The evaluation standard: the review that keeps the program true

HIPAA requires a periodic evaluation of whether your whole security program still matches your clinic, and a review triggered whenever the clinic materially changes. It is the most forgotten standard, and it is the one that keeps every other part honest.

Last verified: 2026-07-26

Every other part of a HIPAA program is a photograph. The risk analysis is a picture of your risks on the day it was done. The policies describe the clinic as it was when they were written. The access list is who could see what as of the last review. Photographs age. The clinic in the picture stops matching the clinic in the building the moment you hire someone, adopt a tool, open a room, or start a telehealth program.

The evaluation standard is the one that notices. It is the least dramatic requirement in the Security Rule and, for that reason, the most forgotten, because nothing breaks the day you skip it. The program just quietly drifts until it describes a clinic that no longer exists.

What the rule requires

Evaluation is a Required standard (45 CFR 164.308(a)(8)). It calls for a periodic technical and nontechnical evaluation, done initially in response to operational or environmental changes affecting the security of ePHI, that establishes the extent to which your security policies and procedures still meet the requirements of the rule. In plain terms: check, on a schedule and when things change, whether your program still matches your clinic and still satisfies HIPAA.

It has a companion in the general rules. Maintenance (45 CFR 164.306(e)) says security measures must be reviewed and modified as needed to continue providing reasonable and appropriate protection, which makes explicit what evaluation implies: the program is not a thing you build once, it is a thing you keep. And the documentation rules require you to review your documentation periodically and update it as needed in response to changes affecting your ePHI (45 CFR 164.316(b)(2)(iii)).

Read together, these three say the same thing from three angles: a compliance program is not finished. It is maintained, or it decays.

The two triggers

Evaluation runs on two clocks, and clinics that remember it usually remember only the first.

The calendar trigger is the obvious one: a regular review, commonly annual, where you look at the whole program and ask whether it still holds. This is the one that lands on a compliance calendar.

The event trigger is the one that matters more and gets skipped. The rule specifically ties evaluation to operational and environmental change. So the review is not only a date, it is a response. Open a second location, and the picture changed. Add a telehealth program, and your data flows changed. Adopt an AI notetaker or a new scheduling platform, and your vendor and risk picture changed. Each of these is supposed to trigger a look, not wait for next year’s calendar entry. A clinic that materially changes in March and does not re-evaluate until December has spent nine months running a program calibrated to a clinic it no longer is.

Why it is the keystone

Every other control is a snapshot. This is the one that notices the snapshot has gone out of date. That is why skipping it is more corrosive than it looks: it does not fail on its own, it lets everything else fail quietly. The risk analysis that was accurate last year is now describing systems you no longer run. The risk management plan is tracking findings against a clinic that has changed shape. The policies name a vendor you dropped and omit the three you added. None of those decay because anyone did something wrong. They decay because time passed and nobody looked, which is precisely the failure evaluation exists to catch.

The ABA-specific version

ABA clinics change shape faster than most small practices, which makes the event trigger especially live:

“Every other control is a snapshot. This is the one that notices the snapshot has gone out of date.”

  • You add a telehealth program, and suddenly session data crosses networks it never did before.
  • A clinician adopts an AI notetaker, and a new vendor is holding session content nobody assessed.
  • You open a second site, and physical controls and access maps that were true for one location are not true for two.
  • You take on school-based work, and the FERPA-versus-HIPAA question reopens for a whole population.

Each of these is a material change, and each is supposed to prompt a fresh look rather than a note to handle it at the annual review.

How it dies

Silently, which is the whole point. There is no incident, no complaint, no missing document on the day evaluation is skipped. The program simply ages. A year passes, then two, and the gap between the documented clinic and the actual clinic widens without anyone noticing, until a breach or an audit measures it. It is the most forgotten standard in the rule because forgetting it has no immediate cost, only a compounding one.

The bottom line

The evaluation standard is the maintenance requirement for the whole program. Review it on a schedule, and re-examine it whenever the clinic materially changes, a new location, a new platform, a telehealth line, a new tool. Its job is not to produce a new artifact. Its job is to keep every other artifact true. Skip it and nothing breaks today. That is exactly why it is the one to put on the calendar and tie to your own moments of change, because it is the standard that decides whether the rest of the program is describing your clinic or a memory of it.

The short version

  • Evaluation (164.308(a)(8)) is a Required standard: a periodic technical and nontechnical review of whether your security program still meets the rule.
  • It has two triggers: a regular cadence, and any material operational or environmental change (a new site, platform, telehealth program, or AI tool).
  • Maintenance (164.306(e)) is its companion: review and modify your security measures as needed, not once, and update the documentation.
  • It is the most forgotten standard because nothing breaks the day it is skipped. The program simply drifts out of date silently.
  • Every other part of the program is calibrated by a picture of your clinic. This is the standard that keeps that picture current.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Item freshness, tracked.

WiseUpHIPAA tracks review dates on the pieces that carry them, and re-checks which threats apply when your clinic's profile changes: a new location, a platform, a telehealth program, an AI tool. It surfaces what is coming due and what has gone stale. A single dated attestation that the whole program was re-evaluated is on the roadmap, not built yet, and the product says so rather than implying otherwise.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.