HIPAA Compliance for ABA Therapy Clinics: How to Store Session Videos Securely

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance for ABA Therapy Clinics: How to Store Session Videos Securely

Kevin Henry

HIPAA

August 21, 2026

6 minutes read
Share this article
HIPAA Compliance for ABA Therapy Clinics: How to Store Session Videos Securely

HIPAA Requirements for ABA Clinics

You are a covered entity if your clinic provides care and conducts standard electronic transactions. That status triggers the HIPAA Privacy, Security, and Breach Notification Rules for any session videos containing patient information.

Practically, you must limit uses and disclosures to the minimum necessary, perform a risk analysis, and implement administrative, physical, and technical safeguards. Selecting HIPAA-Compliant Platforms helps you meet these obligations with audited controls and clear configuration options.

Record only what you need, obtain appropriate consents, and document policies for capture, storage, sharing, and deletion. Keep a current inventory of systems, devices, and vendors touching video data.

Defining Protected Health Information

Protected Health Information (PHI) is any individually identifiable health information. A session video becomes PHI when it can identify a client and relates to care, payment, or operations.

  • Identifiers in videos include faces, voices, names on clipboards, home addresses on packages, screen overlays, or distinctive home/school features.
  • Metadata—file names, timestamps, geotags, IP addresses, and caregiver names—can also identify clients.

To treat a video as de-identified, you must remove identifiers so the client cannot reasonably be recognized, or obtain expert determination. True de-identification of audio and video is difficult; assume PHI unless you have formal proof.

Encryption of Session Videos

Encryption In Transit

Protect uploads, streaming, and sharing with strong TLS (for example, TLS 1.2+), mutual authentication where feasible, and certificate pinning on mobile. Disable insecure ciphers and require HTTPS for all endpoints.

Encryption At Rest

Use robust algorithms such as AES-256 and FIPS-validated cryptographic modules where possible. Encrypt primary storage, backups, thumbnails, and logs that could reference video content.

  • Centralize keys in a hardened KMS or HSM, enforce key rotation, separation of duties, and access approval workflows.
  • On mobile devices, enable full-disk encryption, avoid local caching, auto-upload to secure storage, and securely wipe residual files after confirmation.
  • For live sessions, prefer platforms that support E2EE or server-side encryption with strict controls and a signed Business Associate Agreement.

Implementing Access Controls

Apply Role-Based Access Control so each role sees only what it needs: BCBAs for clinical review, RBTs for supervision, and administrators for audits. Tie access to job duties and the minimum necessary principle.

  • Require unique user IDs, MFA, strong passwords, and SSO with conditional access (device posture, location, risk).
  • Enable audit logging for views, downloads, shares, edits, and deletions; review logs routinely.
  • Use time-bound, purpose-specific access (e.g., “break-the-glass” with manager approval) and disable downloads when not required.
  • Automate session timeouts, screen locks, and watermarking to deter unauthorized redistribution.

Review access monthly, immediately revoke access for role changes or departures, and document each review. Train staff to avoid storing PHI on personal devices or unsanctioned apps.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Business Associate Agreements

A Business Associate Agreement is required with any vendor that creates, receives, maintains, or transmits PHI for your clinic. That includes cloud storage, telehealth/video platforms, analytics tools, and transcription services.

  • Define permitted uses, data ownership, Encryption In Transit and Encryption At Rest expectations, and subcontractor flow-down requirements.
  • Set breach reporting timelines, cooperation duties, and evidence preservation for investigations.
  • Address return or destruction of PHI at contract end, secure deletion expectations for backups, and ongoing audit rights.
  • Clarify support for access logs, retention controls, export capabilities, and incident response procedures.

Do not store session videos with any vendor unwilling to sign a BAA and demonstrate security controls that match your risk profile.

Data Retention and Deletion Policies

Create a written Data Retention Policy that specifies how long you keep session videos, where they are stored, and how you delete them. Align it with clinical needs, payer contracts, and your state’s medical record laws.

  • HIPAA does not set a specific retention period for medical records or videos; it does require keeping HIPAA-related documentation for six years.
  • Set adult and minor retention periods that meet or exceed state rules and payer requirements; apply legal holds when necessary.
  • Automate lifecycle rules: retention tags, archive tiers, deletion queues, manager approval, and immutable logs of every action.
  • Use secure deletion (cryptographic erasure or verified overwrite) and document destruction, including for replicas, caches, and backups.

Limit what you record, segregate high-risk content, and avoid using session videos for training or marketing without explicit authorization.

Staff Training for HIPAA Compliance

Provide role-based onboarding and annual refreshers covering PHI handling, secure recording, approved devices, and incident reporting. Reinforce with simulations, spot checks, and documented acknowledgments.

  • Standardize capture: obtain appropriate consents, frame out bystanders, mute unrelated audio, and confirm uploads before leaving a site.
  • Operational hygiene: no personal clouds, encrypted devices only, lock screens, and report loss/theft immediately.
  • Communication: use approved messaging for links and feedback; never paste video URLs into public channels.
  • Supervision: BCBAs coach RBTs on minimum necessary recording and secure sharing for treatment and quality assurance.

Conclusion

When you classify videos as PHI, encrypt them in transit and at rest, control access by role, execute strong BAAs, and follow a clear retention-and-deletion plan, you reduce risk and stay aligned with HIPAA. This overview is informational; consult counsel for state-specific requirements.

FAQs

What constitutes PHI in ABA therapy session videos?

A video is PHI if it can identify a client and relates to care, payment, or operations. Faces, voices, unique home or school features, names on visible items, timestamps, and metadata can all identify a client, making the video PHI.

How should session videos be encrypted under HIPAA?

Use Encryption In Transit with strong TLS (e.g., TLS 1.2+) for uploads, streaming, and sharing, and Encryption At Rest with robust algorithms like AES-256. Manage keys in a secured KMS/HSM, rotate them, restrict access, and encrypt backups and derived assets.

Who can access stored session videos?

Only workforce members and business associates with a legitimate treatment, payment, or operations need should access videos. Enforce Role-Based Access Control, MFA, least privilege, and audit logs, and use time-limited access for exceptional cases.

How long must ABA clinics retain session videos under HIPAA?

HIPAA does not mandate a specific retention period for videos. Set your Data Retention Policy based on clinical need, payer contracts, and state medical record laws, and retain HIPAA-required documentation for six years. Delete securely when the retention period ends and no legal hold applies.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles