regulation and compliance

What does HIPAA actually require from me as a solo dietitian using a meal plan app?

As a covered entity you owe a risk analysis, business associate agreements and specific safeguards. Here is what applies to a one person practice and its software.

Tidy consulting room corner with closed laptop, filing drawer and linen chair in daylight
The Counseling Table, reporting for registered dietitians in private practice.

If you bill any insurer electronically, or if a clearinghouse or billing service submits claims on your behalf, you are a covered entity under HIPAA and the full Privacy, Security and Breach Notification Rules apply to you. That is true whether your practice has forty employees or exactly one. The obligations that follow are concrete: a written security risk analysis you keep current, signed business associate agreements with every vendor that touches protected health information, a Notice of Privacy Practices, documented policies, workforce training, and a breach response process with defined timelines.

The good news is that the Security Rule is scalable by design. The regulation explicitly says a covered entity may take into account its size, complexity and capabilities when deciding how to implement the standards. A solo practice is not expected to run the same access control program as a hospital system. It is expected to have thought the problem through, written down what it decided, and be able to produce that document.

What follows is the version that applies to a one person nutrition counseling practice and the software it runs on, including a meal plan and check in platform where your clients type things about their bodies every day.

Are you a covered entity, and when you are not

HIPAA reaches health care providers only if they transmit health information electronically in connection with a covered transaction. Covered transactions include claims submission, eligibility inquiries, claim status requests and remittance advice. Submit one electronic claim and you are in.

A cash pay practice that never bills insurance, never checks eligibility electronically, and never gives a client a superbill routed through a clearinghouse is arguably not a covered entity. That is a narrower exit than most people think. Running an eligibility check through a portal to tell a prospective client whether her plan covers medical nutrition therapy is itself a covered transaction.

Two cautions if you conclude you are outside HIPAA. First, state health privacy law usually still applies, and in several states it is stricter. Second, if you contract with a physician group, a hospital, an employer wellness vendor or a digital health company, you are probably a business associate of that entity, which pulls most of the Security Rule onto you by contract and by regulation anyway.

The practical test

Ask three questions. Do I submit claims electronically, directly or through anyone? Do I run electronic eligibility or benefits checks? Do I have a signed business associate agreement with any organization that sends me clients? A yes to any of them means build the compliance program.

Keep reading: How did one dietitian rebuild her practice around group visits instead of one on ones?

The security risk analysis a solo practice must document

This is the single requirement most solo practices skip and the one enforcement actions cite most often. A risk analysis is not a checklist someone sells you. It is an inventory plus a judgment.

Start with the inventory. List every place electronic protected health information lives or passes through: your laptop, your phone, your practice management system, your video platform, your meal planning and check in app, your email, your cloud storage, your billing service, any external drive, and the paper you print. For each, write down who can reach it, how they authenticate, whether the data is encrypted at rest and in transit, and what happens if the device is stolen.

Then assess. For each asset, name the realistic threats, rate likelihood and impact in plain words, and record what control you already have or plan to add. A phone that opens a client messaging app with a four digit code and no remote wipe is a high likelihood, high impact finding with an obvious fix.

Finish with a risk management plan: the fixes, who does them, by when. Date the document. Redo it when something material changes, and at least annually. A four to six page analysis for a solo practice is normal and defensible. Zero pages is not.

Business associate agreements with every vendor touching client data

A business associate is any outside party that creates, receives, maintains or transmits protected health information on your behalf. Your electronic health record vendor. Your billing service. Your telehealth platform. Your meal plan and adherence app. Your cloud backup. Your transcription tool, including an AI note taker.

You need a signed agreement with each one before it touches client data. The agreement must, at minimum, require the vendor to safeguard the information, use it only as permitted, report security incidents and breaches to you, bind its own subcontractors to the same terms, and return or destroy the data at termination.

Vendor typeBAA neededWhy
Meal plan and client check in appYesStores dietary intake, weight, symptoms tied to named clients
Video visit platformYesTransmits the encounter, may store recordings
Email providerYes if used with clientsConsumer tiers usually will not sign; business tiers often will
Scheduling tool with intake questionsYesIntake answers about conditions are PHI
Accountant reviewing revenue onlyNoNo PHI if reports are de-identified
Landlord, cleaning serviceNoIncidental exposure, addressed by physical safeguards

Two failure modes to watch. A vendor that says it is HIPAA compliant on its marketing page but will not sign an agreement is not usable. And a signed agreement does not transfer your liability; if the vendor loses data, you still own the notification duty to your clients.

Keep reading: Is licensure portability changing where I can counsel nutrition clients across state lines?

Texting, email and client check in messages

HIPAA does not ban texting or email. It requires you to assess the risk and either mitigate it or document the client's informed choice. Unencrypted SMS to a personal phone is a real risk, and the Privacy Rule permits it when the client has been warned about that risk and still requests it. Write the warning into your intake paperwork and record which channel each client chose.

The stronger pattern is to move routine contact inside a platform that encrypts messages and logs access. A daily check in that lives in an application with unique logins, an audit trail and an agreement in place is materially safer than a thread of green bubbles on a phone that goes to the gym with you.

Whatever channel you use, the minimum necessary standard applies. An appointment reminder does not need a diagnosis in it. A message asking a client to look at this week's plan does not need her lab values.

Notice of privacy practices and client access rights

You must give each client a Notice of Privacy Practices at or before the first service, make a good faith effort to obtain written acknowledgment of receipt, and post the notice where clients can see it, including on your website if you have one. The notice describes how you use and disclose information, the client's rights and how to complain.

Access rights are the part that generates most day to day work. A client may request a copy of her record, and you must provide it, generally within thirty days, in the form she asks for if you can readily produce it. You may charge a reasonable, cost based fee for labor in copying and for media, but not a search or retrieval fee. She may also request an amendment, request restrictions, and request confidential communications at an alternate address or number.

Have a one page procedure for this before someone asks. Where does the record live, what counts as the designated record set, who exports it, and what does the cover letter say.

See how NourishPlanner handles this for dietetics and nutrition counseling

Breach notification thresholds and timelines

Any acquisition, access, use or disclosure of unsecured protected health information that is not permitted is presumed to be a breach unless you can show a low probability that the information was compromised. That showing requires a documented four factor risk assessment covering the nature of the data, who received it, whether it was actually viewed or acquired, and the extent to which risk has been mitigated.

Encryption is the escape hatch. Data encrypted to current federal standards is considered secured, and its loss is generally not a reportable breach. This is the single best reason to insist on encryption at rest on every laptop, phone and backup.

  • Notify affected individuals without unreasonable delay and no later than sixty days after discovery.
  • For a breach affecting fewer than five hundred people, log it and report to the Secretary within sixty days after the end of the calendar year.
  • For five hundred or more people in a state or jurisdiction, notify individuals, the Secretary and prominent local media without unreasonable delay and within sixty days.
  • Keep the risk assessment, the notification letters and the mailing log for six years.

State privacy laws that go beyond HIPAA

HIPAA is a floor. State law can and does add requirements, and where it is more protective, it controls. Several states impose shorter breach notification windows than sixty days and require notice to the state attorney general. Many have separate data breach statutes that cover names paired with Social Security numbers, financial account numbers or medical information, and those statutes apply to your practice as a business, not only as a provider.

Two categories deserve specific attention in nutrition counseling. Substance use disorder treatment records carry heightened federal protection if you work with a program that falls under that rule. And consumer health data laws in some states reach information collected outside a traditional clinical relationship, including app based wellness data, with consent requirements that are stricter than HIPAA's.

Check your own state board rules too. Licensure regulations often set record retention periods that are longer than anything HIPAA specifies.

What to do this month

Pick a Friday afternoon. Write the asset inventory. Request agreements from every vendor on it and retire the ones that will not sign. Turn on full disk encryption and remote wipe. Draft the risk analysis, date it, and calendar the annual review. Put your notice on the website. That sequence gets a solo practice from exposed to defensible in about two working days.

Then look hard at where your client communication actually happens. If daily food and symptom check ins are landing in personal text threads, moving them into NourishPlanner puts weekly meal plans, client responses and your adherence view inside one system with proper access controls, so the record of the week is in a place you can inventory, encrypt and hand to a client when she asks for it.