Does HIPAA apply to a concierge medicine practice that bills insurance plus charges a retainer?
Yes. The retainer-fee structure does not change HIPAA's covered-entity analysis. Concierge practices conducting standard electronic transactions — insurance claims, eligibility verification, e-prescribing, electronic referrals — are covered entities under §160.103 from inception, regardless of the additional retainer relationship.
Are concierge practices subject to heightened HIPAA enforcement attention?
OCR's risk-tier model under the HITECH Final Rule explicitly considers the harm potential of a breach, which scales with the prominence of affected patients. Concierge breaches involving public figures, executives, or other prominent individuals are positioned to attract enforcement at the upper end of OCR's discretion. The agency has not published a formal segment-specific stance, but enforcement patterns in adjacent contexts (celebrity breaches at hospital systems) suggest heightened attention.
How does HIPAA's minimum-necessary standard apply to prominent-patient scenarios?
Section 164.502(b) requires reasonable efforts to limit PHI access to the minimum necessary for each workforce role's function. For concierge practices, this often justifies compartmentalized record access — named-physician-only sections, reduced administrative footprint, explicit role-based controls that exceed the practice's general minimum-necessary policy. Documenting these enhanced controls makes them audit-defensible.
Do we need BAAs with every concierge-specific partner?
Yes. Every entity receiving PHI on the practice's behalf is a business associate under §160.103: 24/7 nurse lines, travel medicine partners, executive health screening providers, second-opinion services, mental health referral networks, advocacy services. Each requires a current signed BAA under §164.308(b)(1) before any PHI flows.
What state laws apply to concierge practices beyond HIPAA?
California's CMIA, New York's SHIELD Act health-data provisions, Texas HB 300, plus any state-specific medical privacy laws applicable in operating jurisdictions. Some impose stricter notification timelines than HIPAA's 60 days; some impose AG-notification thresholds that catch incidents HIPAA wouldn't require reporting federally. Multi-state concierge practices face a state-by-state matrix.
How should we handle direct patient communication that's part of the concierge value proposition?
Patient communications containing PHI must travel through HIPAA-compliant channels — that is non-negotiable. The implementation question is how to maintain concierge-level accessibility while satisfying §164.530. The practical answer is a HIPAA-compliant messaging platform that fits the direct-physician-access pattern: low-friction, after-hours capable, audit-logged, and indistinguishable in user experience from the SMS workflow it replaces.
What's the simplest path to a defensible compliance program for our concierge practice?
Five steps: (1) risk analysis modeling the concierge-specific threat surface, (2) compartmentalized access controls under §164.502(b), (3) BAAs with every standard and concierge-specific partner, (4) pre-built breach response protocol for prominent-patient scenarios, (5) workforce training including social engineering scenarios. Patient Protect handles all five at $99/month for Pro.
Does a concierge practice have to complete a HIPAA Security Risk Analysis?
Yes. Most concierge practices are straightforwardly covered because they bill, verify eligibility, or conduct other adopted transactions alongside the retainer, and every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a concierge practice that means the EHR, portal, membership and billing systems, physician and staff use of personal devices for direct and after-hours communication, travel and home-visit care, laboratory and hospital coordination, the records of patients likely to attract targeted access, and every service partner from the answering service to the executive-health provider. The retainer model changes the service level, not the analysis.
Which of our concierge vendors need Business Associate Agreements?
Any organization handling PHI on the practice's behalf: the EHR and portal vendors, membership and billing platforms, answering service, secure messaging, telehealth platform, cloud storage and backup, IT support, and concierge-specific service partners that administer care on the practice's behalf rather than delivering it themselves. The distinction matters here more than most places, because a 24/7 nurse line, travel medicine provider, executive-health screening service, second-opinion service, dietitian, or therapist may well be an independent treating provider — in which case the relationship is a treatment disclosure, not a business associate arrangement. Classify each partner individually; this segment has more of them than most.
A patient's assistant is asking for records. What do we do?
Treat it as an authority question, not a relationship question. An executive assistant, family member, or household staffer has no HIPAA right of access simply by being close to the patient. There are three legitimate paths: the person is the patient's personal representative under state law, the patient has signed an authorization naming them, or the patient has requested confidential communications routed through them and that request is documented. Absent one of those, the answer is no — regardless of how well-known the assistant is to the front desk, and regardless of how routine the request feels. This is the single most-exploited path in social engineering aimed at prominent patients, precisely because refusing feels like poor service. Put the standing authorizations on file in advance so the staff is confirming a record rather than making a judgment call under pressure.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a concierge practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.