The HIPAA calendar: what you do, and when

HIPAA fixes about a dozen deadlines and leaves the rest of the calendar to you. Here are the deadlines that are real, the cadences you have to set and defend yourself, and the events that force a review no matter what the calendar says.

Last verified: 2026-07-12

Every clinic owner eventually asks the same question, and it is the right one: what am I supposed to actually do, and how often?

The answer is stranger than you expect. HIPAA fixes about a dozen deadlines, precisely, in days. Everywhere else it says periodic, or regularly, or within a reasonable period of time, and then stops talking.

That silence is deliberate. It is the flexibility clause (45 CFR 164.306(b)) doing its work: a rule that told a twelve-person ABA clinic to do the same things on the same schedule as a hospital system would be a worse rule. But the flexibility has a sting in it. The rule sets a handful of hard deadlines and then, almost everywhere else, says periodic. Which means your cadence is not given to you. It is chosen by you, and you will be held to the choice.

So here are all three layers: the deadlines that are real, the cadences you must set yourself, and the events that force work no matter what month it is.

“The rule sets a handful of hard deadlines and then, almost everywhere else, says periodic. Which means your cadence is not given to you. It is chosen by you, and you will be held to the choice”

Layer one: the deadlines the rule actually fixes

These are not negotiable and not yours to define. Learn them once.

DeadlineWhat it governsCitation
60 daysNotifying individuals of a breach, from discovery. Sixty is the ceiling, not the target; unreasonable delay inside it is still a violation.164.404(b)
60 daysA business associate notifying you of a breach, from their discovery. Negotiate this down in the contract; their day 59 leaves you one day.164.410(b)
At the same timeNotifying HHS of a breach affecting 500 or more individuals, contemporaneously with the individual notices.164.408(b)
60 days after year endSubmitting the annual log of breaches affecting fewer than 500 individuals. The one small clinics forget.164.408(c)
30 daysResponding to a records access request, with one 30-day extension on written notice.164.524(b)(2)
60 daysResponding to an amendment request, with one 30-day extension.164.526(b)(2)
60 daysResponding to a request for an accounting of disclosures, with one 30-day extension. The accounting covers six years back.164.528(c)
30 daysThe correction window. A violation not due to willful neglect, corrected within 30 days of when you knew or should have known, bars a penalty entirely.160.410(b)
6 yearsRetention of required documentation, from creation or from when it was last in effect, whichever is later.164.316(b)(2)(i), 164.530(j)(2)

One of those deserves to be on a wall. The 30-day correction window is the most valuable deadline in HIPAA, because it is the only one that makes a penalty disappear rather than merely arrive on time. A clinic that finds its own problems and closes them inside thirty days is standing inside a defense the regulation wrote for it. How that works in an investigation.

Layer two: the cadences you have to choose

Here the rule tells you the work is required and then hands you the calendar. Every item below is mandatory. Every interval below is our recommendation, not law, and we say so plainly because the honest answer is that you must choose a cadence and be able to defend it.

What the rule requiresWhat the rule says about timingA defensible cadenceCitation
Risk analysisNothing explicit. Required, and must reflect your actual environment.Annual review, plus on any material change. An analysis that predates half your systems is not an analysis of your clinic.164.308(a)(1)(ii)(A)
Risk managementNothing explicit. Reduce identified risks to a reasonable level.Findings reviewed monthly or quarterly, each with an owner and a due date. This is where OCR's attention is moving.164.308(a)(1)(ii)(B)
Information system activity review"Regularly review" audit logs, access reports, incident tracking.Monthly, with a named owner and a note that it happened. A log nobody reads is half the standard.164.308(a)(1)(ii)(D)
Evaluation"Periodic" technical and nontechnical evaluation, in response to environmental or operational change.Annual, plus after any material change. The most forgotten standard in the rule.164.308(a)(8)
Security awarenessPeriodic security reminders (addressable).Monthly, five minutes in a team meeting. Phishing is the recurring topic.164.308(a)(5)(ii)(A)
Privacy trainingEach new workforce member "within a reasonable period of time" after joining, and after material policy changes.Before the first solo session, not at the ninety-day review. Note there is no annual in the text; annual is a practice, not the requirement.164.530(b)(2)
Access reviewNothing explicit. Access must be established, documented, reviewed, and modified.Quarterly, plus immediately on every departure and role change.164.308(a)(4)(ii)(C)
Contingency plan testing"Periodically test and revise" (addressable).Annual. A backup you have never restored is a hope, not a plan.164.308(a)(7)(ii)(D)
Policy and documentation reviewReview "periodically" and update as needed in response to change.Annual, with a version and a date on every policy.164.316(b)(2)(iii)
Security measures reviewReview and modify "as needed" to keep protection reasonable and appropriate.Continuous in practice; formally, with the annual evaluation.164.306(e)
Vendor and BAA registerNothing explicit. Every PHI-touching vendor must be under a signed agreement.Quarterly review, plus at every new tool. The list rots the moment a clinician downloads something.164.502(e), 164.308(b)
Notice of Privacy PracticesRevise and redistribute on any material change to your practices.Reviewed annually; revised whenever the underlying practice changes.164.520(b)(3)

The trap in this table is not laziness. It is writing an ambitious cadence and then not keeping it. Your own policy becomes the standard you are judged against, so a clinic that promises monthly log reviews and performs two a year has manufactured its own finding. Choose intervals you will actually keep, write them down, and keep them.

Layer three: the events that override the calendar

This is the layer that matters most in an ABA clinic, because your business does not run on a calendar. It runs on hiring, turnover, and whatever a clinician downloaded last Tuesday.

Someone is hired. Training before the first solo session. Unique credentials issued. Access granted by role, not by copying someone else’s. Confidentiality acknowledgment signed.

Someone leaves, or changes role. Access revoked the day employment ends, not the week after. Devices returned and wiped. The record of both, dated. In a workforce that turns over like an RBT workforce, this is your most frequently exercised security process.

A new tool or vendor appears. Before it touches a client: what does it hold, who else sees it, has it signed a BAA. The question to ask every time. This is the trigger clinics miss most, because the tool arrives without a decision.

A new location, service line, or platform. A new clinic site, a telehealth program, a new EHR, a new data collection app. Each is a material change to your environment, which triggers the risk analysis review, the evaluation standard, and usually a policy update and retraining.

An incident, of any size. Log it, assess it, and feed it back into the risk analysis. An incident is an unscheduled, expensive discovery about your actual risks, and the four-factor assessment is due whether or not it turns out to be a breach. What to do on the day.

A policy changes materially. Retraining of everyone affected, after it takes effect, documented (45 CFR 164.530(b)(2)(i)(C)).

The regulations change. A final rule, a court decision, a new enforcement initiative. Sweep everything it touches, not just the obvious page. What is changing, and when.

Diligence, or an acquisition approach. Not a compliance event in the legal sense, and absolutely a compliance event in practice: it is the day someone with money at stake reads your file. The request they will send.

The one-page version

If you take nothing else, take this shape:

Every hire and every departure: training in, access out, same day, recorded.

Monthly: read the logs, review the open risk findings, one security reminder to the team.

Quarterly: access review, vendor and BAA review.

Annually: risk analysis review, evaluation, policy review, contingency test, NPP check, and, in January, check whether the penalty figures moved.

Whenever something changes: new tool, new site, new service, new platform, new rule, or an incident. Do not wait for the calendar.

Always: the six-year file, and the thirty-day correction window.

That is a real HIPAA program’s calendar. It is not long, and nothing on it is difficult. What makes it hard is that eight of these items decay continuously in an operation where nobody’s job title contains the word compliance, which is exactly why they need dates and owners rather than good intentions. The twelve parts they belong to.

The short version

  • HIPAA fixes very few intervals: the 60-day breach clock, the 30-day access clock, the six-year retention, and a handful of others. Everything else says periodic or reasonable.
  • Because the rule leaves the cadence to you, your own written policy becomes the standard OCR holds you to. Choose a cadence you will actually keep.
  • Event triggers matter more than the calendar: a new hire, a departure, a new tool, a new location, or an incident each force work regardless of the date.
  • The 30-day correction window is the most valuable deadline in HIPAA: fixing a non-willful violation inside it bars a penalty entirely.
  • A clinic that can show what it does and when it last did it has a program. Everything else is a binder.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

A calendar that runs itself, and proves it ran.

Every item below produces evidence with a date on it. WiseUpHIPAA tracks what is due, what is overdue, and what was last done, from your clinic's real operations, honestly.