HIPAA compliance for private-equity-backed healthcare platforms
A private-equity-backed platform buys its HIPAA risk one practice at a time. Each add-on brings its own systems, vendors, websites, staff habits and breach history. The platforms that handle this well run the same diligence request on every target, give each acquisition a fixed integration plan after close, and keep an enterprise view of risk that leadership and the board actually see.
- Every add-on is a change to your environment: assess it before close and update your enterprise risk analysis after.
- Diligence should cover risk analysis history, breach and complaint history, BAAs and their assignability, legacy systems, websites and tracking, and marketing consent.
- Use a standard post-close integration plan: policies, training, access, vendor consolidation, website and tracking cleanup.
- Rebrands touch HIPAA too: a material change to your privacy practices means a revised Notice of Privacy Practices.
- State transaction notice laws, such as Oregon’s 180-day notice, change deal timelines.
- Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
- Dallas, Texas LLC
- 10-person US client team · Central Time (CST)
- 25+ US healthcare clients
- BAA signed with every client
- HIPAA compliance training across client and delivery teams
- Contracts and invoices in USD
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
How HIPAA works in a platform structure
Short answer: the practices are the covered entities, the platform or MSO is usually their business associate, and the fund sits above both. Responsibility follows that structure.
Most physician and dental platforms combine a management company owned by the platform with professional entities owned by licensed clinicians, because of state corporate practice of medicine or dentistry rules. The management company signs business associate agreements with each practice and runs shared services. Our MSO guide covers that relationship in detail. This page covers what is specific to a platform that is acquiring: diligence, integration and enterprise oversight.
Leadership attention matters here. HHS has made the risk analysis a specific enforcement focus through its Risk Analysis Initiative, and a 2021 amendment to the HITECH Act (Public Law 116-321) requires HHS to consider whether recognized security practices, such as the NIST Cybersecurity Framework or HHS 405(d) practices, were in place for the previous 12 months when deciding penalties. An enterprise program that has been running and documented for a year carries weight. One assembled during an investigation does not.
Pre-close HIPAA diligence
Short answer: send the same request list to every target, score the answers the same way, and price or plan for what you find.
| Area | Ask for | Red flags |
|---|---|---|
| Risk analysis | The latest written analysis, risk management plan and evidence that items were fixed | No written analysis, a template with no local detail, or one several years old |
| Breach history | Incident and breach log, notices sent, HHS reports including annual reports of small breaches | Incidents with no documented risk assessment; ransomware events with no report |
| Regulator contact | OCR complaints and investigations, state attorney general inquiries, board complaints about privacy | Open investigations; corrective action plans still running |
| BAAs | Every BAA and the vendor list it should match | Vendors handling PHI with no BAA; BAAs that cannot be assigned or terminated |
| Systems | Systems inventory, patch status, backup and recovery tests, data storage locations | Unsupported operating systems or servers; offshore EHR storage for Texas patients after January 1, 2026 (Texas SB 1188) |
| Websites and tracking | Every domain and landing page, current and past tags, pixels and session recording tools | Ad pixels on booking, intake or portal pages; chat or form tools without BAAs |
| Marketing consent | How patient lists were built; consent records for texts and calls; call recording disclosures | Purchased lists, texts without documented consent, unannounced recording |
| Workforce | Training records, sanctions, access reviews, offboarding | Shared logins; no training records; former staff with active accounts |
Keep PHI out of the data room where you can. Most of this can be reviewed with summaries, de-identified samples and screenshots. Where you do need PHI, put the right agreement in place first.
State transaction notice laws
These are not HIPAA rules, but they affect platform deal timelines and the record you will want to show regulators. Oregon’s Health Care Market Oversight program requires notice to the Oregon Health Authority of material change transactions at least 180 days before the proposed effective date, and treats a change from physician ownership to private equity ownership as a change in form of ownership. California requires notice of certain health care transactions to its Office of Health Care Affordability, and other states have adopted or proposed similar notice rules. Build the timeline into the deal plan and ask counsel to check each state where the target operates.
A standard post-close integration plan
Short answer: the same plan for every add-on, tracked to completion, with the risk analysis updated as each step lands.
- First weeks: name the practice’s privacy and security officials or liaison; connect it to the platform incident reporting process; remove access for anyone who should not have it; confirm backups work.
- Policies and training: adopt the platform policy set with a location addendum; train every workforce member and keep records. For Texas practices, Health and Safety Code 181.101 requires training within 90 days of hire and a signed statement kept six years.
- Access: move users to platform identity management and role templates; unique logins; audit logging on (45 CFR 164.312).
- Vendors: compare the practice’s vendors to the platform’s; move to platform vendors and BAAs on a schedule; get written confirmation that dropped vendors return or destroy PHI.
- Systems: plan EHR and phone migrations; keep legacy records accessible for as long as state retention rules require; retire unsupported systems.
- Websites and tracking: audit every domain; remove unapproved pixels, chat widgets and form tools; redirect retired domains to the right pages.
- Risk analysis: fold the practice into the enterprise analysis and record what changed.
Rebrands, websites and marketing data
Short answer: the marketing side of integration is where platforms most often inherit PHI leaks, because every acquired practice ran its own website and tools.
- Notice of Privacy Practices. If integration materially changes the practice’s privacy practices, revise the notice and make it available (164.520(b)(3)). Post the new version on the rebranded website.
- Legacy tracking. Old websites often carry ad pixels and session recording on booking and intake pages. HHS’s tracking guidance, as narrowed by the June 2024 AHA v. Becerra ruling on unauthenticated public pages, still treats tracking on authenticated and booking pages as a likely PHI disclosure. See the HIPAA-safe website tracking guide.
- Patient lists. Each practice’s patients are its PHI. Marketing a sister practice’s services to them generally needs authorization unless an exception applies (164.508(a)(3)), and texts need TCPA consent.
- Call recordings and CRM. Consolidate onto one vendor with a BAA, one retention rule and role-based access. Announce recording on every call; several states require all-party consent.
- Consumer health data laws. Website visitor data that is not PHI may still be covered by Washington’s My Health My Data Act, Nevada and Connecticut laws, and California’s CCPA. Washington also bans geofences within 2,000 feet of in-person care locations used for tracking or ads.
- Reviews and profiles. Google Business Profiles move with the rebrand; review replies must never confirm a patient relationship. See responding to reviews under HIPAA.
For marketing, the reporting that matters to a platform is bookings and attended first visits by location and channel, measured in your own systems. That keeps PHI out of ad platforms and gives the board numbers it can trust.
Enterprise oversight: what leadership should see
- Status of the enterprise risk analysis and open risk management items by severity.
- Integration status of each acquired practice against the standard plan.
- Incidents and breaches by quarter, with time from discovery to notification.
- Training completion and access review completion by location.
- Vendor and BAA inventory status, including vendors waiting to be consolidated.
- Website and tracking audit status across every brand and domain.
HHS proposed an update to the Security Rule on January 6, 2025 (90 FR 898) that would, among other things, require a technology asset inventory and network map and make most addressable specifications required. It has not been finalized at the time of writing. A platform that builds those artifacts now will have less to do if it is.
Ichelon Consulting US works with healthcare groups on marketing across many locations and brands. We sign a BAA with every US client, our client-facing and delivery teams hold HIPAA compliance training certificates, and our 10-person US client team in Dallas works Central Time. Read how we work, see the specialties we serve or book a call.
Find the guide for your size and structure
HIPAA compliance as you scale
The pillar: what changes from one office to a private-equity-backed platform.
Solo practice
One office, one owner, a handful of staff and a short vendor list.
Multi-location practice
Several offices, shared systems, a central phone team and location managers.
MSO or management company
A management company serving affiliated practices, usually as a business associate.
HIPAA compliance by role
What owners, practice managers, front desk and marketing staff each need to do.
Sources
- 45 CFR 164.308, administrative safeguards; 164.312, technical safeguards.
- 45 CFR 164.520, notice of privacy practices; 164.508, authorizations.
- HIPAA Security Rule proposed rule, 90 FR 898 (Federal Register, January 6, 2025).
- HHS OCR Risk Analysis Initiative settlement announcement (HHS press room).
- Recognized security practices, HITECH Act section 13412 (HHS).
- Oregon Health Care Market Oversight FAQ (Oregon Health Authority).
- Texas Health and Safety Code 181.101, training; Texas SB 1188, enrolled text.
- Portions of OCR’s tracking technologies bulletin vacated (summary of AHA v. Becerra).
- Chapter 19.373 RCW, Washington My Health My Data Act.
Not legal advice: this guide describes common HIPAA practice for acquisitive healthcare platforms. It is not legal advice. Deal structures and state laws vary, so confirm your obligations with healthcare and transaction counsel.
Related pages from the US team
HIPAA compliance as you scale
How the program changes from one office to a platform.
HIPAA for MSOs
The business associate side of the platform structure.
HIPAA compliance by role
Training and duties by job.
US research
Original data on US healthcare practices’ Google presence.
Every practice welcome — Goals-Driven engagements from $499/mo
We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.
Common questions
Does a private equity fund become subject to HIPAA when it buys a practice?
Not usually by owning it. The practice remains the covered entity, and any MSO or platform company providing services to it is typically a business associate. The fund and its deal team should avoid receiving PHI during diligence unless it is necessary and protected by appropriate agreements; most diligence can be done with de-identified or summary information.
What HIPAA documents should we request in diligence?
The latest risk analysis and remediation evidence, policies, training records, the breach and incident log with any HHS reports, OCR or attorney general correspondence, all business associate agreements, a systems inventory including unsupported software, a list of websites and tracking tools, and records of consent for marketing texts and calls.
What happens to the target’s business associate agreements after close?
In an equity deal the practice usually stays the same legal entity, so its BAAs continue. In an asset deal, or when moving services to the platform’s vendors, check whether each BAA can be assigned and when it can be terminated. Consolidate onto the platform’s vendors and BAAs on a schedule, and confirm data is returned or destroyed by vendors you drop.
Do we need a new Notice of Privacy Practices after an acquisition?
If the acquisition materially changes how the practice uses or discloses PHI, or its contact details for privacy questions, the notice must be revised and made available. A rebrand into the platform name is a common trigger. Post the revised notice on the website and in the office.
How quickly should an acquired practice be integrated into the platform HIPAA program?
HIPAA does not set a timeline. Many platforms work to a fixed plan, such as 90 days for policies, training, access and incident reporting, and longer for system migrations. What matters is that the plan exists, is tracked and is documented.
Do state laws require notice before a healthcare acquisition?
Some do. Oregon requires notice to the Oregon Health Authority at least 180 days before a material change transaction, and California requires notice of certain transactions to its Office of Health Care Affordability. Other states have passed or are considering similar laws, so check each state where the target operates.
A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.
Integrating acquired practices?
A 30-minute call with the US team. We will review the websites, tracking and lead flows you inherited and show you what we would clean up first.