosures to a provider for treatment, so a provider treating a patient can see the chart. The rule still bites on everyone else: billing does not need full clinical notes, the marketing coordinator does not need charts at all, and nobody needs to browse records out of curiosity.

Technical access controls

  • Unique user IDs (required). Every person gets their own login so activity can be traced (164.312(a)(2)(i)). Shared front-desk logins break this.
  • Emergency access procedure (required). A documented way to reach PHI if the normal path fails (164.312(a)(2)(ii)). Keep a break-glass admin account, sealed and logged.
  • Automatic logoff and encryption (addressable). Short idle timeouts on workstations at the front desk and in treatment rooms; encryption on laptops, phones and backups (164.312(a)(2)(iii)–(iv)).
  • Audit controls (required standard). Systems that record activity on ePHI, and someone who looks at the records (164.312(b)).
  • Person or entity authentication. Procedures to verify that whoever is logging in is who they claim to be (164.312(d)). Current rules do not name MFA, but it is the practical way to meet this standard for cloud systems reachable from anywhere.

About MFA and the proposed Security Rule update. HHS published a proposed rule on January 6, 2025 that would, among other changes, make MFA and encryption explicit requirements and remove the "addressable" category. As of October 2026 the Federal Register shows it as a proposed rule with no final rule published. Treat MFA as expected practice now; don't wait for a final rule.

Device rules

Decide in writing which devices can hold PHI. Common rules: practice-owned devices for anything clinical; personal phones allowed only for approved apps that keep PHI inside the app (EHR mobile app, secure messaging), never the camera roll or standard text messages for clinical detail; screen lock and remote wipe enrolled; no PHI on personal email or personal cloud storage. Device and media controls are part of the Security Rule's physical safeguards (164.310(d)).

OCR case: access nobody needed. Yakima Valley Memorial Hospital in Washington paid $240,000 after 23 emergency department security guards used their own logins to look at 419 patients' records they had no job reason to see. The corrective plan required a risk analysis, policy updates, better training and a review of vendor relationships.
Stage 3

Stage 3 · Operate: daily handling of PHI, channel by channel

Short answer: most violations at small practices are not hacks. They are ordinary moments handled badly: a review reply, a text to the wrong number, a patient list shared with a vendor. Write a rule for each channel and practice it.

ChannelThe ruleWhere it goes wrong
Front desk and waiting roomSign-in that does not show the reason for visit; screens angled or filtered; lower voices for sensitive details. HIPAA allows incidental disclosures if you apply reasonable safeguards (164.530(c)).Open sign-in sheets with procedure names; calling out full names with treatment; charts face-up at check-in.
PhonesVerify identity with two identifiers before discussing anything. Check the patient's recorded preferences for who may receive information. Voicemail: minimum details, callback number.Confirming appointments to whoever calls; leaving procedure details on a shared home voicemail.
TextingAppointment reminders with minimal content; clinical detail only in a secure messaging tool covered by a BAA. Marketing texts need prior written consent under TCPA rules, separate from HIPAA.Providers texting photos from personal phones; reminders that name the procedure.
EmailHHS says providers may email patients with reasonable safeguards: check addresses, limit content, and honor a patient's request for another channel. Use encryption or a portal for anything detailed.Autocomplete sending a lab result to the wrong "Sarah"; staff forwarding PHI to personal email to work from home.
Social mediaNo patient stories, photos or comments without a signed HIPAA authorization. Staff personal accounts: no posts about patients, even unnamed ones who could be recognized."Fun day with this celebrity client!"; a treatment room photo with a chart in the background.
Online reviewsReply without confirming the person is a patient or mentioning any treatment detail. Take the conversation offline. See our guide to responding to negative reviews under HIPAA.Defending the practice by correcting the patient's account with clinical facts. OCR has settled several of these.
Marketing dataUsing PHI for marketing generally needs the patient's written authorization (164.508(a)(3)). Keep PHI out of ad platforms and analytics; use aggregate or de-identified data for reporting.Uploading patient lists to build ad audiences; pixels on booking pages sending procedure names.
Incident reportingOne named contact, one simple form, report within hours, no blame for reporting. The practice decides whether it is a breach, not the person who made the mistake.Staff hide the mistake because they fear being fired; the 60-day clock runs out unnoticed.

Breach notification: the clocks you need to know

  • To patients: without unreasonable delay and no later than 60 calendar days after you discover a breach of unsecured PHI (164.404(b)).
  • To HHS: for 500 or more people, at the same time as patient notice; for fewer than 500, log it and report within 60 days after the end of the calendar year (164.408).
  • To the media: when a breach involves more than 500 residents of a state or jurisdiction (164.406).
  • From your vendors: a business associate must tell you without unreasonable delay and no later than 60 days after discovery (164.410). Most practices negotiate a much shorter window in the BAA, because your own clock may start when the vendor knew.

State breach laws can add shorter deadlines or attorney general notice. Your incident plan should list them for every state where your patients live.

Website tracking: where the 2024 court ruling left things

In December 2022 OCR issued a bulletin on online tracking technologies, updated in March 2024. On June 20, 2024, the U.S. District Court for the Northern District of Texas (American Hospital Association v. Becerra) vacated the part of the guidance that said HIPAA applies when a tracker collects an IP address combined with a visit to an unauthenticated public page about a health condition or provider. HHS filed an appeal and then withdrew it in late August 2024, so that ruling stands. The rest of the bulletin was not vacated: tracking on patient portals, booking flows and other authenticated or PHI-bearing pages still needs a BAA with the tracking vendor or patient authorization, and many ad platforms will not sign one. Our HIPAA-safe website tracking guide covers the page-by-page setup, and our guides to HIPAA-safe Google Ads and HIPAA-safe Meta ads cover campaigns.

OCR case: review replies. Elite Dental Associates in Dallas paid $10,000 after responding to Yelp reviews with patients' names and health details, and for lacking a policy on social media disclosures. Manasa Health Center in New Jersey paid $30,000 after disclosing four patients' PHI in replies to negative Google reviews.
Stage 4

Stage 4 · Offboard: end access on the last day and get the data back

Short answer: keep a written list of every system each person and vendor can reach, and work through it on the last day. The list is the control. Without it, something always gets missed.

The Security Rule asks for procedures to terminate access to ePHI when employment or another arrangement ends (164.308(a)(3)(ii)(C)). For vendors, the BAA itself must require that at termination the business associate return or destroy all PHI it still holds and keep no copies, or, if that is not feasible, extend the BAA's protections to what remains (164.504(e)(2)(ii)(J)). The BAA must also let you terminate if the vendor violates a material term (164.504(e)(2)(iii)).

  • Staff: EHR, practice management, booking, phone system and voicemail, shared inboxes, texting tools, cloud drives, payer portals, social and ad accounts, building access, alarm codes. Remove personal-device access and confirm PHI is deleted from them.
  • Vendors: export your data, get written confirmation of return or destruction (including from subcontractors), revoke API keys and integrations, and transfer ownership of anything that should belong to you, such as ad accounts, analytics properties, domains and call-tracking numbers.
  • Records: keep training logs, signed agreements, BAAs and policies for six years from creation or from when they were last in effect (164.530(j)(2)).
OCR case: the login that outlived the job. Pagosa Springs Medical Center in Colorado paid $111,400 after a former employee kept remote access to a web-based scheduling calendar containing patients' ePHI, and the practice had no BAA with the calendar vendor. In a much larger case, Memorial Healthcare System in Florida paid $5.5 million after the login of a former employee at an affiliated physician office was used to access ePHI daily for about a year without detection.

Our HIPAA offboarding checklist has the full printable list for staff and vendors.

Internal roles

Internal roles: what changes for each person

Front desk and patient coordinators

They handle the most PHI with the least training time. Their risk is volume: hundreds of calls, texts and check-ins a week. Give them scripts for identity checks and for third-party callers, a short list of what never goes in a text, and a clean way to escalate. Access covers scheduling, demographics and insurance, not clinical notes. Full detail is on the front desk page.

Providers: MD, DO, NP, PA, RN, aestheticians

Treatment disclosures are exempt from the minimum necessary rule, so providers get broad clinical access. The risks are personal devices (photos and texts), social media, and speaking for the practice in public. In med spas, aestheticians and injectors often take before-and-after photos on phones; those photos are PHI and need a policy, a secure app and written authorization before any marketing use. See the provider page and our before-and-after photo compliance guide.

OCR case: talking to a reporter. Allergy Associates of Hartford in Connecticut paid $125,000 after a doctor discussed a patient's information with a TV reporter, after the practice's privacy officer had told him to say "no comment" or not respond. OCR also noted that the practice took no disciplinary action afterward.

Practice manager or owner

Someone must be designated as privacy official (164.530(a)) and security official (164.308(a)(2)). In small practices that is usually the practice manager or the owner. That person owns the risk analysis (164.308(a)(1)(ii)(A)), the policies, the vendor and BAA file, the sanctions policy (164.530(e)), the incident decisions and the six-year records. They also hold admin rights, which is why their own offboarding needs a written handover. See the practice manager page.

Marketing staff

In-house marketers rarely need PHI to do good work. Default them to aggregate and de-identified reports. When they do touch PHI (lead forms, review-request lists, testimonial releases, call recordings), the rules on authorization and tracking apply in full. See the marketing team page.

Billing staff

Billing needs demographic, insurance and coded clinical data, plus payer portals and payment tools. Limit clinical detail to what coding and claims require. Train on identity checks for balance calls, on handling patient requests for records and accountings, and on faxing to verified numbers. Payer portal logins are often shared; give each biller their own and remove them at exit.

External roles

External roles: what to require before, during and after

Marketing agency

An agency that handles lead forms, call tracking, CRM data, booking data or review requests for you is a business associate. Require a BAA before kickoff, ask which subcontractors (form tools, call tracking, hosting) will see PHI and whether each has a BAA with the agency, get a simple data-flow map, keep ownership of ad and analytics accounts in the practice's name, and make sure the BAA's breach notice window is short. Our page on what to require from agencies and vendors has the full list, and our insight on BAA vendor selection covers how to compare agencies.

Software vendors: EHR, booking, CRM, call tracking, review tools

Most healthcare-specific software vendors offer a BAA as standard. Many general-purpose business tools do not, or offer one only on certain plans. Before you connect a tool to patient data, confirm the BAA covers the plan and features you use, that you can enforce MFA and role-based permissions, that audit logs exist, and how you get your data out at the end. Review tools deserve special care because they are often fed patient names and phone numbers from the EHR.

OCR case: a software vendor as business associate. In April 2026 OCR announced a $10,000 settlement and three-year corrective action plan with a dental patient-communication software company after a 2020 breach affecting about 15 million people. OCR's findings included failing to conduct an accurate risk analysis and failing to notify the covered entities affected.

IT and managed service providers

An MSP with admin access to your network, email or backups is a business associate. Require named technician accounts, MFA on every admin tool, logging of remote sessions and a written incident response role. At the end of the relationship, rotate every admin, service and Wi-Fi password and remove remote-access agents from every machine.

Contractors and locum providers

The question is control. A locum NP working your schedule under your policies is workforce: train them, have them sign, give them time-limited accounts. A separate provider group reading your imaging is treating your patients and does not need a BAA for that, though you still decide what access they get. A billing contractor working from their own company is a business associate.

Cleaning and facilities

Usually not business associates, because any exposure to PHI is incidental. Your safeguards make that true: locked records rooms and shred bins, clean desks, screens locked at night. A shredding company that collects and destroys PHI is a business associate. Disposal is a real risk.

OCR case: disposal. New England Dermatology and Laser Center in Massachusetts paid $300,640 after throwing away empty specimen containers with patient labels (names, birth dates, collection dates) in a parking-lot dumpster for about ten years.
How we work

How Ichelon Consulting US runs the four stages as your external role

We are a healthcare-only marketing agency, so we sit in the "marketing agency" row of the matrix. Here is how we handle each stage with US clients:

  • Onboard: a Business Associate Agreement is signed with every US client before work starts. Our client-facing and delivery teams hold HIPAA compliance training certificates. Contracts and invoices are in USD from our Dallas, Texas LLC.
  • Access: we ask for named-user access to your ad, analytics and website accounts, not shared logins, and we scope access to the work agreed.
  • Operate: we design campaigns and tracking so PHI stays out of ad platforms: no patient lists uploaded for audiences, no pixels on booking, portal or intake pages, and forms and call handling on tools covered by a BAA.
  • Offboard: accounts are in your name from day one, so ending an engagement means removing our users and confirming return or destruction of any PHI we hold, as the BAA requires.

You can read more about our process on how we work, see our US research, or browse all US guides. If you run a med spa, our med spa marketing page, the med spa marketing statistics and the med spa Google presence report are good next reads, along with the med spa HIPAA advertising guide. Dental offices should see the dental HIPAA advertising guide. State advertising rules sit on top of HIPAA; start with our state medical board advertising guide or the Texas guide.

Rollout

A 30-day rollout for a small practice

Short answer: you do not need a consultant to start. You need a list of people, a list of systems, a list of vendors, and a month of steady work.

  1. Week 1, inventory. List every person who works for you (including volunteers, students and per-diem staff) and every system that holds PHI. List every vendor with access to PHI and whether you have a signed BAA on file.
  2. Week 2, access. Build a simple role-to-system table. Remove shared logins. Turn on MFA everywhere it exists. Remove anyone who no longer works for you. Set idle timeouts.
  3. Week 3, training and agreements. Run role-based sessions (30 to 45 minutes each), log attendance, get signed confidentiality acknowledgments, and chase every missing BAA. Stop sending PHI to any vendor that will not sign.
  4. Week 4, operate and offboard. Publish channel rules (phones, text, email, social, reviews). Name the incident contact. Write the offboarding checklist and test it on the next departure. Put a quarterly access review on the calendar.

Then update your risk analysis to reflect what you found. OCR resolution agreements repeatedly cite a missing or inaccurate risk analysis, and it is a required specification (164.308(a)(1)(ii)(A)).

Sources

Sources

Regulation text checked against the Code of Federal Regulations (Cornell LII mirror of the eCFR) in October 2026. OCR case details are from HHS announcements.

Keep reading

Related pages from the US team

HIPAA for front desk staff

The four stages for patient coordinators: phones, sign-in, texting and a printable checklist.

HIPAA for providers in med spas and practices

Photos, personal phones, social media and charting rules for MDs, NPs, PAs, RNs and aestheticians.

HIPAA for practice managers and owners

Policies, risk analysis, vendor files, sanctions and breach response for the person in charge.

HIPAA for in-house marketing teams

Reviews, testimonials, lead data, pixels and email lists without exposing PHI.

What to require from agencies and vendors

BAAs, subcontractor BAAs, data-flow maps and audit rights for every outside company.

HIPAA offboarding checklist

Same-day access removal for staff and a clean exit for vendors, with a printable list.

HIPAA compliance as you scale

What changes from a solo practice to multi-location groups, MSOs and private-equity platforms.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

What are the four stages of HIPAA compliance for staff and vendors?

Onboard, Access, Operate and Offboard. Onboard covers background checks, role-based training and signed confidentiality agreements or Business Associate Agreements. Access covers minimum necessary permissions, unique logins, multi-factor authentication and device rules. Operate covers daily handling of PHI on phones, texts, email, social media, reviews and marketing data, plus incident reporting. Offboard covers removing access the same day, recovering devices and ending vendor relationships with PHI returned or destroyed.

Does every employee need HIPAA training, even if they never see patient records?

The Privacy Rule requires training for all members of the workforce on your PHI policies as necessary and appropriate for their job, and the Security Rule requires a security awareness program for all workforce members, including management. Someone with little PHI exposure can get shorter training, but they still need to know what PHI is, what not to do with it and how to report a problem.

Is a marketing agency a HIPAA business associate?

It is if it creates, receives, maintains or transmits PHI on your behalf, for example by handling lead forms, call recordings, booking data, patient lists for email or review requests, or CRM records. In that case HIPAA requires a Business Associate Agreement before the agency gets any PHI. An agency that works only with de-identified or aggregate data may not be a business associate, but most full-service healthcare agencies touch PHI at some point.

Do cleaning crews or building maintenance need a BAA?

Usually not. HHS guidance says a BAA is not required with janitorial services or similar contractors whose work does not involve using or disclosing PHI, where any exposure is incidental and reasonable safeguards are in place. If a contractor routinely handles records or shreds documents containing PHI, it likely is a business associate.

How fast do we have to remove access when someone leaves?

The Security Rule requires procedures for terminating access when employment or another arrangement ends but does not set a number of hours. In practice, remove access on the last day, before or at the exit conversation for involuntary departures, and document it. OCR has settled cases where former employees kept access to systems with patient information.

Is this guide legal advice?

No. It explains the federal HIPAA rules and published HHS guidance at a general level for practice owners and managers. State privacy laws can add obligations, and rules change, so confirm your policies and contracts with a healthcare privacy attorney.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Want a second pair of eyes on how your marketing handles PHI?

A 30-minute call with the Ichelon Consulting US team. We will walk through your forms, tracking, call handling and vendor list and tell you what we would fix first. We sign a BAA before any engagement starts.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership