Does HIPAA apply to a direct primary care practice that doesn't bill insurance?
Often, but not automatically — and the common shortcut answer is wrong. HIPAA's covered-entity definition under 45 CFR §160.103 turns on whether the practice conducts a standard transaction adopted under Part 162, or has one conducted for it. E-prescribing, electronic lab orders, electronic referrals, and electronic hospital coordination are not adopted covered transactions, so none of them individually makes a practice a covered entity. What usually does: a billing or membership vendor running claims or eligibility on the practice's behalf, or a single insurance-billed service line. Many DPC practices are covered for exactly that reason. Run the test on your own operation rather than assuming either answer.
What if a DPC practice never transmits anything electronically?
Then the practice may genuinely fall outside HIPAA — but check the test rather than the intuition. Coverage turns on conducting an HHS-adopted standard transaction, or having one conducted on your behalf: claims, eligibility, prior authorization, claim status, remittance advice. E-prescribing, electronic lab orders, and electronic care coordination with a hospital are not on that list, so a practice doing all three may still be outside HIPAA. What usually pulls a DPC practice in is a billing or membership vendor transacting on its behalf, or a single insurance-billed service line. Falling outside HIPAA does not mean falling outside the law: state medical-privacy statutes, medical board recordkeeping rules, breach-notification law, and consumer-health privacy statutes in states including Washington, Nevada, and Connecticut can all still apply. Enforcement and remedies vary by statute — Washington's MHMDA is enforceable through its Consumer Protection Act, while several others are attorney-general enforced — so map the specific states you operate in.
Does the 2026 HSA eligibility for DPC fees change HIPAA status?
The HSA-DPC integration that takes effect in 2026 doesn't directly change covered-entity analysis under HIPAA, but it does change the operational reality. HSA-funded payments introduce additional record-keeping requirements, can trigger reporting obligations, and increase the pressure to integrate with insurance and pharmacy benefit infrastructures — each of which in turn creates new electronic transaction surfaces. Practices planning to accept HSA-funded membership fees should treat HIPAA compliance as foundational rather than optional from the date the integration takes effect.
Do I need a BAA with my e-prescribing vendor?
Yes. E-prescribing vendors — Surescripts, DrFirst, plus the e-prescribing modules built into EHRs — handle PHI on behalf of the prescribing practice and qualify as business associates under §160.103. A signed, current BAA is required before any PHI flows. Most DPC practices either rely on the EHR's BAA to indirectly cover the e-prescribing module (sometimes valid, sometimes not, depending on the EHR's own subcontracting language) or have no specific BAA at all.
What's the simplest path to HIPAA compliance for a solo DPC practice?
Four things, in order: (1) Run a documented risk analysis covering every system that touches PHI. (2) Get current, signed BAAs from every technology vendor — EHR, e-prescribing, lab interfaces, secure messaging, payment processor, backup. (3) Replace SMS and personal-device communication with a HIPAA-compliant channel. (4) Document training for yourself and any staff. Patient Protect handles all four at $39/month for the Basic tier with no consultant and no contract.
Can my DPC practice text patients without violating HIPAA?
Yes, within limits — HIPAA does not ban texting. The Privacy Rule allows a covered practice to communicate through the channel a patient requests, with reasonable safeguards and a documented warning about the risks (§164.522(b)). What it does not allow is an ungoverned channel with no record of that decision. The practical solution is a secure messaging platform that carries clinical content while staying as low-friction as the direct-access experience patients are paying for.
Does HIPAA require my DPC practice to have a Privacy Officer?
Yes. The Privacy Rule under §164.530(a) requires every covered entity to designate a Privacy Official and a contact person for receiving complaints. The Security Rule under §164.308(a)(2) requires a Security Official as well. In a solo DPC practice these can be the same person — typically the physician or a senior staff member — but both designations must exist in writing with documented responsibilities.
Does a direct primary care practice have to complete a HIPAA Security Risk Analysis?
If the practice is a covered entity, yes — and that determination comes first. Where the practice, or a third party acting for it, electronically conducts an adopted standard transaction, the full requirement applies: an accurate, thorough, documented assessment of the risks affecting all its ePHI. For a DPC practice that means the EHR and membership platform, direct physician messaging including communication from personal devices, e-prescribing and laboratory workflows, telehealth and home-office access, patient forms and uploaded records, backup and recovery, and every vendor touching PHI. A practice that concludes it is not covered should document that analysis too — the conclusion is only defensible if someone wrote down how it was reached.
Which of our DPC vendors need Business Associate Agreements?
Any organization handling PHI on the practice's behalf: the EHR, membership and billing platform, patient messaging and communication tools, telehealth platform, cloud storage and backup, IT support, virtual assistants and contractors with record access, and the interface or ordering vendors sitting between the practice and outside labs. Reference laboratories themselves are the common misclassification — a lab performing and reporting a test is a treating provider, and HHS gives that relationship as an example where no BAA is required. Specialists, hospitals, and imaging centers receiving referrals are treating providers too. A cash-pay model changes none of this analysis.
If our DPC practice is not a HIPAA covered entity, what actually applies to us?
More than nothing, and it is worth naming precisely. Falling outside HIPAA does not put patient information outside the law. State medical-privacy statutes govern confidentiality of medical records in most states regardless of federal status. Consumer-health privacy laws in a growing number of states reach health data held by non-covered businesses, some with consent, deletion, and data-sale obligations stricter than HIPAA's. Medical board rules impose recordkeeping, retention, and confidentiality duties as a condition of licensure. Membership agreements create contractual privacy commitments the practice can be held to directly. And any breach still triggers state notification law. The practical result is that a non-covered DPC practice usually needs substantially the same controls — it just cannot describe them as HIPAA compliance.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a direct primary care practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.