One-Off Practice Video — Where It Lives
The short version of the video-hosting & governance recommendation — and the decision tree for a single video at a single location, today.
What This Is
A decision-ready recommendation for how SGA hosts, publishes, and governs video across all ~250 locations. Ran the plan through a 6-agent stress test plus a red-team pass. Full doc on the hub under The Studio: sga-growth.dev/studio/video-hosting-governance.html.
Verdict & Architecture in One Breath
Verdict: Approve with modifications
Master library: WS2 asset registry + AWS S3 (existing BAA) — not SharePoint, not a new DAM.
Website embeds: Cloudflare Stream (de-identified) · Vimeo Enterprise + BAA (patient testimonials).
YouTube: Single SGA brand channel. No per-practice channels in year one.
Tier-1 local SEO surface: GBP video, 30-sec vertical, refreshed quarterly across all 248 profiles.
Why the Verdict Isn't "Approve as Written"
- Plan conflates master-of-record with public host — they're two different jobs.
- SharePoint can't do public embed and hits sync ceilings at DSO scale.
- Wistia 2026 pricing punishes scale; BAA posture unresolved.
- Compliance gates (releases, expiration Temporal, Compliance Approver) must ship before the pilot, not after.
- 9:16 short-form (Reels, TikTok, GBP) was missing entirely.
Single Video, Single Location — Decide by Content Type
Track A — De-identified
Doctor bio · practice tour · service explainer · community sponsorship
No identifiable patients on camera.
- Master → S3 under WS2 asset registry.
- Embed on practice site via Cloudflare Stream (interim: direct MP4 from R2 while StreamProvider adapter ships).
- Cut a 30-sec 9:16 vertical and post to that practice's GBP — this is the tier-1 local-SEO play.
- Drop the same 16:9 on the SGA brand channel in a per-location playlist for YouTube search coverage — no per-practice channel needed.
- Zernio out to social if the practice publishes there.
Track B — Patient testimonial / before & after
Identifiable patient on camera or in audio
Includes voice-only, blurred B-roll intercuts, name mentions.
- Stop. Do not shoot without a signed HIPAA marketing authorization (45 CFR 164.508) in hand.
- Legal is finalizing four release templates now (patient auth, model release, staff release, guardian/minor).
- Once signed and Vimeo Enterprise + BAA lands: master to S3, embed via Vimeo Enterprise — not Stream, not YouTube.
- YouTube only if the signed authorization explicitly names YouTube as an approved channel. Otherwise unlisted or absent.
- No paid boost without a separate paid-media consent line.
Never — at any scale, for any one-off
✕New practice-branded Gmail — recovery bomb.
✕New YouTube channel for 1–2 videos — governance tax breaks AI-first posture.
✕SharePoint as public host — no anonymous embed exists.
✕Wistia — BAA unresolved, wrong cost curve.
✕Patient video on Stream or YouTube — neither is in a BAA scope for us today.
✕Auto-captions as final — human-reviewed WebVTT is the publish gate.
The Ask
1Bless the split
Master = WS2/S3. Web embed = Stream (de-ID) or Vimeo Enterprise + BAA (patient). YouTube = brand channels only. Locks the direction so we stop evaluating SharePoint-as-DAM and Wistia.
2Fund fractional Video Ops Lead
0.4–0.6 FTE contractor at $60–90K/yr. Owns intake, taxonomy, compliance sign-off, access reviews. GMs cannot absorb this at 60–80 practices each. Within 3 weeks.
3Unblock the two BAA questions
Written confirmation from Cloudflare (is Stream in our executed BAA scope?) and Vimeo Enterprise (BAA SKU quote + 3-yr price-cap). Both are on the critical path to any patient-facing content. Within 2 weeks.