Yes, we sign a Business Associate Agreement, and the controls behind it exist rather than being promised. Encrypted patient email starts at $7.95 a mailbox a month, with website hosting, intake forms, backups and IT support for practices of one to ten people. It is built for chiropractic, direct primary care and concierge clinics — the practices the large compliance vendors write pages for therapists and hospitals and then ignore.
A health care provider becomes a HIPAA covered entity by transmitting health information electronically in connection with a covered transaction — eligibility checks, claims, referral authorisation and similar. A one-chair practice that does any of these is covered in exactly the same way a hospital is.
A risk analysis, access controls, audit controls, transmission security and a written set of policies. It is not a certification you buy; it is a set of practices you maintain, and your vendors have to support it rather than undermine it.
We cannot make your practice compliant — nobody can sell you that. What we can do is sign a BAA, hold patient data on infrastructure we own in the United States, tell you in writing where it sits and who can reach it, and not be the weak link when you do your risk analysis.
Most solo practitioners genuinely do not know where they stand, and the answer is more specific than either extreme you will hear.
If secure email takes four extra clicks, staff will use their personal accounts instead and you will never find out. We set it up so the compliant path is the easy one.
The safest message is the one that does not contain protected health information at all. Intake forms, document exchange and a patient portal handle what email should not — Hub for Teams at $7.49 per user a month.
Mail retention configured deliberately, access logged, and encrypted off-site backups from $2.09 a month with a restore we have actually run.
The most common HIPAA failure in a small practice is not a breach. It is a receptionist emailing an appointment reminder with a condition in the subject line.
DPC physicians left insurance-based medicine to escape corporate control. The compliance picture is genuinely different, and almost nobody explains it properly.
Per mailbox, monthly. Small practices should not have to ask for a quote to find out.
Yes, as part of onboarding rather than as a paid add-on, and the controls behind it exist: access control and multi-factor authentication on administrative access, audit logging, encryption, tested restores and a written breach notification process.
Usually. You become a covered entity by transmitting health information electronically in connection with a covered transaction — eligibility checks, claims, referrals. A solo practice doing any of those carries the same obligations as a hospital.
No, and be careful of anyone who implies it does. A BAA binds one vendor. Compliance is your risk analysis, your policies, your training and an agreement with every vendor touching patient data. We make sure we are not the weak link.
Possibly not, if you never conduct a covered electronic transaction — but most DPC practices do, through e-prescribing, labs or referrals. And state confidentiality and breach laws apply regardless. It is worth establishing properly rather than assuming either way.
Mail Pro is $7.95 per mailbox a month, which is the tier most practices use. A three-person clinic is under $25 a month for email.
Yes. Mailboxes migrate with history intact and the cutover is scheduled outside clinic hours. We verify message counts on both sides before and after.
Most vendors make you sign first and discover the agreement later. Ask to see ours, and ask what the controls behind it actually are. Then decide.
Don’t like managing? We offer managed services for hosting, ecommerce, web sites, and more.
Liberation’s global edge network provides enhanced performance & security.
Stay informed on the latest tech news, new products, promotions, & more!