HIPAA compliance for MSOs and management companies
A management services organization that runs billing, IT, scheduling or marketing for affiliated practices is usually a HIPAA business associate of each practice. The practices remain covered entities with their own obligations. The MSO is directly liable for the Security Rule and for using PHI the way its business associate agreements allow, and much of the risk sits in shared services, shared marketing and data that crosses from one practice to another.
- Most MSOs are business associates, not covered entities. Each affiliated practice stays a covered entity.
- You need a BAA with every practice and BAAs with your own subcontractors that handle PHI.
- Business associates are directly liable for Security Rule compliance and for uses and disclosures outside the BAA.
- Using one practice’s patient data to market another practice is a disclosure that needs a legal basis. Keep data separated.
- Business associates must report breaches to the practice without unreasonable delay and within 60 days of discovery, or sooner if the BAA says so.
- Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
- Dallas, Texas LLC
- 10-person US client team · Central Time (CST)
- 25+ US healthcare clients
- BAA signed with every client
- HIPAA compliance training across client and delivery teams
- Contracts and invoices in USD
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Covered entity or business associate?
Short answer: in the typical structure, the practices are covered entities and the MSO is their business associate.
Many physician and dental groups use an MSO structure because state corporate practice of medicine or dentistry rules limit who can own a practice. Licensed clinicians own the professional entity, and the MSO, which can have lay or investor owners, provides everything except clinical care under a management services agreement. Under 45 CFR 160.103, an organization that performs functions involving PHI on behalf of a covered entity is a business associate. Billing, scheduling, IT, call center and marketing services all qualify.
Two exceptions are worth checking with counsel. If the MSO itself provides care and bills for it, it may be a covered health care provider. If it converts nonstandard data into standard electronic transactions for the practices, it may meet the definition of a health care clearinghouse, which is also a covered entity.
Since the 2013 Omnibus Rule, business associates are directly liable for complying with the Security Rule, for uses and disclosures not permitted by their BAA, for breach notification to the covered entity and for getting BAAs from their own subcontractors. "We are just the management company" is not a defense.
The BAA chain: up to each practice, down to every subcontractor
Short answer: one BAA with each practice, one with each subcontractor, and the terms should line up.
| Agreement | Between | What to get right |
|---|---|---|
| Upstream BAA | Each practice and the MSO | Permitted uses (including marketing services), breach reporting deadline, who handles patient notification, return or destruction of data, audit rights |
| Downstream BAAs | The MSO and each subcontractor | Terms at least as protective as the upstream BAA, the same or shorter reporting deadline, subcontractor’s own subcontractors |
| Management services agreement | Each practice and the MSO | Which compliance tasks the MSO performs (risk analysis support, training, policies) and which stay with the practice |
Under 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and in no case later than 60 calendar days after discovery. Many practices ask for a shorter deadline in the BAA. Make sure your subcontractor BAAs give you enough time to meet it.
Keeping each practice’s data separate
Short answer: shared systems are fine. Shared access to every practice’s patients is the risk.
- Logical separation in shared systems. The EHR, phone system and CRM can be shared, with data tagged by practice and roles that limit who sees which practice.
- Minimum necessary for MSO staff. A billing specialist needs claims data, not call recordings. A marketing analyst needs booking status and lead source, not charts (164.502(b)).
- Unique logins and audit logs for MSO staff, reviewed on a schedule (164.312(a) and (b)).
- Offboarding a practice. When a practice leaves, the BAA should say how its data is returned or destroyed and how long the MSO keeps any copy.
- Data location. For practices with Texas patients, Texas SB 1188 requires electronic health records stored on or after January 1, 2026 to be kept physically in the United States or a US territory. Check where your hosting and backup vendors store data.
Shared marketing: where MSOs get into trouble
Short answer: the MSO often runs marketing for every practice, which is efficient, but patient data must still be used practice by practice.
- Cross-practice patient lists. Sending a dermatology practice’s patients an offer from an affiliated med spa uses one covered entity’s PHI for another’s marketing. Under 164.501 and 164.508(a)(3), that generally needs authorization unless an exception applies. Build consented lists instead.
- One tag inventory for every brand’s website. MSOs often run dozens of practice websites. Keep ad pixels off booking flows, intake forms and portals on all of them, with one approved tag set. See the HIPAA-safe website tracking guide.
- Central call team. Recordings are PHI for whichever practice the caller contacted. Use the strictest state recording rule your callers are in and announce recording.
- Ad platforms. Google does not offer a BAA for Google Analytics, and Meta’s Business Tools Terms prohibit sending health information. Measure bookings in your own systems and send only signals that carry no PHI.
- Texting. Promotional texts need TCPA consent for each practice’s list; see the healthcare SMS compliance guide.
- Consumer health data laws. Website visitor data that is not PHI may still be covered in Washington (My Health My Data Act), Nevada and Connecticut, and as sensitive personal information under California’s CCPA.
MSOs choosing between running an all-in-one automation platform in-house and hiring a healthcare marketing team should read our criteria-based comparison.
The MSO compliance program in practice
- Officers: the MSO names a privacy official and a security official for its own workforce and systems. Each practice designates its own, even if an MSO employee fills the role under contract.
- Risk analysis: the MSO analyzes its shared systems and supports each practice’s analysis of its own environment. Update both when systems change or a practice joins (164.308(a)(1)).
- Policies: MSO policies for its workforce, plus a standard policy set the practices can adopt. Write down which policies belong to whom.
- Training: MSO staff trained as business associate workforce, by role. For Texas, Health and Safety Code 181.101 requires training within 90 days of hire and a signed statement kept six years, and Chapter 181 defines covered entity broadly enough to include business associates.
- Incident response: one process for all practices, with clear handoffs so each practice can meet its own notification duties.
- Documentation: keep it six years (164.316(b)(2)).
Ichelon Consulting US works as a business associate for practices and management companies. We sign a BAA with every US client, our client-facing and delivery teams hold HIPAA compliance training certificates, and our US client team works from Dallas, Texas. Read how we work, see our US research or book a call.
Find the guide for your size and structure
HIPAA compliance as you scale
The pillar: what changes from one office to a private-equity-backed platform.
Solo practice
One office, one owner, a handful of staff and a short vendor list.
Multi-location practice
Several offices, shared systems, a central phone team and location managers.
Private-equity-backed platform
Acquisitions every quarter, inherited systems and diligence on every deal.
HIPAA compliance by role
What owners, practice managers, front desk and marketing staff each need to do.
Sources
- 45 CFR 160.103, definitions (business associate, covered entity, health care clearinghouse).
- 45 CFR 164.504(e), business associate contracts; 164.502(e), disclosures to business associates.
- 45 CFR 164.410, notification by a business associate.
- 45 CFR 164.508, authorizations; 164.501, definition of marketing.
- 45 CFR 164.105, affiliated covered entities.
- Business associates (HHS guidance).
- Texas Health and Safety Code 181.001; 181.101.
- Texas SB 1188, enrolled text (2025).
- HIPAA and Google Analytics (Google); Meta Business Tools Terms (Meta).
- Chapter 19.373 RCW, Washington My Health My Data Act.
Not legal advice: this guide describes common HIPAA practice for management services organizations. It is not legal advice. Entity structures and state corporate practice rules vary, so confirm your obligations with healthcare counsel.
Related pages from the US team
HIPAA compliance as you scale
How the program changes from one office to a platform.
Choosing a vendor that signs a BAA
What to ask a marketing vendor before it touches PHI.
HIPAA compliance by role
Training and duties by job.
Agency vs all-in-one automation platform
How MSOs choose between running tools and hiring a team.
Every practice welcome — Goals-Driven engagements from $499/mo
We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.
Common questions
Is an MSO a HIPAA covered entity?
Usually not. An MSO that provides administrative, billing, IT or marketing services to practices handles PHI on their behalf, which makes it a business associate. It could be a covered entity in its own right if it provides care and bills for it, or if it acts as a health care clearinghouse by converting nonstandard data into standard transactions. Have counsel confirm your status.
Does the MSO or the practice notify patients after a breach?
The practice, as the covered entity, is responsible for notifying individuals, HHS and, where required, the media. The MSO must notify the practice without unreasonable delay and no later than 60 days after discovering the breach. The BAA can delegate notification tasks to the MSO and set a shorter reporting deadline.
Can an MSO run one marketing CRM for all its practices?
Yes, if it is set up carefully. Each practice’s patient data should be separated, used for that practice’s purposes as its BAA allows, and accessible to staff by role. Pooling patient lists so one practice’s patients receive another practice’s marketing is a disclosure that generally needs patient authorization or another legal basis.
Who should be the privacy officer, the MSO or the practice?
Both. Each practice, as a covered entity, must designate a privacy official and a security official. The MSO, as a business associate, should name its own officials for its workforce and systems. The MSO can supply a person to fill the practice roles under contract, but the practice remains responsible.
What subcontractors does an MSO need BAAs with?
Any vendor that creates, receives, maintains or transmits PHI on the MSO’s behalf: cloud hosting, EHR and practice management, phone and call recording, texting, CRM, IT and security providers, document storage and the marketing agency. Each needs a business associate agreement with the MSO.
Can affiliated practices share one Notice of Privacy Practices?
Sometimes. Entities under common ownership or control can designate themselves as a single affiliated covered entity, and organized health care arrangements can use a joint notice. Many MSO-affiliated practices are not commonly owned in the legal sense because of corporate practice of medicine rules, so confirm with counsel.
A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.
Running marketing for several practices?
A 30-minute call with the US team. We will review how leads, call recordings and patient lists move between your practices and your shared systems.