A new surgeon starts at your multi-site group on the first of the month. Her license is verified, her NPI is active, three payer enrollments are pending, and someone in the front office has already put her on the OR schedule for a procedure your governing documents never authorized her to perform. That gap — between "we checked her out" and "we said yes to this specific list of services" — is the reason you need to define privileging in writing before a single patient is booked.

This guide is for the administrator, credentialing coordinator, or privacy officer who owns that file. It covers what privileging is operationally, who signs what, where protected health information enters the process, and which of your vendors need a Business Associate Agreement because of it.

Privileging, Defined in One Paragraph

Privileging is the organizational decision granting a specific clinician permission to perform a specific, enumerated set of services within your practice or facility, based on verified education, training, licensure, current competence, and health status. Credentialing answers "is this person who they claim to be, and are the qualifications real?" Privileging answers "given those qualifications, what exactly may they do here?" Credentialing produces a verified file. Privileging produces a signed delineation of privileges — a list, service by service, approved by whoever your bylaws or policies designate as the granting authority.

Enrollment is a third thing entirely. Enrollment gets the clinician into Medicare, Medicaid, and commercial payer networks so claims adjudicate. A clinician can be fully enrolled and still hold no privileges. A clinician can hold full privileges and still have claims deny because enrollment lagged. Keep three separate trackers.

Where the Authority to Define Privileging Comes From

If you operate a hospital, ambulatory surgery center, or other Medicare-certified facility, the Conditions of Participation require an organized governing body that appoints practitioners and approves the scope of what each may do. Your medical staff bylaws are the controlling document, and they should define privileging categories, the approval chain, the appointment term, and the process for temporary and emergency grants.

If you operate an office-based group practice, no federal rule hands you a bylaws template. You still need the function. Payers with delegated credentialing arrangements will audit for it, malpractice carriers ask about it, and plaintiff's counsel will subpoena whatever you have. A four-page privileging policy approved by your board beats an oral understanding every time.

The three privilege categories most practices use

  • Core privileges — the bundle a board-certified clinician in that specialty is presumed competent to perform, granted as a block.
  • Special or advanced privileges — individually requested procedures requiring documented additional training, case logs, or proctoring.
  • Temporary privileges — time-limited grants for locum coverage or a pending application, with a hard expiration date your system enforces.

Write the criteria before anyone applies. Criteria written after a specific request looks like the criteria were written for that request.

The Onboarding Workflow, With Owners and Clocks

Assign every step to a named role, not to "credentialing." Here is a workable sequence for a group practice bringing on a physician or advanced practice clinician.

  1. Day 0 — Application issued. Credentialing coordinator sends the application, the delineation-of-privileges request form, and the release authorizing primary source contact. The clinician requests privileges affirmatively; you never assume.
  2. Days 1–30 — Primary source verification. License, DEA, board certification, education, training, work history with gap explanations, malpractice claims history, and a National Practitioner Data Bank query. Verification means from the source, not from a copy the applicant emailed you.
  3. Days 20–40 — Peer references. Written references from clinicians who have observed the applicant performing the requested privileges. Store these as confidential; state peer-review statutes generally protect them, and your policy should say so.
  4. Days 40–50 — Review and recommendation. Department lead or medical director reviews the file against written criteria and recommends the specific privilege list.
  5. Days 50–60 — Approval and effective date. Governing body or designated officer signs. The signed delineation is the operative document. Scheduling, EHR role assignment, and OR block access all key off it.
  6. First 6–12 months — Focused review. A defined number of cases or encounters reviewed against defined measures before the privilege converts from provisional to full.
  7. Ongoing — Periodic review and reappointment. Most bylaws set reappointment at two years; some accreditation programs and state rules allow up to three. Between cycles, run ongoing performance data so reappointment is not a rubber stamp.

Build expiration alerts for license, DEA, board certification, malpractice coverage, and the privilege term itself. A lapsed license discovered by a payer during a delegated credentialing audit costs far more than a calendar reminder.

Where PHI Enters the Privileging File

Most of a credentialing file is provider data — Social Security number, DEA registration, claims history, Data Bank reports. That is sensitive, but it is not protected health information.

PHI enters the moment you review charts. Focused and ongoing performance review means pulling encounters, operative notes, complication logs, readmission data, and patient complaints. Those are patient records, fully covered by the Privacy Rule.

The good news: you do not need patient authorization. HHS guidance on uses and disclosures for treatment, payment, and health care operations treats reviewing the competence and qualifications of health care professionals and evaluating practitioner performance as health care operations. Chart review for privileging is a permitted internal use.

The obligations that still apply:

  • Minimum necessary. A reviewer evaluating endoscopy technique does not need the patient's full longitudinal record. Pull the relevant encounter, not the chart.
  • Access controls. Reviewers get role-based access scoped to the review, and it ends when the review ends. Your EHR access review should flag standing "quality reviewer" accounts that nobody has touched in a year.
  • Audit logging. Peer review chart access looks exactly like snooping in a log unless you can tie it to a documented review assignment. Keep the assignment memo.
  • Storage. Privileging packets with chart excerpts get stored on the same footing as clinical records — encrypted, access-limited, retention-scheduled. Not a shared drive folder named "Credentialing 2026."

Which Privileging Vendors Need a BAA — and Which Do Not

This is where practices get it backwards in both directions. Run every vendor in the privileging chain through one question: does this vendor create, receive, maintain, or transmit PHI on our behalf?

Generally no BAA required

A credentialing verification organization performing license, board, education, and Data Bank verification handles provider data only. Contract for confidentiality, data security, and Data Bank use restrictions — but that is a commercial agreement, not a BAA. Same for credentialing software that stores applications, expirables, and rosters with no patient data in it. Same for a locum agency that supplies clinicians; the clinician working under your direction is workforce, and the workforce exception means no BAA for the individual.

BAA required

An external peer reviewer — the out-of-state specialist you send five de-identified-in-name-only operative notes to — receives PHI. So does a quality consultant abstracting charts for ongoing performance data, a coding or documentation auditor whose findings feed reappointment, a telehealth platform that hosts encounters supporting a privileging decision, and any credentialing platform that adds a quality or case-log module holding identifiable patient information. HHS's business associate guidance is the reference to keep next to your vendor list.

The external peer reviewer is the one practices miss most often. It feels like a professional courtesy, so nobody papers it. If you are about to email chart material to a reviewer who is not on your payroll, you need an executed agreement first — and a signature-ready Business Associate Agreement you can generate in a six-step wizard and export as PDF or DOCX closes that gap the same afternoon, without a subscription or a two-week legal queue.

Then add these vendors to your actual BAA inventory. Not the folder. The inventory, with execution dates, renewal dates, and the named individual who owns the relationship.

Records Requests: What Comes Out of the Privileging File

Three requests hit this file, and they get three different answers.

A patient requests their record. The right of access reaches the designated record set — the medical and billing records you use to make decisions about that individual. Peer review committee minutes and privileging deliberations generally sit outside it. The underlying chart never does. If a note was reviewed as part of a competence evaluation, the note is still fully producible on a patient access request.

Plaintiff's counsel subpoenas the credentialing file. Route it to counsel before anything moves. State peer-review privilege statutes vary substantially in what they protect and how easily protection is waived — for example, by circulating committee material outside the committee. Your document handling in ordinary operations determines whether the privilege holds later.

A payer audits delegated credentialing. Expect a file review against the delegation agreement: verification timeliness, Data Bank queries, committee approval dates, reappointment currency. Prepare by sampling your own files quarterly rather than by scrambling for two weeks.

Four Failure Modes Worth Auditing This Quarter

Privileges that outlived their expiration. Temporary grants issued for a locum who is still working eleven months later. Pull every temporary privilege and check the end date today.

Scheduling that does not match the delineation. If schedulers cannot see the approved privilege list, they will book from memory. Put the list where the booking happens.

Chart excerpts in email. Privileging packets attached to unencrypted messages, sent to a personal address for weekend reading, is a routine path to a reportable incident. The OCR breach portal is full of email-based disclosures that started as a convenience.

No risk analysis coverage. Credentialing and peer-review systems hold PHI and rarely appear in the asset inventory. NIST SP 800-66r2 is the practical guide for scoping those systems into the Security Rule risk analysis. If your risk analysis, policy set, and supporting documentation need a rebuild rather than a patch, automated HIPAA risk analysis and policy generation will get you a defensible baseline faster than a consultant's discovery call.

Assign It Before Friday

Pick one person to own privileging end to end — application intake, verification, committee packet, approval routing, expirables, and the vendor list attached to all of it. Give that person authority to hold a start date. Then review the chain of people who touch chart material during focused and ongoing review and confirm each external party has an executed agreement on file.

If any of them do not, generate the Business Associate Agreement, get it signed, and file it with the privileging record it belongs to. It is a one-time purchase and a fifteen-minute task, and it is the difference between a documented disclosure and an unexplained one.