The policy binder problem: how clinics fail before the audit starts

OCR's own audit scale rates a template policy as negligible effort. Most ABA clinics are carrying exactly that artifact and believe it is protecting them. What the rule actually asks of a policy, and why nobody has to sign it.

Last verified: 2026-07-14

Most ABA clinics believe their policies are the settled part of the program. They bought a policy pack, or inherited one, or downloaded a set from a professional association. The binder is on the shelf. It has the right chapter headings. It feels finished.

It may be the most dangerous document in the building. Not because it is wrong, exactly, but because of what it proves. When a regulator reads it, that binder does not read as evidence of compliance. It reads as evidence that nobody did the work.

We do not have to speculate about this. OCR published its own grading scale, and it named the artifact.

OCR grades a template policy as negligible effort

In its 2016-2017 HIPAA Audits Industry Report, published December 2020, OCR audited 166 covered entities and 41 business associates and rated each on a scale of 1 to 5. A rating of 1 means compliance. A rating of 5 means no serious attempt.

A rating of 4 is defined as an entity that made negligible efforts to comply, and OCR gives exactly one illustration of what that looks like: policies and procedures submitted for review that were copied directly from an association template, alongside training evidence that is poorly documented and generic.

Read what OCR chose as its example. Not a missing policy. Not an incorrect policy. A policy copied from a template.

And in the risk analysis findings, OCR made the same point a second way, listing among the failures that entities offered third party template policy manuals containing no evidence of entity-specific review or revision, and no evidence of implementation.

A generic manual is not a neutral starting point in OCR’s eyes. It is an affirmative finding against you. OCR’s own example of negligible effort is a policy copied from a template. Most clinics are carrying exactly that artifact and believe it is protecting them.

The scores, which are worse than the industry admits

From the same audits, and these are OCR’s own published figures:

“OCR's own example of negligible effort is a policy copied from a template. Most clinics are carrying exactly that artifact and believe it is protecting them”

Audited requirementResult
Risk analysis, covered entitiesZero percent earned the top rating. Not one entity out of those audited. 14% were rated 1 or 2; the remaining 86% were rated 3, 4, or 5.
Risk management, covered entities94% failed to implement appropriate risk management activities. For business associates, 88%.
Right of access89% failed to show they were correctly implementing it.
Notice of Privacy Practices content2% fully met the content requirements.
Breach notification content67% omitted required content from their notices.
Breach notification timeliness71% met the deadline. One of only two areas where the industry did well.

These were not clinics that ignored HIPAA. Most of them had binders. The binder was not what OCR was measuring.

What the rule actually asks of a policy

Here is the part almost nobody reads, and it is short.

The Security Rule’s documentation standard (45 CFR 164.316) tells you to maintain your policies in written form, which may be electronic, and then attaches exactly three implementation specifications. All three are marked Required, which under 45 CFR 164.306(d) means they cannot be waived with a documented rationale:

Retention (164.316(b)(2)(i)). Six years from creation or from when the policy last was in effect, whichever is later. Note the second half: a superseded policy’s clock starts when it stopped being in effect, not when it was written.

Availability (164.316(b)(2)(ii)). The documentation must be available to the persons responsible for implementing the procedures it covers. Not archived. Reachable by the RBT who has to decide something on a Tuesday.

Updates (164.316(b)(2)(iii)). Review the documentation periodically and update it in response to environmental or operational changes.

That is the whole test. Retention, availability, review.

The Privacy Rule adds one sentence that matters more than any of them. Under 45 CFR 164.530(i)(1), your policies must be reasonably designed, taking into account the size and the type of activities of the covered entity.

Taking into account the size and the type of activities. That is a tailoring requirement written into the standard itself. A policy that could belong to any clinic in the country has not taken your clinic into account, and it fails that sentence on its face, before anyone examines whether you follow it.

The signature myth

While we are here, because half this industry sells it: HIPAA nowhere requires a signature on an internal policy.

Not in the Security Rule. 45 CFR 164.316(b)(1)(i) says maintain them in written or electronic form, and stops. Not in the Privacy Rule. 45 CFR 164.530(j)(1)(i) says written or electronic form, and stops.

The rule is perfectly capable of demanding a signature when it wants one:

ArtifactSignature required?Citation
Patient authorizationYes. The signature of the individual and the date are core required elements.164.508(c)(1)(vi)
NPP acknowledgmentYes. A direct treatment provider must make a good faith effort to obtain a written acknowledgment of receipt.164.520(c)(2)(ii)
Business associate agreementYes. It is a contract; contract law supplies the assent, not HIPAA.164.504(e)
Designation of your privacy officerNo. It must be documented. Not signed.164.530(a)(2)
Your internal policies and proceduresNo. Maintained in written or electronic form. That is all the rule says.164.316(b)(1), 164.530(j)(1)

The pattern is clean. HIPAA demands a signature where someone outside the organization is granting or agreeing to something. Internal governance documents require records, not ceremonies.

So the wet signature on the front of the binder is doing nothing for you, and it can do something worse: it creates the impression that the ceremony was the compliance. In its actual audit document requests, OCR asked for evidence that the documentation is available to the people responsible for the process, and evidence that it is periodically reviewed and updated. A signature demonstrates neither.

An authenticated, timestamped, versioned record that a named officer reviewed a specific version of a specific policy on a specific date is better evidence than a signature, because it is dated, structured, and provable.

The trap, stated plainly

The binder creates a feeling of completion that stops the work.

A clinic with no policies knows it has a problem. A clinic with a generic binder believes it does not. So it never asks the questions the binder never asked it:

  • Do staff carry paper charts in cars between sessions?
  • Do RBTs collect data on personal phones, and what happens to the camera roll?
  • Do you record telehealth sessions, and where do those recordings actually live?
  • Which parents have portal access, and who provisions and revokes it?
  • What is your real turnover, and what happens to system access the day someone stops showing up?

Your real policy is whatever you actually do about those things. The binder describes a clinic that does not exist. When OCR asks for evidence that the policy is implemented, and the policy describes a clinic you are not, there is no evidence to give.

That is what failing before the audit starts means. The failure is already sitting on the shelf. The audit only discovers it.

One finding that should be read aloud in every ABA clinic

Buried in OCR’s right-of-access results is a failure mode this field practices as standard procedure.

Among the reasons entities were marked down: procedures that required individuals to submit signed authorization forms, which OCR noted exceed what is required for a right of access request. OCR also observed that many entities incorrectly told patients they had 60 days to respond, when the rule gives 30 (45 CFR 164.524(b)(2)).

A parent asking for their child’s records is exercising a right, not requesting a favor. If your intake packet makes them sign a release to get it, and your policy says 60 days, you have described, in your own documentation, two violations. The right of access, in full.

And the finding we are obliged to quote against ourselves

In the same report, under risk analysis, OCR wrote that entities incorrectly assumed that a purchased security product satisfied all Security Rule requirements, and stated plainly that the responsibility to maintain an appropriate risk analysis rests with the entity. It added that many entities rely on outside firms, and that those firms frequently failed to meet the requirements.

We sell software. So let us be the ones to say it: no product, including ours, discharges your duty. A tool can make the work tractable, keep the evidence current, and tell you the truth about where you stand. It cannot be compliant on your behalf, and any vendor implying otherwise is telling you something useful about themselves. There is no such thing as HIPAA certification. HHS does not recognize one.

What a defensible policy set actually looks like

Four properties. That is the whole specification.

It is specific to your clinic. It names your systems, your data flows, your staffing model, your physical realities. If you could hand it to the clinic across town and it would still fit them, it does not fit you.

It is available to the people who follow it. Required, at 164.316(b)(2)(ii), and it means reachable in the moment of decision, not filed.

It is reviewed, and the review is recorded, with a date and a version. The rule says periodically and deliberately declines to define it, which means you choose the cadence and are then held to your own choice. What we would defend, and why.

It is implemented, and the implementation leaves a trail. OCR asks for the policy, and then asks for proof you follow it: the training that happened, the access that was revoked, the risk that was tracked. A policy with no operational trail behind it is an assertion, not evidence.

The uncomfortable summary

If you have a binder you did not write, about a clinic you do not run, that nobody has read since the day it was purchased, you do not have a policy problem you can fix during an audit. You have a finding that predates the audit by years.

The good news is that the fix is not more paperwork. It is less paperwork that actually describes you. And if the binder is the diagnosis, what a real policy is actually made of is the cure, named system by named system.

The short version

  • OCR's published audit rating scale defines a rating of 4, negligible effort, using one example: policies copied directly from an association template.
  • In the same audits, zero percent of covered entities earned the top rating on risk analysis, 94% failed risk management, and 89% failed the right of access.
  • HIPAA never requires a signature on an internal policy. It requires three things, all Required: retention for six years, availability to the people who follow it, and periodic review.
  • The Privacy Rule requires policies to be reasonably designed for the size and activities of your clinic. A policy that could belong to any clinic fails that on its face.
  • OCR says explicitly that buying a product does not discharge the duty. The responsibility stays with the entity, and that is true of our product too.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

A policy that describes your clinic.

WiseUpHIPAA builds your policies from your clinic's actual facts: your systems, your staffing model, your physical realities. Not a template with your name at the top. And it will show you red where red is true.