Every claim sourced, every citation linked, every page dated. HIPAA for ABA clinics, written by people who live in it.
If you read nothing else, read these. They decide whether the rest of the library applies to you, and what to do first if it does.
The actual legal test for whether HIPAA applies to your clinic, the one electronic transaction that flips the answer, and why betting on the exemption is a bad trade.
Risk analysis is the most commonly cited HIPAA Security Rule failure in OCR enforcement, the subject of a dedicated enforcement initiative, and the one document your entire security program is supposed to stand on. Here is what a real one contains.
The whole program in one place: the twelve things a real HIPAA compliance program contains, what the rule says about each, what it takes to run it by hand in a clinic with thirty staff and no compliance officer, and how to tell whether yours is real.
The first hour, the decision that determines everything, the four-factor assessment, and every notification clock, written for the day you actually need it.
The situations a clinic actually hits. Personal phones, session recordings, school districts, and the day a device goes missing.
Every role, tool, and room in an ABA clinic mapped to the word HIPAA uses for it, and what changes the moment you know which word applies.
The legal test for who is a business associate, the vendor-by-vendor walkthrough for an ABA clinic, the narrow truth about the conduit exception, and what a vendor's HIPAA compliant badge does and does not mean.
Texts with parents, session photos in the camera roll, the data app on a personal device: what HIPAA actually says about phones you do not own, and the three honest options for a clinic that cannot buy everyone a tablet.
A BCBA started using an AI scribe last month. It is a business associate, it may be training on your clients' sessions, and nobody signed anything. The questions to ask, and what the vendor's answers actually mean.
Video of a child's session is the most sensitive thing your clinic produces. Where it actually lives, why the personal Drive folder is a violation nobody committed on purpose, and how to build a lawful path from camera to storage.
Two parents share a password, a grandparent has it, a custody order changed, and nobody revoked anything. Why unique user identification is the one requirement with no judgment call in it, and how to run a portal that survives a real family.
The COVID-era permission to use FaceTime and consumer Zoom for telehealth ended in 2023. What the ordinary rules require now, what to ask your platform, and the half of the session you do not control.
Physical safeguards written for locked doors and server rooms, applied honestly to in-home ABA: what an incidental disclosure actually is, what you owe a family whose home is your workplace, and the six things that belong in an in-home policy.
The exclusion inside the definition of PHI that sends most school records to FERPA instead, why the answer depends on whose record it is rather than where the session happened, and the questions to settle before you sign a district contract.
There are two separate training requirements, not one, and the certificate you bought probably satisfies neither. What the rules require, what OCR expects to see, and how to run training at RBT hiring speed.
HIPAA is a floor, not a ceiling. What preemption actually means, the categories where states routinely go further, and why a multi-state ABA operator cannot run one compliance program and call it done.
The tablet left at a client's home, the phone gone from the car: what happens next under HIPAA, why encryption decides which of two very different days you are having, and the five-minute drill that makes the answer boring.
Still one of the most common breaches in small practice. What to do in the first hour, why a paper fax and an efax are legally different animals, and the four factors that decide whether you are notifying families.
Right of access is OCR's most-enforced HIPAA obligation. A parent's records request starts a 30-day clock, ABA session notes are not psychotherapy notes you can withhold, and the fee you may charge is narrow.
45 CFR 164.520 requires a plain-language notice describing how you use and disclose PHI, given no later than first service. A notice that still describes last year's clinic is not a compliant one, it is a stale one.
Access gets the enforcement attention, but a parent has five more rights: to amend the record, to an accounting of disclosures, to request restrictions (one of which you must grant), to confidential communications, and to a current Notice of Privacy Practices.
What a real compliance program contains, who runs it, on what cadence, and what happens when someone finally checks.
HIPAA requires appropriate, consistently applied sanctions, not a template in a binder. What the Security and Privacy Rules actually demand of an ABA clinic, and the decisions only you can make.
HIPAA access is a lifecycle, not a state: grant it to the right people, give each a traceable identity, and revoke it the day someone leaves. What the rule requires, and where turnover breaks it.
HIPAA requires a way for your workforce to report problems, and forbids punishing them for it. Most clinics meet that with a line in the handbook that fails the moment it matters. What a real channel looks like, and the accidental-retaliation trap nobody sees coming.
Most HIPAA obligations move in months. This one moves in hours. The three lists a real termination procedure needs, who runs each, by when, and the dated record that survives an audit.
A buyer's counsel opens HIPAA diligence with one request, and the answer moves your price. What the request actually contains, item by item, why the six-year window is not a coincidence, and what a red answer does to a deal.
HIPAA requires a periodic evaluation of whether your whole security program still matches your clinic, and a review triggered whenever the clinic materially changes. It is the most forgotten standard, and it is the one that keeps every other part honest.
HIPAA fixes about a dozen deadlines and leaves the rest of the calendar to you. Here are the deadlines that are real, the cadences you have to set and defend yourself, and the events that force a review no matter what the calendar says.
OCR's own audit scale rates a template policy as negligible effort. Most ABA clinics are carrying exactly that artifact and believe it is protecting them. What the rule actually asks of a policy, and why nobody has to sign it.
The risk analysis finds the gaps. The risk management plan is what you do about them, and it is a separate Required obligation. Owner, date, and evidence on every finding, or a documented decision to accept the risk.
Not a title on an org chart. The weekly, monthly, quarterly, and annual questions someone has to ask out loud in an ABA clinic, why the answers never arrive on their own, and the provision that makes asking early worth real money.
A signed policy that does not match your clinic is not protection, it is evidence against you. OCR has penalized a behavioral health provider for exactly that. What a real policy is made of, using the one every clinic needs, and a five-question test for the ones on your shelf.
HIPAA contains a whistleblower provision most clinic owners have never read. What 45 CFR 164.502(j) actually permits, who whistleblowers turn out to be in an ABA clinic, why they do it, and the one fact that should change how you run your internal channel.
The Security, Privacy, Breach Notification, and Enforcement Rules, read closely and cited to the section.
45 CFR 164.312(a)(1) does not decide who should reach ePHI. It requires your systems to actually enforce whatever access decision you already made elsewhere, and a shared login defeats it instantly.
The most expensive misunderstanding in the HIPAA Security Rule, what 45 CFR 164.306(d) actually requires you to do, and a full table of every implementation specification and how it is labelled.
Nine standards, more than half the Security Rule, and the family where enforcement actually happens. The program behind the technology, standard by standard, for a clinic whose workforce turns over at RBT speed.
45 CFR 164.312(b) requires systems that record and examine activity, not just one that records it. A log nobody reads has only done half of what the rule asks.
45 CFR 164.308(a)(7) requires three plans, all Required: data backup, disaster recovery, and emergency mode operation. The two addressable specs are where most clinics quietly stop.
45 CFR 164.310(d) governs what happens to hardware and media that ever held ePHI, from the moment it enters your clinic to the moment it's gone. Deleting files is not disposal.
45 CFR 164.310(a)(1) sounds like badge systems and server rooms. At clinic scale it is a short, answerable list: who has keys, does it change when staff leave, and can a parent in the waiting room see the front desk screen.
From complaint or breach report to resolution: how OCR opens an investigation, what it can and cannot do, the factors that move a penalty, the defense written into the regulation, and where a clinic actually has leverage.
45 CFR 164.308(a)(1)(ii)(D) is the human half of audit controls. A system can record everything and still fail this standard, if nobody ever regularly looks at what it recorded.
45 CFR 164.312(c) protects ePHI from improper alteration or destruction. In ABA, a silently altered session note or a data collection app that drops trials is not just a compliance failure, it changes a child's programming.
45 CFR 164.312(d) requires you to verify that whoever is accessing ePHI is who they claim to be. MFA is not named in the text, but in 2026, on a system holding children's clinical records, the case for skipping it is hard to write.
Four standards written in 2003 for buildings and server rooms, applied honestly to a clinic whose ePHI rides in a backpack: facilities, workstations, devices, and the two disposal rules everyone learns about the hard way.
45 CFR 164.308(a)(6) requires a plan for identifying and responding to security incidents, and the definition is broader than most clinics assume. The phishing email an RBT reported counts.
The five technical standards of the HIPAA Security Rule, what each one demands, and what they look like in an ABA clinic where the workstation is a tablet in a family's living room.
A rule built on a presumption and a burden of proof. Why encryption decides whether it applies at all, why the clock starts before you notice, and why an empty incident log is the worst answer you can give.
One question governs the whole rule: may this information move, to this person, for this reason. The permission structure, the individual rights, the administrative machinery, and the four places an ABA clinic gets it wrong.
How the HIPAA Security Rule is actually built: the four duties, the flexibility clause everyone forgets, the required and addressable machinery, and a map of all three safeguard families.
45 CFR 164.312(e) covers ePHI while it moves, not just while it sits still. An emailed progress note, a synced session video, a text about a client, all count, whether or not they feel like transmission.
45 CFR 164.308(a)(3)(ii)(A) requires a procedure for deciding who is authorized to work with ePHI, before that access is granted. Trust is not a procedure, and 'everyone here is trusted' is not an answer to who.
45 CFR 164.308(a)(3)(ii)(B) requires a procedure to determine that a workforce member's access to ePHI is appropriate. It does not require a background check on everyone, it requires you to have actually asked the question.
45 CFR 164.310(b) and (c) were written for desks in offices. The definition does not care where the device sits: the field tablet, the RBT's phone, and the BCBA's home laptop all count.
The regulation translated section by section, without losing what it actually says.
Every section of the Breach Notification Rule, 164.400 through 164.414, translated line by line: what counts as a breach, the four-factor test, the 60-day clocks, and who must be told what.
The load-bearing definitions of HIPAA, 160.103, 164.304, 164.402, and the never-translated 164.501, rendered readable: who is covered, what counts as PHI, and the two definitions that decide what a parent can demand.
The full Privacy Rule, 164.502 through 164.530, translated section by section: when PHI can move, when it needs permission, the individual rights, and an honest note on the 2024 provisions a federal court vacated.
Every section of the Security Rule, 164.302 through 164.316, translated line by line into language you will actually read, with the same structure as the official text and nothing legally lost.
What OCR does, what it costs, and what is changing in the rules.
OCR restarted its audit program in December 2024, and fifty organizations were selected. In the same period it received more than thirty thousand complaints. Which of those two numbers should decide how you spend your attention.
A curated set of real HIPAA enforcement actions, chosen for what they tell a small clinic: who gets investigated, what OCR finds, what it costs, and what would have prevented it.
The four civil penalty tiers with the amounts in force since January 28, 2026, the 2019 enforcement discretion OCR still applies, the factors that move a penalty up or down, criminal exposure, and what any of it means for a small clinic.
The Security Rule overhaul that has not landed, the reproductive health rule a court erased, the Part 2 changes that did take effect, and the penalty numbers that moved. What is law today, what is only proposed, and what it means for an ABA clinic.
The glossary, the questions clinics ask most, and how HIPAA got to be the way it is.
Thirty-two straight answers, each with the citation behind it, each linking to the page that goes deeper. The questions clinic owners ask us, answered honestly, including the ones where the answer is no.
The Security Rule was written in 2003, before the smartphone. That single fact explains most of what feels strange about applying it to a clinic whose workstation is a tablet in a family's living room.
117 terms, acronyms, and agency names, A to Z, each defined faithfully to the regulation with its citation attached. The vocabulary of HIPAA, without the fog.
Every HIPAA control an ABA clinic has to run, taught one obligation at a time and paired with what satisfying it actually looks like. The set grows as each control is written.
Risk analysis is the most commonly cited HIPAA Security Rule failure in OCR enforcement, the subject of a dedicated enforcement initiative, and the one document your entire security program is supposed to stand on. Here is what a real one contains.
The risk analysis finds the gaps. The risk management plan is what you do about them, and it is a separate Required obligation. Owner, date, and evidence on every finding, or a documented decision to accept the risk.
HIPAA requires appropriate, consistently applied sanctions, not a template in a binder. What the Security and Privacy Rules actually demand of an ABA clinic, and the decisions only you can make.
Not a title on an org chart. The weekly, monthly, quarterly, and annual questions someone has to ask out loud in an ABA clinic, why the answers never arrive on their own, and the provision that makes asking early worth real money.
HIPAA access is a lifecycle, not a state: grant it to the right people, give each a traceable identity, and revoke it the day someone leaves. What the rule requires, and where turnover breaks it.
45 CFR 164.308(a)(3)(ii)(A) requires a procedure for deciding who is authorized to work with ePHI, before that access is granted. Trust is not a procedure, and 'everyone here is trusted' is not an answer to who.
45 CFR 164.308(a)(3)(ii)(B) requires a procedure to determine that a workforce member's access to ePHI is appropriate. It does not require a background check on everyone, it requires you to have actually asked the question.
Most HIPAA obligations move in months. This one moves in hours. The three lists a real termination procedure needs, who runs each, by when, and the dated record that survives an audit.
There are two separate training requirements, not one, and the certificate you bought probably satisfies neither. What the rules require, what OCR expects to see, and how to run training at RBT hiring speed.
45 CFR 164.310(a)(1) sounds like badge systems and server rooms. At clinic scale it is a short, answerable list: who has keys, does it change when staff leave, and can a parent in the waiting room see the front desk screen.
45 CFR 164.310(b) and (c) were written for desks in offices. The definition does not care where the device sits: the field tablet, the RBT's phone, and the BCBA's home laptop all count.
45 CFR 164.310(d) governs what happens to hardware and media that ever held ePHI, from the moment it enters your clinic to the moment it's gone. Deleting files is not disposal.
45 CFR 164.312(a)(1) does not decide who should reach ePHI. It requires your systems to actually enforce whatever access decision you already made elsewhere, and a shared login defeats it instantly.
45 CFR 164.312(b) requires systems that record and examine activity, not just one that records it. A log nobody reads has only done half of what the rule asks.
45 CFR 164.312(c) protects ePHI from improper alteration or destruction. In ABA, a silently altered session note or a data collection app that drops trials is not just a compliance failure, it changes a child's programming.
45 CFR 164.312(d) requires you to verify that whoever is accessing ePHI is who they claim to be. MFA is not named in the text, but in 2026, on a system holding children's clinical records, the case for skipping it is hard to write.
45 CFR 164.312(e) covers ePHI while it moves, not just while it sits still. An emailed progress note, a synced session video, a text about a client, all count, whether or not they feel like transmission.
45 CFR 164.520 requires a plain-language notice describing how you use and disclose PHI, given no later than first service. A notice that still describes last year's clinic is not a compliant one, it is a stale one.
Right of access is OCR's most-enforced HIPAA obligation. A parent's records request starts a 30-day clock, ABA session notes are not psychotherapy notes you can withhold, and the fee you may charge is narrow.
A rule built on a presumption and a burden of proof. Why encryption decides whether it applies at all, why the clock starts before you notice, and why an empty incident log is the worst answer you can give.
45 CFR 164.308(a)(6) requires a plan for identifying and responding to security incidents, and the definition is broader than most clinics assume. The phishing email an RBT reported counts.
HIPAA requires a periodic evaluation of whether your whole security program still matches your clinic, and a review triggered whenever the clinic materially changes. It is the most forgotten standard, and it is the one that keeps every other part honest.
45 CFR 164.308(a)(7) requires three plans, all Required: data backup, disaster recovery, and emergency mode operation. The two addressable specs are where most clinics quietly stop.
No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.