The HIPAA calendar: what you do, and when
HIPAA fixes about a dozen deadlines and leaves the rest of the calendar to you. Here are the deadlines that are real, the cadences you have to set and defend yourself, and the events that force a review no matter what the calendar says.
Last verified: 2026-07-12
Every clinic owner eventually asks the same question, and it is the right one: what am I supposed to actually do, and how often?
The answer is stranger than you expect. HIPAA fixes about a dozen deadlines, precisely, in days. Everywhere else it says periodic, or regularly, or within a reasonable period of time, and then stops talking.
That silence is deliberate. It is the flexibility clause (45 CFR 164.306(b)) doing its work: a rule that told a twelve-person ABA clinic to do the same things on the same schedule as a hospital system would be a worse rule. But the flexibility has a sting in it. The rule sets a handful of hard deadlines and then, almost everywhere else, says periodic. Which means your cadence is not given to you. It is chosen by you, and you will be held to the choice.
So here are all three layers: the deadlines that are real, the cadences you must set yourself, and the events that force work no matter what month it is.
“The rule sets a handful of hard deadlines and then, almost everywhere else, says periodic. Which means your cadence is not given to you. It is chosen by you, and you will be held to the choice”
Layer one: the deadlines the rule actually fixes
These are not negotiable and not yours to define. Learn them once.
| Deadline | What it governs | Citation |
|---|---|---|
| 60 days | Notifying individuals of a breach, from discovery. Sixty is the ceiling, not the target; unreasonable delay inside it is still a violation. | 164.404(b) |
| 60 days | A business associate notifying you of a breach, from their discovery. Negotiate this down in the contract; their day 59 leaves you one day. | 164.410(b) |
| At the same time | Notifying HHS of a breach affecting 500 or more individuals, contemporaneously with the individual notices. | 164.408(b) |
| 60 days after year end | Submitting the annual log of breaches affecting fewer than 500 individuals. The one small clinics forget. | 164.408(c) |
| 30 days | Responding to a records access request, with one 30-day extension on written notice. | 164.524(b)(2) |
| 60 days | Responding to an amendment request, with one 30-day extension. | 164.526(b)(2) |
| 60 days | Responding to a request for an accounting of disclosures, with one 30-day extension. The accounting covers six years back. | 164.528(c) |
| 30 days | The correction window. A violation not due to willful neglect, corrected within 30 days of when you knew or should have known, bars a penalty entirely. | 160.410(b) |
| 6 years | Retention of required documentation, from creation or from when it was last in effect, whichever is later. | 164.316(b)(2)(i), 164.530(j)(2) |
One of those deserves to be on a wall. The 30-day correction window is the most valuable deadline in HIPAA, because it is the only one that makes a penalty disappear rather than merely arrive on time. A clinic that finds its own problems and closes them inside thirty days is standing inside a defense the regulation wrote for it. How that works in an investigation.
Layer two: the cadences you have to choose
Here the rule tells you the work is required and then hands you the calendar. Every item below is mandatory. Every interval below is our recommendation, not law, and we say so plainly because the honest answer is that you must choose a cadence and be able to defend it.
| What the rule requires | What the rule says about timing | A defensible cadence | Citation |
|---|---|---|---|
| Risk analysis | Nothing explicit. Required, and must reflect your actual environment. | Annual review, plus on any material change. An analysis that predates half your systems is not an analysis of your clinic. | 164.308(a)(1)(ii)(A) |
| Risk management | Nothing explicit. Reduce identified risks to a reasonable level. | Findings reviewed monthly or quarterly, each with an owner and a due date. This is where OCR's attention is moving. | 164.308(a)(1)(ii)(B) |
| Information system activity review | "Regularly review" audit logs, access reports, incident tracking. | Monthly, with a named owner and a note that it happened. A log nobody reads is half the standard. | 164.308(a)(1)(ii)(D) |
| Evaluation | "Periodic" technical and nontechnical evaluation, in response to environmental or operational change. | Annual, plus after any material change. The most forgotten standard in the rule. | 164.308(a)(8) |
| Security awareness | Periodic security reminders (addressable). | Monthly, five minutes in a team meeting. Phishing is the recurring topic. | 164.308(a)(5)(ii)(A) |
| Privacy training | Each new workforce member "within a reasonable period of time" after joining, and after material policy changes. | Before the first solo session, not at the ninety-day review. Note there is no annual in the text; annual is a practice, not the requirement. | 164.530(b)(2) |
| Access review | Nothing explicit. Access must be established, documented, reviewed, and modified. | Quarterly, plus immediately on every departure and role change. | 164.308(a)(4)(ii)(C) |
| Contingency plan testing | "Periodically test and revise" (addressable). | Annual. A backup you have never restored is a hope, not a plan. | 164.308(a)(7)(ii)(D) |
| Policy and documentation review | Review "periodically" and update as needed in response to change. | Annual, with a version and a date on every policy. | 164.316(b)(2)(iii) |
| Security measures review | Review and modify "as needed" to keep protection reasonable and appropriate. | Continuous in practice; formally, with the annual evaluation. | 164.306(e) |
| Vendor and BAA register | Nothing explicit. Every PHI-touching vendor must be under a signed agreement. | Quarterly review, plus at every new tool. The list rots the moment a clinician downloads something. | 164.502(e), 164.308(b) |
| Notice of Privacy Practices | Revise and redistribute on any material change to your practices. | Reviewed annually; revised whenever the underlying practice changes. | 164.520(b)(3) |
The trap in this table is not laziness. It is writing an ambitious cadence and then not keeping it. Your own policy becomes the standard you are judged against, so a clinic that promises monthly log reviews and performs two a year has manufactured its own finding. Choose intervals you will actually keep, write them down, and keep them.
Layer three: the events that override the calendar
This is the layer that matters most in an ABA clinic, because your business does not run on a calendar. It runs on hiring, turnover, and whatever a clinician downloaded last Tuesday.
Someone is hired. Training before the first solo session. Unique credentials issued. Access granted by role, not by copying someone else’s. Confidentiality acknowledgment signed.
Someone leaves, or changes role. Access revoked the day employment ends, not the week after. Devices returned and wiped. The record of both, dated. In a workforce that turns over like an RBT workforce, this is your most frequently exercised security process.
A new tool or vendor appears. Before it touches a client: what does it hold, who else sees it, has it signed a BAA. The question to ask every time. This is the trigger clinics miss most, because the tool arrives without a decision.
A new location, service line, or platform. A new clinic site, a telehealth program, a new EHR, a new data collection app. Each is a material change to your environment, which triggers the risk analysis review, the evaluation standard, and usually a policy update and retraining.
An incident, of any size. Log it, assess it, and feed it back into the risk analysis. An incident is an unscheduled, expensive discovery about your actual risks, and the four-factor assessment is due whether or not it turns out to be a breach. What to do on the day.
A policy changes materially. Retraining of everyone affected, after it takes effect, documented (45 CFR 164.530(b)(2)(i)(C)).
The regulations change. A final rule, a court decision, a new enforcement initiative. Sweep everything it touches, not just the obvious page. What is changing, and when.
Diligence, or an acquisition approach. Not a compliance event in the legal sense, and absolutely a compliance event in practice: it is the day someone with money at stake reads your file. The request they will send.
The one-page version
If you take nothing else, take this shape:
Every hire and every departure: training in, access out, same day, recorded.
Monthly: read the logs, review the open risk findings, one security reminder to the team.
Quarterly: access review, vendor and BAA review.
Annually: risk analysis review, evaluation, policy review, contingency test, NPP check, and, in January, check whether the penalty figures moved.
Whenever something changes: new tool, new site, new service, new platform, new rule, or an incident. Do not wait for the calendar.
Always: the six-year file, and the thirty-day correction window.
That is a real HIPAA program’s calendar. It is not long, and nothing on it is difficult. What makes it hard is that eight of these items decay continuously in an operation where nobody’s job title contains the word compliance, which is exactly why they need dates and owners rather than good intentions. The twelve parts they belong to.
The short version
- HIPAA fixes very few intervals: the 60-day breach clock, the 30-day access clock, the six-year retention, and a handful of others. Everything else says periodic or reasonable.
- Because the rule leaves the cadence to you, your own written policy becomes the standard OCR holds you to. Choose a cadence you will actually keep.
- Event triggers matter more than the calendar: a new hire, a departure, a new tool, a new location, or an incident each force work regardless of the date.
- The 30-day correction window is the most valuable deadline in HIPAA: fixing a non-willful violation inside it bars a penalty entirely.
- A clinic that can show what it does and when it last did it has a program. Everything else is a binder.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Notification to individuals, the 60-day clock45 CFR 164.404https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.404
- Notification to the Secretary, including the annual log45 CFR 164.408https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.408
- Notification by a business associate45 CFR 164.410https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.410
- Access of individuals, the 30-day clock45 CFR 164.524https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.524
- Amendment of protected health information45 CFR 164.526https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.526
- Accounting of disclosures45 CFR 164.528https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.528
- Policies and procedures and documentation, including the six-year rule and periodic review45 CFR 164.316https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.316
- Administrative safeguards, including evaluation and training45 CFR 164.308https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- Security standards: General rules, including ongoing maintenance45 CFR 164.306https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.306
- Administrative requirements, including training and documentation45 CFR 164.530https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- Affirmative defenses, the 30-day correction window45 CFR 160.410https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-D/section-160.410
- Notice of privacy practices, including revision on material change45 CFR 164.520https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520
A calendar that runs itself, and proves it ran.
Every item below produces evidence with a date on it. WiseUpHIPAA tracks what is due, what is overdue, and what was last done, from your clinic's real operations, honestly.