Skip to main content
If you run the practice or manage billing operations, this is your section. Start here to set up your team and lock in HIPAA-appropriate controls on day one.

First week checklist

1

Complete the practice profile

Name, NPI, Tax ID, specialty, primary payers. Practice settings →
2

Enforce 2FA for all users

Required for anyone who touches PHI. Two-factor auth →
3

Invite your team

Add users with the right roles. Team management →
4

Configure notifications

Slack, email, or in-app for deadlines, outcomes, and HIPAA-relevant events. Practice settings →
5

Review audit logs

Confirm PHI access is recorded as expected. Audit logs →
6

Request a BAA

If you’re a covered entity, request the BAA → before sending PHI.

Roles at a glance

RoleTypical userAccess
userBilling staffOwn work; PHI access within the practice
analystAnalytics / reportingAggregated or anonymized data only
supportCustomer-facing supportRead-only PHI, scoped
adminPractice adminFull access within the practice; cannot delete the practice
super_adminDenialbase internal (not for customers)Full platform, heavily audited

Compliance controls

2FA enforcement

Require TOTP or passkeys for everyone. Admins can require it at invite time.

Session policy

Idle timeout, max session duration, concurrent session limits.

Audit log export

Download PHI access logs for HIPAA audit purposes.

Data export / deletion

Exports for patient data-access requests; full practice deletion on offboarding.