Three HIPAA Questions ABA Leaders Ask the Privacy Rule That Only the Security Rule Answers
Sep 03, 2026
During a recent webinar for ABA leaders, Rose and I spent most of an hour inside the HIPAA Privacy Rule. The audience wanted to know what a family can request, what an agency has to hand over, and how quickly. Good questions, and the Privacy Rule answers every one of them.
Then the questions shifted. Where should session notes live? Who in the agency should have access to the practice management system? What happens when a technician's phone goes missing?
Each one arrived framed as a privacy question. Each one gets its answer from the HIPAA Security Rule instead. The mislabel matters, because an agency that files these questions under privacy tends to answer them with a privacy tool, such as a confidentiality policy or a staff reminder, when the rule calls for a control: a system setting, a written procedure, or a documented decision.
What separates the Privacy Rule from the Security Rule?
The Privacy Rule (45 CFR Part 164, Subpart E) governs uses and disclosures of protected health information (PHI) in any form: what you may share, with whom, and which rights the individual holds. The Security Rule (Subpart C) governs how you protect electronic PHI (ePHI) against unauthorized access, alteration, and loss. It requires administrative, physical, and technical safeguards, and it requires you to document the reasoning behind each one.
A shorthand that holds up: the Privacy Rule tells you what may happen to the information. The Security Rule tells you how to make sure nothing else happens to it.
Where should session notes live?
The Security Rule names no approved location. It requires you to know every place ePHI lives and to protect each one. The risk analysis standard (45 CFR 164.308(a)(1)(ii)(A)) requires an accurate and thorough assessment of the risks to ePHI your agency creates, receives, maintains, or transmits. You can't assess a location you haven't inventoried.
For an ABA agency, session notes tend to spread. A data collection app, a practice management system, a technician's notes app, a supervisor's laptop, and an email thread where a draft went out for review all count as locations. The question "where should notes live" turns into "where do notes live now, and which of those locations have controls we chose on purpose."
The practical answer: decide which systems may hold session notes, write that decision down as policy, and treat any other location as a gap to close. Our post on behavior analysts working from home covers the remote-work version of this problem.
Who should have access to the practice management system?
Three linked Security Rule standards answer this. Workforce security (164.308(a)(3)) requires procedures that limit ePHI to the workforce members who need it and end that access when someone leaves. Information access management (164.308(a)(4)) requires policies for authorizing and granting access. Access control (164.312(a)) covers the technical side: a unique user identification for every person, plus a documented decision on automatic logoff and encryption.
Many practice management systems ship with a few role templates and a habit of leaving administrative rights with whoever set the system up. The rule expects your agency to decide who needs what, grant that much, review it, and remove it at offboarding. The Privacy Rule's minimum necessary standard (164.502(b)) points the same direction, which explains why the question feels like a privacy question. The Security Rule supplies the machinery.
What happens when a technician's phone goes missing?
Two Security Rule standards settle how bad a lost phone gets long before the phone disappears. Device and media controls (164.310(d)(1)) require policies covering the receipt, removal, and disposal of hardware and electronic media that hold ePHI. Encryption sits in the technical safeguards as an addressable specification (164.312(a)(2)(iv)), which means your agency must implement it or document why an equivalent alternative measure protects ePHI as well.
Encryption carries a second consequence. The breach notification rule defines unsecured PHI as PHI not rendered unusable, unreadable, or indecipherable through a method HHS has specified (164.402), and HHS guidance names encryption as that method. A lost phone with a passcode, full-device encryption, and a remote wipe becomes a security incident to log and review. A lost phone with session data in an unencrypted notes app becomes a breach risk assessment and, quite possibly, notification letters to families. Our breach reportability post walks through that assessment.
Both paths depend on knowing the phone held ePHI in the first place, which loops back to the first question.
Why the mislabel costs something
If a leader hears "who has access" as a privacy question, the answer tends to come out as a confidentiality policy and an annual reminder. Those matter, and the Privacy Rule requires them. The Security Rule asks for something a reminder can't deliver: a documented risk analysis, a written decision on each addressable specification, and evidence that the control exists. The documentation standard (164.316) requires you to keep those records for six years from creation or last effective date.
In an audit or an investigation by the HHS Office for Civil Rights, the question rarely reads "did your staff know to be careful." It reads "show me the risk analysis and the policies it produced." A confidentiality reminder can't answer that request.
Check your state's law
HIPAA sets a floor. Several states impose their own data security and breach notification requirements on health information, including shorter notice deadlines and their own definitions of what counts as secured data. Your agency's device, access, and breach procedures likely need to satisfy the stricter of the two, so confirm your state's requirements before you finalize any of them.
Frequently asked questions
Does HIPAA require ABA agencies to encrypt phones and laptops? No, not in those words. Encryption remains an addressable specification, so your agency must implement it or document why an equivalent alternative protects ePHI as well. For an agency with staff carrying devices into homes, encryption tends to end up as the reasonable choice, and it keeps a lost device out of breach notification.
Is a lost work phone a HIPAA breach? No, not automatically. If the device carried ePHI encrypted to the HHS standard and can't be accessed, the loss counts as a security incident to document rather than a breach. If the ePHI sat unencrypted, your agency owes a breach risk assessment, and notification may follow.
Can a BCBA keep session notes in a personal notes app? No, not unless your agency has designated that app as an approved location and applied controls to it. Every place ePHI lives falls within the required risk analysis, and an undesignated app rarely has the access controls, encryption, or backup the Security Rule expects.
Does the Privacy Rule or the Security Rule decide who can see the practice management system? Both. The Privacy Rule's minimum necessary standard sets the principle that access should match the job. The Security Rule's workforce security, information access management, and access control standards supply the specific procedures and technical settings that enforce it.
Where to start
Most ABA leaders asking these questions already run reasonable agencies. They just learned HIPAA as a privacy topic, because that's how the training modules teach it, and the Security Rule never got equal time.
If you'd like to see how your agency's safeguards measure up, we built a free 49-item cyber-readiness self-evaluation adapted from HICP Technical Volume 1, the federal cybersecurity guidance written for small healthcare organizations. We rewrote it for how ABA agencies operate, so it covers telehealth platforms, data collection apps, parent texting, and session recordings. Each item explains the practice in plain language, describes full implementation, and gives an example of doing it almost right. A scoring workbook totals your readiness by practice area so you can see where to begin.
Start with the three questions above. Most agencies can answer them today, and the remaining work involves writing those answers down as policy and confirming that the controls behind them exist.
Stay connected with news and updates!
Join our mailing list to receive the latest news and updates from our team.
Don't worry. We won't share your information.
We hate SPAM. We'll never sell your information.