Compliance & Telehealth
The HIPAA Checklist for Solo Dietitians: Minimum Viable Compliance
A realistic HIPAA checklist for solo registered dietitians: BAAs, the annual risk assessment, device security, breach basics, and a printable 15-item list.
HIPAA guidance is written for hospitals with compliance departments. You are one person with a laptop, a caseload, and maybe three hours a month for administrative work that doesn't bill. So most solo RDs land in one of two bad places: ignoring HIPAA entirely ("I'm too small to matter") or losing sleep over an imagined standard no solo practice actually meets.
Both are wrong. The moment you bill insurance electronically — submit a claim, run an eligibility check, receive an ERA — you're a covered entity, full stop. There is no small-practice exemption. But compliance for a practice of one is genuinely achievable in a weekend of setup plus a few hours a year of maintenance.
Here's the minimum viable version: what the rules actually require, translated to a solo practice, ending with a printable 15-item checklist.
You're a covered entity. Here's what that means
HIPAA has three operative rules for you:
| Rule | What it governs | Solo-practice translation |
|---|---|---|
| Privacy Rule | Who can see and receive PHI | Notice of Privacy Practices, patient access rights, minimum-necessary sharing |
| Security Rule | How electronic PHI is protected | Risk assessment, device security, access controls, vendor BAAs |
| Breach Notification Rule | What happens when PHI is exposed | Notify affected patients (and HHS) on defined timelines |
PHI is broader than clinical notes: names attached to appointment times, intake forms, claim files, session recordings, even the email thread where a client mentions her A1c. If it identifies a patient and relates to their health or payment for care, treat it as PHI.
BAAs: the vendor paper trail
A business associate agreement (BAA) is a contract making your vendor legally responsible for protecting the PHI it handles for you. You need one with every vendor that touches PHI:
- Practice management platform / EHR
- Clearinghouse and billing tools
- Email provider (if any PHI ever transits email — practically, yes)
- Cloud storage and backup
- Scheduling and intake-form tools
- AI scribe or charting tool
- Telehealth video platform
- Fax service, phone/voicemail transcription if used clinically
Free consumer tiers usually won't sign one — standard free Gmail is the classic trap; the paid workspace tier with a BAA is fine. Walk your whole stack once and record the date of each BAA; the full vendor-by-vendor breakdown is in our HIPAA-compliant tool stack guide.
The risk assessment (yes, annually, yes, you)
The Security Rule requires a risk analysis — an honest inventory of where ePHI lives, what could go wrong, and what you're doing about it. It's the single most cited gap when regulators investigate small practices.
The solo version is not a 90-page document. HHS publishes a free Security Risk Assessment (SRA) tool designed for small practices; working through it takes an afternoon. The output — identified risks, your fixes, the date — is your documentation. Repeat at least annually and whenever your stack changes.
Policies you actually need written
You don't need a hospital's policy binder. You do need a short written version of:
- Privacy policy / Notice of Privacy Practices — given to every patient at intake.
- Security policy — how devices, passwords, and access are handled (a page or two).
- Breach response procedure — the steps you'd follow, written before you need them.
- Sanction policy — trivially short when the workforce is you, but required; it matters the day you hire.
- Record retention schedule — HIPAA documentation must be kept six years; clinical record retention follows state law (often longer).
"Written" means a document you could hand an investigator, dated and revisited annually.
Device security basics
Most solo-practice exposure is a lost laptop or phone, not a hacker:
- Full-disk encryption on (FileVault on Mac, BitLocker on Windows) — an encrypted lost laptop is generally a non-breach; an unencrypted one is a reportable event.
- Screen lock with a short timeout on every device that touches PHI.
- Unique, strong passwords + a password manager + two-factor authentication on the EHR, email, and clearinghouse.
- No PHI in personal SMS or consumer messaging apps. Scheduling logistics with consent, fine; clinical content, no.
- Separate user account if the computer is shared at home — better, a dedicated work device. The family iPad is not an EHR terminal.
- Automatic updates on; unpatched systems are the other classic entry point.
Breach basics
A breach is an impermissible use or disclosure of PHI — a misdirected email with an intake form, a stolen unencrypted phone, a vendor incident. If it happens: contain, assess, document. Affected individuals must generally be notified without unreasonable delay, at most 60 days. Under 500 people affected: log it and report to HHS annually. 500+: 60-day HHS notification plus media notice — and, realistically, a lawyer. The documented risk assessment and encryption you set up above are exactly what turn "incident" into "non-event."
Patient right of access
Patients have the right to copies of their records — generally within 30 days of the request (one 30-day extension is possible), in the form they ask for when readily producible, for at most a reasonable cost-based fee. Some states are stricter on timelines and fees, so verify your state's rules. Slow-walking records requests is one of the most actively enforced HIPAA provisions, including against small practices. Build a simple habit: request in writing, fulfill fast, note the date.
Train yourself, and write it down
Workforce training is required even when the workforce is one person. Take a short HIPAA training annually (inexpensive online courses are fine), keep the certificate, and note the date in your compliance folder. Undocumented training is, to an investigator, no training.
The violations solo RDs actually commit
- Texting clinical details over standard SMS
- Using free consumer email for PHI with no BAA
- Charting on a shared family computer with no separate account
- No BAA with the AI scribe or scheduling tool quietly holding session data — session recordings are PHI too (see recording consent rules)
- No risk assessment, ever
- Keeping intake PDFs in an unencrypted downloads folder
Notice none of these are exotic. They're defaults you have to consciously replace.
The printable 15-item checklist
- Confirm covered-entity status (you bill electronically → yes)
- Inventory every place PHI lives (devices, apps, drawers)
- BAA signed with every PHI-touching vendor
- Replace any free-tier tool that won't sign a BAA
- Complete the HHS SRA tool; save the output
- Full-disk encryption on all devices
- Screen locks + auto-timeout everywhere
- Password manager + 2FA on EHR, email, clearinghouse
- Notice of Privacy Practices given at intake
- Written security policy + breach procedure + sanction policy
- No PHI in personal SMS or consumer apps
- Records-request workflow (30-day clock)
- Annual HIPAA training, certificate saved
- Six-year retention system for compliance docs
- Calendar reminder: repeat risk assessment and review annually
Print it, work through it once, then it's an annual afternoon. That's minimum viable compliance — real protection, not performative paperwork.
How Alva helps: Alva consolidates the riskiest parts of a solo stack — intake forms, session recordings, charting, claims, and payment posting — into one HIPAA-compliant platform with a BAA, which means fewer vendors to vet and fewer places PHI can leak. One tool, one agreement, $99/month. Start a 7-day free trial.
Frequently asked questions
Does HIPAA apply to a solo dietitian in private practice?
Almost certainly yes. If you transmit health information electronically in connection with billing — submitting insurance claims, checking eligibility, receiving electronic remittances — you are a covered entity under HIPAA, regardless of practice size. A purely cash-pay practice that never bills electronically may fall outside the definition, but state privacy laws and professional ethics still apply.
Do I need a BAA with every software vendor I use?
You need a business associate agreement with every vendor that creates, receives, stores, or transmits protected health information on your behalf — your EHR or practice platform, clearinghouse, email provider if PHI touches it, cloud storage, scheduling tool, and any AI scribe. Vendors that never touch PHI, like your accounting software, do not need one.
Is a HIPAA risk assessment really required for a practice of one?
Yes. The Security Rule requires a risk analysis and it applies to covered entities of every size. For a solo practice it can be proportionate — HHS publishes a free Security Risk Assessment tool aimed at small practices. Do it, fix what it surfaces, document it, and repeat it at least annually.
Can I text my clients about their appointments?
Appointment logistics with minimal detail are generally considered acceptable if the client has agreed to receive texts, but clinical content over standard SMS is a common violation because SMS is unencrypted. Keep texts to scheduling, get consent in your intake paperwork, and move anything clinical to a secure portal or encrypted channel.
What do I do if I have a HIPAA breach in my solo practice?
Contain it, assess what information was exposed and to whom, and document everything. Affected individuals must generally be notified without unreasonable delay and within 60 days. Breaches affecting fewer than 500 people are reported to HHS annually; 500 or more triggers notification within 60 days plus media notice. When in doubt, consult a healthcare attorney promptly.