HIPAA for Non-Clinician Founders: What You're Actually Responsible For
You own the brand, not the medicine. HIPAA still applies to you. In the standard telehealth structure, the physician-owned medical group is the covered entity, and your company, the brand/MSO that handles patient data on its behalf, is a business associate with direct legal obligations under HIPAA: sign business associate agreements (BAAs) up and down your vendor chain, limit who sees protected health information (PHI), secure it, train your team, and report breaches. You cannot outsource that status. What you can outsource is the heavy technical lifting: an infrastructure partner can supply the encrypted platform, audit trails, access controls, and its own BAA, which removes most of the engineering burden but none of your operational duties. The failure mode that catches non-clinician founders most often is not the clinical stack at all; it is the marketing stack, where advertising pixels quietly ship health data to ad platforms. This guide explains where you sit in the HIPAA map, who signs what, and the short list of things you personally have to run.
This is general information, not legal advice.
Key takeaways
- A telehealth brand or MSO that handles patient data on behalf of its affiliated medical group is a business associate under HIPAA, with direct legal obligations and direct liability.
- Every entity that touches PHI in your stack needs a business associate agreement in the chain: platform, pharmacy connectivity, cloud vendors, support tools, and any analytics vendor with PHI access.
- The most common HIPAA failure at telehealth startups is marketing data: tracking pixels and ad-platform integrations that transmit health information have drawn sustained regulatory scrutiny.
- Founders cannot delegate everything; access control decisions, a current vendor inventory, workforce training, and breach-response readiness stay in-house no matter who builds the platform.
- An infrastructure partner like MyOrbitHealth covers the technical safeguards, including a BAA in every contract, SOC 2 controls, HITRUST-aligned architecture, and US-region encrypted data residency.
What does HIPAA actually regulate?
HIPAA regulates protected health information: any information that links an identifiable person to their health condition, care, or payment for care. In a telehealth funnel, PHI shows up earlier than most founders expect. A completed intake questionnaire is PHI. An email address attached to a weight-loss consultation booking is PHI. A prescription status, a refill date, a "your provider has responded" notification, all PHI. The name of someone browsing your marketing site generally is not, until it gets connected to a health service.
Three rules matter day to day: the Privacy Rule (how PHI may be used and disclosed, including the minimum necessary standard), the Security Rule (administrative, physical, and technical safeguards for electronic PHI), and the Breach Notification Rule (what happens when something goes wrong).
Are you a covered entity or a business associate?
Almost certainly a business associate, and the distinction determines your obligations.
Covered entities are healthcare providers, health plans, and clearinghouses. In the MSO model that non-clinician telehealth founders use, the covered entity is the physician-owned professional corporation (PC) that actually treats patients. It owns the medical records and the treatment relationship.
Business associates are organizations that create, receive, maintain, or transmit PHI on a covered entity's behalf. That is your MSO: you handle patient support, billing coordination, the customer relationship, and the technology through which care is delivered. Since the HITECH updates, business associates are directly liable under HIPAA, meaning regulators can pursue your company itself, not just the medical group, for security failures, improper disclosures, and missing BAAs.
Kill the common misconception here: "we're just the brand, HIPAA is the doctors' problem." Business associate status attaches based on what you do with the data, not what your marketing says, and even data you think of as commercial, like a customer's subscription to a TRT program, is health information because the product implies a condition and treatment. If you are still mapping how a non-clinician structures this business at all, start with our guide to starting a telehealth business without a medical license; HIPAA sits alongside the corporate-practice rules covered there.
How does the BAA chain work, and who signs with whom?
A business associate agreement is the contract that binds a PHI-handling vendor to HIPAA's requirements: permitted uses, safeguards, breach reporting, and obligations for subcontractors. The rule of thumb is simple: wherever PHI flows across a company boundary, a BAA must exist at that boundary. In a typical white-label telehealth brand, the chain looks like this:
- Medical group (PC) ↔ your MSO. The covered entity signs a BAA with your company, because you handle PHI on its behalf. In practice this is usually built into the management services agreement package.
- Your MSO ↔ platform/infrastructure partner. The company hosting intake, the EMR, messaging, and prescribing data signs a BAA with you (and typically with the medical group). MyOrbitHealth includes a BAA in every contract for exactly this reason.
- Platform ↔ its subcontractors. Cloud hosting, e-prescribing rails, video vendors. These are subcontractor business associates; your platform is responsible for having BAAs with them, and you are responsible for confirming it does.
- Pharmacy partners. Pharmacies are covered entities in their own right for dispensing, but data flows between your stack and pharmacy connectivity layers still need agreement coverage; verify how your platform papers this.
- Your own vendors. Customer support helpdesk, email/SMS provider, call recording, data warehouse, any AI tools your team uses: if patient information passes through them, each needs a BAA. If a vendor will not sign one, PHI cannot go there. That single test disqualifies most consumer-grade tools, including standard email accounts and generic chat apps, for patient communication.
- Analytics and advertising vendors. The hard case, and the next section.
One more nuance: a BAA is necessary but not sufficient. Signing a BAA with a vendor that has sloppy security does not protect you; it just documents who to blame. Vendor selection is a security decision, not a paperwork exercise.
Why is marketing data the biggest HIPAA trap for founders?
Because it lives on your side of the house, it is invisible in the clinical stack, and it is exactly where growth-stage habits from e-commerce turn toxic.
The mechanism: advertising pixels and tracking scripts (ad-platform pixels, session-recording tools, some analytics configurations) capture what users do on your site and app, then transmit it to the vendor for attribution and retargeting. On a shoe store, harmless. On a telehealth site, that same pixel can transmit that an identifiable person completed a semaglutide intake, booked a men's-health consult, or hit the "prescription approved" confirmation page. That is a disclosure of health information to an ad platform that has not signed a BAA and will not sign one for advertising use.
This is not theoretical. In recent years, the federal agencies that enforce health privacy and consumer protection law have repeatedly scrutinized tracking technologies on health-related websites, issued guidance warning that transmitting health data through pixels can violate the law, and pursued enforcement actions against digital health and telehealth companies over sharing user health data with advertising platforms. Well-known consumer health brands have faced regulatory action and class-action litigation over exactly this pattern. The direction is unambiguous: regulators treat pixel data on health sites as health data.
What careful telehealth brands do instead:
- Keep marketing and clinical surfaces separated. Pixels can live on the public marketing site; they must not fire inside the intake flow, patient portal, or any authenticated experience.
- Audit tags quarterly. Tag managers accumulate scripts. Someone must own the list of what fires where and what each script transmits.
- Use privacy-safe conversion measurement. Server-side, de-identified, or aggregate conversion approaches, designed with counsel, rather than raw pixel events from health pages.
- Treat "anonymous" claims skeptically. IP address plus a GLP-1 intake URL is usually identifiable in regulators' eyes.
If you run paid acquisition, this belongs in the same pre-launch workstream as LegitScript certification and ad-platform approvals, not something to retrofit after the first attorney letter.
What does a founder actually have to operate day to day?
Strip away the mystique and HIPAA operations for a lean telehealth brand come down to five running disciplines.
1. Access controls and minimum necessary. The minimum necessary standard says people should access only the PHI required for their job. Your growth marketer does not need diagnoses. Your customer support lead needs order status, not chart notes. Concretely: role-based access in every tool, no shared logins, offboarding that revokes access the day someone leaves, and a periodic review of who can see what. Platforms like OrbitOS ship role-based access and a full audit trail, but you decide which of your employees gets which role.
2. A living vendor inventory. One document listing every vendor that touches PHI, what data it receives, whether a BAA is signed, and who owns the relationship. Update it whenever anyone connects a new tool, which in practice means making yourself or one ops lead the gatekeeper for new SaaS.
3. Workforce training. Everyone who might encounter PHI, contractors included, gets HIPAA training at onboarding and annual refreshers. Off-the-shelf courses are fine; the point is documented training plus practical rules (no PHI in personal email, no screenshots into chat, phishing awareness).
4. Breach-response basics. Before an incident, not after: know who you call (counsel, your platform's security contact), keep a simple written incident-response plan, and understand the notification clock. HIPAA requires notifying affected individuals and regulators of breaches of unsecured PHI, generally within 60 days of discovery, faster for some state laws. Your BAAs should obligate vendors to report incidents to you promptly, because their breach starts your clock.
5. A risk analysis, on paper. The Security Rule expects a documented risk assessment: where PHI lives, what could go wrong, what safeguards exist. For a brand on managed infrastructure this is a modest exercise, but "we never wrote anything down" is the finding that turns an incident into a penalty.
None of this requires a compliance department. It requires an owner, a checklist, and consistency.
What does the infrastructure partner cover vs what stays your job?
This split is the heart of the build-vs-buy decision for compliance. A credible partner removes the entire technical safeguard layer; nothing removes your administrative layer. Here is the division on MyOrbitHealth, which is representative of what to demand from any platform you evaluate (Beluga, OpenLoop, Fuse, and Telegra will each draw this line slightly differently; ask them to draw it in writing):
| Infrastructure partner covers | Stays the founder's job |
|---|---|
| Signed BAA included in every contract | BAAs with your own vendors (support desk, email/SMS, warehouse) |
| Encrypted PHI storage and transit, US-region data residency | Deciding which team members get which access roles |
| SOC 2 controls and HITRUST-aligned architecture | Maintaining the vendor inventory and gatekeeping new tools |
| Role-based access system and full audit trail (OrbitOS) | Workforce HIPAA training and enforcement of internal rules |
| Secure intake, EMR, messaging, and e-prescribing infrastructure | Keeping ad pixels and trackers out of patient-facing surfaces |
| Subcontractor BAAs for its own cloud and clinical vendors | Your marketing site, tag manager, and analytics configuration |
| Platform-side incident detection and security monitoring | Your incident-response plan and breach notification duties |
| Compliance-maintained platform updates as rules evolve | Documented risk analysis for your own operations |
Read the right-hand column carefully before signing with anyone. If a sales deck implies the platform makes you "fully HIPAA compliant" with no work on your side, that is a red flag about the vendor's sophistication. The honest pitch, and the one we make, is that the platform eliminates the part that requires security engineers and leaves you the part that requires discipline. Our white-label telehealth platform guide covers the rest of the evaluation checklist beyond HIPAA.
Note also that HIPAA is only one layer of the regulatory stack. Provider licensing runs state by state, and your compliance posture has to match where your patients are; see telehealth licensing by state for how a 50-state footprint actually works. MyOrbitHealth's provider network covers all 50 states with 1,240+ board-certified providers across 38+ specialties, which means the licensing layer and the HIPAA layer come from one accountable partner instead of a stack of vendors pointing at each other.
Frequently asked questions
Is a telehealth brand owner a covered entity under HIPAA?
Usually not. The covered entity is the physician-owned medical group that treats patients. The founder's company is typically a business associate because it handles patient data on the medical group's behalf, and business associates carry direct HIPAA obligations and direct liability for violations.
Do I need a BAA with my telehealth platform?
Yes. Any platform that stores or transmits patient data on your behalf must sign a business associate agreement before PHI touches it. MyOrbitHealth includes a BAA in every contract; treat a platform that hesitates on this as disqualified.
Can I use Google Analytics or a Meta pixel on my telehealth site?
Only with real care and ideally with counsel involved. Regulators have warned that tracking technologies transmitting health information to third parties can violate privacy law, and telehealth companies have faced enforcement over it. The conservative pattern is pixels on public marketing pages only, never inside intake flows, portals, or booking confirmations.
What is the minimum necessary rule in plain English?
Each person should be able to see only the patient information their job requires, and each disclosure should include only what is needed for its purpose. In practice it means role-based access in every system, no shared logins, and support staff seeing order status rather than clinical charts.
What happens if my telehealth startup has a data breach?
You investigate, contain, and document the incident, and breaches of unsecured PHI generally require notifying affected individuals and federal regulators within 60 days of discovery, with large breaches also reported to media. Your vendors' BAAs should require them to report incidents to you quickly, because your notification clock starts at discovery.
Does using a HIPAA-compliant platform make my company HIPAA compliant?
No. A compliant platform covers the technical safeguards: encryption, access control systems, audit trails, and secure infrastructure. Your company still owns workforce training, access role decisions, vendor BAAs and inventory, marketing-data hygiene, a risk analysis, and breach response. Compliance is the platform plus your operating discipline.
Get the technical layer handled so you can run the rest
The founder's real HIPAA job is short: control access, know your vendors, train your team, keep pixels away from patients, and be ready for a bad day. Everything else, the encrypted infrastructure, audit trails, SOC 2 controls, HITRUST-aligned architecture, US-region data residency, and a BAA in every contract, is what MyOrbitHealth exists to provide. Book a demo with MyOrbitHealth to see how founders launch on infrastructure where the hard part of HIPAA is already built.