As of September 2026, a dietitian is a HIPAA covered entity only if the practice, or a billing service acting for it, sends a covered transaction such as a claim or eligibility check electronically. A cash-pay practice issuing superbills is not covered. NutraPlanner encrypts client notes at the field level, requires two-factor authentication for practitioners and records access to client records in an audit log.
Is a private-practice dietitian a HIPAA covered entity?
Only if the practice transmits a covered transaction electronically. HIPAA's definition of "covered entity" is a closed list of three: a health plan, a health care clearinghouse, and "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter". A dietitian is a "health care provider" in the definitional sense, and nutrition counseling is "health care", but neither fact alone makes the practice covered.
The covered transactions are the financial and administrative exchanges between a provider and a payer: claims, payment and remittance advice, coordination of benefits, claim status, enrollment, eligibility, premium payments, referral certification and authorization, first report of injury, health care electronic funds transfers, since May 26, 2026, health care claims attachments, and a residual twelfth item for anything else the Secretary prescribes by regulation. Emailing a client, storing records in cloud software, running a client portal and taking card payments are not on the list. None of them is a "transaction" in the regulation's sense.
CMS states the provider branch of the test as two questions in its covered-entity decision tool: does the person furnish, bill or receive payment for health care, and does the person "transmit (send) any covered transactions electronically?" If the answer to the second is no, the tool's conclusion is that the provider "is NOT a covered health care provider and therefore not a covered entity". HHS says the same thing in prose: a provider is covered "only if they transmit any information in an electronic form in connection with a transaction for which HHS has adopted a standard".
A dietitian who takes cash, card or HSA payment directly, hands the client a superbill to submit themselves, and never sends an eligibility check, claim, claim-status query or remittance in electronic form is not a covered entity, and no HIPAA rule applies to the practice. What that superbill has to carry, and why no federal field list exists, is in what goes on a US dietitian superbill.
What makes a cash-pay dietitian a covered entity?
Any one covered transaction sent electronically, once: a single claim to any payer, an eligibility or benefits check, a remittance advice received electronically, or a claims attachment. The regulation contains no "one claim only" or de minimis exception. Nothing in the rule reverses the status later, and once covered, the practice is covered for all of its protected health information, including the records of clients who pay cash.
CMS treats a billing service's transaction as the provider's own: its decision tool states that "if a healthcare provider uses another entity (such as a clearinghouse) to conduct covered transactions in electronic form on its behalf, the health care provider is considered to be conducting the transaction in electronic form". A practice that contracts a billing company to submit claims for its one or two insurance clients has crossed the line even though it never touched a claim itself. The regulation contemplates exactly that arrangement at 45 CFR 162.923(c).
Whether to cross the line is a business decision. Medicare medical nutrition therapy and in-network commercial work both require electronic claims in practice, and the trade-off is set out in which insurers cover dietitian services in the US and what billing them requires.
What does a HIPAA-covered dietitian have to do?
A covered practice has six core duties, and none has a solo-practice exemption. It must deliver a Notice of Privacy Practices with the prescribed header no later than the first service, make a good-faith effort to obtain written acknowledgment, and post the notice prominently on the practice website if the site describes the practice's services. It must carry out a risk analysis, which is a "Required" implementation specification, not an "addressable" one, along with risk management, a sanction policy and information-system activity review. It must name a security official. It must train its workforce on both the Security Rule and its own privacy policies, and document the training. It must designate a privacy official and a complaints contact. And it must keep its written policies and procedures for six years from creation or from when they were last in effect.
The six-year documentation duty is where the widely repeated "HIPAA requires six years" figure comes from. It attaches to the documentation of compliance, not to client records. HIPAA sets no medical-record retention period at all, and HHS says so in its own FAQ.
How long the clinical chart itself must be kept is a question of state law, and for a dietitian the answer is different from the one on most retention charts. See how long a US dietitian must keep client records. How the privacy decision fits with licensure, records, billing, entity and tax is mapped in starting a dietitian private practice in the US.
| Obligation | Provision | What it requires |
|---|---|---|
| Notice of Privacy Practices | 45 CFR 164.520 | Prescribed header; delivered by the first service; written acknowledgment sought; posted on the website |
| Risk analysis and risk management | 45 CFR 164.308(a)(1)(ii) | "Required" specifications: an accurate and thorough assessment, and measures to reduce risk |
| Security official | 45 CFR 164.308(a)(2) | One named person responsible for the security policies, even in a practice of one |
| Workforce training | 45 CFR 164.308(a)(5), 164.530(b) | Security awareness program, and privacy training on the practice's own policies, documented |
| Privacy official and complaints contact | 45 CFR 164.530(a) | Both designated; in a solo practice, the same person |
| Business associate agreements | 45 CFR 164.502(e), 164.504(e) | Written contract before PHI goes to any vendor that creates, receives, maintains or transmits it |
| Documentation retention | 45 CFR 164.316(b)(2), 164.530(j) | Policies, procedures and required records kept six years: this is the six-year rule |
Does a dietitian need a business associate agreement with software vendors?
Only a covered dietitian does. The duty exists only "with respect to a covered entity". A business associate is any person who, on the covered entity's behalf, "creates, receives, maintains, or transmits protected health information" for a regulated function, and the definition names billing and practice management expressly. Practice-management software, a billing service, a cloud backup provider and a transcription service are all business associates of a covered practice. Before disclosing PHI to any of them the practice must obtain "satisfactory assurance" in the form of a written contract that establishes the permitted uses.
Another treating provider is not a business associate: the definition excludes "a health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual", so a referral to or from a physician needs no agreement. And a signed agreement that the practice knows is being breached does not protect it. A covered entity that "knew of a pattern of activity or practice of the business associate that constituted a material breach" must take reasonable steps to cure it or terminate the contract.
A practice that is not a covered entity owes no BAA under HIPAA, and a vendor cannot make it one by offering a BAA. Whether that practice should still hold vendors to equivalent terms is a matter of the state laws below, several of which reach it whether or not HIPAA does.
If HIPAA does not apply to my practice, what does?
The FTC Act, the state breach law, and in several states a health-privacy or consumer-health-data statute drafted without reference to HIPAA at all. Section 5 of the FTC Act prohibits "unfair or deceptive acts or practices in or affecting commerce", and the Commission's power runs against "persons, partnerships, or corporations", so a sole proprietor is reachable. The FTC and HHS have said jointly that the Act's obligations apply to "companies that collect, use, or share health information that aren't required to comply with HIPAA", and in 2023 they wrote to around 130 hospital systems and telehealth providers about web-tracking disclosures on that basis. The health-privacy enforcement docket to date is apps and platforms, not solo clinical practices.
The FTC's Health Breach Notification Rule is narrower than its name suggests for a clinical practice. It reaches vendors of "personal health records", and a personal health record must be "managed, shared, and controlled by or primarily for the individual". A chart in a practice-controlled system does not fit that description on the plain words, and the 2024 amendment's worked examples are all health apps. Whether a client-facing portal in which the client manages their own record and connects a wearable changes the answer is unresolved.
Texas is the state that reaches a cash-pay dietitian most directly. Health and Safety Code chapter 181 defines "covered entity" as any person who, for professional gain or fees, "engages, in whole or in part, and with real or constructive knowledge, in the practice of assembling, collecting, analyzing, using, evaluating, storing, or transmitting protected health information". There is no small-practice exemption and no non-HIPAA exemption. The only entities carved out are insurers and employers. A Texas covered entity must train each employee within 90 days of hire and again within a year of any material change in the law, keep the signed training statements for six years, provide an electronic health record within 15 business days of a written request if its system can, and post on its website and in its office instructions for requesting records, contacting the licensing board and filing a complaint. The 60-day and every-two-years training figures still printed by compliance vendors were repealed in 2013. A companion chapter added in 2025 also requires that electronic health records be physically maintained in the United States.
Washington, Nevada and Connecticut have consumer-health-data statutes with no revenue or volume floor. Washington's My Health My Data Act reaches any entity that conducts business in the state and determines the purpose and means of collecting consumer health data. A "small business" is a sub-class with a later compliance date, not an exemption. The Act requires separate consent for sharing and a deletion right that reaches backups within 45 days, and it is enforced through the Consumer Protection Act. Nevada's statute mirrors it with a 45-day response deadline and no private right of action. Connecticut's consumer-health-data provisions apply "notwithstanding" the general threshold, and from July 1, 2026, the general volume threshold is gone for anyone processing sensitive data, which consumer health data is. In all three, the HIPAA carve-out is written for entities HIPAA already regulates.
California is unresolved. The Confidentiality of Medical Information Act reaches "a person licensed or certified pursuant to Division 2" of the Business and Professions Code. The dietitian chapter sits inside Division 2, but it issues no license or certificate. The qualifications it sets are validated by the Commission on Dietetic Registration, not by a California board. Whether that makes a California RDN a "provider of health care" under the Act is a question the text does not answer, and a practice there should take advice rather than assume either way. Florida, by contrast, is clear: its definition of "health care practitioner" enumerates the dietetics licensure part expressly, so a Florida licensed dietitian is a "records owner" with the statute's confidentiality and access duties.
| Law | Who it reaches | What it requires of a small practice |
|---|---|---|
| FTC Act § 5 | Any for-profit person or partnership in commerce | No unfair or deceptive health-data practices; no enforcement action found against a solo clinical practice |
| FTC Health Breach Notification Rule | Vendors of "personal health records" managed by or for the individual | Probably not a practice-controlled chart; a client-managed portal is an open question |
| Texas HSC ch. 181 | Any person who stores or uses PHI for fees; no size floor | Training at 90 days; EHR access in 15 business days; website and office postings; US data residency for EHRs |
| Washington My Health My Data Act | Any business determining the purpose and means of collecting consumer health data | Separate consent to share; deletion including backups within 45 days |
| Nevada NRS 603A.400–.550 | Same test as Washington; exempts only persons "subject to" HIPAA | Consent to collect, separate consent to share; requests answered in 45 days |
| Connecticut consumer-health-data provisions | Every person doing business in the state, no threshold | Opt-in consent for sensitive data; no sale of consumer health data without consent |
| California CMIA | Unresolved for a California RDN | If it applies, a broad confidentiality duty enforced in negligence; take advice |
| Florida § 456.057 | Florida licensed dietitians, enumerated expressly | Records-owner confidentiality and access duties; copies "in a timely manner" |
How quickly must a dietitian report a data breach?
Under HIPAA, to the individual without unreasonable delay and "in no case later than 60 calendar days after discovery", where discovery is constructive: the clock starts on the first day the breach "by exercising reasonable diligence would have been known". A breach is presumed unless the practice can demonstrate a low probability that the information was compromised, and the practice bears the burden of proving it notified. Breaches of 500 or more individuals go to HHS at the same time. Smaller ones go into a log reported within 60 days of year-end.
State breach laws apply alongside HIPAA, and the assumption that HIPAA compliance satisfies them is wrong in every one of the five states examined. Texas contains no HIPAA provision at all. California relieves only the content of the notice. New York excuses the individual notice but still requires notice to the Attorney General, the Department of State, the State Police and the Department of Financial Services whenever any New York resident is notified. Florida's relief is keyed to the practice's federal regulator and covers the department notice only if a copy is sent to the department on time. Illinois offers the broadest deeming and forfeits it unless the Attorney General is told within five business days of HHS.
The deadlines have also tightened. California's business breach notice has carried a hard 30-calendar-day limit since January 1, 2026. New York's is 30 days from discovery. Florida's is 30 days on an access-based trigger, the lowest bar of the five. Texas allows 60 days for individuals but requires Attorney General notice within 30 days at 250 or more residents. Illinois alone sets no numeric outer limit.
| State | Individual notice deadline | State notice | Does HIPAA compliance excuse it? |
|---|---|---|---|
| California | 30 calendar days from discovery (since 2026-01-01) | AG: sample notice within 15 days if more than 500 residents | Notice content only; every other duty survives |
| Texas | 60 days from determining the breach | AG within 30 days at 250 or more residents | No: chapter 521 has no HIPAA provision |
| New York | 30 days from discovery; trigger is access OR acquisition | AG, Department of State, State Police and DFS for any resident | Individual notice only; the state notices survive |
| Florida | 30 days; trigger is unauthorized access | Department of Legal Affairs within 30 days at 500 or more | Individual notice yes; department notice only if a copy is sent on time |
| Illinois | No numeric limit; "most expedient time possible" | AG no later than consumers, at more than 500 residents | Yes, if the AG is told within 5 business days of HHS |
Frequently asked questions
Is a cash-pay dietitian who never bills insurance a HIPAA covered entity?
No. Under 45 CFR 160.103 a health care provider is a covered entity only if it transmits health information electronically in connection with a covered transaction such as a claim, eligibility check or remittance. A dietitian who takes payment directly from clients and issues a superbill for them to submit themselves sends no covered transaction and is not a covered entity. Emailing clients, using cloud software and storing records electronically do not change that, because none of them is a transaction in the regulation's sense.
Does using a billing service make a dietitian a HIPAA covered entity?
Yes, if the billing service transmits any covered transaction electronically for the practice. CMS's covered-entity decision tool states that a provider that uses another entity such as a clearinghouse to conduct covered transactions in electronic form on its behalf is considered to be conducting the transaction itself. A single electronic claim submitted by a billing company for one insurance client makes the whole practice a covered entity, including its cash-pay records.
Does HIPAA require a dietitian to keep client records for six years?
No. The six-year period in 45 CFR 164.316 and 164.530 applies to policies, procedures and compliance documentation, not to medical records. HHS states in its own FAQ that the HIPAA Privacy Rule does not include medical record retention requirements and that state laws generally govern how long records are kept. For a dietitian, most states set no period at all; New York sets six years by Board of Regents rule.
What privacy law applies to a Texas dietitian who is not covered by HIPAA?
Texas Health and Safety Code chapter 181. Its definition of "covered entity" reaches any person who, for fees or professional gain, engages in assembling, collecting, storing or transmitting protected health information, with no small-practice or non-HIPAA exemption. A Texas dietitian must train staff within 90 days of hire, provide electronic records within 15 business days of a written request where the system allows, and post records-request and complaint instructions on the practice website and in the office. The 60-day and biennial training figures often quoted were repealed in 2013.
Does Washington's My Health My Data Act apply to a solo dietitian practice?
On its terms, yes. A "regulated entity" is any legal entity that conducts business in Washington and determines the purpose and means of collecting consumer health data, with no revenue or volume threshold; a "small business" is a sub-class with a later compliance date, not an exemption. The Act's HIPAA carve-out excludes information that is protected health information under HIPAA, which a non-covered practice's records are not. A separate carve-out for information handled under Washington's health-care-information chapter may apply to certified dietitians, but whether a title-protection certification qualifies is not settled.
If a dietitian complies with HIPAA breach rules, does that satisfy state breach law?
Not fully in any of the five states examined. Texas has no HIPAA provision in its breach statute. California deems HIPAA compliance sufficient only for the content of the notice. New York excuses the individual notice but still requires notifying the Attorney General, the Department of State, the State Police and the Department of Financial Services. Florida's relief covers the department notice only if a copy is sent on time. Illinois deems full compliance but only if the Attorney General is notified within five business days of HHS.
References
- 45 CFR 160.103 — Definitions (covered entity, health care provider, transaction) — eCFR
- CMS — Covered Entity Decision Tool (PDF)
- HHS OCR — Covered Entities and Business Associates
- 91 FR 14350 — Adoption of standards for health care claims attachments (effective May 26, 2026)
- 45 CFR 164.520 — Notice of privacy practices — eCFR
- 45 CFR 164.308 — Administrative safeguards — eCFR
- 45 CFR 164.502 — Uses and disclosures, including business associates — eCFR
- 45 CFR 164.404 — Notification to individuals (breach) — eCFR
- HHS OCR FAQ 580 — Does HIPAA require covered entities to keep medical records for any period?
- FTC and HHS — Collecting, Using, or Sharing Consumer Health Information? Look to HIPAA, the FTC Act, and the Health Breach Notification Rule
- 16 CFR Part 318 — Health Breach Notification Rule — eCFR
- Texas Health and Safety Code chapter 181 — Medical Records Privacy
- RCW 19.373 — Washington My Health My Data Act
- NRS 603A — Nevada consumer health data provisions
- Conn. Gen. Stat. chapter 743jj — Connecticut Data Privacy Act
- Cal. Civ. Code § 56.05 — CMIA definitions
- Fla. Stat. § 456.057 — Ownership and control of patient records
- Cal. Civ. Code § 1798.82 — Breach notification (30-day deadline from 2026)
- Tex. Bus. & Com. Code § 521.053 — Notification of breach
- N.Y. Gen. Bus. Law § 899-aa — Notification of breach
- Fla. Stat. § 501.171 — Security of confidential personal information
- 815 ILCS 530 — Illinois Personal Information Protection Act
Similar articles
Start a Dietitian Practice in Canada: Rules by Province
Registration, titles, record retention, privacy law and incorporation — what differs by province, with key primary sources linked.
Read article →Practice managementCanadaDo Dietitians Charge GST/HST in Canada? The Three-Part Test
The Excise Tax Act puts maintaining health and preventing disease inside the exemption. The three conditions that actually decide it.
Read article →