HIPAA questions ABA clinics actually ask
Thirty-two straight answers, each with the citation behind it, each linking to the page that goes deeper. The questions clinic owners ask us, answered honestly, including the ones where the answer is no.
Last verified: 2026-07-12
Every question below is one an ABA clinic owner has actually asked. The answers are short and cited; each links to the page that carries the reasoning.
A word about the shape of these answers before you start. The most useful answers on this page are the ones that tell you to stop worrying about something, and there are more of those than you expect. HIPAA causes a great deal of unnecessary fear, and fear makes clinicians hesitate at exactly the moments they should act.
Does HIPAA even apply to us
Is my ABA clinic a covered entity? If you transmit health information electronically in connection with a covered transaction, yes, and you have been since the first time it happened. Submitting a claim, checking eligibility, or requesting an authorization electronically all count, and typing into a payer portal counts. The full test.
“The most useful answers on this page are the ones that tell you to stop worrying about something, and there are more of those than you expect”
We are cash-pay only and never bill insurance. Are we exempt? Possibly, genuinely. If you conduct none of the covered transactions electronically, you are not a covered entity. But you are one portal login or one Medicaid client away from a different answer, and state law and payer contracts still reach you. The honest version.
Our billing company submits the claims, not us. Does that help? No. Outsourcing the typing does not outsource the status. A provider whose claims are transmitted electronically on its behalf is a covered entity.
Does HIPAA apply to us in a school? It depends on whose record it is, not where the session happened. Your own clinical record about your own client stays yours under HIPAA. Records you create for a district about its students can be FERPA education records instead. The distinction, and its limits.
Records and parents
Can a parent demand a copy of their child’s session notes? Almost always yes. The parent is generally the personal representative, session notes sit in the designated record set, and you have 30 days (45 CFR 164.524). The right of access.
Are ABA session notes psychotherapy notes? Almost never. The definition excludes session times, modalities, test results, and summaries of treatment plan, symptoms, functional status, and progress (45 CFR 164.501). Nearly everything an ABA clinic writes is excluded. Withholding notes from a parent on that basis is a right-of-access violation, not a protection.
Can we charge a parent for records? A reasonable, cost-based fee for copying labor, supplies, and postage. Never a retrieval or search fee (45 CFR 164.524(c)(4)).
A divorced parent wants records and the other objects. What do we do? Both parents are usually personal representatives and both usually have access. That can change with a court order, and state law governs the details. What matters operationally is that you can actually implement whatever the answer is, which requires individual logins rather than a household password. The parent portal problem.
Do we need parental consent to talk to another treating provider? No. Disclosures for treatment are permitted without authorization (45 CFR 164.506). Clinics hesitate over this constantly and the hesitation harms clients.
Can we send session data to the school? Not without authorization, in the ordinary case. The school is not treating your client, so this is not a treatment disclosure. Get a written authorization (45 CFR 164.508); parents almost always want the school and clinic talking, so it is easy to obtain and routinely forgotten.
Devices, apps, and vendors
Can RBTs use their personal phones? Yes, if you govern it. A personal phone that touches ePHI is a workstation regardless of who owns it. The camera roll is the real hazard: a session photo syncs to a personal cloud account with no BAA behind it, automatically. Three honest options.
Do we need a BAA with our practice management vendor? Our cloud storage? Our AI notetaker? Yes, yes, and yes. Anyone outside your workforce who creates, receives, maintains, or transmits PHI for you is a business associate. Storage counts even if the vendor cannot read the data. The vendor walkthrough.
Our vendor says they are HIPAA compliant. Is that enough? No. That is a marketing claim about the product. The signed BAA is the legal instrument, and without one, every disclosure to that vendor is a violation.
Can we use ChatGPT or a consumer AI assistant for notes? Not with PHI. Consumer AI tiers generally will not sign a BAA, and that refusal is the vendor telling you PHI does not belong in their product. Even with a BAA, ask whether they train on your data; a BAA cannot authorize model training on client PHI. The AI notetaker.
Is texting a parent a HIPAA violation? Not automatically, but it is a transmission of ePHI, and consumer messaging has no BAA behind it and leaves the message resting on two phones and a carrier. Use a covered channel where you can.
Can we record sessions? Yes, with written parental consent, and the recording must land in a BAA-covered system, never a camera roll or a personal cloud folder. Recordings cannot be de-identified: a face and a voice are both listed identifiers. Where recordings actually go.
Security requirements
Does HIPAA require encryption? Not by name. It is an addressable specification, which means you must assess it and either implement it or document why not and do something equivalent (45 CFR 164.306(d)(3)). For devices that ride into family homes, the honest assessment nearly always ends in yes.
Does HIPAA require multi-factor authentication? No, not in the current rule. But if your risk analysis identifies credential theft as a likely risk, and it will, then required risk management makes MFA very hard to honestly decline. The proposed rule would mandate it. The honest version.
Does addressable mean optional? No. It means assess it, then either implement it, or document why it is not reasonable and appropriate and implement an equivalent alternative. Doing nothing and writing nothing is not one of the options. The full explanation, with a table.
Can staff share a login? No. Unique user identification is required, not addressable (45 CFR 164.312(a)(2)(i)). It is the one place in the technical safeguards with no judgment call in it.
How long do we have to keep audit logs? The Security Rule does not set a retention period for audit logs. The six-year rule applies to required documentation, including the record of the activity reviews you performed. Your own policy sets your log retention, and OCR will hold you to the policy you wrote.
Breaches
A tablet went missing. Is that a breach? If it was encrypted properly and the passcode did not travel with it, generally no: the data was not unsecured PHI and the notification machinery does not fire. If it was not encrypted, it is presumed a breach unless a documented four-factor assessment honestly shows a low probability of compromise. The day it happens.
We faxed to the wrong number. What now? Call the recipient, ask for written confirmation the fax was destroyed, and document everything with times. That confirmation is your strongest evidence in the four-factor assessment. The first hour.
How long do we have to notify? Individuals: without unreasonable delay and no later than 60 days from discovery. Discovery runs on what your organization knew or should have known (45 CFR 164.404). HHS: at the same time if 500 or more are affected, otherwise in an annual log.
Do we have to report small breaches? Yes. Fewer than 500 individuals means it goes in a log submitted to HHS within 60 days after the calendar year ends. It is not optional; it is just on a different schedule.
Should we log incidents that turn out to be nothing? Yes, and this surprises people. An empty incident log does not read as a clean clinic. It reads as a clinic that never looked. Why the rule is built that way.
Program and enforcement
Is an online HIPAA training certificate enough? No. There are two training requirements, and both are about your policies: privacy training at hire and after material changes (45 CFR 164.530(b)), and a security awareness program for everyone including management (45 CFR 164.308(a)(5)). A generic course cannot teach your policies. What counts.
Is HIPAA training required annually? The word annually does not appear in the requirement. It is a hiring trigger and a material-change trigger. Annual is a reasonable practice on top, not a substitute.
What is the first thing OCR asks for? Your risk analysis. Its absence is the most cited finding in Security Rule enforcement, and it is read as proof the program was never real. Why it decides everything.
Are we too small for OCR to care? No. OCR scales the penalty to the organization; it does not skip the organization. A software vendor settled for $10,000 in 2026, with OCR explicitly noting it considered the entity’s financial condition, and attached three years of monitoring. The settlements, read honestly.
We found a problem. Are we better off hiding it? No, and the regulation is unusually generous here: no penalty may be imposed for a violation that is not willful neglect and is corrected within 30 days of when you knew or should have known (45 CFR 160.410(b)). Finding and fixing your own problems is a defense written into the rule. How an investigation works.
Can HIPAA stop us from reporting suspected child abuse? No. The Privacy Rule explicitly permits disclosures for abuse reporting (45 CFR 164.512(b) and (c)). No clinician should ever hesitate over a mandated report because of HIPAA. Say that plainly in your training.
Is the Security Rule changing? A substantial rewrite was proposed in January 2025 and is not law. No final rule has issued, and the federal agenda now shows final action in July 2027. Meanwhile OCR enforces the rule that exists. What is changing, and when.
Does software make us HIPAA compliant? No, and any vendor who says otherwise is telling you something useful about themselves. There is no such thing as HIPAA certification. Software can make the work tractable and keep the evidence current. The program is still yours to run.
The short version
- Many common HIPAA fears are unfounded: reporting suspected abuse, coordinating with another treating provider, and incidental overhearing are all permitted.
- Several common beliefs are wrong in the dangerous direction: session notes are not psychotherapy notes, addressable is not optional, and an annual training video is not the requirement.
- The answers here are short by design; each one links to the page that carries the full reasoning and the citations.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Definitions, general45 CFR 160.103https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- Security standards: General rules45 CFR 164.306https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.306
- Administrative safeguards45 CFR 164.308https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- Technical safeguards45 CFR 164.312https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
- Uses and disclosures: general rules45 CFR 164.502https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- Definitions, Privacy Rule, including psychotherapy notes45 CFR 164.501https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.501
- Access of individuals to protected health information45 CFR 164.524https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.524
- Definitions, including breach and unsecured PHI45 CFR 164.402https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402
- Uses and disclosures for which an authorization is not required45 CFR 164.512https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.512
- Administrative requirements, including training and sanctions45 CFR 164.530https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
Straight answers, and an honest picture of your own.
These are the questions everyone asks. The one that matters is where your clinic actually stands. WiseUpHIPAA computes that from what is really there, including the parts that are red.