Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
September 10, 2026
3 min read

What HIPAA Compliance Looks Like When AI Enters Your ABA Practice

Joshua Farrow
Clinical AI Director
Signup for our Newsletter
Oops! Something went wrong while submitting the form.

AI is showing up in ABA practices in two directions at once. Your team is experimenting with consumer AI tools on their own. And the platforms you already rely on are shipping AI-powered features into your workflow. Both of those carry HIPAA implications that many practices haven't worked through yet.

This isn't a reason to panic. The HIPAA principles you've been applying for years still hold. But the surface area those principles cover just got wider, and the compliance conversation needs to catch up.

AI showed up before ABA had a framework for it

The regulatory and ethical frameworks that govern ABA practice weren't written with generative AI in mind. That's starting to change, but slowly.

HHS has proposed updates to the HIPAA Security Rule that would require AI systems creating, receiving, maintaining, or transmitting ePHI to be listed as part of a practice's technology asset inventory. That means regulators are already treating AI as part of compliance infrastructure, not a separate conversation.

On the ethics side, Jennings and Cox (2023) published a peer-reviewed analysis in Behavior Analysis in Practice arguing that the existing BACB Ethics Code sections on confidentiality and data protection need to be actively extended to AI contexts because the code itself doesn't explicitly address them.

None of this means you need to wait for the guidance to be finalized before making decisions. But we should all keep in mind we're operating in a period where the rules are catching up to the technology. The clinical leaders who are thinking about this now will be better positioned than the ones who assume someone else will figure it out.

AI enters your practice through two doors

When clinical leaders think about AI and HIPAA, they tend to picture one scenario: a vendor adding an AI feature to the platform. The actual picture has two fronts running in parallel, and they need different responses.

Door 1: The AI your team brings in from outside

Your BCBAs® and RBTs® are problem-solvers by training. When documentation takes too long or a task feels repetitive, they may look for faster ways to clean up the language on a program description, to draft a caregiver update, or to summarize a research article. And they might not tell you they’re using an AI chatbot for that. 

A Wolters Kluwer Health survey of over 500 healthcare workers found that nearly 20% admitted to using unapproved AI tools in the workplace. That's the number people will admit to in a survey. The real number is likely higher.

The compliance issue is that consumer AI tools are not HIPAA business associates. Free-tier versions of popular AI tools won't sign a Business Associate Agreement (BAA). Data entered into them may be retained, used to train models, or accessible to vendor staff. A session note pasted into a consumer AI tool to "make it sound more professional" turns a productivity shortcut into a PHI disclosure to a third party without a BAA. Same with a behavior graph uploaded for interpretation help, or an intake summary pasted in to generate a treatment plan draft.

Your responsibility here isn't to ban every new tool (that approach just drives usage underground). It's to know what's happening in your practice, name the risk clearly, and give your team compliant paths to the same outcomes they're chasing before they build workarounds you can't see.

Door 2: The AI features your ABA software adds

The second door opens more quietly. Your ABA software vendor sends a release note about a new AI-assisted feature: session narrative drafting, authorization tracking, or billing error detection. The feature looks helpful, and you already have a BAA with the vendor, so it feels safe by default.

But the compliance question goes one layer deeper. If your vendor's AI feature is powered by a third-party model provider, you need to know whether that third party also has a BAA with your vendor. This is sometimes called the BAA chain. If any link in that chain is missing, PHI is leaving the environment your compliance program covers.

Before you pilot any vendor AI feature, get clear answers on a couple of things:

Where is the AI processing happening?
When the AI produces something that goes into a clinical or billing record, who is the named human accountable for reviewing it? 

Those answers should be clear and documented before your team starts relying on any new AI feature.

HHS has stated that covered entities cannot delegate their HIPAA compliance obligations to AI vendors. Your vendor's compliance matters, but it doesn't replace yours.

The four things HIPAA-compliant AI requires

There's no HIPAA certification. Not for software, not for AI, not for anything. Compliance is a set of ongoing obligations. Vendors that market their AI as "HIPAA-compliant" are describing an intention, not a legal designation. What actually matters is whether the tool and the way your practice uses it meet a few foundational requirements.

  1. The BAA chain has to be complete

Every entity that creates, receives, maintains, or transmits PHI on your behalf needs a signed BAA. When your vendor adds an AI feature powered by a third-party model, the vendor needs a BAA with that provider, too. If any link in that chain is missing, you have a compliance gap, even if you weren't the one who introduced it.

  1. PHI should stay inside the environments your BAA covers

The safest default for general-purpose AI use is de-identification. When PHI has to be involved, the processing should happen inside your platform's environment, under the BAA that already governs your relationship with that vendor. If data leaves that environment to reach an external AI service, you need to know about it and account for it in your compliance program.

  1. A named human owns every AI output

AI can draft, suggest, summarize, and flag. It can't be accountable. Someone with a name, whether that’s the clinician who signs a note, the supervisor who approves a treatment plan update, or the billing lead who submits a claim, needs to own every piece of output that enters the record. Human review of AI-generated content that touches clinical or billing records is the standard the field is converging on.

  1. You can audit what the AI did

If you can't trace what the AI did, when, and on whose behalf, you don't have compliance. You have a process you can't explain during a payer review. Any AI feature you adopt should produce an audit trail with the same rigor as the rest of your documentation system. Changes tracked, timestamps logged, outputs tied to a responsible user.

The "HIPAA-compliant" label on a piece of software doesn't mean your practice is compliant. Configuration, usage, and the decisions your team makes every day are where compliance really lives.

Extending what you already know into new terrain

If you've spent years building a practice that takes PHI seriously, training your team on device security, running access controls, and reviewing documentation before it goes out, you already have the instincts this moment requires. The HIPAA principles that govern how you handle data today are the same principles that apply to AI. The surface area those principles cover has just gotten bigger.

Here I’m covering the compliance foundation. Once you have that in place, the next question is where AI actually belongs in your workflows: Which tasks are worth piloting? How do you evaluate tools, run a responsible pilot, and measure whether the time saved actually translates into better clinical outcomes? Those are different kinds of decisions, and they deserve a framework.

Emaley McCulloch, Motivity's Chief Clinical Officer, put together a practical toolkit for that. It walks through how to match AI tools to ABA work, a governance layer that applies to every decision, and a step-by-step pilot design you can run. If you've read this far and you're thinking about what comes next, the toolkit is a good place to start.

Download the free ABA Clinical Leader's AI Toolkit →

Related Articles