A sanctions policy is a set of decisions, not a document

HIPAA requires appropriate, consistently applied sanctions, not a template in a binder. What the Security and Privacy Rules actually demand of an ABA clinic, and the decisions only you can make.

Last verified: 2026-07-26

Most clinics treat a HIPAA sanctions policy as a document you write. Download a template, change the letterhead, drop it in a binder, tick the box. That is the wrong mental model, and it is the reason so many sanctions policies collapse the first time anyone leans on them.

A sanctions policy is not a document. It is a set of decisions. The document is only the readout of the decisions you made. If you never actually made the decisions, you do not have a policy. You have a page.

What the rule actually requires

There are two sanctions obligations in HIPAA, and they run in parallel.

“A sanctions policy is not a document. It is a set of decisions.”

The Security Rule requires a sanction policy at 45 CFR 164.308(a)(1)(ii)(C), one of the nine standards in its administrative safeguards. In Security Rule terms it is a Required implementation specification, not an addressable one, which means you do not get to assess it away as unreasonable for your environment. The text is short: apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate.

The Privacy Rule carries its own sanctions obligation at 45 CFR 164.530(e)(1). This one is a standard, not an implementation specification, so the Required or addressable labels do not apply to it at all; it is mandatory on its own terms. A covered entity must have and apply appropriate sanctions against workforce members who fail to comply with its privacy policies and procedures, or with the requirements of the Privacy Rule or the Breach Notification Rule themselves.

Read those two sentences carefully, because what they do not say is as important as what they do. Neither rule tells you to build a five-tier disciplinary matrix. Neither prescribes categories of violation. Neither hands you a form. Both require the same two things: that your sanctions be appropriate, and that you actually apply them.

The same standard carves itself out. It does not apply to a workforce member’s actions that meet the conditions of 45 CFR 164.502(j) or 164.530(g)(2), the whistleblower and anti-retaliation provisions. Sanctioning someone for protected activity is not a gap in your policy, it is a violation in its own right.

The only sanction-specific thing HIPAA requires you to write down is the sanctions you actually imposed, and that requirement is Privacy Rule vocabulary: 45 CFR 164.530(e)(2), the documentation specification sitting directly alongside the Privacy sanctions standard, which requires you to document the sanctions that are applied, if any. The Security Rule has no sanction-documentation specification at all. Its general documentation standard at 45 CFR 164.316(b)(1) requires your policies and procedures to be in writing, which covers the sanction policy itself, and separately requires a written record of any action the Security Rule tells you to document. It never tells you to document a sanction. So the duty to record what you actually did lands entirely on the Privacy Rule side.

So the regulation gives you a duty and almost no structure. That sounds like freedom. It is actually the trap.

Why “appropriate and consistent” is the hard part

“Appropriate” and “applied consistently” are not self-executing. To sanction appropriately, you have to have already decided what appropriate means for your clinic, before the incident, in the calm. To sanction consistently, two similar violations by two different people have to land on similar consequences, which is impossible if nobody wrote down what similar means.

That is where the decisions come in. A defensible sanctions policy is the set of choices that turn “appropriate and consistent” from a slogan into something you can actually do under pressure:

  • Which categories of violation your clinic recognizes. An RBT texting a session note to a parent in the wrong app is not the same kind of failure as a BCBA pulling up a former client’s record out of curiosity. If your policy cannot tell those apart, it cannot be consistent about them.
  • What consequence each category carries. Coaching, written warning, retraining, suspension, termination. The point is not the labels. The point is that you decided, in advance, so that the consequence is a policy and not a mood.
  • A written reason whenever you depart from your own norm. If a category that would normally draw a warning draws a termination in your clinic, that is a defensible choice, but only if the reason is recorded. Without the reason, it is not a stricter policy. It is an unexplained one, and an unexplained sanction is the kind that gets challenged and loses.

None of this is dictated by the regulation. All of it is how you satisfy the regulation’s actual demand, which is that your sanctions be appropriate and evenly applied. The tiered, category-based structure is the defensible method. It is not a form HIPAA handed you. It is the work HIPAA left to you.

The template problem

Here is what a downloaded sanctions template actually is: someone else’s decisions, wearing your clinic’s name.

The categories were chosen by a stranger who never saw your workforce. The tiers were set by a stranger who does not know whether your clinic runs mostly RBTs in family homes or mostly clinical staff in a center. When an auditor asks why a given violation sits at a given tier, the honest answer is “the template said so,” and that answer is the sound of a policy failing in real time. You cannot defend a decision you never made.

This is the exact failure this whole category of compliance theater produces. A document that looks complete and decides nothing. A binder that answers “do you have a sanctions policy?” with yes and “what does it say about an RBT sharing PHI in a group chat?” with silence.

What “adopted” should mean

A sanctions policy is not adopted when a file is uploaded. It is adopted when an actual appointed officer, your privacy officer or your security officer, reviews the decisions and attests to them. The attestation records who made the call and when. That is the difference between a policy your clinic owns and a document your clinic possesses.

And once it is attested, it is settled. You do not quietly edit an attested policy in place, because then nobody can say what was in force when a given incident happened. You revise it by issuing a new version and attesting that. The old version stays exactly as it was, as the record of what governed at the time. A sanctions policy that can be silently edited after the fact is not a record. It is a moving target, and a moving target is worthless the moment you need to prove what your rule was on the day something went wrong.

What this looks like in an ABA clinic

The reason the decisions matter is that ABA clinics generate exactly the violations a generic template never anticipated. A few your policy should already have a category and a tier for:

  • An RBT shares a session note or a photo in a parent group chat, because the group chat is how the whole team already communicates.
  • A BCBA opens the record of a former client, or a neighbor’s child, with no treatment reason.
  • Billing staff email a spreadsheet with client names and service codes to the wrong address.
  • A field RBT keeps client data on a personal phone that is never encrypted and occasionally lost.
  • Someone runs session audio through an AI notetaker that nobody vetted and that retains the recording on servers you have never seen.

For each of these, your clinic, not a vendor, decides the category and the consequence. That is the decision. The document just writes it down. When you can answer “what happens to an RBT who does X” without hesitating and without guessing, you have a sanctions policy. When you cannot, you have a page.

The bottom line

Honest compliance software does not write your sanctions policy for you and call it done. That would just be a fancier template, someone else’s decisions with a nicer font. The useful thing software can do is make you make the decisions, record who attested them, freeze them once attested, and keep every sanction you apply recorded against the category and tier it fell under, so inconsistency becomes visible instead of invisible. It cannot make you consistent. It can take away the excuse of not knowing. That is harder than filling in a template. It is also the only version that survives contact with an actual incident.

A sanctions policy is a set of decisions. Make them on purpose, in the calm, and write them down. That is the whole job.

This article deliberately states no dollar penalty figures. HIPAA civil monetary penalties are inflation-adjusted annually and are further affected by OCR’s standing enforcement-discretion policy on annual caps, so any specific number belongs in a dedicated, separately sourced enforcement piece rather than here.

The short version

  • A HIPAA sanctions policy is a set of decisions made in advance, not a template you download and file.
  • Two obligations run in parallel: the Security Rule sanction policy (Required, 164.308(a)(1)(ii)(C)) and the Privacy Rule sanctions standard (164.530(e)(1)).
  • Only the Privacy Rule requires you to document the sanctions you actually applied (164.530(e)(2)); the Security Rule has no sanction-documentation specification.
  • The sanctions standard carves out whistleblower and anti-retaliation activity (164.502(j), 164.530(g)(2)); sanctioning protected activity is a violation in its own right.
  • Software cannot make you consistent, but it can make inconsistency visible by recording every sanction against its category and tier.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Make the decisions once, on purpose.

See how WiseUpHIPAA turns a sanctions policy into decisions you attest, freeze, and keep a record of applying.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.