🇮🇳 India 🇺🇸 US
Healthcare SEO AI search (AIO) Local SEO & Google Business Profile Content marketing Performance marketing Google Ads Meta Ads Email & SMS marketing Reputation management Website design Branding YouTube & video Marketing consulting
Dental practices Pediatric practices Primary care Med spas Dermatology IVF & fertility Dallas (HQ) Houston New York All US cities and specialties
US healthcare marketing statistics Med spa consumer behavior report Dental patient experience report Google benchmarks: 9 specialties Free tools All US research US case studies
Software
Healthcare practices Pharma Medical devices
About Ichelon Consulting US How we work Santosh Reddy, Director Ravi Kumarraju, Partner & Director
Book a call with the US team Call +1 (724) 612-3694
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · HIPAA by role

HIPAA for practice managers and owners: running the four stages for everyone else

A practice manager keeps the practice HIPAA compliant by acting as (or appointing) the privacy and security officials, keeping a current risk analysis, running the four stages (Onboard, Access, Operate, Offboard) for every staff member and vendor, holding the BAA file, deciding whether incidents are breaches, and keeping six years of records. In most small practices this person also holds the admin keys, which makes their own handover the riskiest offboarding of all.

Guide for US practice owners · Published October 4, 2026

TL;DR
  • You must designate a privacy official (45 CFR 164.530(a)) and a security official (164.308(a)(2)). One person can hold both.
  • A risk analysis is required, not optional (164.308(a)(1)(ii)(A)). OCR corrective plans ask for it again and again.
  • Keep a vendor register: every company with PHI access and its signed BAA. No BAA, no PHI.
  • An impermissible disclosure is presumed a breach unless a documented four-factor risk assessment shows low probability of compromise (164.402).
  • Keep policies, training logs, BAAs and decisions for six years (164.530(j)).
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Ichelon Consulting US
  • Dallas, Texas LLC
  • 10-person US client team · Central Time (CST)
  • 25+ US healthcare clients
  • BAA signed with every client
  • HIPAA compliance training across client and delivery teams
  • Contracts and invoices in USD
How we work with US practices →
Trusted by US practices · case studies → 25+ US clients · 8 shown · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Your job

The practice manager owns the system, not just their own conduct

Short answer: other roles follow rules. You write them, check them and prove them. When OCR investigates, it asks for documents, and in a small practice you are the one who has to produce them.

This page applies our four-stage HIPAA framework to practice managers, office managers, administrators and owner-operators. Your duties fall into two layers: running Onboard, Access, Operate and Offboard for every person and vendor, and going through those stages yourself, with admin rights that make your mistakes larger.

The required designations

  • Privacy official, responsible for developing and implementing privacy policies, plus a contact person for complaints (164.530(a)).
  • Security official, responsible for Security Rule policies and procedures (164.308(a)(2)).

Write the designation down, date it and keep it. If an outside IT provider does most of the security work, the security official is still someone inside the practice who oversees them.

The four stages

Running the four stages for the whole practice

Stage 1 · Onboard everyone

  • Training for every new workforce member within a reasonable period after joining, retraining after material policy changes, and documentation of both (164.530(b)). Check your state too: Texas requires training within 90 days of hire with signed records kept six years (Texas Health and Safety Code 181.101).
  • A security awareness program for all workforce, including management (164.308(a)(5)).
  • A workforce clearance procedure, so access is appropriate before it is granted (164.308(a)(3)(ii)(B)).
  • A signed BAA before any vendor touches PHI (164.502(e), 164.504(e)). Compare vendor paper against HHS's sample BAA provisions.

Stage 2 · Control access

  • A role-to-system access table that reflects minimum necessary for each role (164.514(d)).
  • Unique logins (required), emergency access procedure (required), automatic logoff and encryption decisions documented (164.312(a)).
  • Audit controls and a schedule for reviewing activity logs (164.312(b), 164.308(a)(1)(ii)(D)). Monthly is a practical start for EHR access reports.
  • MFA on every system that offers it, even though the current rule does not name it.
  • A quarterly access review: does everyone on each system still work here, in the same role?

Stage 3 · Keep daily operations safe

  • Channel rules for phones, texts, email, social media and reviews (see the front desk page).
  • A risk analysis that reflects your actual systems and vendors (164.308(a)(1)(ii)(A)), and a risk management plan to act on it.
  • A sanctions policy that you apply and document (164.530(e), 164.308(a)(1)(ii)(C)).
  • Security incident procedures (164.308(a)(6)) and a breach decision process (below).
  • A current Notice of Privacy Practices, posted and provided as required.

Stage 4 · Offboard reliably

Termination procedures for workforce access (164.308(a)(3)(ii)(C)) and BAA terms that require return or destruction of PHI at the end (164.504(e)(2)(ii)(J)). Use the offboarding checklist and keep each completed copy.

OCR case: access that was never reviewed. Memorial Healthcare System in Florida paid $5.5 million after the login of a former employee at an affiliated physician office was used to access ePHI daily for about a year without detection. OCR cited failures to review, modify or terminate users' access and to regularly review system activity records.
Vendors and breaches

The vendor register and the breach decision

Vendor register

List every company that creates, receives, maintains or transmits PHI for you: EHR, booking, texting, email, call tracking, CRM, review tools, IT provider, billing, shredding, cloud storage, marketing agency. For each, record the BAA date, breach-notice window, subcontractors, internal owner and exit steps. Review it twice a year and every time someone signs up for a new tool, which in practice is how most unregistered vendors appear. Our page on what to require from agencies and vendors covers the contract terms.

OCR case: no BAA before disclosure. Raleigh Orthopaedic Clinic in North Carolina paid $750,000 after giving x-ray films and PHI for about 17,300 patients to a company without a BAA. Its corrective plan required a named person responsible for BAAs, a standard template and BAA records kept for six years after each relationship ends.

Deciding whether an incident is a breach

An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless you can show a low probability that the PHI was compromised, based on a risk assessment of at least four factors (164.402):

  1. The nature and extent of the PHI, including identifiers and likelihood of re-identification.
  2. Who used it or received it.
  3. Whether it was actually acquired or viewed.
  4. How far the risk has been mitigated.

If it is a breach: patients within 60 days of discovery (164.404); HHS at the same time for 500 or more people, or in an annual log within 60 days of year-end for fewer (164.408); the media for more than 500 residents of a state (164.406). Add state deadlines, which can be shorter.

Documentation

Keep policies, training records, designations, risk analyses, sanctions, BAAs, incident assessments and complaint records for six years from creation or from when they were last in effect (164.530(j)).

OCR case: no policy. When Elite Dental Associates in Dallas settled for $10,000 over Yelp review replies that disclosed PHI, OCR also noted that the practice had no policy on social media disclosures and a non-compliant Notice of Privacy Practices.
Checklist

Printable practice manager HIPAA checklist

Stage 1 · Onboard (program level)

  • Privacy official and security official designated in writing
  • Role-based training materials for desk, providers, billing, marketing and managers
  • Training log with dates and signed acknowledgments; state-law timing checked
  • Confidentiality agreement template; BAA template compared with HHS sample provisions

Stage 2 · Access

  • Role-to-system access table approved
  • No shared logins; MFA enabled where available; break-glass account sealed
  • Monthly EHR access report reviewed; quarterly access review on the calendar
  • Device inventory with encryption status

Stage 3 · Operate

  • Risk analysis updated in the last 12 months; risk management plan in progress
  • Vendor register complete, each PHI vendor with a signed BAA
  • Channel rules published (phones, texts, email, social, reviews)
  • Sanctions policy applied and documented
  • Incident form, four-factor assessment template and state breach-law list ready

Stage 4 · Offboard (including your own handover)

  • Offboarding checklist used and filed for every departure and vendor exit
  • Admin credentials and vendor register handed over in writing
  • Privacy and security official roles reassigned and dated
  • All admin and shared passwords rotated on your last day

Owners of med spas can pair this with our med spa HIPAA advertising guide, med spa marketing, the med spa marketing statistics, the med spa Google presence report and the state medical board advertising guide. Dental practices: the dental HIPAA advertising guide. Marketing staff on your team should read HIPAA for marketing teams. Browse all US guides or book a call.

Sources

Sources

Keep reading

Related pages from the US team

HIPAA compliance by role

The full four-stage framework and the roles-by-stages matrix.

What to require from agencies and vendors

BAA terms, subcontractors, data flows and audit rights.

HIPAA offboarding checklist

Same-day access removal for staff and a clean exit for vendors.

HIPAA for front desk staff

Phone, check-in and texting rules with a printable checklist.

HIPAA-compliant healthcare marketing

Authorizations, testimonials, email and ads in one guide.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

Does a small practice need a HIPAA privacy officer?

Yes. Every covered entity must designate a privacy official responsible for its privacy policies and a contact person for complaints, and a security official responsible for Security Rule policies. In a small practice the practice manager or owner usually holds both roles, which is allowed.

How often should we do a HIPAA risk analysis?

The current Security Rule requires an accurate and thorough risk analysis and ongoing risk management but does not set a fixed frequency. Update it at least yearly and whenever you add a major system, move offices, change vendors or have an incident. The January 2025 proposed Security Rule update would make annual reviews explicit; as of October 2026 it is still a proposal.

What goes in a HIPAA vendor register?

Each vendor's name, what it does, what PHI it receives, the systems it touches, the date the BAA was signed, the BAA's breach-notice window, the subcontractors it uses for your data, the internal owner of the relationship and the review date. Add the termination steps you will need when the relationship ends.

Who decides whether an incident is a reportable breach?

The practice, usually through the privacy official with legal advice where needed. HIPAA presumes an impermissible use or disclosure is a breach unless a documented risk assessment of at least four factors shows a low probability that the PHI was compromised. Keep the assessment even when you conclude no notification is required.

Do we have to sanction staff for HIPAA violations?

You must have and apply appropriate sanctions against workforce members who fail to comply with your privacy and security policies, and document the sanctions applied. Sanctions should fit the violation, from retraining for an honest mistake to termination for deliberate snooping. Never sanction someone for reporting a problem.

What happens to HIPAA duties when the practice manager leaves?

Formally reassign the privacy and security official roles, transfer admin credentials and the vendor register, rotate every shared and admin password, and remove the departing manager's access the same day. Document the handover.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Need your marketing vendors to fit your HIPAA program?

A 30-minute call with the Ichelon Consulting US team. We sign a BAA with every US client and can walk you through how our team handles PHI.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership