Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Concierge Medicine Practices

The HIPAA compliance and security operating system for concierge practices. Greater access for the patient means more communication paths, more service partners, more personal devices — and a patient roster that attracts targeted social engineering. Patient Protect runs the risk analysis across that surface, sets communication and access policy, and keeps the evidence.

The honest answer to the question concierge practices most often misclassify.

Most vendor content gives a marketing-flavored hedge. The page below answers the question directly, with primary-source references where they exist. This is the section that matters most if you’re trying to figure out whether your operation is actually a covered entity.

Covered entity status

Most concierge practices are covered entities under 45 CFR §160.103, and the analysis is usually straightforward: they submit electronic claims and run eligibility verification, both of which are standard transactions adopted under 45 CFR Part 162. The retainer-fee component does not change that. Worth noting for accuracy — e-prescribing and electronic referrals are not themselves adopted covered transactions, so a practice that has dropped insurance entirely should re-run the test rather than assume its status carried over. For the large majority of concierge practices that still bill in some form, coverage attaches and stays attached.

Business associate status

Concierge practices are providers, not BAs. The BA cascade applies in the standard direction: the EHR, billing service, e-prescribing platform, lab interfaces, secure messaging tool, telehealth platform, payment processor where PHI flows, and any concierge-specific service vendors (24/7 nurse line, travel medicine partners, executive health screening providers) are all BAs and require BAAs under §164.308(b)(1).

Where the gray zone lives

The genuine gray zone for concierge practices is not whether HIPAA applies — it does — but rather the heightened operational requirements that come with serving prominent patients. HIPAA's minimum-necessary standard under §164.502(b) takes on heightened weight when the patient is a public figure: every additional staff member with access to the record increases the breach surface for a target whose breach has outsized media and reputational consequences. Some concierge practices operate enhanced privacy protocols (compartmentalized records, named-physician-only access, reduced administrative footprint) that exceed HIPAA minimums but reflect the actual threat model. The practice's choice is whether to formalize and document these enhanced protocols — making them legally defensible — or operate them informally where they fail the audit framework.

State consumer-health law

State medical privacy laws (California CMIA, Texas HB 300, New York's SHIELD Act health-data provisions) add layers above HIPAA, particularly for practices in jurisdictions that concentrate concierge operations. Some states impose stricter notification timelines than HIPAA's 60 days; some impose AG-notification thresholds that catch incidents HIPAA wouldn't require reporting at the federal level. Concierge practices operating in multiple states face a notification matrix calibrated to the prominent-individual scenario — the kind of breach where state AGs typically engage.

Operational events that move a concierge practice from theoretical non-coverage into clearly-covered-entity territory.

  1. Submitting any electronic health care claim (837), including for the insurance-billed portion of a hybrid retainer model.
  2. Conducting electronic eligibility or benefit verification (270/271).
  3. Requesting prior authorization or referral certification electronically (278).
  4. Checking claim status electronically (276/277), or receiving electronic remittance advice (835).
  5. Having a billing service, management company, or clearinghouse conduct any of the above for the practice.

What does not, by itself, make you a covered entity: sending an electronic prescription, submitting an electronic lab order, receiving an HL7 or FHIR result, running a patient portal, making an ordinary electronic referral, storing treatment photographs, hiring a medical director, or performing a medical service. None of these appear on CMS’s list of adopted standard transactions. They may still carry real security and state-law obligations — they just are not what decides HIPAA covered-entity status.

OCR has not published large-scale enforcement actions targeting concierge practices specifically as a segment, but breaches involving prominent individuals — including the 2017 OCR resolution agreement with Memorial Healthcare System ($5.5 million) and several cases involving celebrity-patient breaches at large hospital systems — signal heightened agency attention when prominent individuals are affected. The OCR's risk-tier model under the HITECH Final Rule explicitly considers the harm potential of the breach, which scales with the prominence of affected patients. A concierge breach involving public figures is positioned to attract enforcement at the upper end of OCR's discretion.
OCR enforcement record observation

Not legal advice. This page summarizes how HIPAA and related state consumer-health privacy laws apply to concierge medicine practices based on Patient Protect’s reading of the relevant CFR provisions and state statutes. Operators with applicability questions specific to their setup should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where concierge medicine practices are most exposed.

Standard risk analysis missing the actual threat model

Most concierge practices use compliance vendors that produce risk analyses calibrated for general primary care. The actual concierge threat model — paparazzi-driven social engineering, celebrity-patient targeting, asymmetric breach impact — is not what those analyses cover. The result is a documented risk analysis that satisfies the audit but does not protect the practice from the threats it actually faces.

Concierge-specific partner BAAs missing across the long tail

Beyond the standard EHR/lab/billing BAAs, concierge practices typically have ten to twenty partner relationships that touch PHI: 24/7 nurse lines, travel medicine partners, executive health screening, second-opinion services, mental health referral networks, dietitians, physical therapists, advocacy services. Most have unsigned templates or no BAA at all on the long-tail partners.

Asymmetric breach impact for prominent-patient incidents

A breach affecting one prominent patient can produce more reputational, legal, and regulatory consequence than a breach affecting hundreds of routine patients. Most concierge operators have not run the breach-impact analysis with the patient prominence factored in, and consequently have not built a response protocol calibrated to the actual stakes.

Patient communication discipline at the boundary of concierge accessibility

Concierge's value proposition includes direct, accessible communication with the physician — text, email, video, phone. The compliance reality is that patient communications must travel through HIPAA-compliant channels. Many concierge practices operate under informal communication patterns that create §164.530 exposure on every message.

Built for concierge medicine practices, not hospital systems.

Risk analysis modeling the concierge-specific threat surface

The SRA wizard models the actual threat surface concierge practices face: social engineering, paparazzi-driven access attempts, prominent-patient targeting, asymmetric breach impact. The output is a risk register grounded in the actual threats, not the generic primary-care threat model competitors design around.

Compartmentalized access controls calibrated for prominent patients

Role-based access management with explicit support for compartmentalized record access — named-physician-only sections, reduced administrative footprint per record, granular logging of access to identifiable prominent-patient records. Documented under §164.502(b) for audit defensibility.

BAA tracking for the concierge partner ecosystem

The Vendor Risk Scanner pre-loads the long-tail concierge partner ecosystem: 24/7 nurse lines, travel medicine partners, executive health screening providers, second-opinion services, mental health referral networks, advocacy services. Surfaces the BAA gaps generic compliance vendors miss because they don't model the concierge operating pattern.

Heightened breach response protocols for prominent-patient scenarios

Pre-built breach response with accelerated timelines, pre-drafted patient communications, AG-coordination procedures, and media-handling protocols specific to prominent-patient incidents. Assembled before any incident occurs rather than during the 72-hour window after one.

Secure communication that fits the concierge accessibility model

HIPAA-compliant text, email, and video that doesn't make the practice less responsive than the SMS-and-personal-email pattern it replaces. Audit-logged, role-aware, and calibrated for after-hours physician-direct communication.

Continuous compliance scoring with prominent-patient overlay

Real-time compliance recalculation that accounts for prominent-patient roster changes, new partner relationships, communication pattern drift. The dashboard surfaces the specific risks that scale with the patient base, not just the generic compliance score.

State-specific HIPAA rules for concierge medicine practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

District of Columbia compliance requirements for concierge medicine practices

In addition to federal HIPAA requirements, concierge medicine practices operating in District of Columbia must comply with the following state-specific obligations.

Breach notification deadline

In the most expedient time possible and without unreasonable delay, subject to the needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

The statute does not fix a numeric outer bound. Unreasonable delay is itself a violation and may result in state enforcement action, so treat the operative timeframe as the shortest window your incident circumstances reasonably support.

Attorney General notification

Required for all breaches

Your practice must notify the state AG in addition to affected patients and HHS.

District of Columbia-specific laws & requirements

DC uses the New-York pattern: HIPAA covers individual notice, but AG notice is independent

For HIPAA-regulated entities operating in DC, satisfying HIPAA breach-notification obligations to individuals is deemed to satisfy the § 28-3852 individual-notice requirement under subsection (g). But the separate DC Attorney General notification obligation under § 28-3852(b-1) is triggered independently once a breach affects 50 or more DC residents, and HIPAA compliance does not substitute for that AG notice. Practices notifying HHS under HIPAA still owe a separate written AG notice to DC.

Source: D.C. Code § 28-3852(a)

Verified against primary state authority as of August 2026. General reference — consult legal counsel for your specific obligations.

Primary sources: code.dccouncil.gov · oag.dc.gov

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for concierge medicine practices.

Does HIPAA apply to a concierge medicine practice that bills insurance plus charges a retainer?

Yes. The retainer-fee structure does not change HIPAA's covered-entity analysis. Concierge practices conducting standard electronic transactions — insurance claims, eligibility verification, e-prescribing, electronic referrals — are covered entities under §160.103 from inception, regardless of the additional retainer relationship.

Are concierge practices subject to heightened HIPAA enforcement attention?

OCR's risk-tier model under the HITECH Final Rule explicitly considers the harm potential of a breach, which scales with the prominence of affected patients. Concierge breaches involving public figures, executives, or other prominent individuals are positioned to attract enforcement at the upper end of OCR's discretion. The agency has not published a formal segment-specific stance, but enforcement patterns in adjacent contexts (celebrity breaches at hospital systems) suggest heightened attention.

How does HIPAA's minimum-necessary standard apply to prominent-patient scenarios?

Section 164.502(b) requires reasonable efforts to limit PHI access to the minimum necessary for each workforce role's function. For concierge practices, this often justifies compartmentalized record access — named-physician-only sections, reduced administrative footprint, explicit role-based controls that exceed the practice's general minimum-necessary policy. Documenting these enhanced controls makes them audit-defensible.

Do we need BAAs with every concierge-specific partner?

Yes. Every entity receiving PHI on the practice's behalf is a business associate under §160.103: 24/7 nurse lines, travel medicine partners, executive health screening providers, second-opinion services, mental health referral networks, advocacy services. Each requires a current signed BAA under §164.308(b)(1) before any PHI flows.

What state laws apply to concierge practices beyond HIPAA?

California's CMIA, New York's SHIELD Act health-data provisions, Texas HB 300, plus any state-specific medical privacy laws applicable in operating jurisdictions. Some impose stricter notification timelines than HIPAA's 60 days; some impose AG-notification thresholds that catch incidents HIPAA wouldn't require reporting federally. Multi-state concierge practices face a state-by-state matrix.

How should we handle direct patient communication that's part of the concierge value proposition?

Patient communications containing PHI must travel through HIPAA-compliant channels — that is non-negotiable. The implementation question is how to maintain concierge-level accessibility while satisfying §164.530. The practical answer is a HIPAA-compliant messaging platform that fits the direct-physician-access pattern: low-friction, after-hours capable, audit-logged, and indistinguishable in user experience from the SMS workflow it replaces.

What's the simplest path to a defensible compliance program for our concierge practice?

Five steps: (1) risk analysis modeling the concierge-specific threat surface, (2) compartmentalized access controls under §164.502(b), (3) BAAs with every standard and concierge-specific partner, (4) pre-built breach response protocol for prominent-patient scenarios, (5) workforce training including social engineering scenarios. Patient Protect handles all five at $99/month for Pro.

Does a concierge practice have to complete a HIPAA Security Risk Analysis?

Yes. Most concierge practices are straightforwardly covered because they bill, verify eligibility, or conduct other adopted transactions alongside the retainer, and every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a concierge practice that means the EHR, portal, membership and billing systems, physician and staff use of personal devices for direct and after-hours communication, travel and home-visit care, laboratory and hospital coordination, the records of patients likely to attract targeted access, and every service partner from the answering service to the executive-health provider. The retainer model changes the service level, not the analysis.

Which of our concierge vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR and portal vendors, membership and billing platforms, answering service, secure messaging, telehealth platform, cloud storage and backup, IT support, and concierge-specific service partners that administer care on the practice's behalf rather than delivering it themselves. The distinction matters here more than most places, because a 24/7 nurse line, travel medicine provider, executive-health screening service, second-opinion service, dietitian, or therapist may well be an independent treating provider — in which case the relationship is a treatment disclosure, not a business associate arrangement. Classify each partner individually; this segment has more of them than most.

A patient's assistant is asking for records. What do we do?

Treat it as an authority question, not a relationship question. An executive assistant, family member, or household staffer has no HIPAA right of access simply by being close to the patient. There are three legitimate paths: the person is the patient's personal representative under state law, the patient has signed an authorization naming them, or the patient has requested confidential communications routed through them and that request is documented. Absent one of those, the answer is no — regardless of how well-known the assistant is to the front desk, and regardless of how routine the request feels. This is the single most-exploited path in social engineering aimed at prominent patients, precisely because refusing feels like poor service. Put the standing authorizations on file in advance so the staff is confirming a record rather than making a judgment call under pressure.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a concierge practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Compliance built for the patient base concierge practices actually serve.

$99/month for Pro — the tier most concierge practices need given the prominent-patient threat model. Includes secure messaging, breach simulation, AI compliance assistant, and prominent-patient overlay tracking.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions