Your new front-desk hire at the Elm Street office can read a thread about her neighbor's mammogram results at Riverside.
Nobody decided that. No one sat in a meeting and approved it. The tool has one permission level, she got a login, and the login opens everything.
Small-town and suburban groups feel this faster than big networks do, because the patient list and the staff list overlap. Your receptionist's kids go to school with your patients' kids.
That's usually an asset. In a system that can't scope staff access by office, it's a liability nobody wrote down.
Practice Fusion already gives you user accounts and role settings for the chart. The texting tool sitting next to it typically doesn't โ one shared office password, or a per-user login that grants the same everything to everyone.
OCR's Guam settlement in April 2025 cited unauthorized employee access alongside the ransomware that prompted the review. Staff opening records they had no reason to open is a finding on its own, not a footnote to a bigger incident.
Below: what the all-or-nothing login costs a group your size, how a practice manager builds the permission model, and what changes the next time someone resigns.
Centralizing across offices is the reason you bought the platform. A patient calls Fairground; anyone can help, coverage stops depending on who's in the building. Without scoping, that same design hands every account a key to every conversation in the group.
The Security Rule's workforce security standard (45 CFR ยง164.308(a)(3)) expects authorization to match the job, including procedures for ending access when employment ends. NIST's implementation guide, SP 800-66 Rev. 2, describes least privilege as the working form of that expectation.
Default-everything isn't a decision the group made. It's the absence of one, which is harder to explain to an investigator than a bad choice would be.
A shared office login means no audit log for patient texting can tell you who opened a thread. Four people, one account, zero attribution.
Then someone leaves. Offboarding access revocation at a practice with no IT department means an afternoon of changing passwords. Then you text the other offices the new one, which everyone writes on a sticky note by Thursday.
Curogram works as the compliance backbone by making permission management without IT a real option. One console, plain-language settings, and no scripting. Your administrator sets it up and maintains it between other work.
Granular RBAC builds a user's view from office, duty, and role at the same time, so five offices don't need fifty custom roles. A duty map for a typical group:
|
Duty |
Opens |
Doesn't open |
|---|---|---|
|
Front desk, one office |
Scheduling and confirmations at that office |
Any other office, any clinical thread |
|
Billing |
Billing threads, all five offices |
Clinical and scheduling threads |
|
Clinical staff |
Clinical threads at assigned offices |
Billing, other offices |
|
Practice manager |
Everything, plus permission editing |
โ |
Float staff get temporary access the same way, with dates attached. Grant Riverside and Oak Hill from the 3rd to the 17th, and on the 18th it ends by itself. Nobody has to remember, which is the only reason it actually stays temporary.
Sends, views, permission changes, exports โ each one recorded with a name and a timestamp, generated as a byproduct of people doing their jobs.
That's the record an access review asks for, and it's also what makes the group's wider texting governance policy provable rather than aspirational.
Holiday coverage, a maternity leave, someone filling in across town โ access flexes for the dates it's needed and closes after. Permissions in June reflect June, not every favor anyone did since January.
Five offices, six or seven duties, one pass through the console. Groups usually spend longer arguing about who counts as clinical staff than they spend entering it, and the model stops living in a spreadsheet that gets updated whenever someone remembers.
One deactivation ends access at every office immediately. The person's history stays in the log, which is what an access review wants to see, and no one changes a single password. The same scoping is what makes a shared inbox across offices safe to actually share.
Centralized communication is only safe when access is scoped, and scoped access is what lets a growing group centralize without flinching.
Practice Fusion handles your chart permissions. Curogram handles their conversation permissions, held to the same standard and logged the same way.
When you look at one list this week. Every person whose login opens patient messages at an office where they have never worked a shift. That list should end up empty.
Book a demo and turn your offices and duties into a working permission model during the call, float coverage included.