🇮🇳 India 🇺🇸 US
Healthcare SEO AI search (AIO) Local SEO & Google Business Profile Content marketing Performance marketing Google Ads Meta Ads Email & SMS marketing Reputation management Website design Branding YouTube & video Marketing consulting
Dental practices Pediatric practices Primary care Med spas Dermatology IVF & fertility Dallas (HQ) Houston New York All US cities and specialties
US healthcare marketing statistics Med spa consumer behavior report Dental patient experience report Google benchmarks: 9 specialties Free tools All US research US case studies
Software
Healthcare practices Pharma Medical devices
About Ichelon Consulting US How we work Santosh Reddy, Director Ravi Kumarraju, Partner & Director
Book a call with the US team Call +1 (724) 612-3694
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · HIPAA by practice size

HIPAA compliance for multi-location practices: one program, many front desks

A multi-location practice should run one HIPAA program, not one per office. That means one accountable privacy official and security official, a liaison at each location, one policy set with short local addenda, role-based access to shared systems, and one list of every vendor and website tool. Each new office should open with a checklist, not a copy of the last office’s habits.

Guide for US practice owners · Published October 4, 2026

TL;DR
  • Run one program: one officer pair, one policy set, one vendor and BAA inventory, one incident process.
  • Name a privacy liaison at each location for training sign-offs, incident reports and patient questions.
  • Shared systems need role-based access: the central call team sees every schedule, not every chart.
  • Use a new-location checklist and update the risk analysis before each office opens.
  • Marketing is a common leak: one tag inventory per website and no location-level tools without approval.
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Ichelon Consulting US
  • Dallas, Texas LLC
  • 10-person US client team · Central Time (CST)
  • 25+ US healthcare clients
  • BAA signed with every client
  • HIPAA compliance training across client and delivery teams
  • Contracts and invoices in USD
How we work with US practices →
Trusted by US practices · case studies → 25+ US clients · 8 shown · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
One program

Why one program beats one binder per office

Short answer: because HIPAA holds the covered entity responsible for every location, and inconsistency is where incidents happen.

Groups usually reach two or three offices by copying what worked at the first one. By office four or five, each location has its own habits: a different texting app, a different way of handling records requests, a front desk that still shares a login. The fix is structural:

  • One accountable privacy official and one security official for the covered entity (45 CFR 164.530(a) and 164.308(a)(2)), with time set aside for the role.
  • A privacy liaison at each location, usually the office manager, who runs local training sign-offs, collects incident reports the same day and answers patient privacy questions.
  • One version-controlled policy set with a one-page addendum per office for the genuinely local details: layout, devices, network and which state’s laws apply.
  • One incident process. Every office reports to the same place, using the same form, so the four-factor breach risk assessment in 164.402 is done consistently.

If your offices are separate legal entities, each is a covered entity in its own right. Entities under common ownership or control can designate themselves as a single affiliated covered entity under 164.105(b), documented in writing, which lets them run the single program described here.

Access

Shared systems and role-based access

Short answer: centralizing systems is good; giving everyone access to everything is not. Build role templates and review them every quarter.

RoleTypical accessUsually not needed
Front desk, single officeThat office’s schedule, demographics, insurance, check-inOther offices’ schedules; clinical notes beyond what check-in needs
Central call or scheduling teamEvery office’s schedule, demographics, call recordings for quality reviewClinical notes, billing detail
Billing teamClaims, payments, insurance and the clinical detail billing requiresCall recordings, marketing data
Marketing staff or agencyLead source, booking status, de-identified or aggregated reports; call recordings where the BAA allowsCharts, diagnoses, payment data
CliniciansCharts for patients they treat; cross-office access by role where patients move between officesBulk exports

The Security Rule requires unique user identification and audit controls (164.312(a)(2)(i) and 164.312(b)), and the minimum necessary standard (164.502(b) and 164.514(d)) applies to how much each role can see. In practice: no shared logins anywhere, same-day removal when someone leaves, quarterly access reviews and someone assigned to look at audit logs on a schedule (164.308(a)(1)(ii)(D)). For Texas offices, SB 1188 adds a state requirement that electronic health record information be accessible to people who need it for treatment, payment or operations duties.

New offices

The new-location checklist

Short answer: treat each new office as a change to your environment, and update the risk analysis before the doors open.

  1. Risk analysis update: physical layout (can waiting patients see screens or hear check-in?), network, devices, alarm and access to records areas (164.310).
  2. Devices: encrypted workstations and laptops, added to the device inventory, with screen locks and no local PHI storage where possible.
  3. Accounts: role-based logins created from templates, not copied from another user.
  4. Training: every new hire trained before they get access, with records kept; in Texas, within 90 days of hire with a signed statement kept six years (Health and Safety Code 181.101).
  5. Notice of Privacy Practices: posted in the office and available at first visits.
  6. Phone and texting: the new number added to the existing phone and recording setup under the same BAA, with the recording announcement.
  7. Marketing: new location page and Google Business Profile set up from the approved template, with the approved tag set and no new tools.
  8. State law check if the office is in a new state.

Closing or moving an office needs its own checklist: where the paper and electronic records go, how devices are wiped or destroyed (164.310(d)), and how patients are told where their records are.

Vendors

One vendor and BAA inventory

Short answer: one list, one owner, and a rule that no location adds a vendor that touches PHI on its own.

Record for each vendor the service, the PHI involved, the signed BAA and its terms, subcontractors, where the data is stored and how it comes back when the contract ends. Texas SB 1188 requires electronic health records of Texas residents stored on or after January 1, 2026 to be physically kept in the United States or a US territory, so storage location belongs on the list. Review the inventory each year and whenever an office opens. Vendors that will not sign a BAA, including Google Analytics and the ad platforms, belong on a separate list with a note on how you keep PHI away from them.

Marketing

Marketing across locations without leaking PHI

Short answer: multi-location marketing multiplies the places patient data can escape: more location pages, more phone numbers, more profiles and more tools. Standardize all of it.

  • Location pages and booking: one approved tag set across every location page. Keep ad pixels off booking flows, intake forms and portals. In June 2024 a federal court vacated part of HHS’s tracking guidance about unauthenticated public pages, but tracking on booking and intake flows is still risky. See the HIPAA-safe website tracking guide.
  • Call tracking and recording: tracking numbers per location are useful for attribution, and every recording is PHI. One vendor, one BAA, one retention period, and an announcement on every call. California, Florida and Washington require all-party consent; Texas requires one party.
  • Google Business Profiles: one per location, managed centrally, with review replies that never confirm a patient relationship. See responding to reviews under HIPAA and our guide to getting more Google reviews.
  • CRM and texting: a CRM holding appointment data needs a BAA and role-based access. Promotional texts need TCPA consent; see the healthcare SMS compliance guide.
  • Ads: location targeting and broad audiences, conversion signals that carry no PHI, and ad copy that does not imply knowledge of the viewer’s condition.

Reporting should show bookings and attended visits by location, measured in your own systems, rather than relying on data sent back to ad platforms. Ichelon Consulting US reports this way for multi-location groups on Ichelon Agency OS, signs a BAA with every US client, and runs a 10-person US client team in Dallas. Read how we work or book a call.

Multi-state

When your locations cross state lines

HIPAA is federal, but state law follows your offices and your patients. Add each new state to your policy addenda and training, and check:

  • State medical privacy laws, such as Texas Health and Safety Code Chapter 181 and California’s Confidentiality of Medical Information Act.
  • Consumer health data laws for non-PHI data, such as Washington’s My Health My Data Act, which bans geofences within 2,000 feet of in-person health care locations used for tracking or ads.
  • State breach notification laws, which can apply alongside HIPAA’s.
  • Call recording and texting rules.
  • Medical board advertising rules, covered in our state guides, for example Texas and California.

If your group is moving toward a management company structure or outside investment, read the MSO guide and the private-equity platform guide next.

HIPAA by practice size

Find the guide for your size and structure

HIPAA compliance as you scale

The pillar: what changes from one office to a private-equity-backed platform.

Solo practice

One office, one owner, a handful of staff and a short vendor list.

MSO or management company

A management company serving affiliated practices, usually as a business associate.

Private-equity-backed platform

Acquisitions every quarter, inherited systems and diligence on every deal.

HIPAA compliance by role

What owners, practice managers, front desk and marketing staff each need to do.

Keep reading

Related pages from the US team

HIPAA compliance as you scale

How the program changes from one office to a platform.

HIPAA compliance by role

Training and duties by job, from front desk to marketing.

US locations we serve

Markets where Ichelon Consulting US works with practices.

US services

SEO, ads, reviews and reporting for healthcare groups.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

Does each location need its own HIPAA privacy officer?

No. A single covered entity designates one privacy official and one security official. Many groups add a privacy liaison at each location who handles local questions and escalates incidents. If the locations are separate legal entities, each is its own covered entity, though commonly owned entities may be able to designate themselves as a single affiliated covered entity.

Do we need a separate risk analysis for every office?

You need one analysis that accurately covers every office. Most groups run an enterprise-wide analysis with a walkthrough section for each location covering physical layout, local devices, network and staff practices, and update it whenever an office opens, moves or changes systems.

Can front desk staff at one location see patients from another location?

Only if their role needs it. Under the minimum necessary standard, access should match the job. A central scheduling team may need access to all schedules; front desk staff at one office usually need only that office. Configure roles in the EHR and phone system accordingly.

How should call recordings be handled across several states?

Treat them as PHI, keep them with a vendor that signs a BAA, limit who can listen, and follow the strictest state recording law your callers are in. Several states, including California, Florida and Washington, require all parties to consent, so announce recording at the start of every call.

Can a location manager set up their own marketing tools?

It is safer not to allow it. Local tools such as chat widgets, form builders, texting apps and ad pixels are a common way PHI reaches vendors without a BAA. Keep a central approval step for any tool that collects patient information or sits on the website.

What changes when we open an office in a new state?

HIPAA stays the same, but state laws on medical privacy, breach notification, call recording, texting and advertising may differ. Add the new state to your policies and training, check its medical board advertising rules, and confirm breach notification duties to that state’s residents.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Running several locations?

A 30-minute call with the US team. We will map how leads and patient data move from each location’s website, phone line and Google Business Profile into your systems.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership