What changes when I hire my first clinician?
Short answer: four things. Training, access, individual logins, and offboarding. If HIPAA applies to you, the rules do not change when you grow. What changes is that they now apply to somebody who is not you.
I am Scott Derby, I am an attorney, and this is where practices get caught out. Growing is not the risk. Growing without updating your safeguards is.
When you add someone new to your team, four things change.
Training. This is the one the law ties directly to hiring. You must train every new workforce member within a reasonable period after they join, tailored to what their job actually requires, and you must document that you did it. That is mandatory, not good practice. Separately, you need a security awareness and training program covering everyone, including yourself.
Access. You must identify who needs access to protected health information to do their job, and which categories of information they need, and you must make reasonable efforts to limit access to that.
Individual logins for apps that store protected health information. This rule requires you to assign a unique name or number for identifying and tracking each user. If you have a shared front desk login, that has to go. If two people use one login, you cannot tell which person did what.
Offboarding. You need procedures to terminate access when somebody’s employment, or other arrangement with you, ends. This also applies when there is a role change within the company, not just a departure from it. Write that procedure now, before the next change occurs.
Then there is the question I get asked most, and it is a good one. Is a contract clinician part of my workforce, an independent provider, or a business associate?
A tax form does not answer that. Under HIPAA, a contractor can be part of your workforce if their work is under your direct control, whether or not you pay them as an employee. A separate provider who receives information in order to treat a patient generally does not need a business associate agreement just for that. But an outside person or company performing services on your behalf that involve protected health information may well be one.
Each person is only one of those three. Never two, and never all three. What decides which one they are is control. If you direct how the work gets done, that person is part of your workforce. If you do not direct the work, and they handle protected health information for you, that person is a business associate. So the answer depends on the actual arrangement, not the label on the contract.
Decide which one each person is, write down why, and keep it. That way the decision exists before anyone asks you about it.
None of this is hard. It is just different from practicing by yourself, and it is far easier to set up before the first day than to reconstruct a year later.
This is general information about federal HIPAA. It is accurate as of writing and it can change. Your state very likely has its own privacy rules that sit on top of HIPAA and can be stricter, so treat this as a starting point rather than the final word, and check what applies where you practice. This is education, not legal advice for your specific situation.