HIPAA for practice managers and owners: running the four stages for everyone else
A practice manager keeps the practice HIPAA compliant by acting as (or appointing) the privacy and security officials, keeping a current risk analysis, running the four stages (Onboard, Access, Operate, Offboard) for every staff member and vendor, holding the BAA file, deciding whether incidents are breaches, and keeping six years of records. In most small practices this person also holds the admin keys, which makes their own handover the riskiest offboarding of all.
- You must designate a privacy official (45 CFR 164.530(a)) and a security official (164.308(a)(2)). One person can hold both.
- A risk analysis is required, not optional (164.308(a)(1)(ii)(A)). OCR corrective plans ask for it again and again.
- Keep a vendor register: every company with PHI access and its signed BAA. No BAA, no PHI.
- An impermissible disclosure is presumed a breach unless a documented four-factor risk assessment shows low probability of compromise (164.402).
- Keep policies, training logs, BAAs and decisions for six years (164.530(j)).
- Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
- Dallas, Texas LLC
- 10-person US client team · Central Time (CST)
- 25+ US healthcare clients
- BAA signed with every client
- HIPAA compliance training across client and delivery teams
- Contracts and invoices in USD
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
The practice manager owns the system, not just their own conduct
Short answer: other roles follow rules. You write them, check them and prove them. When OCR investigates, it asks for documents, and in a small practice you are the one who has to produce them.
This page applies our four-stage HIPAA framework to practice managers, office managers, administrators and owner-operators. Your duties fall into two layers: running Onboard, Access, Operate and Offboard for every person and vendor, and going through those stages yourself, with admin rights that make your mistakes larger.
The required designations
- Privacy official, responsible for developing and implementing privacy policies, plus a contact person for complaints (164.530(a)).
- Security official, responsible for Security Rule policies and procedures (164.308(a)(2)).
Write the designation down, date it and keep it. If an outside IT provider does most of the security work, the security official is still someone inside the practice who oversees them.
Running the four stages for the whole practice
Stage 1 · Onboard everyone
- Training for every new workforce member within a reasonable period after joining, retraining after material policy changes, and documentation of both (164.530(b)). Check your state too: Texas requires training within 90 days of hire with signed records kept six years (Texas Health and Safety Code 181.101).
- A security awareness program for all workforce, including management (164.308(a)(5)).
- A workforce clearance procedure, so access is appropriate before it is granted (164.308(a)(3)(ii)(B)).
- A signed BAA before any vendor touches PHI (164.502(e), 164.504(e)). Compare vendor paper against HHS's sample BAA provisions.
Stage 2 · Control access
- A role-to-system access table that reflects minimum necessary for each role (164.514(d)).
- Unique logins (required), emergency access procedure (required), automatic logoff and encryption decisions documented (164.312(a)).
- Audit controls and a schedule for reviewing activity logs (164.312(b), 164.308(a)(1)(ii)(D)). Monthly is a practical start for EHR access reports.
- MFA on every system that offers it, even though the current rule does not name it.
- A quarterly access review: does everyone on each system still work here, in the same role?
Stage 3 · Keep daily operations safe
- Channel rules for phones, texts, email, social media and reviews (see the front desk page).
- A risk analysis that reflects your actual systems and vendors (164.308(a)(1)(ii)(A)), and a risk management plan to act on it.
- A sanctions policy that you apply and document (164.530(e), 164.308(a)(1)(ii)(C)).
- Security incident procedures (164.308(a)(6)) and a breach decision process (below).
- A current Notice of Privacy Practices, posted and provided as required.
Stage 4 · Offboard reliably
Termination procedures for workforce access (164.308(a)(3)(ii)(C)) and BAA terms that require return or destruction of PHI at the end (164.504(e)(2)(ii)(J)). Use the offboarding checklist and keep each completed copy.
The vendor register and the breach decision
Vendor register
List every company that creates, receives, maintains or transmits PHI for you: EHR, booking, texting, email, call tracking, CRM, review tools, IT provider, billing, shredding, cloud storage, marketing agency. For each, record the BAA date, breach-notice window, subcontractors, internal owner and exit steps. Review it twice a year and every time someone signs up for a new tool, which in practice is how most unregistered vendors appear. Our page on what to require from agencies and vendors covers the contract terms.
Deciding whether an incident is a breach
An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless you can show a low probability that the PHI was compromised, based on a risk assessment of at least four factors (164.402):
- The nature and extent of the PHI, including identifiers and likelihood of re-identification.
- Who used it or received it.
- Whether it was actually acquired or viewed.
- How far the risk has been mitigated.
If it is a breach: patients within 60 days of discovery (164.404); HHS at the same time for 500 or more people, or in an annual log within 60 days of year-end for fewer (164.408); the media for more than 500 residents of a state (164.406). Add state deadlines, which can be shorter.
Documentation
Keep policies, training records, designations, risk analyses, sanctions, BAAs, incident assessments and complaint records for six years from creation or from when they were last in effect (164.530(j)).
Printable practice manager HIPAA checklist
Stage 1 · Onboard (program level)
- Privacy official and security official designated in writing
- Role-based training materials for desk, providers, billing, marketing and managers
- Training log with dates and signed acknowledgments; state-law timing checked
- Confidentiality agreement template; BAA template compared with HHS sample provisions
Stage 2 · Access
- Role-to-system access table approved
- No shared logins; MFA enabled where available; break-glass account sealed
- Monthly EHR access report reviewed; quarterly access review on the calendar
- Device inventory with encryption status
Stage 3 · Operate
- Risk analysis updated in the last 12 months; risk management plan in progress
- Vendor register complete, each PHI vendor with a signed BAA
- Channel rules published (phones, texts, email, social, reviews)
- Sanctions policy applied and documented
- Incident form, four-factor assessment template and state breach-law list ready
Stage 4 · Offboard (including your own handover)
- Offboarding checklist used and filed for every departure and vendor exit
- Admin credentials and vendor register handed over in writing
- Privacy and security official roles reassigned and dated
- All admin and shared passwords rotated on your last day
Owners of med spas can pair this with our med spa HIPAA advertising guide, med spa marketing, the med spa marketing statistics, the med spa Google presence report and the state medical board advertising guide. Dental practices: the dental HIPAA advertising guide. Marketing staff on your team should read HIPAA for marketing teams. Browse all US guides or book a call.
Sources
- 45 CFR 164.530 (privacy official, training, sanctions, documentation): law.cornell.edu/cfr/text/45/164.530
- 45 CFR 164.308 (security official, risk analysis, workforce security, training, incidents): law.cornell.edu/cfr/text/45/164.308
- 45 CFR 164.312 (access and audit controls): law.cornell.edu/cfr/text/45/164.312
- 45 CFR 164.402 (breach definition and four-factor risk assessment): law.cornell.edu/cfr/text/45/164.402
- 45 CFR 164.404, 164.406, 164.408 (notification to individuals, media, HHS): law.cornell.edu/cfr/text/45/164.408
- 45 CFR 164.504(e) (BAA contents): law.cornell.edu/cfr/text/45/164.504
- HHS, Sample Business Associate Agreement Provisions: hhs.gov
- Proposed HIPAA Security Rule update (Jan 6, 2025): federalregister.gov
- Texas Health and Safety Code 181.101: statutes.capitol.texas.gov
- OCR, Memorial Healthcare System: hhs.gov
- OCR, Raleigh Orthopaedic Clinic: hhs.gov
- OCR, Elite Dental Associates: hhs.gov
Related pages from the US team
HIPAA compliance by role
The full four-stage framework and the roles-by-stages matrix.
What to require from agencies and vendors
BAA terms, subcontractors, data flows and audit rights.
HIPAA offboarding checklist
Same-day access removal for staff and a clean exit for vendors.
HIPAA for front desk staff
Phone, check-in and texting rules with a printable checklist.
HIPAA-compliant healthcare marketing
Authorizations, testimonials, email and ads in one guide.
Every practice welcome — Goals-Driven engagements from $499/mo
We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.
Common questions
Does a small practice need a HIPAA privacy officer?
Yes. Every covered entity must designate a privacy official responsible for its privacy policies and a contact person for complaints, and a security official responsible for Security Rule policies. In a small practice the practice manager or owner usually holds both roles, which is allowed.
How often should we do a HIPAA risk analysis?
The current Security Rule requires an accurate and thorough risk analysis and ongoing risk management but does not set a fixed frequency. Update it at least yearly and whenever you add a major system, move offices, change vendors or have an incident. The January 2025 proposed Security Rule update would make annual reviews explicit; as of October 2026 it is still a proposal.
What goes in a HIPAA vendor register?
Each vendor's name, what it does, what PHI it receives, the systems it touches, the date the BAA was signed, the BAA's breach-notice window, the subcontractors it uses for your data, the internal owner of the relationship and the review date. Add the termination steps you will need when the relationship ends.
Who decides whether an incident is a reportable breach?
The practice, usually through the privacy official with legal advice where needed. HIPAA presumes an impermissible use or disclosure is a breach unless a documented risk assessment of at least four factors shows a low probability that the PHI was compromised. Keep the assessment even when you conclude no notification is required.
Do we have to sanction staff for HIPAA violations?
You must have and apply appropriate sanctions against workforce members who fail to comply with your privacy and security policies, and document the sanctions applied. Sanctions should fit the violation, from retraining for an honest mistake to termination for deliberate snooping. Never sanction someone for reporting a problem.
What happens to HIPAA duties when the practice manager leaves?
Formally reassign the privacy and security official roles, transfer admin credentials and the vendor register, rotate every shared and admin password, and remove the departing manager's access the same day. Document the handover.
A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.
Need your marketing vendors to fit your HIPAA program?
A 30-minute call with the Ichelon Consulting US team. We sign a BAA with every US client and can walk you through how our team handles PHI.