Skip to main content
A HIPAA program for a small MSO-PC group has six components. The one most often missing, and most often cited in enforcement, is the security risk analysis.

Prerequisites

  • A designated privacy officer and security officer for each PC (often the same person, often MSO-provided)
  • The MSO–PC BAA executed, see Put a BAA in place
  • An inventory of every system and vendor that touches PHI

Who is responsible for what

Business associates are directly liable. Since the HITECH Act and the 2013 Omnibus Rule, your MSO has independent regulatory obligations, its own risk analysis, safeguards, training, and breach reporting. It is not merely contractually exposed through the BAA.1

The six components

1

Security risk analysis, do this one first

This is required, and its absence is among the most frequently cited findings in OCR enforcement. It must be an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI.A right-sized version:
  1. Inventory ePHI, every system, device, and location where it lives, including backups and any analytics warehouse
  2. Identify threats and vulnerabilities per asset
  3. Assess likelihood and impact
  4. Document current safeguards
  5. Rank residual risk
  6. Write a remediation plan with owners and dates
  7. Update annually and on material change, new system, new location, new entity
HHS and ONC publish a Security Risk Assessment Tool suitable for small practices.2
2

Policies

A minimum set, actually written and actually followed:
  • Notice of Privacy Practices (and it must be provided to patients)
  • Uses and disclosures; minimum necessary
  • Patient rights: access, amendment, accounting of disclosures, restrictions
  • Access control and workforce authorization
  • Device and media controls, including personal devices
  • Password and authentication standards
  • Encryption
  • Audit logging and review
  • Incident response and breach notification
  • Sanctions for workforce violations
  • Business associate management
  • Retention and destruction
A short policy people follow beats a long one nobody reads.
3

Training

At onboarding and annually, for both entities’ workforces. Document completion with dates — undocumented training is training you cannot prove.Include role-specific content: front desk staff face different risks than billers, who face different risks than clinicians.
4

BAA inventory

Every vendor handling PHI, with execution dates, breach notification windows, and review dates.
A denial analytics warehouse built from 835 data holds PHI. Teams building it as a finance project routinely miss the BAA, the encryption, and its inclusion in the risk analysis. See HIPAA for MSO-PC operators.AI vendors are the same problem with an extra trap: BAA coverage is scoped per service with substantial exclusions, and a zero-data-retention setting is not a substitute for the agreement. See LLMs, zero data retention, and HIPAA.
See Put a BAA in place.
5

Breach response plan

Written, and tested at least once.Under the Breach Notification Rule, an impermissible use or disclosure of unsecured PHI is presumed to be a breach unless you demonstrate a low probability of compromise through a documented risk assessment considering the specified factors.3State breach laws apply on top and are frequently stricter and faster. A multi-state group faces the union of them.Confirm the BAA’s notification window is short enough for the PC to meet its own deadline.
6

Security basics

The controls that prevent most incidents:
  • Multi-factor authentication everywhere. The 2024 Change Healthcare compromise reportedly involved a remote access service without MFA.
  • Encryption in transit and at rest, including laptops and mobile devices
  • Role-based access, reviewed quarterly
  • Prompt offboarding, terminated employees’ access removed same-day
  • Audit logging, with periodic review
  • Patching on a defined cadence
  • Backups, tested by actually restoring
  • Email security, phishing is the most common entry point

Where enforcement actually comes from

Most enforcement follows a complaint or a breach report, not a random audit. The recurring patterns:
  1. Missing or inadequate security risk analysis
  2. No BAA with a vendor handling PHI
  3. Impermissible disclosures, including responding to an online review with clinical detail
  4. Failure to provide patients access to their own records, a sustained enforcement priority
  5. Insufficient access controls, including former employees retaining access
  6. Unencrypted lost or stolen devices
Train staff never to respond to online reviews with any clinical detail, including confirming that someone was a patient. It is a recurring source of enforcement and it happens because a well-meaning employee wanted to correct the record.

MSO-PC-specific items

  • A BAA per PC. Each professional entity is a separate covered entity.
  • Segregate records across PCs in a shared EHR. A clinician in one state generally has no treatment relationship justifying access to another PC’s patients.
  • Document who serves as each PC’s privacy officer, especially where the MSO provides the person.
  • Never put PHI in bank memo fields. Financial institutions’ payment processing is excluded from the business associate definition — the exclusion covers processing payments, not receiving clinical data.
  • 42 C.F.R. Part 2 imposes a stricter regime on substance use disorder records. If any PC delivers SUD treatment, treat it as a separate workstream. See Behavioral health.

Verify it worked

  • Security risk analysis completed, documented, with a remediation plan
  • Policy set written and accessible
  • Training delivered and documented, both entities
  • BAA inventory complete, including analytics infrastructure
  • Breach response plan written and tested
  • MFA everywhere; encryption in transit and at rest
  • Access reviewed quarterly; offboarding same-day
  • A BAA per PC
  • Privacy officer designated per covered entity
  • Annual review calendared

Sources

  1. HITECH Act, Pub. L. 111-5, div. A, tit. XIII; HIPAA Omnibus Rule, 78 Fed. Reg. 5566 (Jan. 25, 2013). HHS OCR, Business Associates.
  2. HHS/ONC, Security Risk Assessment Tool.
  3. 45 C.F.R. §§ 164.400–414. HHS OCR, Breach Notification Rule.