What a HIPAA compliance officer actually does

Not a title on an org chart. The weekly, monthly, quarterly, and annual questions someone has to ask out loud in an ABA clinic, why the answers never arrive on their own, and the provision that makes asking early worth real money.

Last verified: 2026-07-14

The Security Rule requires you to name a security official (45 CFR 164.308(a)(2)) and the Privacy Rule requires a privacy official (45 CFR 164.530(a)). Both are Required. Neither rule says a word about what that person does on a Tuesday.

So here is the job, honestly, and it starts with a fact about your clinic that nobody likes to say out loud.

Nobody is thinking about compliance, and that is not negligence

The people in your building are thinking about authorizations, about staffing tomorrow’s session, and about whether the payer paid. That is a clinic running correctly.

Which means the clinic’s reality never enters a compliance system on its own. Nobody logs in to announce that they started faxing again because a payer asked. Nobody files a note that an RBT is collecting data on her personal phone, or that a stack of data sheets has been in someone’s trunk since Tuesday. Those things happened because they solved a problem, and the compliance consequence never crossed anyone’s mind.

A compliance system that waits to be told the truth will be confidently, provably wrong about the clinic, with a timestamp on it. A stale record that looks current is worse than no record. It is a lie with an audit trail.

That is the whole reason the officer exists. The officer is not a service wrapped around the software. The officer is how reality gets into the system, because there is no other path and there never was.

“A compliance system that waits to be told the truth will be confidently, provably wrong about the clinic, with a timestamp on it. A stale record that looks current is worse than no record”

The provision that makes asking early worth money

Before the cadence, the reason for it.

45 CFR 160.410(b): a violation that is not due to willful neglect and is corrected within 30 days of when the entity knew, or with reasonable diligence would have known, of it, may not have a penalty imposed. Not reduced. Not mitigated. An affirmative defense, written into the regulation.

Read what that does to the economics of a weekly conversation. Something goes wrong in every clinic eventually. If it surfaces on Tuesday and is closed inside thirty days, the rule itself removes the penalty. If nobody asks, it surfaces two years later inside a breach investigation, where it is not a correction, it is a finding.

The officer’s cadence is not administrative hygiene. It is a machine for finding things while the thirty-day window is still open, and almost nobody in this market is selling it that way because almost nobody knows the provision exists. How that plays out in an investigation.

There is a sting worth naming honestly: discovery runs on what you knew or should have known with reasonable diligence (45 CFR 164.404(a)(2)). A clinic with an officer asking every week is held to a sharper discovery standard than one with nobody asking. That is not an argument against asking. It means the asking itself must be recorded, because the log of the asking is the evidence of the diligence.

The cadence, set by how fast the fact changes

Not by how the regulation is organized. By how fast the underlying truth decays.

CadenceThemeWhy this speed
WeeklyPeople and eventsTurnover is the fastest-moving risk in an ABA clinic, and an incident nobody names in the first week gets remembered wrong or not at all.
MonthlySystems and driftTools, devices, vendors, and physical arrangements accumulate quietly and nobody notices until someone looks.
QuarterlyEvidenceAre we actually doing what our policies say? This is where the gap between paper and practice shows.
AnnualThe whole modelDoes the system's picture of this clinic still match the clinic?
EventClocksSome things start a legal timer the moment they happen. They do not wait for a meeting.

The annual review is the settlement, not the work. If the weekly and monthly asking is honest, the annual review confirms what is already known. If it is not, the annual review is a year of archaeology performed in a panic.

The six weekly questions

Fifteen to thirty minutes. These are the job. Note the phrasing: ask them in human words, because “were there any security incidents this week” is answered no by every clinic that ever had one.

1. Who joined? Training before PHI access, access provisioned to the right systems only, clearance done. The rule wants each new workforce member trained within a reasonable period after joining (45 CFR 164.530(b)(2)(i)(B)). An RBT who has been in homes for three weeks untrained is a live finding, not a paperwork gap.

2. Who left, and is their access actually gone? The single highest-value question in this entire article. Ask it as a list, never as a yes or no: the practice management system, email, the data collection app, the scheduling tool, the parent portal, the fax account, the building keys, the clinic laptop, and every paper record in their car (45 CFR 164.308(a)(3)(ii)(C)). A departed RBT with live credentials is an open door into every client record.

3. Did anyone’s role change? A tech promoted, an admin taking on billing, someone covering a caseload. Access follows the job, and it accumulates unless somebody removes it (45 CFR 164.502(b)).

4. Did anything go sideways with patient information this week? Say it in their language: Did anyone email the wrong parent? Did a phone or a laptop go missing? Did a parent see another child’s data? Did anything go to the wrong fax number?

This is the breach discovery question, and asking it weekly is what makes discovery honest. The 60-day clock runs from discovery (45 CFR 164.404(b)), and a clinic that never asks never discovers, which means it has a clock running that it does not know about.

5. Any new clients? New PHI, and the Notice of Privacy Practices obligations attach, including the good faith effort to obtain a written acknowledgment of receipt (45 CFR 164.520(c)(2)(ii)).

6. Did anyone start using anything new? The shadow IT question, in plain words: did anyone sign up for an app, a scheduling tool, a transcription thing, an AI note-writer, a texting service, a new payer portal?

This is where the fax comes back. Nobody announces it. Somebody just did it, because a payer asked.

The monthly hour: systems and drift

New vendors, tools, or subscriptions, because anything touching PHI needs a BAA before access, not after (45 CFR 164.502(e)). New devices, lost devices, and the harder question: whose personal phone has client data on it right now. Physical changes: new office, moved records, changed locks, a new person with a key, a shredding vendor who stopped showing up.

Paper: where is it, who took it out, and did it come back? This is the ABA question that generic guides never ask. Data sheets travel to homes, to schools, into cars. Is anything still in a car right now? Has anything not come back?

Training overdue. Payer changes, because a payer that changes how it wants records is changing how PHI moves and nobody thinks of it as a compliance event. And parent complaints or record requests, because complaints must be documented (45 CFR 164.530(d)(2)) and a records request starts a 30-day clock (45 CFR 164.524(b)(2)). A request sitting in a BCBA’s inbox for six weeks is a right-of-access violation, in OCR’s most enforced area.

The quarterly half day: evidence

Access recertification, line by line, person by person, system by system. Not “does this look right” but “does this person still need this, and who says so.”

Information system activity review, which is Required and which almost no small clinic performs (45 CFR 164.308(a)(1)(ii)(D)). Look at the logs. The ABA version of the question: did a BCBA open records for clients who are not theirs? Did anyone open a chart at 2am?

The BAA sweep. The risk register, and the only question that matters about it: last quarter you said you would fix things, did you? OCR’s audits found 94% of covered entities failing risk management, mostly because they analyzed and then did nothing.

The incident log, read for patterns, because three misdirected emails in a quarter is not three incidents, it is one process failure. And sanctions: were any applied, and were they documented (45 CFR 164.530(e)(2))? A sanction policy that has never been applied, in a clinic where things have gone wrong, is a policy nobody believes.

The annual settlement

Risk analysis refresh. Evaluation, which is a separate standard almost nobody performs (45 CFR 164.308(a)(8)): the risk analysis asks what could go wrong, the evaluation asks whether the program actually worked. Policy review. NPP still accurate. Training cycle complete and documented. Contingency plan tested. Officer designations still the right people, still documented.

The under-500 breach log, submitted to HHS within 60 days after the calendar year ends (45 CFR 164.408(c)). The deadline small clinics forget entirely.

And the one only a human can do: full inventory reconciliation. Does the system’s picture of this clinic still match the clinic? Walk the building. Open the closet. Look in the car.

The event lane

These do not wait for a meeting.

EventClockCitation
Suspected breach of unsecured PHINotify individuals without unreasonable delay, no later than 60 days from discovery164.404(b)
Any incident at allFour-factor assessment, to decide whether it is a reportable breach164.402
Anything found and fixableCorrect within 30 days of knowing, and no penalty may be imposed160.410(b)
TerminationAccess revoked. Not next week.164.308(a)(3)(ii)(C)
New vendor touching PHIBAA executed before access, not after the pilot164.502(e)
Patient or parent record request30 days, one 30-day extension if justified164.524(b)(2)
A disclosure outside treatment, payment, or operationsLog it as you go; the accounting cannot be reconstructed later164.528
ComplaintLog it, and its disposition164.530(d)(2)
Change in lawPromptly document and implement the revised policy164.530(i)(3)

The single most important instruction an officer gives a clinic: if anything happens with patient information, call me the same day. Do not wait for our meeting, and do not decide for yourself whether it is serious. The 60-day clock runs from discovery, and a clinic that sits on something for three weeks because it was not sure has burned half its clock and most of its thirty-day correction window.

The questions nobody else asks

A generic HIPAA officer’s checklist contains none of these, because writing them requires knowing what an RBT does on a Tuesday.

Are RBTs collecting session data on personal phones, which app, does it sync, and what happens to that data when they quit? Do therapists text parents, from personal numbers, with a child’s name and progress in the thread? Where do session recordings live, who can see them, are they ever deleted? What leaves with the RBT for a school visit, and what comes back? Does a BCBA have access only to their own clients, or to everything, because most systems default to everything? Who provisions parent portal access, and who removes it in a custody dispute?

And the people nobody counts: the billing contractor, the owner’s spouse who helps with scheduling, the intake coordinator with full system access because it was easier. Every one of them is a workforce member under 45 CFR 160.103, which means training, a role, and a sanction policy that applies to them.

Who this person can be

The rule does not require a credential, a certification, or an outside firm. It requires a named human with the authority to actually do something (45 CFR 164.308(a)(2); 45 CFR 164.530(a)), and the designation must be documented.

In a small ABA clinic that is usually the owner, the clinical director, or the practice manager. It works when that person genuinely has the authority to make an RBT stop doing something and the time to ask the questions above. It fails, quietly and completely, when the title is assigned to someone with neither.

Which is the honest test, and it has nothing to do with software: is there a named person who asked these questions this month, and is there a record that they did? If yes, you have a compliance program. If no, you have a binder, and the binder is the finding.

The short version

  • Correcting a non-willful violation within 30 days of when you knew, or should have known, bars a penalty entirely. That single provision is what makes asking early worth money.
  • Nobody at a clinic will log in to report that they started faxing again. Reality has to be asked for, out loud, on a cadence.
  • Cadence follows how fast the fact changes: people weekly, systems monthly, evidence quarterly, the whole model annually.
  • The six weekly questions are the job. Phrase them in human words, because 'were there any security incidents' is answered no by every clinic that ever had one.
  • The annual review is the settlement, not the work. If the weekly asking was honest, the annual review confirms what is already known.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Someone has to ask. Then it has to count.

WiseUpHIPAA generates the officer's questions from your clinic's actual configuration, and one answer updates everything it touches: the assets, the threats, the policies, the controls, the clocks. And if you would rather not do the asking, we will.