Compliance & Telehealth

The HIPAA Checklist for Solo Dietitians: Minimum Viable Compliance

A realistic HIPAA checklist for solo registered dietitians: BAAs, the annual risk assessment, device security, breach basics, and a printable 15-item list.

HIPAA guidance is written for hospitals with compliance departments. You are one person with a laptop, a caseload, and maybe three hours a month for administrative work that doesn't bill. So most solo RDs land in one of two bad places: ignoring HIPAA entirely ("I'm too small to matter") or losing sleep over an imagined standard no solo practice actually meets.

Both are wrong. The moment you bill insurance electronically — submit a claim, run an eligibility check, receive an ERA — you're a covered entity, full stop. There is no small-practice exemption. But compliance for a practice of one is genuinely achievable in a weekend of setup plus a few hours a year of maintenance.

Here's the minimum viable version: what the rules actually require, translated to a solo practice, ending with a printable 15-item checklist.

You're a covered entity. Here's what that means

HIPAA has three operative rules for you:

Rule What it governs Solo-practice translation
Privacy Rule Who can see and receive PHI Notice of Privacy Practices, patient access rights, minimum-necessary sharing
Security Rule How electronic PHI is protected Risk assessment, device security, access controls, vendor BAAs
Breach Notification Rule What happens when PHI is exposed Notify affected patients (and HHS) on defined timelines

PHI is broader than clinical notes: names attached to appointment times, intake forms, claim files, session recordings, even the email thread where a client mentions her A1c. If it identifies a patient and relates to their health or payment for care, treat it as PHI.

BAAs: the vendor paper trail

A business associate agreement (BAA) is a contract making your vendor legally responsible for protecting the PHI it handles for you. You need one with every vendor that touches PHI:

Free consumer tiers usually won't sign one — standard free Gmail is the classic trap; the paid workspace tier with a BAA is fine. Walk your whole stack once and record the date of each BAA; the full vendor-by-vendor breakdown is in our HIPAA-compliant tool stack guide.

The risk assessment (yes, annually, yes, you)

The Security Rule requires a risk analysis — an honest inventory of where ePHI lives, what could go wrong, and what you're doing about it. It's the single most cited gap when regulators investigate small practices.

The solo version is not a 90-page document. HHS publishes a free Security Risk Assessment (SRA) tool designed for small practices; working through it takes an afternoon. The output — identified risks, your fixes, the date — is your documentation. Repeat at least annually and whenever your stack changes.

Policies you actually need written

You don't need a hospital's policy binder. You do need a short written version of:

  1. Privacy policy / Notice of Privacy Practices — given to every patient at intake.
  2. Security policy — how devices, passwords, and access are handled (a page or two).
  3. Breach response procedure — the steps you'd follow, written before you need them.
  4. Sanction policy — trivially short when the workforce is you, but required; it matters the day you hire.
  5. Record retention schedule — HIPAA documentation must be kept six years; clinical record retention follows state law (often longer).

"Written" means a document you could hand an investigator, dated and revisited annually.

Device security basics

Most solo-practice exposure is a lost laptop or phone, not a hacker:

Breach basics

A breach is an impermissible use or disclosure of PHI — a misdirected email with an intake form, a stolen unencrypted phone, a vendor incident. If it happens: contain, assess, document. Affected individuals must generally be notified without unreasonable delay, at most 60 days. Under 500 people affected: log it and report to HHS annually. 500+: 60-day HHS notification plus media notice — and, realistically, a lawyer. The documented risk assessment and encryption you set up above are exactly what turn "incident" into "non-event."

Patient right of access

Patients have the right to copies of their records — generally within 30 days of the request (one 30-day extension is possible), in the form they ask for when readily producible, for at most a reasonable cost-based fee. Some states are stricter on timelines and fees, so verify your state's rules. Slow-walking records requests is one of the most actively enforced HIPAA provisions, including against small practices. Build a simple habit: request in writing, fulfill fast, note the date.

Train yourself, and write it down

Workforce training is required even when the workforce is one person. Take a short HIPAA training annually (inexpensive online courses are fine), keep the certificate, and note the date in your compliance folder. Undocumented training is, to an investigator, no training.

The violations solo RDs actually commit

Notice none of these are exotic. They're defaults you have to consciously replace.

The printable 15-item checklist

  1. Confirm covered-entity status (you bill electronically → yes)
  2. Inventory every place PHI lives (devices, apps, drawers)
  3. BAA signed with every PHI-touching vendor
  4. Replace any free-tier tool that won't sign a BAA
  5. Complete the HHS SRA tool; save the output
  6. Full-disk encryption on all devices
  7. Screen locks + auto-timeout everywhere
  8. Password manager + 2FA on EHR, email, clearinghouse
  9. Notice of Privacy Practices given at intake
  10. Written security policy + breach procedure + sanction policy
  11. No PHI in personal SMS or consumer apps
  12. Records-request workflow (30-day clock)
  13. Annual HIPAA training, certificate saved
  14. Six-year retention system for compliance docs
  15. Calendar reminder: repeat risk assessment and review annually

Print it, work through it once, then it's an annual afternoon. That's minimum viable compliance — real protection, not performative paperwork.

How Alva helps: Alva consolidates the riskiest parts of a solo stack — intake forms, session recordings, charting, claims, and payment posting — into one HIPAA-compliant platform with a BAA, which means fewer vendors to vet and fewer places PHI can leak. One tool, one agreement, $99/month. Start a 7-day free trial.

Frequently asked questions

Does HIPAA apply to a solo dietitian in private practice?

Almost certainly yes. If you transmit health information electronically in connection with billing — submitting insurance claims, checking eligibility, receiving electronic remittances — you are a covered entity under HIPAA, regardless of practice size. A purely cash-pay practice that never bills electronically may fall outside the definition, but state privacy laws and professional ethics still apply.

Do I need a BAA with every software vendor I use?

You need a business associate agreement with every vendor that creates, receives, stores, or transmits protected health information on your behalf — your EHR or practice platform, clearinghouse, email provider if PHI touches it, cloud storage, scheduling tool, and any AI scribe. Vendors that never touch PHI, like your accounting software, do not need one.

Is a HIPAA risk assessment really required for a practice of one?

Yes. The Security Rule requires a risk analysis and it applies to covered entities of every size. For a solo practice it can be proportionate — HHS publishes a free Security Risk Assessment tool aimed at small practices. Do it, fix what it surfaces, document it, and repeat it at least annually.

Can I text my clients about their appointments?

Appointment logistics with minimal detail are generally considered acceptable if the client has agreed to receive texts, but clinical content over standard SMS is a common violation because SMS is unencrypted. Keep texts to scheduling, get consent in your intake paperwork, and move anything clinical to a secure portal or encrypted channel.

What do I do if I have a HIPAA breach in my solo practice?

Contain it, assess what information was exposed and to whom, and document everything. Affected individuals must generally be notified without unreasonable delay and within 60 days. Breaches affecting fewer than 500 people are reported to HHS annually; 500 or more triggers notification within 60 days plus media notice. When in doubt, consult a healthcare attorney promptly.

Alva Health

Let Alva handle the admin

Alva automates charting, insurance claims, eligibility checks, and follow-ups for private-practice dietitians — so you get paid without the paperwork.

Start your 7-day free trial → Free for 7 days, then $99/month · Cancel anytime · HIPAA compliant