Why Default Access Is a Risk Your Team Should Not Run

Here is a detail that surprises a lot of practice owners when they first dig into the administrative side of ChiroTouch: unless you explicitly set group restrictions in the User Security window, every user on the system has full access to every administrative function. That means the receptionist who checks patients in could, in theory, delete an EDI claims batch, modify a fee schedule, change trading-partner credentials, or alter who is permitted to edit signed chart notes. In a small chiropractic practice where three or four people share two or three workstations, that default is a genuine operational and data-integrity risk. It does not mean someone will do something malicious; it means a well-intentioned click during a busy Friday afternoon can overwrite a ledger entry, void a claim, or change a patient's insurance policy order, and the only way to trace what happened is to dig through system auditing logs after the fact.

The fix is straightforward and lives entirely inside the Maintenance application. Open Maintenance, click Users, then click the Security button to bring up the User Security window. From there, click New, type a descriptive group name such as Front Desk – Standard or Billing Team, and click OK. Select the relevant staff members in the System Users column and move them into the Group Members list. The critical step is the permissions panel on the right. By default, the new group inherits every available action, so your job is to remove the ones that do not belong to that role. For a front-desk group, you might keep Access Front Desk, Access Patients, and View Insurance, while removing Delete EDI Batches, Export Claims, Edit Fee Schedules, and Change Security Settings. For a billing assistant, you might allow Access Accounting and Post Insurance Payments but strip out Maintenance-level functions like Edit Payer Info or Edit Diagnoses. The available permissions list is long—covering alert restrictions, charge-note authoring, ledger edits, inventory management, report access, scheduler controls, and dozens of granular actions—so take the time to walk through each category rather than relying on the defaults.

Note permissions deserve special attention because they are the audit trail your practice relies on if a payer, a patient, or an auditor asks who changed what and when. ChiroTouch offers separate controls for adding, editing, and deleting patient notes, chart notes, charge notes, and insurance ledger notes, and it distinguishes between actions the original author can take and actions someone else can take. The restrictions labeled Edit Patient Notes If Not Author and Delete Patient Notes If Not Author are particularly useful: they let a front-desk staff member add a scheduling note to a chart while preventing them from rewriting or removing a clinical note that a provider wrote and signed. If you employ massage therapists, assistants, or part-time staff who need to be in the system for scheduling or simple lookups, a tightly scoped group with read-only note permissions keeps the clinical record intact without locking those people out of the tools they need day to day.

Two additional restrictions are worth flagging for office managers who want a safety net against routine mistakes. The Retroactive Ledger Data Entry restriction prevents a user from adding new charges, payments, or miscellaneous transactions to past dates, which stops accidental back-dated entries from distorting your aging reports and reconciliation. And it is important to remember that no user, regardless of how broad their group permissions are, gets access to the provider applications such as the Provider All-In-One unless they have been explicitly assigned as a provider in the system. That separation means a billing team member cannot open a chart and alter a treatment plan, and a front-desk employee cannot accidentally post a clinical note under a provider's credentials. Review your group assignments at least quarterly, and always revisit them after hiring, a role change, or the departure of a team member. Keeping a simple written list of who belongs to which group and what that group can do is a small administrative habit that saves a lot of time when you are troubleshooting a permission issue or onboarding a new office manager.

Sources and further reading