← All Resources

Medical Practices

Two Medical Practices, One Office: Where HIPAA Risk Gets Complicated

Two practices can share an address, Internet connection or IT provider without treating every account, computer and data store as one environment. The complication is making the boundaries clear and enforceable.

Short answer

Shared space does not eliminate each practice’s need to understand and protect its own PHI. Independent practices should document their relationships and use appropriate identity, access, network, device, storage, printing, vendor and incident controls so one organization’s users do not gain unintended access to the other’s information.

Begin with the organizational relationship

Two medical groups in one suite may be separate covered entities, part of a single covered entity or participants in another legally recognized arrangement. Technology design should follow that legal and operational reality rather than decide it. The practices should confirm the relationship and information-sharing authority with qualified counsel.

Once the boundary is understood, document which organization owns each system, employs each user, controls each record set and responds to incidents. Ambiguity becomes a security problem when everyone assumes someone else removes access or reviews a shared vendor.

Shared credentials erase accountability

A shared workstation does not require a shared login. HHS states that workforce members using a system that maintains ePHI must have a unique name or number so access and activity can be identified and tracked. Generic “frontdesk” accounts make it difficult to know who viewed, changed or exported information.

Use individual accounts, role-appropriate access and a consistent onboarding and offboarding process. If staff work for both practices, grant each person the access required for each role rather than making the entire environment open to everyone in the suite.

Common technology can create invisible crossover

Shared PCs may retain downloads, browser sessions, cached documents or saved passwords. Common servers and file shares can expose folders through overly broad permissions. Multifunction printers may store scans or route them to the wrong address book. Shared backup systems can combine data without clear restoration and access boundaries.

A flat network can also let a compromised or unmanaged device from one practice reach systems used by the other. HIPAA does not prescribe a particular firewall brand or network diagram, but risk analysis may support segmentation, separate wireless networks, restricted management paths and other controls appropriate to the environment.

Sharing an Internet connection or IT provider can still work

The practices can use common infrastructure when the design preserves appropriate separation. A shared Internet circuit can feed distinct network segments. One IT provider can manage both organizations with separate documentation, administrative roles, credential vaults, device policies, service records and authorization paths.

The provider relationship should be documented for each practice, including the services involving PHI or ePHI and the applicable Business Associate Agreement. Support technicians should know which practice can authorize access and should not use one organization’s administrator account to work in the other’s systems.

Do not overlook physical and workflow boundaries

Screens, paper, conversations, unlocked rooms and shared storage can bypass careful network design. Position workstations to reduce incidental viewing, secure records and devices, use appropriate screen-lock settings and define how documents move between reception, clinical and billing areas.

Map workflows that cross the boundary intentionally. Referrals, shared clinical staff, billing support or common equipment may involve permitted information exchange, but the access path and responsibility should be understood. “We share an office” is not a complete authorization rule.

Plan for changes and incidents

The environment changes when a provider joins, an employee begins working for both groups, one practice moves, a shared application is replaced or the IT provider changes. Review accounts, devices, data ownership, contracts and recovery procedures as part of those changes.

Incident plans should address crossover. If malware is found on a shared reception PC, who disconnects it, who preserves evidence, which practices are notified and which systems are reviewed? The answer should not depend on which owner happens to be in the office.

If an incident may involve Florida residents’ covered personal information, each practice may also need to evaluate FIPA separately from HIPAA and from the other practice’s obligations. Shared infrastructure does not make the federal and state notification analyses interchangeable.

Current rule and proposed changes

HHS’s Security Rule update remains proposed, and HHS states that the current Security Rule remains in effect. The separation measures discussed here are risk-based ways to support current access, accountability and safeguard requirements; they are not a claim that HIPAA mandates one specific network architecture.

What this means for the practices

Draw a simple diagram of people, devices, systems, vendors and data for each practice. Highlight anything shared. For every shared item, decide who owns it, who may access it, how access is logged, how data is separated, who supports it and what happens during an outage or incident.

The goal is not to duplicate every cable and device. It is to make the organizational boundary visible in technology, procedures and documentation so shared resources do not become shared risk by accident.

Related support

GO InfoTek can design and manage appropriately separated networks, identities, devices and support processes for practices that share facilities or providers, and connect those technical boundaries to each practice’s risk analysis and documentation.

Medical practice servicesNetwork & infrastructureManaged IT services

This article provides general information to support technology, cybersecurity and compliance discussions. It is not legal advice and does not replace review of your organization’s specific obligations with qualified legal or compliance professionals.

Sources and Further Reading

A practical next step

Discuss Your Environment with GO InfoTek

Start with the systems, safeguards, documentation and questions your organization has today.

Schedule a Conversation