A float nurse gets two sites for two weeks, a billing team sees billing threads network-wide, and a departing employee loses everything in one action. The villain is the all-or-nothing login that older tools force on networks.
Either every user can read every patient conversation at every site, or the tool gets locked down until staff route around it. Least-privilege access isn't bureaucracy. It's what makes a shared platform safe enough to share, and it's written into the Security Rule at 45 CFR §164.312(a)(1).
A float nurse covers Westgate on Tuesday and Northside on Thursday. Give her the access she needs for those two shifts. In most patient texting tools, you've just handed her every conversation at all twelve locations, permanently.
That's the trade most multi-site groups are making without ever naming it. We think it's the wrong one, and it isn't the only option on the table.
Chart permissions in eCW already reflect your org chart. Facilities, departments, provider groups, security roles — that structure exists, and your team maintains it.
The texting layer bolted on beside the chart usually ignores all of it. One permission level, one shared login per site, or a spreadsheet somebody updates when they remember.
Unauthorized access and disclosure breaches rose 17.4% in 2025, based on OCR breach portal data. Over-broad access is how a small mistake becomes a reportable one. A front-desk hire opens a behavioral health thread she had no reason to see, and now the network owes a breach determination.
Three things follow: what all-or-nothing access costs across a network, how a permission model gets administered day to day, and what an access review looks like when the log is complete.
The Villain: The All-or-Nothing Login
Sharing Is the Point, and Also the Risk
Multi-location groups centralize communication so a patient can call any site and get help. That's the whole return on the project.
Without scoping, the same design that makes coverage possible makes every account a doorway into every conversation in the network.
The Question With No Good Answer
An auditor asks why a scheduler hired six weeks ago at your Lakeview clinic could read behavioral health threads at Westgate. "The tool only has one permission level" satisfies nobody — not the auditor, not the patient, not your board.
Under the minimum necessary standard (45 CFR §164.502(b)), access should stop at what the role requires. An RBAC healthcare communication platform is how that standard gets enforced instead of assumed.
Departures Become Scrambles
Every resignation turns into a manual lockout across every tool that person touched. Offboarding access revocation in healthcare rarely fails at the EHR — it fails at the fourteenth system nobody kept a list of.
IT then faces two bad choices: accept the exposure, or split back into per-location tools and recreate the silo the network just paid to eliminate.

The Guide: The Compliance Backbone
Permissions That Compose
Curogram works as the compliance backbone by scoping staff access by location and department, then layering role on top. The three dimensions compose rather than stack into presets, which is what lets one model cover a 12-site group without fifty custom roles.
Curogram Highlight: Granular RBAC
Granular RBAC builds each user's view from location, department, and role together, administered from one console. A worked example, using the float nurse from the opening:
|
Setting |
Value |
|---|---|
|
Locations |
Westgate, Northside |
|
Departments |
Primary Care |
|
Role |
Clinical — send, reply, view chart context |
|
Grant window |
Mar 3 – Mar 17 |
|
Behavioral health threads |
Excluded |
On March 18, the grant expires on its own. Nobody files a ticket, and her two weeks of activity stays in the log where an access review can see it.
Central permission management for clinics means one console handles all twelve sites. A site manager can be given queue assignment without being handed permission editing.
The Log Behind Every Action
Audit logs for patient texting by staff record sends, views, permission changes, and exports with timestamps. That satisfies the Audit Controls standard at 45 CFR §164.312(b).
It also makes offboarding one action. Deactivate the user, and access ends everywhere while the history stays intact. Both belong in the wider policy we set out in our guide to HIPAA-compliant texting governance.
The Success: Exactly Enough Access, Everywhere
From Indefensible to Exemplary
Every message access scoped and logged. That's the audit posture change one migration buys, and it's the difference between explaining a permission model and showing one.
Coverage Without Permission Creep
Floats, cross-site help, holiday coverage — all of it flexes without leaving residue. Least-privilege patient messages stay least-privilege in June because the March grant already expired.
Offboarding Becomes a Checkbox
One deactivation, all locations, immediate. The historical record stays available for review, which is exactly what an access reviewer wants to find. The same permission model is what makes a shared inbox across every location safe to actually share.
Conclusion: Share the Platform, Not the Exposure
Centralized communication earns its keep only when access is scoped — and only scoped access lets a network centralize with confidence.
eCW governs your chart permissions. Curogram governs their conversation permissions, with the same discipline and the same logs.
Run one list this week: everyone who can currently read patient messages at a location they've never worked. Then shrink that list to zero.
Book a demo and bring your org chart. We'll map it to a permission model in the session, including how floats and delegated site admins are handled.
Frequently Asked Questions
An admin grants specific sites for specific dates. Access starts and ends on those dates automatically, so coverage flexibility stops producing permanent permission creep that nobody remembers to clean up.
Central admins hold the permission model. Site managers can receive bounded controls like queue assignment without permission-editing rights. Every change either group makes is written to the audit log.
One deactivation removes access everywhere instantly. Their past activity stays in the audit log. That's what an access review needs to confirm the account was scoped correctly while it was active.
Shared logins destroy attribution. When four people use one account, no log can say who opened a thread. Both the minimum necessary standard and any breach investigation depend on that answer.
Access maps onto facilities and departments the way your eCW organization already defines them. The permission model matches the org chart you maintain, so nobody has to invent a second one.
