If you run the practice or manage billing operations, this is your section. Start here to set up your team and lock in HIPAA-appropriate controls on day one.
First week checklist
1
Complete the practice profile
Name, NPI, Tax ID, specialty, primary payers. Practice settings →
2
Enforce 2FA for all users
Required for anyone who touches PHI. Two-factor auth →
3
Invite your team
Add users with the right roles. Team management →
4
Configure notifications
Slack, email, or in-app for deadlines, outcomes, and HIPAA-relevant events. Practice settings →
5
Review audit logs
Confirm PHI access is recorded as expected. Audit logs →
6
Request a BAA
If you’re a covered entity, request the BAA → before sending PHI.
Roles at a glance
Compliance controls
2FA enforcement
Require TOTP or passkeys for everyone. Admins can require it at invite time.
Session policy
Idle timeout, max session duration, concurrent session limits.
Audit log export
Download PHI access logs for HIPAA audit purposes.
Data export / deletion
Exports for patient data-access requests; full practice deletion on offboarding.