HIPAA WORKFORCE TRAINING
The HIPAA Policy Checklist for ABA Agencies
HIPAA doesn't just ask you to have policies. It asks you to train your workforce on your policies, tailored to what each person actually does. That starts with knowing which policies you need.
Get the full list of the written policies HIPAA expects your agency to have, triaged into where to start and what comes next.
Get the checklist
Enter your details and it's yours instantly.
We'll also send occasional compliance resources. Unsubscribe anytime.
WHAT THE RULE ACTUALLY REQUIRES
The training you're doing may not be the training HIPAA asks for.
Most ABA agencies run a generic HIPAA awareness course once at hire and once a year. It teaches the law in the abstract: what PHI is, why privacy matters, what a breach looks like in general.
That's not what the regulation actually requires. HIPAA expects you to train your workforce on your agency's own policies and procedures, tailored to each person's job duties, and to retrain after material changes. An RBT and a biller shouldn't get the same training, because they don't touch information the same way.
Generic training can be complete, current, and well-produced, and still miss the mark, because it was never about your agency in the first place.
IF YOU'RE THINKING "WE'VE GOT THIS COVERED"
Two reassurances worth a second look.
"We do annual HIPAA training already."
Completing a course isn't the same as being trained on your own policies. If the training never referenced how your agency handles records, devices, or minimum necessary, it didn't meet the standard, no matter how many staff clicked through it.
"Our software vendor handles HIPAA."
A "HIPAA-compliant" platform protects the data it holds. It doesn't write your policies, train your people on them, or document that training. Those obligations stay with you, and they're exactly what an auditor asks to see.
WHAT'S INSIDE THE CHECKLIST
Every policy, triaged so you know where to start.
The checklist lays out 30 written policies HIPAA expects an ABA agency to have, split into two tiers so a full slate of requirements motivates you instead of burying you:
Start Here — the foundation. The must-have policies your program stands on, each with a plain-language description of what it should cover.
Next Steps — the rest of a defensible program, to work through once the foundation holds.
Each item names the policy and describes what it should address, and the list flags where something is good practice rather than a strict HIPAA requirement, so you always know what's mandatory and what's smart.
WHERE AGENCIES BUILD THIS
Reading the list is the easy part. Building it is where agencies stall.
Every policy on the checklist has to say how your agency operates. Then your workforce has to be trained on it. Then it all has to hold up if you're ever asked to prove it. That's a lot to carry alone, and it's exactly why we built the ABA Compliance Collective.
Inside the Collective you get policy-builder tools created by experts in ABA and compliance, so you customize a defensible starting point instead of staring at a blank page. You get the training pieces that turn a policy on paper into a workforce that actually knows it. And you get direct access to Michael and Rose, alongside ABA leaders working the same problems.
$3,497/year or $350/month. Join today and stop starting from scratch.
EXPLORE THE COLLECTIVENOT SURE WHERE YOU STAND?
Get a personalized read on your compliance posture in about three minutes.
GET THE CHECKLIST
Start with the list. Build from there.
Know exactly which written policies HIPAA expects your ABA agency to have, and where to begin.
GET THE CHECKLIST