Setting Up Role-Based Access in ChiroTouch Without Guesswork

In a typical chiropractic office, the front desk coordinator, the billing lead, the massage therapist, and the provider each need a very different slice of the system. ChiroTouch handles this through the User Security window, but the default state is permissive: every user can perform every administrative function until you explicitly restrict them. That means a new front-desk hire could, without your knowledge, delete an insurance payment or modify a signed chart note. Taking twenty minutes to build two or three user groups and strip away irrelevant permissions is one of the highest-impact maintenance tasks a practice manager can complete, and it requires no IT ticket or vendor call.

To get started, open the Maintenance application, click Users, and select the Security button. From the User Security window you can click New, type a descriptive group name (for example, "Front Desk – Billing" or "Massage Therapy"), and then add individual system users to that group with the Add button. Once members are in place, the Actions menu on the left lets you browse every available permission category—Patient Notes, Charge Notes, Insurance Ledger Notes, Patient Charges, Service Charges, Patient Payments, Insurance Payments, Provider All-In-One, Reports, Scheduler, Maintenance, and more. Selecting an action and clicking the arrow moves it into the Restricted list, effectively turning that capability off for everyone in the group. If you later need to grant it back, the same arrow works in reverse. Because the restrictions are group-level, adding a new employee to the right group on day one means their access is correct before they ever touch a keyboard.

Note authoring restrictions deserve special attention, because they protect the integrity of the clinical and billing record. ChiroTouch lets you separate "Edit if Author" from "Edit if Not Author" for patient notes, charge notes, insurance ledger notes, and insurance policy notes. In practice, that means a front-desk user who accidentally types a billing note can still edit or delete their own entry, but cannot rewrite a note the provider wrote. There is also a Scribe Access restriction that, when enabled for a specific provider, prevents any scribe from creating or editing chart notes under that provider's credentials regardless of the scribe's individual settings. For offices that use Rheo AI Scribe or another dictation workflow, toggling this setting per provider gives you a clean audit trail without having to monitor every note entry in real time.

Application-level access is controlled through the Login Restrictions section of the same security window. You can block or allow access to Front Desk, Provider, Provider All-In-One, Scheduler, CT Announcer, CT Sign-In, ChiroStat, CT InTouch, CT Secure, the QPP Dashboard, and a dozen other modules. This is especially useful for support staff or part-time owners who log in occasionally: you can give them read-only access to Reports while keeping Maintenance, DB Maintenance, and Security Settings out of reach. InTouch campaign and template permissions are managed in the same place, so a marketing coordinator can create and edit campaigns but be prevented from deleting an approved one. If a user reports that a button is missing or an application will not open, the first thing a ChiroTouch support representative or your IT contact should check is whether the relevant permission sits in the Restricted list for that user's group. Keeping a one-page cheat sheet of your group names and their key restrictions next to the server documentation will save everyone a lot of back-and-forth when troubleshooting access questions.

Sources and further reading