Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Direct Primary Care Practices

The HIPAA compliance and security operating system for direct primary care practices. Cash-pay does not answer the covered-entity question, and "we don't bill insurance" is not a security strategy. Patient Protect documents where you actually land, then runs the risk analysis, policies, training, vendor agreements, and evidence — plus the state-law layer that applies either way.

The honest answer to the question dpc practices most often misclassify.

Most vendor content gives a marketing-flavored hedge. The page below answers the question directly, with primary-source references where they exist. This is the section that matters most if you’re trying to figure out whether your operation is actually a covered entity.

Covered entity status

A DPC practice is a covered entity under 45 CFR §160.103 when it conducts one of the standard transactions adopted under 45 CFR Part 162 — or has a third party conduct one on its behalf. Those transactions are a defined list: health care claims (837), eligibility inquiry and response (270/271), prior authorization and referral certification (278), claim status (276/277), payment and remittance advice (835), enrollment, premium payment, coordination of benefits, and retail pharmacy drug claims under the NCPDP Telecommunication Standard. Ordinary prescriber-to-pharmacy e-prescribing under NCPDP SCRIPT is not on that list. That distinction matters more in DPC than almost anywhere, because a practice can be doing a great deal electronically — prescribing, ordering labs, coordinating with a hospital — without conducting a single covered transaction. What most often pulls a DPC practice in is a billing or membership vendor transacting on its behalf, or one insurance-billed service line. The threshold is the transaction, not volume: one qualifying transaction is enough. Cash-pay status does not settle the question in either direction. Run the test and document the conclusion.

Business associate status

DPC practices are not typically acting as business associates — they are providers, not vendors processing PHI on someone else's behalf. The BA question shows up in reverse: every technology platform the practice uses is a business associate to the DPC practice, and a written BAA is required under §164.308(b)(1) before any PHI flows. For modern DPC stacks that means BAAs with the EHR (Atlas.md, Hint, Elation, AthenaOne, Nextech are the common choices), the e-prescribing service (Surescripts, DrFirst), every lab interface (Quest, LabCorp, regional labs), the secure messaging tool, the payment processor where PHI touches it, the telehealth platform, and any backup or compliance vendor.

Where the gray zone lives

There is a narrow theoretical case for a DPC practice to operate outside HIPAA: pure cash-pay, zero electronic transactions, no e-prescribing, no electronic lab orders, no electronic hospital coordination, no electronic insurance verification. This is operationally impossible to maintain in 2026. Forty-plus states require electronic prescribing for controlled substances; many require it for all prescriptions. The DPC Frontier community generally treats HIPAA compliance as table stakes regardless of the technical applicability argument — see dpcfrontier.com for the community's working consensus. The real exposure is operating as if HIPAA does not apply, then routinely e-prescribing on a Tuesday — a §164.530 violation hiding inside a misclassified-status assumption. OCR has not yet published an enforcement action specifically targeting a DPC practice, which means DPC operators have less precedent to anchor on than dental or medical-practice operators do — so the conservative reading of the rule is the right one.

State consumer-health law

Even practices that fall outside HIPAA face state consumer-health privacy laws that increasingly impose comparable or stricter obligations — and unlike HIPAA, some are privately enforceable. Washington's My Health My Data Act (RCW 19.373) prohibits collecting or sharing 'consumer health data' without specific consent, with statutory damages and injunctive remedies. Nevada's SB 370 (2023) imposes parallel obligations with explicit applicability to wellness, telehealth, and direct-care models. Connecticut's Personal Data Privacy Act, California's CMIA plus the CPRA health-data overlay, and a growing list of other states are following the same pattern. The strategic implication for DPC: even where HIPAA technically would not apply, state law often will — and the compliance program that satisfies HIPAA largely satisfies state requirements as a byproduct.

Operational events that move a direct primary care practice from theoretical non-coverage into clearly-covered-entity territory.

  1. Submitting an electronic health care claim, or having a billing service submit one on the practice's behalf (837).
  2. Running electronic eligibility or benefit verification against a health plan (270/271).
  3. Requesting prior authorization or referral certification electronically (278).
  4. Checking claim status electronically (276/277), or receiving electronic remittance advice (835).
  5. Engaging any third party — biller, clearinghouse, management company — that conducts one of these transactions for the practice.
  6. Adding a partner provider or service line that conducts any of the above. Coverage attaches to the legal entity conducting the transaction, so map which entity is actually transacting.

What does not, by itself, make you a covered entity: sending an electronic prescription, submitting an electronic lab order, receiving an HL7 or FHIR result, running a patient portal, making an ordinary electronic referral, storing treatment photographs, hiring a medical director, or performing a medical service. None of these appear on CMS’s list of adopted standard transactions. They may still carry real security and state-law obligations — they just are not what decides HIPAA covered-entity status.

As of 2026, OCR has not published an enforcement action specifically targeting a direct primary care practice. That is a function of segment newness rather than absence of risk — and it is the reason DPC operators should adopt a conservative reading of HIPAA's covered-entity definition rather than waiting for the first DPC-specific enforcement action to clarify their obligations.
OCR enforcement record observation

Not legal advice. This page summarizes how HIPAA and related state consumer-health privacy laws apply to direct primary care practices based on Patient Protect’s reading of the relevant CFR provisions and state statutes. Operators with applicability questions specific to their setup should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where direct primary care practices are most exposed.

The 'we don't bill insurance' misconception

DPC practices commonly operate on the assumption that the absence of insurance billing means HIPAA does not apply. That assumption is wrong the moment the practice e-prescribes — which nearly every modern DPC practice does. Operating under the wrong assumption produces real exposure: untrained staff, no risk analysis, no BAAs with technology vendors, no breach notification protocol when an incident hits.

Lab interface BAAs that DPC practices specifically miss

DPC practices order labs differently than insurance-billed practices — directly through Quest, LabCorp, or regional reference labs, often at negotiated cash rates patients pay through the practice. A reference lab performing and reporting a test is generally a treating provider, and HHS gives that relationship as an example where no BAA is required. The vendors between the practice and the lab — ordering platforms, interfaces, results-routing services — generally are business associates and do require agreements. The same split applies to the specialty labs DPC practices use disproportionately: hormone panels, food sensitivity, microbiome testing, advanced cardiac markers. Getting that classification wrong in either direction is the most common finding in DPC compliance reviews.

Membership-model communication blurs HIPAA's lines

DPC's value proposition is direct, accessible communication — text, voice, email, video. Patients expect to message their physician directly. The operational reality is that staff and physicians often communicate from personal phones, personal email, and consumer messaging apps that are not HIPAA-compliant. OCR has consistently treated unsecured patient communication as a willful-neglect category in enforcement actions.

Solo and small-practice scale means no IT department

DPC practices skew small — many are solo physician plus one to three staff. No dedicated IT, no security operations, no continuous monitoring of the practice's attack surface. Ransomware groups have systematically targeted small healthcare practices because of this exact gap; attacks on practices under ten employees have grown faster than any other healthcare segment since 2021.

Built for direct primary care practices, not hospital systems.

Risk analysis calibrated for the DPC technology stack

The SRA wizard satisfies §164.308(a)(1) without requiring a consultant, a spreadsheet, or institutional IT support. Specifically modeled around the DPC stack — Atlas.md or Hint or Elation, e-prescribing service, lab interface, telehealth, secure messaging — rather than the hospital-system threat model that most compliance vendors design around. The output is a risk register your DPC operation can actually act on, not a 60-page document modeled for a 200-bed hospital.

BAA tracking that knows the DPC vendor ecosystem

The Vendor Risk Scanner pre-loads templates and known BAA status for the platforms DPC practices actually use — Atlas.md, Hint, Elation, Surescripts, DrFirst, Quest, LabCorp, regional reference labs, common secure-messaging vendors. Surfaces missing or weak agreements with specific clause-level analysis before they become enforcement findings. This is the differentiator over generic compliance vendors that ship one BAA template and expect the practice to fit every relationship into it.

Secure messaging built for direct-care workflows

Replaces SMS and personal-device communication with a HIPAA-compliant channel calibrated for how DPC operates: physician-direct, after-hours capable, audit-logged, no per-message overhead. Removes the highest-frequency and least-defensible compliance gap in DPC practices — and does it without making the practice less responsive than the SMS workflow it is replacing.

Policy generation modeled on DPC operations

Auto-generated policies for the scenarios that don't show up in dental or hospital-system templates: membership-agreement language compatible with HIPAA's §164.520 notice requirements, hybrid billing protocols when one provider in the practice bills insurance, hospital coordination procedures when a member gets admitted, after-hours communication standards. Reviewed against current OCR enforcement trends, not 2013-era templates that are still the default for most vendors.

Training that respects solo and small-practice scale

Eighty-plus training modules with completion tracking, designed to work at DPC scale — short, scenario-based, with content actually relevant to direct-care workflows rather than generic hospital-employee training repackaged. The physician owner can complete required training in an evening; a small staff completes onboarding in a single afternoon.

Continuous compliance scoring instead of an annual snapshot

The Autonomous Compliance Engine recalculates compliance state in real time as the practice changes — new staff member added, new vendor signed, new workflow rolled out. The result is an audit-ready position year-round, not a binder that is accurate only at the moment of the annual review and stale every other day of the year.

State-specific HIPAA rules for direct primary care practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

District of Columbia compliance requirements for direct primary care practices

In addition to federal HIPAA requirements, direct primary care practices operating in District of Columbia must comply with the following state-specific obligations.

Breach notification deadline

In the most expedient time possible and without unreasonable delay, subject to the needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

The statute does not fix a numeric outer bound. Unreasonable delay is itself a violation and may result in state enforcement action, so treat the operative timeframe as the shortest window your incident circumstances reasonably support.

Attorney General notification

Required for all breaches

Your practice must notify the state AG in addition to affected patients and HHS.

District of Columbia-specific laws & requirements

DC uses the New-York pattern: HIPAA covers individual notice, but AG notice is independent

For HIPAA-regulated entities operating in DC, satisfying HIPAA breach-notification obligations to individuals is deemed to satisfy the § 28-3852 individual-notice requirement under subsection (g). But the separate DC Attorney General notification obligation under § 28-3852(b-1) is triggered independently once a breach affects 50 or more DC residents, and HIPAA compliance does not substitute for that AG notice. Practices notifying HHS under HIPAA still owe a separate written AG notice to DC.

Source: D.C. Code § 28-3852(a)

Verified against primary state authority as of August 2026. General reference — consult legal counsel for your specific obligations.

Primary sources: code.dccouncil.gov · oag.dc.gov

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for direct primary care practices.

Does HIPAA apply to a direct primary care practice that doesn't bill insurance?

Often, but not automatically — and the common shortcut answer is wrong. HIPAA's covered-entity definition under 45 CFR §160.103 turns on whether the practice conducts a standard transaction adopted under Part 162, or has one conducted for it. E-prescribing, electronic lab orders, electronic referrals, and electronic hospital coordination are not adopted covered transactions, so none of them individually makes a practice a covered entity. What usually does: a billing or membership vendor running claims or eligibility on the practice's behalf, or a single insurance-billed service line. Many DPC practices are covered for exactly that reason. Run the test on your own operation rather than assuming either answer.

What if a DPC practice never transmits anything electronically?

Then the practice may genuinely fall outside HIPAA — but check the test rather than the intuition. Coverage turns on conducting an HHS-adopted standard transaction, or having one conducted on your behalf: claims, eligibility, prior authorization, claim status, remittance advice. E-prescribing, electronic lab orders, and electronic care coordination with a hospital are not on that list, so a practice doing all three may still be outside HIPAA. What usually pulls a DPC practice in is a billing or membership vendor transacting on its behalf, or a single insurance-billed service line. Falling outside HIPAA does not mean falling outside the law: state medical-privacy statutes, medical board recordkeeping rules, breach-notification law, and consumer-health privacy statutes in states including Washington, Nevada, and Connecticut can all still apply. Enforcement and remedies vary by statute — Washington's MHMDA is enforceable through its Consumer Protection Act, while several others are attorney-general enforced — so map the specific states you operate in.

Does the 2026 HSA eligibility for DPC fees change HIPAA status?

The HSA-DPC integration that takes effect in 2026 doesn't directly change covered-entity analysis under HIPAA, but it does change the operational reality. HSA-funded payments introduce additional record-keeping requirements, can trigger reporting obligations, and increase the pressure to integrate with insurance and pharmacy benefit infrastructures — each of which in turn creates new electronic transaction surfaces. Practices planning to accept HSA-funded membership fees should treat HIPAA compliance as foundational rather than optional from the date the integration takes effect.

Do I need a BAA with my e-prescribing vendor?

Yes. E-prescribing vendors — Surescripts, DrFirst, plus the e-prescribing modules built into EHRs — handle PHI on behalf of the prescribing practice and qualify as business associates under §160.103. A signed, current BAA is required before any PHI flows. Most DPC practices either rely on the EHR's BAA to indirectly cover the e-prescribing module (sometimes valid, sometimes not, depending on the EHR's own subcontracting language) or have no specific BAA at all.

What's the simplest path to HIPAA compliance for a solo DPC practice?

Four things, in order: (1) Run a documented risk analysis covering every system that touches PHI. (2) Get current, signed BAAs from every technology vendor — EHR, e-prescribing, lab interfaces, secure messaging, payment processor, backup. (3) Replace SMS and personal-device communication with a HIPAA-compliant channel. (4) Document training for yourself and any staff. Patient Protect handles all four at $39/month for the Basic tier with no consultant and no contract.

Can my DPC practice text patients without violating HIPAA?

Yes, within limits — HIPAA does not ban texting. The Privacy Rule allows a covered practice to communicate through the channel a patient requests, with reasonable safeguards and a documented warning about the risks (§164.522(b)). What it does not allow is an ungoverned channel with no record of that decision. The practical solution is a secure messaging platform that carries clinical content while staying as low-friction as the direct-access experience patients are paying for.

Does HIPAA require my DPC practice to have a Privacy Officer?

Yes. The Privacy Rule under §164.530(a) requires every covered entity to designate a Privacy Official and a contact person for receiving complaints. The Security Rule under §164.308(a)(2) requires a Security Official as well. In a solo DPC practice these can be the same person — typically the physician or a senior staff member — but both designations must exist in writing with documented responsibilities.

Does a direct primary care practice have to complete a HIPAA Security Risk Analysis?

If the practice is a covered entity, yes — and that determination comes first. Where the practice, or a third party acting for it, electronically conducts an adopted standard transaction, the full requirement applies: an accurate, thorough, documented assessment of the risks affecting all its ePHI. For a DPC practice that means the EHR and membership platform, direct physician messaging including communication from personal devices, e-prescribing and laboratory workflows, telehealth and home-office access, patient forms and uploaded records, backup and recovery, and every vendor touching PHI. A practice that concludes it is not covered should document that analysis too — the conclusion is only defensible if someone wrote down how it was reached.

Which of our DPC vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR, membership and billing platform, patient messaging and communication tools, telehealth platform, cloud storage and backup, IT support, virtual assistants and contractors with record access, and the interface or ordering vendors sitting between the practice and outside labs. Reference laboratories themselves are the common misclassification — a lab performing and reporting a test is a treating provider, and HHS gives that relationship as an example where no BAA is required. Specialists, hospitals, and imaging centers receiving referrals are treating providers too. A cash-pay model changes none of this analysis.

If our DPC practice is not a HIPAA covered entity, what actually applies to us?

More than nothing, and it is worth naming precisely. Falling outside HIPAA does not put patient information outside the law. State medical-privacy statutes govern confidentiality of medical records in most states regardless of federal status. Consumer-health privacy laws in a growing number of states reach health data held by non-covered businesses, some with consent, deletion, and data-sale obligations stricter than HIPAA's. Medical board rules impose recordkeeping, retention, and confidentiality duties as a condition of licensure. Membership agreements create contractual privacy commitments the practice can be held to directly. And any breach still triggers state notification law. The practical result is that a non-covered DPC practice usually needs substantially the same controls — it just cannot describe them as HIPAA compliance.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a direct primary care practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Compliance built for the way DPC actually operates.

$39/month for Basic, $99/month for Pro. No per-patient pricing, no insurance-billing assumptions baked in, no contracts. The same platform that handles thousand-patient panels works for solo DPC practices.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions