Your employee can legally take PHI to a lawyer, and it is not your breach

HIPAA contains a whistleblower provision most clinic owners have never read. What 45 CFR 164.502(j) actually permits, who whistleblowers turn out to be in an ABA clinic, why they do it, and the one fact that should change how you run your internal channel.

Last verified: 2026-07-14

An RBT believes a supervisor is documenting sessions that did not happen. She is not sure. She is worried about her job, and she is worried about the client.

If she takes what she has, including client records, to an attorney, has she committed a HIPAA violation? Have you?

The answer is in a provision most clinic owners have never read, and the second half of it surprises people more than the first.

What the rule actually says

45 CFR 164.502(j)(1) is titled Disclosures by whistleblowers. Read closely, because the sentence is constructed carefully:

A covered entity is not considered to have violated the Privacy Rule if a member of its workforce or a business associate discloses protected health information, provided two conditions are met.

One, the belief. The person believes in good faith that the covered entity has engaged in conduct that is unlawful or otherwise violates professional or clinical standards, or that the care, services, or conditions the entity provides potentially endanger one or more patients, workers, or the public.

Two, the recipient. The disclosure goes to a health oversight agency or public health authority authorized to investigate or oversee the relevant conduct, or to an appropriate health care accreditation organization, for the purpose of reporting the allegation. Or it goes to an attorney the workforce member retained to determine their own legal options.

That is the whole provision, and three things in it are worth sitting with.

It protects you, not them. The clause is written from the covered entity’s side: you have not violated the rule because of what they disclosed. HIPAA does not give employees a right here so much as it removes your liability for their disclosure, which means the reflex of treating a whistleblower’s disclosure as a reportable breach by your clinic is usually wrong.

Good faith, not correctness. The test is what the person reasonably believed, not whether the allegation turns out to be true. An employee who is sincerely wrong is still inside the provision. You do not get to decide afterward that they were mistaken and therefore in violation.

An attorney counts as a recipient. This is the part that lands hardest. Your employee may take client information to a lawyer for the purpose of working out what their own options are, and the rule specifically contemplates it.

The permitted list is also genuinely narrow, and worth knowing from the other direction. It does not include the press. It does not include social media. It does not include a competitor, a parent, or a Facebook group. A workforce member who posts client information publicly is outside this provision entirely, no matter how justified their underlying concern.

The other half of the section

The same paragraph contains a second, smaller provision people miss. Under 45 CFR 164.502(j)(2), a workforce member who is the victim of a criminal act may disclose protected health information about the suspected perpetrator to a law enforcement official, limited to the identifying information listed at 45 CFR 164.512(f)(2)(i).

In practice this is the RBT who is assaulted during a session and needs to file a police report. She is not committing a violation by naming who did it, and your clinic is not either. Clinicians in this field hesitate over exactly this, and the hesitation is unnecessary.

Who whistleblowers actually are

The word conjures somebody dramatic. In a small clinic it is almost always one of four ordinary people.

The employee who raised it internally and watched nothing happen. By a wide margin the most common. They told a supervisor, or the owner, or filled in whatever passes for a complaint process, and the thing continued. Every week of silence converts a concerned employee into a documenting one.

The employee who raised it and was punished. Sometimes overtly, more often through a schedule change, a lost caseload, or a sudden performance conversation. This person now has two grievances, and retaliation is itself a separate violation (45 CFR 164.530(g), 45 CFR 160.316).

The employee who left. Distance clarifies. People who said nothing while employed frequently say something after, particularly if the exit was unpleasant, and in a field with turnover as high as ABA that population grows every quarter. They are also, statistically, how most OCR files actually open: complaints, not audits.

The one who never worked for you. A parent, a school staff member, a business associate’s employee. The whistleblower provision reaches business associates too, which means your billing company’s staff sit inside it.

Why they do it

Three reasons, and the order matters because it tells you which one you can actually influence.

Because they think something is genuinely wrong, and no one internally would deal with it. This is the dominant motive and it is not complicated. People generally want the problem fixed, not the clinic punished, and they escalate when fixing stops looking possible.

Because they are protecting themselves. An employee who has watched something questionable often reasons that if it ever surfaces, silence will look like participation. Reporting becomes self-defense, and the attorney route in 164.502(j)(1)(ii)(B) exists precisely for the person trying to work out where they stand.

Because of money, in one specific circumstance. If the concern involves billing a government program, a different body of law takes over. The False Claims Act allows a private individual to bring an action on the government’s behalf and receive a share of any recovery (31 U.S.C. 3730). For an ABA clinic billing Medicaid, that is not a HIPAA question at all, and it is a far larger financial exposure than a privacy complaint. Documentation that does not match services delivered is where these cases start.

What this means for how you run the clinic

The uncomfortable insight is in the sequencing. Almost nobody’s first move is a federal agency. The whistleblower provision is not aimed at disloyal employees. It exists because the internal path failed, and it sits in the text because the drafters assumed it sometimes would.

Which reframes what you actually control:

“The whistleblower provision is not aimed at disloyal employees. It exists because the internal path failed, and it sits in the text because the drafters assumed it sometimes would”

Give concerns somewhere to go. The OIG’s compliance guidance asks for at least one reporting path that allows anonymous reporting and sits outside the ordinary chain of command, precisely so a concern about a supervisor does not have to be delivered to that supervisor. How a real channel works, and the trap most clinics miss.

Close the loop. The single most reliable way to turn an internal reporter into an external one is silence. They do not need to be told everything. They need to know somebody looked.

Do not retaliate, and do not let it happen by accident. Overt retaliation is rare; a write-up two weeks after a report, from a manager who had no idea, is common. That is still a problem, and it is the one that turns a resolvable complaint into a case with a sympathetic plaintiff.

Fix the thing. Every provision on this page is procedural. None of it addresses the underlying question of whether the person was right. If they were, the compliance exposure is the smaller half of your problem.

The short version

Your employee may lawfully disclose protected health information to a regulator or to their own attorney if they believe in good faith something is wrong, and your clinic has not violated HIPAA when they do. You cannot contract that away, and you should not want to.

What you can do is make sure that by the time anyone considers it, they have already been heard.

The short version

  • 45 CFR 164.502(j) says a covered entity has not violated the Privacy Rule when a workforce member discloses PHI as a whistleblower. It is a safe harbor for you, not a permission slip they need from you.
  • The permitted recipients are narrow: a health oversight agency, a public health authority, an accreditation organization, or an attorney the employee retained to assess their own options.
  • The test is good faith belief in unlawful conduct, a violation of professional or clinical standards, or conditions that potentially endanger patients, workers, or the public. It does not require them to be right.
  • A separate provision lets a workforce member who is the victim of a crime give law enforcement limited information about the suspected perpetrator.
  • Most whistleblowers raised it internally first. The provision is a symptom of a channel that did not work, which makes your internal channel the real control.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

The channel is the control.

Almost every external report started as an internal concern that went nowhere. WiseUpHIPAA builds the reporting channel as real software, with the modes, the record, and the retaliation check, so the concern gets resolved while it is still yours to resolve.