Make an asset register before granting access
List the domain registrar, DNS, hosting, source repository, business email, advertising accounts, analytics, payment relationships, support tools and each vendor portal. For each, record the contracting entity, account administrator, billing owner, recovery method and vendor access. Identify assets operated within a vendor's account rather than your own. Ask what happens to them if the service ends, including whether transfer is permitted and what assistance costs.
Where permitted, establish the brand's account directly and invite collaborators. Avoid putting a durable asset solely under a contractor's personal email. Document exceptions and agreed transfer processes in a register your team can test.
Separate control, access and permission to use data
A domain, an advertising account, a transaction report and a clinical chart have different responsibilities. HHS describes individual rights over health information and limits on its use and disclosure. Do not describe patients or their protected health information as ordinary brand assets that can be used without restrictions. Ask qualified advisers and the care entities to determine the brand's role and the rules that apply to the proposed data flows.
For clinical information, record the custodian, system holding the record, entities with authorized access and process for patient requests. Define what nonclinical support staff may view and why. Identify who approves an export and its destination. A downloadable file does not establish permission to send it to an advertising tool, a new vendor or a prospective buyer. Use the HIPAA data-flow map to keep the purpose attached to every connection.
Source context: HHS: Your Rights Under HIPAA
Use named roles and tested recovery
Create a role list for finance, support, technical maintenance, marketing and clinical work. Grant access for the task and review it when the task changes. Use individual logins where available, protect accounts with suitable authentication and keep recovery information in an approved secure system. Do not store passwords or recovery codes in the asset worksheet. Name a backup administrator where the service permits one and test account recovery without disrupting live operations.
Bask's documentation describes permission assignment and access suspension or removal for team members. Whatever platform you choose, demonstrate those actions with your proposed roles. HHS describes authorizing ePHI access according to role for regulated entities. Broad administrative convenience is not a reason to expose a clinical record to every agency, contractor or executive. Have the designated privacy and security owners approve the access model.
Source context: Bask Health: Inviting Your Team Members, HHS: Summary of the HIPAA Security Rule
Put the departure process into the agreements
Ask contracts to distinguish business assets, licensed vendor software, work created for the engagement, operational exports and clinical information. For each category, request the available handover format, notice, assistance, cost and timing. Confirm whether you receive editable source files or only a hosted result. Verify what remains dependent on an active vendor subscription. Keep the signed agreement alongside the register rather than relying on a remembered sales call.
For applicable business associate arrangements, HHS explains that contracts address permitted uses and disclosures and the handling of protected health information at termination. Have counsel adapt those requirements to the parties and retention responsibilities. Do not interpret a generic instruction to return or destroy information as permission for the founder to erase clinical records. Review the migration and exit checklist with the responsible custodians.
Source context: HHS: Business Associate Contracts
Review the register when people and vendors change
During onboarding, give each person the approved role and record the sponsor who requested it. During departure, remove access, revoke relevant sessions or keys and transfer assigned work. Verify the result instead of assuming an email request completed it. When a vendor changes, inspect integrations, notification destinations and billing permissions as well as the obvious portal login. A departed contractor may otherwise remain attached through an automation.
Review business ownership and access after a domain change, agency change, platform migration or financing event. Keep the review proportionate: the aim is a usable inventory with clear authority. A diligence folder should show who controls the brand assets and how authorized operations continue when a person leaves. It should not become an unnecessary duplicate repository of patient records.
Asset and access register
Add account identifiers and owners in your secure internal version. Record recovery procedures, not secret credentials, in this worksheet.
On small screens, scroll the table sideways to view every column.
| Asset | Control to verify | Departure evidence |
|---|---|---|
| Domain and DNS | Registrant, billing and recovery authority | Transfer terms and backup administrator |
| Website and creative files | Repository access and usage rights | Editable files and deployment instructions |
| Advertising and analytics | Business account and delegated permissions | Access removal and integration review |
| Payments and finance | Contracting entity and reporting rights | Processor-approved transition process |
| Clinical records | Custodian and authorized access | Approved transfer and retention process |
Before you move forward
- Name the entity and administrator for every material account.
- Document vendor-controlled accounts and transfer limits.
- Approve permissions by task and data purpose.
- Test recovery and staff access removal.
- Have counsel and custodians review clinical record handover.
Sources and scope
Source check: October 10, 2026. Primary sources support the rules and vendor descriptions cited above. Worksheets are original planning tools, not provider commitments or forecasts. Requirements can change; confirm current terms for your program.
- HHS: Your Rights Under HIPAA
Supports patient rights, protected information and limits on use and disclosure. Does not establish brand ownership of records. Checked October 10, 2026.
- Bask Health: Inviting Your Team Members
Vendor documentation for assigning permissions and suspending or removing user access. Checked October 10, 2026.
- HHS: Summary of the HIPAA Security Rule
Supports role-appropriate ePHI access questions. Specific configuration needs an entity-level assessment. Checked October 10, 2026.
- HHS: Business Associate Contracts
Supports permitted-use and termination questions for applicable business associate contracts. HHS notes its samples do not replace legal advice. Checked October 10, 2026.