HIPAA and Healthy Roster
Table of Contents
HIPAA and Healthy Roster
HIPAA stands for Health Insurance Portability and Accountability Act. HIPAA requires health care providers and organizations, as well as their business associates, to develop and follow procedures that ensure the confidentiality and security of all protected health information (PHI).
Healthy Roster is software designed to connect parents, coaches, athletes, and patients with their organization’s Providers. Because Healthy Roster values the privacy of its consumers, our software is strictly HIPAA compliant while allowing for the communication and transferring of protected health information only between persons that the parent or adult athlete has allowed permissions.
What this means is that only the Provider user, the adult athlete / patient or the parent will see protected health information unless permission has been granted through Healthy Roster to a coach or administrator to also see that PHI.
To see who has access to your athlete’s / patients PHI see step by step below:
Please Note: Terminology is different based on your setting, for example, a clinical setting uses Care Group as Organizations, Patient instead of Athlete, and Visits instead of Treatment, lastly Problems instead of Injuries, but the steps are still the same.
Step-By-Step Tutorial
- Navigate to the patient profile
-
Click Manage Users

- You will now see who has Direct Access, Inherited Access, as well as Pending Invitations or be able to add users and edit accordingly
- Direct Access: Those that have direct access to the patient profile (Typically the Patient/Parent/Primary User, Organizational User, Team User)
- Inherited Access: Users with the highest level of access, their access cannot be changed (Assigned Providers and Admin)
- Invitations: Invitations that have been sent but not accepted
Want to understand Direct vs Inherited Access better? Follow along here: Understanding Direct Access and Inherited Access

One more thing to note, if a new user such as a coach is added to your patient's Care Circle after you have already accepted permissions for the existing members of the Care Circle when you set up your account, you will be prompted to allow or deny permissions for those additions. They will not automatically be allowed to view the PHI in your patient's account.