Is your ABA clinic even covered by HIPAA?

The actual legal test for whether HIPAA applies to your clinic, the one electronic transaction that flips the answer, and why betting on the exemption is a bad trade.

Last verified: 2026-07-12

Most HIPAA content skips this question entirely, because the people writing it assume the answer. But HIPAA does not apply to you because you are in health care. It applies to you because you meet a legal definition, and the definition has an actual test in it.

For most ABA clinics the answer is yes, and it became yes earlier than anyone noticed. For a small number it is genuinely no. Here is the test, so you can stop guessing.

The test

The rules apply to three kinds of organization (45 CFR 160.102): health plans, health care clearinghouses, and, the one that matters here, a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter.

An ABA clinic is a health care provider under the definition at 45 CFR 160.103, which reaches anyone who furnishes, bills, or is paid for health care in the normal course of business. That part is not in question.

So for a provider, the whole test lives in the second half of the sentence. You are a covered entity if you transmit health information electronically, in connection with a covered transaction. Not because you are licensed. Not because you see clients. Not because you keep records on a computer. Because of that specific act.

Which means the question becomes: what is a covered transaction?

The transactions

They are defined at 45 CFR 160.103 and given technical standards in 45 CFR Part 162. The list is about the business of health care, and mostly about the conversation between a provider and a payer: health care claims or equivalent encounter information, payment and remittance advice, coordination of benefits, health care claim status, enrollment and disenrollment in a health plan, eligibility for a health plan, health plan premium payments, referral certification and authorization, first report of injury, health claims attachments, and electronic funds transfers.

Read the list again slowly, because three entries on it are things an ABA clinic does casually, without thinking of them as transactions at all.

Submitting a claim. One claim, submitted electronically, to one payer, once, and the test is met. There is no minimum volume, no grace period, and no undo.

Checking eligibility. Verifying a family’s benefits before intake is an eligibility transaction. Do it electronically and the test is met.

Requesting an authorization. ABA runs on prior authorization. Requesting one is a referral certification and authorization transaction. Do it electronically and the test is met.

The three quiet triggers

This is where clinics that believe they are exempt find out they are not.

The payer portal counts. The regulation defines direct data entry as entry of data, for example using web browsers, that is immediately transmitted into a health plan’s computer (45 CFR 162.103), and provides rules for providers who use it (45 CFR 162.923(b)). Typing a client’s information into a payer’s website to check benefits or request an authorization is conducting a covered transaction electronically. Nobody thinks of a browser tab as an electronic claims system. The regulation does.

Your billing company counts. Under 45 CFR 162.923(c), a covered entity may use a business associate, including a clearinghouse, to conduct transactions on its behalf. HHS is explicit that a provider who submits claims electronically through a billing service or clearinghouse is covered. Handing the billing to someone else outsources the typing, not the legal status.

Paper has a narrow definition. The exclusion people half-remember is real but small: under the definition of electronic media at 45 CFR 160.103, a paper-to-paper fax and a voice phone call do not count as electronic transmission, because the information did not exist in electronic form immediately before sending. A computer-generated fax, an efax service, or an emailed claim does not get that shelter.

So who is actually not covered?

A clinic that is entirely private pay, submits no claims to anyone, never checks eligibility or requests authorization through any electronic channel, gives families no superbills that a billing agent transmits electronically on the clinic’s behalf, and conducts none of the other listed transactions electronically. That clinic does not meet the definition at 45 CFR 160.102, and HIPAA, as a regulation, does not bind it.

Such clinics exist. If yours is one, you deserve the straight answer, so here it is: you are not a covered entity, and no compliance vendor should be allowed to scare you out of knowing that.

Now here is the rest of the straight answer.

“You are not a covered entity, and no compliance vendor should be allowed to scare you out of knowing that.”

Why the exemption is a bad thing to lean on

It is fragile in one direction. The exemption survives only as long as every trigger stays untouched. One staff member checking benefits in a portal, one family whose funding shifts to Medicaid, one contract with a school district that pays through a plan, one grant program that wants electronic encounter data, and the status flips. It does not flip for that client. It flips for the clinic, and the Privacy Rule then covers all the protected health information you hold, not just the record that tripped the wire.

It ends the moment you grow. Insurance funding is how ABA scales. A clinic planning to stay cash-only forever is planning to stay small forever, which is a legitimate choice, but then the exemption is a description of your business model, not a compliance strategy.

Not covered is not the same as unregulated. Your state almost certainly has health record confidentiality and breach notification laws that do not care about HIPAA’s definitions. Your professional ethics obligations around client confidentiality apply regardless. And every payer contract you ever sign will impose privacy and security obligations by contract on top of whatever the law says.

You may still be inside HIPAA through the side door. A business associate is anyone who creates, receives, maintains, or transmits protected health information in performing services for a covered entity (45 CFR 160.103). If your clinic performs functions for another covered provider or a plan, you can carry HIPAA obligations as a business associate without ever being a covered entity yourself.

The honest bottom line

If your clinic bills insurance, or checks benefits, or requests authorizations through anything with a screen, you are a covered entity, and you have been since the first time it happened. The question worth your attention is not whether HIPAA applies. It is whether you could show, today, that you are doing what it requires.

If your clinic truly conducts none of the covered transactions electronically, you are not a covered entity. Write down why you believe that, review it whenever your billing or funding changes, and understand that you are one portal login away from a different answer. A clinic that knows exactly where the line is stands in a much stronger position than a clinic that never looked.

The short version

  • A provider is covered only if it transmits health information electronically in connection with a covered transaction; that is a real legal test.
  • One electronic claim, eligibility check, or authorization request, ever, meets the test, and payer portals count.
  • A billing company transmitting on your behalf makes you covered; outsourcing the typing does not outsource the status.
  • A truly paper-and-cash clinic is genuinely exempt, but the exemption is one portal login away from gone.
  • Not covered is not unregulated: state law, ethics obligations, and payer contracts still apply.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Covered is a fact. Compliant is a program.

If your clinic bills insurance, the coverage question is settled and the real question is what you can show. WiseUpHIPAA is built for ABA clinics: it works out what applies to you, holds your decisions and the evidence behind them, and shows you honestly where you stand, including the parts that are not done yet.