HIPAA Compliance Requirements for Speech-Language Pathology Practices
Your speech-language pathology (SLP) practice handles sensitive Protected Health Information, so meeting HIPAA Compliance Requirements for Speech-Language Pathology Practices is non‑negotiable. This guide breaks down what you must do under the HIPAA Privacy Rule and HIPAA Security Rule—from determining covered entity status to telehealth safeguards—so you can protect patients and operate confidently.
Covered Entity Status
You are a covered entity if you are a health care provider who electronically transmits health information in connection with standard transactions (for example, claims, eligibility checks, or remittance). Most solo and group SLP practices that bill electronically fall into this category.
School-based SLPs often work with education records governed by FERPA rather than HIPAA; however, if you bill Medicaid or send standard electronic transactions, those activities can make you a covered entity for that portion of your work. Contract SLPs may also be Business Associates of a covered entity, requiring a Business Associate Agreement.
How to confirm your status
- List all electronic billing and administrative transactions your practice performs.
- Identify clearinghouses, practice management, or EHR vendors used to transmit PHI.
- Document your determination and revisit it when your workflows or payers change.
Develop Privacy Policies
The HIPAA Privacy Rule requires written policies that govern how you use and disclose PHI, ensure “minimum necessary,” and honor patient rights. Designate a privacy officer, define a complaint process, and train your workforce initially and periodically.
Policy essentials to include
- Permitted uses and disclosures for treatment, payment, and health care operations.
- Patient rights: access, amendment, restrictions, confidential communications, and accounting of disclosures.
- Identity verification before releasing PHI and procedures for third‑party requests.
- Marketing, fundraising, and sale-of-PHI restrictions (authorization required where applicable).
- Sanction policy for violations and a process to log, investigate, and mitigate incidents.
Keep policies current, communicate updates to staff, and maintain documentation for at least six years as part of your Risk Analysis Documentation and governance records.
Implement Authorization Forms
HIPAA authorization is required for uses and disclosures of PHI beyond treatment, payment, and operations or when mandated by policy (for example, marketing, testimonials, or releasing session videos to non‑treating third parties). Use a clear, standalone form distinct from consent to treat.
Elements of a valid authorization
- Description of the information to be disclosed and the purpose of the disclosure.
- Who may disclose and who may receive the PHI.
- Expiration date or event, right to revoke, and a statement about potential redisclosure.
- Signature and date of the individual or a personal representative (with authority documented).
- A copy provided to the individual and retention according to your record schedule.
In pediatric care, ensure the signer has legal authority. For recordings of therapy sessions, obtain explicit authorization that covers creation, storage, and any sharing.
Conduct Security Risk Assessment
The HIPAA Security Rule requires an organization‑wide risk analysis of electronic PHI and documented risk management. Your Risk Analysis Documentation must show how you identified threats, evaluated likelihood and impact, and implemented reasonable and appropriate safeguards.
Step-by-step approach
- Inventory systems containing ePHI: EHR, billing, email, telehealth, mobile devices, backups, and cloud storage.
- Map data flows (collection, transmission, storage, access, and disposal).
- Identify threats and vulnerabilities, then rate risk by likelihood and impact.
- Select controls and Encryption Standards appropriate to risk (see below) and assign owners and timelines.
- Implement, test, and monitor; update the analysis after major changes or incidents.
Safeguards to prioritize
- Access controls: unique user IDs, role‑based permissions, automatic logoff, and multi‑factor authentication.
- Audit controls: enable logs for EHR, telehealth, email, and file access; review routinely.
- Integrity and availability: secure backups, tested restores, anti‑malware, and prompt patching.
- Device security: full‑disk encryption, mobile device management, and remote wipe for lost devices.
- Encryption Standards: encrypt data in transit (for example, TLS) and at rest (for example, AES), guided by your risk analysis.
- Incident response: documented procedures for detection, containment, notification, and post‑incident review.
Establish Business Associate Agreements
A Business Associate handles PHI on your behalf. Before sharing PHI, you must execute a Business Associate Agreement that binds the vendor to safeguard PHI and report breaches. Subcontractors of business associates must be bound as well.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Common business associates for SLP practices
- EHR/practice management and billing companies or clearinghouses.
- Telehealth platforms, eFax, secure email, and cloud storage providers.
- IT support, data destruction/shredding, transcription, and appointment reminder services.
What your BAA should cover
- Permitted uses/disclosures, minimum necessary, and prohibition on unauthorized uses.
- Safeguard obligations aligned with the HIPAA Security Rule and breach notification timelines.
- Subcontractor flow‑downs, right to audit/assess, and termination for cause.
- Return or secure destruction of PHI at contract end and cooperation during investigations.
Publish Notice of Privacy Practices
Your Notice of Privacy Practices explains how you use and disclose PHI and the rights patients have under the HIPAA Privacy Rule. Provide it at first service, post it prominently in your office, and make it available on your website.
What to include
- Permitted uses and disclosures, including examples relevant to SLP care.
- Patient rights and how to exercise them (access, amendment, restrictions, confidential communications).
- Your duties, how to file a complaint, and contact information for your privacy officer.
- Effective date, how changes will be communicated, and availability upon request.
Obtain and retain acknowledgment of receipt when feasible, and keep each version of your Notice of Privacy Practices and related documentation for at least six years.
Use Secure Communication Channels
Choose communication tools that protect PHI and align with your risk analysis. Favor secure portals and messaging; if a patient prefers unencrypted email after being advised of risks, document the preference and still limit content to the minimum necessary.
Email, messaging, and portals
- Use services that support Encryption Standards (for example, TLS in transit) and offer a Business Associate Agreement.
- Enable secure patient portals for documents, intake forms, and messaging whenever possible.
- Avoid standard SMS for PHI; if used at a patient’s request, keep messages limited and documented.
Phones, voicemail, and fax/eFax
- Limit voicemail content to minimal identifiers and callback information.
- Use eFax providers that sign BAAs; verify recipient numbers and cover sheets with confidentiality notices.
- Confirm patient contact preferences and alternative addresses as requested.
Device and data protections
- Encrypt laptops and mobile devices; enforce strong passwords and multi‑factor authentication.
- Separate work and personal data; enable automatic lock and remote wipe.
- Retain and dispose of messages and files according to your retention schedule.
Maintain Record Retention
HIPAA requires you to retain privacy, security, and breach‑related documentation (including policies, BAAs, and Risk Analysis Documentation) for at least six years from creation or last effective date. Medical record retention periods are set by state law and payer rules, which may require longer timelines, especially for minors.
Build a practical retention schedule
- Treatment records and billing: follow your state’s medical record laws and relevant payer contracts.
- Authorizations and consents: retain for the longer of state record rules or six years.
- Policies, training logs, BAAs, notices, and risk analyses: retain at least six years.
- Access logs and audit trails: retain as your risk analysis and state rules require.
Secure storage and destruction
- Store PHI in controlled, backed‑up systems; restrict access by role.
- Shred paper and cryptographically wipe or destroy media; obtain certificates of destruction from vendors.
Ensure Telehealth Compliance
Telepractice follows the same HIPAA rules as in‑person care. Use a telehealth platform offering a Business Associate Agreement, strong encryption, and administrative controls, and include telehealth in your risk analysis and policies.
Platform configuration
- Enable waiting rooms, unique meeting IDs, and host controls; require passwords for sessions.
- Use end‑to‑end or strong transport encryption consistent with your Encryption Standards.
- Disable cloud recordings by default; if recordings are clinically necessary, obtain authorization and store securely.
Session workflow
- Verify patient identity, confirm location, and obtain informed consent for telehealth.
- Ensure private spaces on both ends; use headsets and privacy screens when needed.
- Have a contingency plan for technical failures and emergencies.
Understand Penalties for Non-Compliance
HIPAA features a tiered civil penalty structure that scales by level of culpability—from reasonable cause to willful neglect—with per‑violation fines and annual caps. Serious or intentional misuse of PHI can also trigger criminal penalties. Regulatory actions may include corrective action plans and ongoing monitoring.
Beyond federal enforcement, state attorneys general can bring actions, contracts can be terminated, and reputational damage can be significant. Maintaining current policies, training, Business Associate Agreements, and documented risk management materially reduces exposure.
Risk‑reduction checklist
- Complete and update your risk analysis; track mitigation to closure.
- Train all workforce members on the HIPAA Privacy Rule and HIPAA Security Rule.
- Execute and monitor BAAs; stop using vendors unwilling to sign.
- Prepare an incident response and breach notification plan and test it.
Conclusion
By confirming covered entity status, formalizing privacy policies, using valid authorizations, documenting your security risk analysis, executing robust BAAs, publishing your Notice of Privacy Practices, securing communications, retaining records properly, and hardening telehealth, your SLP practice can meet HIPAA requirements with confidence and protect every patient’s Protected Health Information.
FAQs
What defines a covered entity in speech-language pathology?
An SLP is a covered entity when acting as a health care provider that electronically transmits health information in connection with standard transactions such as claims or eligibility checks. Most private practices that bill electronically qualify; school‑based SLPs may be under FERPA, but HIPAA can still apply to specific billing activities.
How should SLPs conduct a HIPAA risk assessment?
Inventory where ePHI lives, map how it flows, identify threats and vulnerabilities, and rate risks by likelihood and impact. Choose and implement safeguards—access controls, audit logs, backups, and Encryption Standards—then document decisions, timelines, and testing. Reassess after technology or workflow changes and retain your Risk Analysis Documentation for at least six years.
When are authorization forms required?
Use HIPAA authorization when a disclosure isn’t for treatment, payment, or health care operations—for example, testimonials or marketing, sharing session videos with third parties not involved in care, research without a waiver, or other non‑routine disclosures. Authorizations must contain all required elements and be retained per your record schedule.
What are the penalties for HIPAA violations in SLP practices?
Penalties range from tiered civil fines that increase with negligence to potential criminal liability for intentional misuse of PHI. Enforcement can also require corrective action plans and monitoring, while state authorities and payers may impose additional consequences. Strong policies, training, BAAs, and timely incident response reduce risk significantly.
Table of Contents
- Covered Entity Status
- Develop Privacy Policies
- Implement Authorization Forms
- Conduct Security Risk Assessment
- Establish Business Associate Agreements
- Publish Notice of Privacy Practices
- Use Secure Communication Channels
- Maintain Record Retention
- Ensure Telehealth Compliance
- Understand Penalties for Non-Compliance
- FAQs
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.