Knowledge base

The knowledge base

Every claim sourced, every citation linked, every page dated. HIPAA for ABA clinics, written by people who live in it.

Start here

Four questions worth answering first

If you read nothing else, read these. They decide whether the rest of the library applies to you, and what to do first if it does.

16 articles

ABA in practice

The situations a clinic actually hits. Personal phones, session recordings, school districts, and the day a device goes missing.

Your clinic, translated into HIPAA's vocabulary

Every role, tool, and room in an ABA clinic mapped to the word HIPAA uses for it, and what changes the moment you know which word applies.

Last verified: 2026-07-12

Which of your vendors need a BAA, and how to actually get one

The legal test for who is a business associate, the vendor-by-vendor walkthrough for an ABA clinic, the narrow truth about the conduit exception, and what a vendor's HIPAA compliant badge does and does not mean.

Last verified: 2026-07-12

Your RBTs have PHI on their personal phones

Texts with parents, session photos in the camera roll, the data app on a personal device: what HIPAA actually says about phones you do not own, and the three honest options for a clinic that cannot buy everyone a tablet.

Last verified: 2026-07-12

The AI notetaker nobody vetted

A BCBA started using an AI scribe last month. It is a business associate, it may be training on your clients' sessions, and nobody signed anything. The questions to ask, and what the vendor's answers actually mean.

Last verified: 2026-07-12

Session recordings in the wrong cloud

Video of a child's session is the most sensitive thing your clinic produces. Where it actually lives, why the personal Drive folder is a violation nobody committed on purpose, and how to build a lawful path from camera to storage.

Last verified: 2026-07-12

One family, one login: the parent portal problem

Two parents share a password, a grandparent has it, a custody order changed, and nobody revoked anything. Why unique user identification is the one requirement with no judgment call in it, and how to run a portal that survives a real family.

Last verified: 2026-07-12

Telehealth ABA: the enforcement pass expired and nobody told you

The COVID-era permission to use FaceTime and consumer Zoom for telehealth ended in 2023. What the ordinary rules require now, what to ask your platform, and the half of the session you do not control.

Last verified: 2026-07-12

The living room is your facility

Physical safeguards written for locked doors and server rooms, applied honestly to in-home ABA: what an incidental disclosure actually is, what you owe a family whose home is your workplace, and the six things that belong in an in-home policy.

Last verified: 2026-07-12

School-based ABA: HIPAA or FERPA?

The exclusion inside the definition of PHI that sends most school records to FERPA instead, why the answer depends on whose record it is rather than where the session happened, and the questions to settle before you sign a district contract.

Last verified: 2026-07-12

What actually counts as HIPAA training

There are two separate training requirements, not one, and the certificate you bought probably satisfies neither. What the rules require, what OCR expects to see, and how to run training at RBT hiring speed.

Last verified: 2026-07-12

When your state law beats HIPAA

HIPAA is a floor, not a ceiling. What preemption actually means, the categories where states routinely go further, and why a multi-state ABA operator cannot run one compliance program and call it done.

Last verified: 2026-07-12
Act today

A field device went missing

The tablet left at a client's home, the phone gone from the car: what happens next under HIPAA, why encryption decides which of two very different days you are having, and the five-minute drill that makes the answer boring.

Last verified: 2026-07-12
Act today

The fax went to the wrong number

Still one of the most common breaches in small practice. What to do in the first hour, why a paper fax and an efax are legally different animals, and the four factors that decide whether you are notifying families.

Last verified: 2026-07-12

Right of access: the 30-day clock on a records request

Right of access is OCR's most-enforced HIPAA obligation. A parent's records request starts a 30-day clock, ABA session notes are not psychotherapy notes you can withhold, and the fee you may charge is narrow.

Last verified: 2026-07-26

The Notice of Privacy Practices: a promise that has to stay current

45 CFR 164.520 requires a plain-language notice describing how you use and disclose PHI, given no later than first service. A notice that still describes last year's clinic is not a compliant one, it is a stale one.

Last verified: 2026-09-08

The patient rights beyond access

Access gets the enforcement attention, but a parent has five more rights: to amend the record, to an accounting of disclosures, to request restrictions (one of which you must grant), to confidential communications, and to a current Notice of Privacy Practices.

Last verified: 2026-07-26
12 articles

Running the program

What a real compliance program contains, who runs it, on what cadence, and what happens when someone finally checks.

A sanctions policy is a set of decisions, not a document

HIPAA requires appropriate, consistently applied sanctions, not a template in a binder. What the Security and Privacy Rules actually demand of an ABA clinic, and the decisions only you can make.

Last verified: 2026-07-26

Access, granted and revoked

HIPAA access is a lifecycle, not a state: grant it to the right people, give each a traceable identity, and revoke it the day someone leaves. What the rule requires, and where turnover breaks it.

Last verified: 2026-07-26

How a compliance reporting channel should actually work, and the trap most clinics miss

HIPAA requires a way for your workforce to report problems, and forbids punishing them for it. Most clinics meet that with a line in the handbook that fails the moment it matters. What a real channel looks like, and the accidental-retaliation trap nobody sees coming.

Last verified: 2026-07-14
Checklist

The day someone leaves: a HIPAA termination checklist for ABA clinics

Most HIPAA obligations move in months. This one moves in hours. The three lists a real termination procedure needs, who runs each, by when, and the dated record that survives an audit.

Last verified: 2026-07-14

The day you sell your clinic, they will ask for this

A buyer's counsel opens HIPAA diligence with one request, and the answer moves your price. What the request actually contains, item by item, why the six-year window is not a coincidence, and what a red answer does to a deal.

Last verified: 2026-07-12

The evaluation standard: the review that keeps the program true

HIPAA requires a periodic evaluation of whether your whole security program still matches your clinic, and a review triggered whenever the clinic materially changes. It is the most forgotten standard, and it is the one that keeps every other part honest.

Last verified: 2026-07-26
Checklist

The HIPAA calendar: what you do, and when

HIPAA fixes about a dozen deadlines and leaves the rest of the calendar to you. Here are the deadlines that are real, the cadences you have to set and defend yourself, and the events that force a review no matter what the calendar says.

Last verified: 2026-07-12

The policy binder problem: how clinics fail before the audit starts

OCR's own audit scale rates a template policy as negligible effort. Most ABA clinics are carrying exactly that artifact and believe it is protecting them. What the rule actually asks of a policy, and why nobody has to sign it.

Last verified: 2026-07-14

The risk management plan: what you did about what you found

The risk analysis finds the gaps. The risk management plan is what you do about them, and it is a separate Required obligation. Owner, date, and evidence on every finding, or a documented decision to accept the risk.

Last verified: 2026-07-26

What a HIPAA compliance officer actually does

Not a title on an org chart. The weekly, monthly, quarterly, and annual questions someone has to ask out loud in an ABA clinic, why the answers never arrive on their own, and the provision that makes asking early worth real money.

Last verified: 2026-07-14

What real HIPAA policies look like, and why templates fail the audit

A signed policy that does not match your clinic is not protection, it is evidence against you. OCR has penalized a behavioral health provider for exactly that. What a real policy is made of, using the one every clinic needs, and a five-question test for the ones on your shelf.

Last verified: 2026-07-14

Your employee can legally take PHI to a lawyer, and it is not your breach

HIPAA contains a whistleblower provision most clinic owners have never read. What 45 CFR 164.502(j) actually permits, who whistleblowers turn out to be in an ABA clinic, why they do it, and the one fact that should change how you run your internal channel.

Last verified: 2026-07-14
21 articles

The rules

The Security, Privacy, Breach Notification, and Enforcement Rules, read closely and cited to the section.

Access control: enforcing the decision you already made

45 CFR 164.312(a)(1) does not decide who should reach ePHI. It requires your systems to actually enforce whatever access decision you already made elsewhere, and a shared login defeats it instantly.

Last verified: 2026-09-08

Addressable does not mean optional

The most expensive misunderstanding in the HIPAA Security Rule, what 45 CFR 164.306(d) actually requires you to do, and a full table of every implementation specification and how it is labelled.

Last verified: 2026-07-12

Administrative safeguards: what 45 CFR 164.308 actually requires

Nine standards, more than half the Security Rule, and the family where enforcement actually happens. The program behind the technology, standard by standard, for a clinic whose workforce turns over at RBT speed.

Last verified: 2026-07-12

Audit controls: who opened this child's record, and when

45 CFR 164.312(b) requires systems that record and examine activity, not just one that records it. A log nobody reads has only done half of what the rule asks.

Last verified: 2026-09-08

Contingency planning: the backup nobody has tested

45 CFR 164.308(a)(7) requires three plans, all Required: data backup, disaster recovery, and emergency mode operation. The two addressable specs are where most clinics quietly stop.

Last verified: 2026-09-09

Device and media controls: the standard your clinic lives in daily

45 CFR 164.310(d) governs what happens to hardware and media that ever held ePHI, from the moment it enters your clinic to the moment it's gone. Deleting files is not disposal.

Last verified: 2026-09-08

Facility access controls: the questions are smaller than you think

45 CFR 164.310(a)(1) sounds like badge systems and server rooms. At clinic scale it is a short, answerable list: who has keys, does it change when staff leave, and can a parent in the waiting room see the front desk screen.

Last verified: 2026-09-08

How an OCR investigation actually works

From complaint or breach report to resolution: how OCR opens an investigation, what it can and cannot do, the factors that move a penalty, the defense written into the regulation, and where a clinic actually has leverage.

Last verified: 2026-07-12

Information system activity review: the logs exist so someone reads them

45 CFR 164.308(a)(1)(ii)(D) is the human half of audit controls. A system can record everything and still fail this standard, if nobody ever regularly looks at what it recorded.

Last verified: 2026-09-08

Integrity: the standard almost everyone skips

45 CFR 164.312(c) protects ePHI from improper alteration or destruction. In ABA, a silently altered session note or a data collection app that drops trials is not just a compliance failure, it changes a child's programming.

Last verified: 2026-09-08

Person or entity authentication: the rule does not name a method

45 CFR 164.312(d) requires you to verify that whoever is accessing ePHI is who they claim to be. MFA is not named in the text, but in 2026, on a system holding children's clinical records, the case for skipping it is hard to write.

Last verified: 2026-09-08

Physical safeguards: what 45 CFR 164.310 actually requires

Four standards written in 2003 for buildings and server rooms, applied honestly to a clinic whose ePHI rides in a backpack: facilities, workstations, devices, and the two disposal rules everyone learns about the hard way.

Last verified: 2026-07-12

Security incident procedures: three questions, answered before you need them

45 CFR 164.308(a)(6) requires a plan for identifying and responding to security incidents, and the definition is broader than most clinics assume. The phishing email an RBT reported counts.

Last verified: 2026-09-08

Technical safeguards: what 45 CFR 164.312 actually requires

The five technical standards of the HIPAA Security Rule, what each one demands, and what they look like in an ABA clinic where the workstation is a tablet in a family's living room.

Last verified: 2026-07-12

The Breach Notification Rule, from the top

A rule built on a presumption and a burden of proof. Why encryption decides whether it applies at all, why the clock starts before you notice, and why an empty incident log is the worst answer you can give.

Last verified: 2026-07-12

The Privacy Rule, from the top

One question governs the whole rule: may this information move, to this person, for this reason. The permission structure, the individual rights, the administrative machinery, and the four places an ABA clinic gets it wrong.

Last verified: 2026-07-12

The Security Rule, from the top

How the HIPAA Security Rule is actually built: the four duties, the flexibility clause everyone forgets, the required and addressable machinery, and a map of all three safeguard families.

Last verified: 2026-07-12

Transmission security: PHI in motion is still PHI

45 CFR 164.312(e) covers ePHI while it moves, not just while it sits still. An emailed progress note, a synced session video, a text about a client, all count, whether or not they feel like transmission.

Last verified: 2026-09-08

Workforce authorization: the decision before the access

45 CFR 164.308(a)(3)(ii)(A) requires a procedure for deciding who is authorized to work with ePHI, before that access is granted. Trust is not a procedure, and 'everyone here is trusted' is not an answer to who.

Last verified: 2026-09-08

Workforce clearance: appropriate access, not a background check requirement

45 CFR 164.308(a)(3)(ii)(B) requires a procedure to determine that a workforce member's access to ePHI is appropriate. It does not require a background check on everyone, it requires you to have actually asked the question.

Last verified: 2026-09-08

Workstation use and security: the tablet in the living room is a workstation

45 CFR 164.310(b) and (c) were written for desks in offices. The definition does not care where the device sits: the field tablet, the RBT's phone, and the BCBA's home laptop all count.

Last verified: 2026-09-08
4 articles

Plain English

The regulation translated section by section, without losing what it actually says.

4 articles

Enforcement and penalties

What OCR does, what it costs, and what is changing in the rules.

3 articles

Reference

The glossary, the questions clinics ask most, and how HIPAA got to be the way it is.

25 articles

What real compliance looks like

Every HIPAA control an ABA clinic has to run, taught one obligation at a time and paired with what satisfying it actually looks like. The set grows as each control is written.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.