🇮🇳 India 🇺🇸 US
Healthcare SEO AI search (AIO) Local SEO & Google Business Profile Content marketing Performance marketing Google Ads Meta Ads Email & SMS marketing Reputation management Website design Branding YouTube & video Marketing consulting
Dental practices Pediatric practices Primary care Med spas Dermatology IVF & fertility Dallas (HQ) Houston New York All US cities and specialties
US healthcare marketing statistics Med spa consumer behavior report Dental patient experience report Google benchmarks: 9 specialties Free tools All US research US case studies
Software
Healthcare practices Pharma Medical devices
About Ichelon Consulting US How we work Santosh Reddy, Director Ravi Kumarraju, Partner & Director
Book a call with the US team Call +1 (724) 612-3694
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · HIPAA by practice size

HIPAA compliance for MSOs and management companies

A management services organization that runs billing, IT, scheduling or marketing for affiliated practices is usually a HIPAA business associate of each practice. The practices remain covered entities with their own obligations. The MSO is directly liable for the Security Rule and for using PHI the way its business associate agreements allow, and much of the risk sits in shared services, shared marketing and data that crosses from one practice to another.

Guide for US practice owners · Published October 4, 2026

TL;DR
  • Most MSOs are business associates, not covered entities. Each affiliated practice stays a covered entity.
  • You need a BAA with every practice and BAAs with your own subcontractors that handle PHI.
  • Business associates are directly liable for Security Rule compliance and for uses and disclosures outside the BAA.
  • Using one practice’s patient data to market another practice is a disclosure that needs a legal basis. Keep data separated.
  • Business associates must report breaches to the practice without unreasonable delay and within 60 days of discovery, or sooner if the BAA says so.
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Ichelon Consulting US
  • Dallas, Texas LLC
  • 10-person US client team · Central Time (CST)
  • 25+ US healthcare clients
  • BAA signed with every client
  • HIPAA compliance training across client and delivery teams
  • Contracts and invoices in USD
How we work with US practices →
Trusted by US practices · case studies → 25+ US clients · 8 shown · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Status

Covered entity or business associate?

Short answer: in the typical structure, the practices are covered entities and the MSO is their business associate.

Many physician and dental groups use an MSO structure because state corporate practice of medicine or dentistry rules limit who can own a practice. Licensed clinicians own the professional entity, and the MSO, which can have lay or investor owners, provides everything except clinical care under a management services agreement. Under 45 CFR 160.103, an organization that performs functions involving PHI on behalf of a covered entity is a business associate. Billing, scheduling, IT, call center and marketing services all qualify.

Two exceptions are worth checking with counsel. If the MSO itself provides care and bills for it, it may be a covered health care provider. If it converts nonstandard data into standard electronic transactions for the practices, it may meet the definition of a health care clearinghouse, which is also a covered entity.

Since the 2013 Omnibus Rule, business associates are directly liable for complying with the Security Rule, for uses and disclosures not permitted by their BAA, for breach notification to the covered entity and for getting BAAs from their own subcontractors. "We are just the management company" is not a defense.

The BAA chain

The BAA chain: up to each practice, down to every subcontractor

Short answer: one BAA with each practice, one with each subcontractor, and the terms should line up.

AgreementBetweenWhat to get right
Upstream BAAEach practice and the MSOPermitted uses (including marketing services), breach reporting deadline, who handles patient notification, return or destruction of data, audit rights
Downstream BAAsThe MSO and each subcontractorTerms at least as protective as the upstream BAA, the same or shorter reporting deadline, subcontractor’s own subcontractors
Management services agreementEach practice and the MSOWhich compliance tasks the MSO performs (risk analysis support, training, policies) and which stay with the practice

Under 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery. Many practices ask for a shorter deadline in the BAA. Make sure your subcontractor BAAs give you enough time to meet it.

Data separation

Keeping each practice’s data separate

Short answer: shared systems are fine. Shared access to every practice’s patients is the risk.

  • Logical separation in shared systems. The EHR, phone system and CRM can be shared, with data tagged by practice and roles that limit who sees which practice.
  • Minimum necessary for MSO staff. A billing specialist needs claims data, not call recordings. A marketing analyst needs booking status and lead source, not charts (164.502(b)).
  • Unique logins and audit logs for MSO staff, reviewed on a schedule (164.312(a) and (b)).
  • Offboarding a practice. When a practice leaves, the BAA should say how its data is returned or destroyed and how long the MSO keeps any copy.
  • Data location. For practices with Texas patients, Texas SB 1188 requires electronic health records stored on or after January 1, 2026 to be kept physically in the United States or a US territory. Check where your hosting and backup vendors store data.
Shared marketing

Shared marketing: where MSOs get into trouble

Short answer: the MSO often runs marketing for every practice, which is efficient, but patient data must still be used practice by practice.

  • Cross-practice patient lists. Sending a dermatology practice’s patients an offer from an affiliated med spa uses one covered entity’s PHI for another’s marketing. Under 164.501 and 164.508(a)(3), that generally needs authorization unless an exception applies. Build consented lists instead.
  • One tag inventory for every brand’s website. MSOs often run dozens of practice websites. Keep ad pixels off booking flows, intake forms and portals on all of them, with one approved tag set. See the HIPAA-safe website tracking guide.
  • Central call team. Recordings are PHI for whichever practice the caller contacted. Use the strictest state recording rule your callers are in and announce recording.
  • Ad platforms. Google does not offer a BAA for Google Analytics, and Meta’s Business Tools Terms prohibit sending health information. Measure bookings in your own systems and send only signals that carry no PHI.
  • Texting. Promotional texts need TCPA consent for each practice’s list; see the healthcare SMS compliance guide.
  • Consumer health data laws. Website visitor data that is not PHI may still be covered in Washington (My Health My Data Act), Nevada and Connecticut, and as sensitive personal information under California’s CCPA.

MSOs choosing between running an all-in-one automation platform in-house and hiring a healthcare marketing team should read our criteria-based comparison.

Program

The MSO compliance program in practice

  1. Officers: the MSO names a privacy official and a security official for its own workforce and systems. Each practice designates its own, even if an MSO employee fills the role under contract.
  2. Risk analysis: the MSO analyzes its shared systems and supports each practice’s analysis of its own environment. Update both when systems change or a practice joins (164.308(a)(1)).
  3. Policies: MSO policies for its workforce, plus a standard policy set the practices can adopt. Write down which policies belong to whom.
  4. Training: MSO staff trained as business associate workforce, by role. For Texas, Health and Safety Code 181.101 requires training within 90 days of hire and a signed statement kept six years, and Chapter 181 defines covered entity broadly enough to include business associates.
  5. Incident response: one process for all practices, with clear handoffs so each practice can meet its own notification duties.
  6. Documentation: keep it six years (164.316(b)(2)).

Ichelon Consulting US works as a business associate for practices and management companies. We sign a BAA with every US client, our client-facing and delivery teams hold HIPAA compliance training certificates, and our US client team works from Dallas, Texas. Read how we work, see our US research or book a call.

HIPAA by practice size

Find the guide for your size and structure

HIPAA compliance as you scale

The pillar: what changes from one office to a private-equity-backed platform.

Solo practice

One office, one owner, a handful of staff and a short vendor list.

Multi-location practice

Several offices, shared systems, a central phone team and location managers.

Private-equity-backed platform

Acquisitions every quarter, inherited systems and diligence on every deal.

HIPAA compliance by role

What owners, practice managers, front desk and marketing staff each need to do.

Sources

Sources

  1. 45 CFR 160.103, definitions (business associate, covered entity, health care clearinghouse).
  2. 45 CFR 164.504(e), business associate contracts; 164.502(e), disclosures to business associates.
  3. 45 CFR 164.410, notification by a business associate.
  4. 45 CFR 164.508, authorizations; 164.501, definition of marketing.
  5. 45 CFR 164.105, affiliated covered entities.
  6. Business associates (HHS guidance).
  7. Texas Health and Safety Code 181.001; 181.101.
  8. Texas SB 1188, enrolled text (2025).
  9. HIPAA and Google Analytics (Google); Meta Business Tools Terms (Meta).
  10. Chapter 19.373 RCW, Washington My Health My Data Act.

Not legal advice: this guide describes common HIPAA practice for management services organizations. It is not legal advice. Entity structures and state corporate practice rules vary, so confirm your obligations with healthcare counsel.

Keep reading

Related pages from the US team

HIPAA compliance as you scale

How the program changes from one office to a platform.

Choosing a vendor that signs a BAA

What to ask a marketing vendor before it touches PHI.

HIPAA compliance by role

Training and duties by job.

Agency vs all-in-one automation platform

How MSOs choose between running tools and hiring a team.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

Is an MSO a HIPAA covered entity?

Usually not. An MSO that provides administrative, billing, IT or marketing services to practices handles PHI on their behalf, which makes it a business associate. It could be a covered entity in its own right if it provides care and bills for it, or if it acts as a health care clearinghouse by converting nonstandard data into standard transactions. Have counsel confirm your status.

Does the MSO or the practice notify patients after a breach?

The practice, as the covered entity, is responsible for notifying individuals, HHS and, where required, the media. The MSO must notify the practice without unreasonable delay and no later than 60 days after discovering the breach. The BAA can delegate notification tasks to the MSO and set a shorter reporting deadline.

Can an MSO run one marketing CRM for all its practices?

Yes, if it is set up carefully. Each practice’s patient data should be separated, used for that practice’s purposes as its BAA allows, and accessible to staff by role. Pooling patient lists so one practice’s patients receive another practice’s marketing is a disclosure that generally needs patient authorization or another legal basis.

Who should be the privacy officer, the MSO or the practice?

Both. Each practice, as a covered entity, must designate a privacy official and a security official. The MSO, as a business associate, should name its own officials for its workforce and systems. The MSO can supply a person to fill the practice roles under contract, but the practice remains responsible.

What subcontractors does an MSO need BAAs with?

Any vendor that creates, receives, maintains or transmits PHI on the MSO’s behalf: cloud hosting, EHR and practice management, phone and call recording, texting, CRM, IT and security providers, document storage and the marketing agency. Each needs a business associate agreement with the MSO.

Can affiliated practices share one Notice of Privacy Practices?

Sometimes. Entities under common ownership or control can designate themselves as a single affiliated covered entity, and organized health care arrangements can use a joint notice. Many MSO-affiliated practices are not commonly owned in the legal sense because of corporate practice of medicine rules, so confirm with counsel.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Running marketing for several practices?

A 30-minute call with the US team. We will review how leads, call recordings and patient lists move between your practices and your shared systems.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership