Integrity: the standard almost everyone skips

45 CFR 164.312(c) protects ePHI from improper alteration or destruction. In ABA, a silently altered session note or a data collection app that drops trials is not just a compliance failure, it changes a child's programming.

Last verified: 2026-09-08

Most of the Security Rule gets skipped through neglect. Integrity gets skipped through invisibility. Nothing breaks the day you ignore it. There is no locked door left open, no unencrypted laptop, no shared login. The failure here does not announce itself. It just means that at some point, nobody can say for certain whether the data in front of them is the data that was actually recorded.

What the rule actually requires

Integrity is a Required standard: implement policies and procedures to protect electronic protected health information from improper alteration or destruction (45 CFR 164.312(c)(1)).

It carries one implementation specification, Addressable: a mechanism to authenticate ePHI, meaning electronic procedures to corroborate that ePHI has not been altered or destroyed in an unauthorized manner (164.312(c)(2)). Addressable does not mean skippable, it means you assess whether the measure is reasonable for your systems, then implement it or document a genuine alternative.

Where access control and audit controls are about who gets in and who did what, integrity is about something narrower and easy to overlook: whether the data itself can be trusted once it’s there.

Why ABA makes this concrete instead of abstract

In a lot of covered entities, integrity is a fairly abstract concern. In ABA, it is not. Session notes and data collection drive clinical decisions in near real time. A data collection app that silently drops trials during a sync, a session note edited after the fact with no record of the change, a progress report generated from data nobody can verify is complete, these are not hypothetical edge cases. They are the specific way this standard fails in this field.

“A session note edited after the fact with no trace is not just a compliance failure. The child's programming is driven by that data.”

A session note edited after the fact with no trace is not only a compliance failure. The child’s programming is driven by that data. An integrity failure here can change what a clinician decides to do next, not just what an auditor finds later.

What a real answer looks like, next to what most clinics have

What the rule requires What most clinics actually have
Edit visibility Changes are tracked: who changed what, and what it was before Records can be edited with no trace of the prior version
Sync reliability Data collection is verified complete Trials or sessions silently drop with nothing flagging the gap
Backups Backups are verified restorable Backups exist, but nobody has tried to restore from one
Awareness The clinic knows this standard exists Most clinics have never assessed it at all

The gap in the last row is the real story. Facility access controls and encryption get attention because their absence is visible. Integrity gets skipped quietly because its absence is invisible, right up until someone needs to know whether a record is trustworthy and discovers there is no way to check.

What this looks like in practice

There is no prescribed method, only the outcome the rule requires. In practice this usually means: version history on clinical records, so a prior state can be recovered. An edit trail that records who changed what and what it replaced. Integrity checks on backups. A restore that has actually been performed at least once, not merely assumed to work because a backup job runs on schedule.

The short version

  • Integrity (164.312(c)(1)) requires policies and procedures to protect ePHI from improper alteration or destruction.
  • The mechanism to authenticate ePHI (164.312(c)(2)) is Addressable: an electronic way to confirm data has not been altered or destroyed without authorization.
  • This is the quietest standard in the Security Rule and the one most clinics skip entirely, because nothing announces the failure.
  • In ABA, integrity failures are not only compliance failures. A session note edited without a trace, or a data collection app that silently drops trials, changes the record a child's programming is built on.
  • In practice this means version history, an edit trail showing who changed what and what it was before, and a restore that has actually been tested, not assumed to work.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

A record of what changed, and who changed it.

WiseUpHIPAA keeps an edit trail on the records that matter, so alteration is visible instead of silent. Not a hope that nothing was changed. Evidence either way.

Ready to get your HIPAA program in order?

No pressure, no pitch. Book a 20-minute call, or just email a question and we'll point you the right way.