Knowledge base

The knowledge base

Every claim sourced, every citation linked, every page dated. HIPAA for ABA clinics, written by people who live in it.

Start here

Four questions worth answering first

If you read nothing else, read these. They decide whether the rest of the library applies to you, and what to do first if it does.

16 articles

ABA in practice

The situations a clinic actually hits. Personal phones, session recordings, school districts, and the day a device goes missing.

Is your ABA clinic even covered by HIPAA?

The actual legal test for whether HIPAA applies to your clinic, the one electronic transaction that flips the answer, and why betting on the exemption is a bad trade.

Last verified: 2026-07-12

Your clinic, translated into HIPAA's vocabulary

Every role, tool, and room in an ABA clinic mapped to the word HIPAA uses for it, and what changes the moment you know which word applies.

Last verified: 2026-07-12

Your risk analysis is why OCR would call

Risk analysis is the most commonly cited HIPAA Security Rule failure in OCR enforcement, the subject of a dedicated enforcement initiative, and the one document your entire security program is supposed to stand on. Here is what a real one contains.

Last verified: 2026-07-12

Which of your vendors need a BAA, and how to actually get one

The legal test for who is a business associate, the vendor-by-vendor walkthrough for an ABA clinic, the narrow truth about the conduit exception, and what a vendor's HIPAA compliant badge does and does not mean.

Last verified: 2026-07-12

Your RBTs have PHI on their personal phones

Texts with parents, session photos in the camera roll, the data app on a personal device: what HIPAA actually says about phones you do not own, and the three honest options for a clinic that cannot buy everyone a tablet.

Last verified: 2026-07-12

The AI notetaker nobody vetted

A BCBA started using an AI scribe last month. It is a business associate, it may be training on your clients' sessions, and nobody signed anything. The questions to ask, and what the vendor's answers actually mean.

Last verified: 2026-07-12

Session recordings in the wrong cloud

Video of a child's session is the most sensitive thing your clinic produces. Where it actually lives, why the personal Drive folder is a violation nobody committed on purpose, and how to build a lawful path from camera to storage.

Last verified: 2026-07-12

One family, one login: the parent portal problem

Two parents share a password, a grandparent has it, a custody order changed, and nobody revoked anything. Why unique user identification is the one requirement with no judgment call in it, and how to run a portal that survives a real family.

Last verified: 2026-07-12

Telehealth ABA: the enforcement pass expired and nobody told you

The COVID-era permission to use FaceTime and consumer Zoom for telehealth ended in 2023. What the ordinary rules require now, what to ask your platform, and the half of the session you do not control.

Last verified: 2026-07-12

The living room is your facility

Physical safeguards written for locked doors and server rooms, applied honestly to in-home ABA: what an incidental disclosure actually is, what you owe a family whose home is your workplace, and the six things that belong in an in-home policy.

Last verified: 2026-07-12

School-based ABA: HIPAA or FERPA?

The exclusion inside the definition of PHI that sends most school records to FERPA instead, why the answer depends on whose record it is rather than where the session happened, and the questions to settle before you sign a district contract.

Last verified: 2026-07-12

What actually counts as HIPAA training

There are two separate training requirements, not one, and the certificate you bought probably satisfies neither. What the rules require, what OCR expects to see, and how to run training at RBT hiring speed.

Last verified: 2026-07-12

When your state law beats HIPAA

HIPAA is a floor, not a ceiling. What preemption actually means, the categories where states routinely go further, and why a multi-state ABA operator cannot run one compliance program and call it done.

Last verified: 2026-07-12
Act today

You think you had a breach. What now.

The first hour, the decision that determines everything, the four-factor assessment, and every notification clock, written for the day you actually need it.

Last verified: 2026-07-12
Act today

A field device went missing

The tablet left at a client's home, the phone gone from the car: what happens next under HIPAA, why encryption decides which of two very different days you are having, and the five-minute drill that makes the answer boring.

Last verified: 2026-07-12
Act today

The fax went to the wrong number

Still one of the most common breaches in small practice. What to do in the first hour, why a paper fax and an efax are legally different animals, and the four factors that decide whether you are notifying families.

Last verified: 2026-07-12
9 articles

Running the program

What a real compliance program contains, who runs it, on what cadence, and what happens when someone finally checks.

How a compliance reporting channel should actually work, and the trap most clinics miss

HIPAA requires a way for your workforce to report problems, and forbids punishing them for it. Most clinics meet that with a line in the handbook that fails the moment it matters. What a real channel looks like, and the accidental-retaliation trap nobody sees coming.

Last verified: 2026-07-14
Checklist

The day someone leaves: a HIPAA termination checklist for ABA clinics

Most HIPAA obligations move in months. This one moves in hours. The three lists a real termination procedure needs, who runs each, by when, and the dated record that survives an audit.

Last verified: 2026-07-14

The day you sell your clinic, they will ask for this

A buyer's counsel opens HIPAA diligence with one request, and the answer moves your price. What the request actually contains, item by item, why the six-year window is not a coincidence, and what a red answer does to a deal.

Last verified: 2026-07-12
Checklist

The HIPAA calendar: what you do, and when

HIPAA fixes about a dozen deadlines and leaves the rest of the calendar to you. Here are the deadlines that are real, the cadences you have to set and defend yourself, and the events that force a review no matter what the calendar says.

Last verified: 2026-07-12

The policy binder problem: how clinics fail before the audit starts

OCR's own audit scale rates a template policy as negligible effort. Most ABA clinics are carrying exactly that artifact and believe it is protecting them. What the rule actually asks of a policy, and why nobody has to sign it.

Last verified: 2026-07-14

What a HIPAA compliance officer actually does

Not a title on an org chart. The weekly, monthly, quarterly, and annual questions someone has to ask out loud in an ABA clinic, why the answers never arrive on their own, and the provision that makes asking early worth real money.

Last verified: 2026-07-14

What a HIPAA program actually needs

The whole program in one place: the twelve things a real HIPAA compliance program contains, what the rule says about each, what it takes to run it by hand in a clinic with thirty staff and no compliance officer, and how to tell whether yours is real.

Last verified: 2026-07-12

What real HIPAA policies look like, and why templates fail the audit

A signed policy that does not match your clinic is not protection, it is evidence against you. OCR has penalized a behavioral health provider for exactly that. What a real policy is made of, using the one every clinic needs, and a five-question test for the ones on your shelf.

Last verified: 2026-07-14

Your employee can legally take PHI to a lawyer, and it is not your breach

HIPAA contains a whistleblower provision most clinic owners have never read. What 45 CFR 164.502(j) actually permits, who whistleblowers turn out to be in an ABA clinic, why they do it, and the one fact that should change how you run your internal channel.

Last verified: 2026-07-14
8 articles

The rules

The Security, Privacy, Breach Notification, and Enforcement Rules, read closely and cited to the section.

Addressable does not mean optional

The most expensive misunderstanding in the HIPAA Security Rule, what 45 CFR 164.306(d) actually requires you to do, and a full table of every implementation specification and how it is labelled.

Last verified: 2026-07-12

Administrative safeguards: what 45 CFR 164.308 actually requires

Nine standards, more than half the Security Rule, and the family where enforcement actually happens. The program behind the technology, standard by standard, for a clinic whose workforce turns over at RBT speed.

Last verified: 2026-07-12

How an OCR investigation actually works

From complaint or breach report to resolution: how OCR opens an investigation, what it can and cannot do, the factors that move a penalty, the defense written into the regulation, and where a clinic actually has leverage.

Last verified: 2026-07-12

Physical safeguards: what 45 CFR 164.310 actually requires

Four standards written in 2003 for buildings and server rooms, applied honestly to a clinic whose ePHI rides in a backpack: facilities, workstations, devices, and the two disposal rules everyone learns about the hard way.

Last verified: 2026-07-12

Technical safeguards: what 45 CFR 164.312 actually requires

The five technical standards of the HIPAA Security Rule, what each one demands, and what they look like in an ABA clinic where the workstation is a tablet in a family's living room.

Last verified: 2026-07-12

The Breach Notification Rule, from the top

A rule built on a presumption and a burden of proof. Why encryption decides whether it applies at all, why the clock starts before you notice, and why an empty incident log is the worst answer you can give.

Last verified: 2026-07-12

The Privacy Rule, from the top

One question governs the whole rule: may this information move, to this person, for this reason. The permission structure, the individual rights, the administrative machinery, and the four places an ABA clinic gets it wrong.

Last verified: 2026-07-12

The Security Rule, from the top

How the HIPAA Security Rule is actually built: the four duties, the flexibility clause everyone forgets, the required and addressable machinery, and a map of all three safeguard families.

Last verified: 2026-07-12
4 articles

Plain English

The regulation translated section by section, without losing what it actually says.

4 articles

Enforcement and penalties

What OCR does, what it costs, and what is changing in the rules.

3 articles

Reference

The glossary, the questions clinics ask most, and how HIPAA got to be the way it is.