<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Compliance &amp; Ethics Archives - Mrs. Speech Online</title>
	<atom:link href="https://mrsspeechonline.com/category/clinical-practice-management/compliance-ethics/feed/" rel="self" type="application/rss+xml" />
	<link>https://mrsspeechonline.com/category/clinical-practice-management/compliance-ethics/</link>
	<description>Tips &#38; Resources for SLPs, Educators &#38; Parents</description>
	<lastBuildDate>Sun, 12 Oct 2025 20:58:26 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://mrsspeechonline.com/wp-content/uploads/2025/09/Mrs.-Speech-Icon-1-150x150.png</url>
	<title>Compliance &amp; Ethics Archives - Mrs. Speech Online</title>
	<link>https://mrsspeechonline.com/category/clinical-practice-management/compliance-ethics/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Speech-Pathologists at the Heart of Outreach</title>
		<link>https://mrsspeechonline.com/slp-community-outreach/</link>
					<comments>https://mrsspeechonline.com/slp-community-outreach/#respond</comments>
		
		<dc:creator><![CDATA[Jennifer]]></dc:creator>
		<pubDate>Tue, 12 Aug 2025 17:22:31 +0000</pubDate>
				<category><![CDATA[Clinical]]></category>
		<category><![CDATA[Compliance & Ethics]]></category>
		<category><![CDATA[Collaboration]]></category>
		<category><![CDATA[Communication disorder]]></category>
		<category><![CDATA[Community]]></category>
		<category><![CDATA[National Speech-Language-Hearing Month]]></category>
		<category><![CDATA[SLP Advocacy]]></category>
		<category><![CDATA[TPT]]></category>
		<guid isPermaLink="false">https://vmx.erb.mybluehost.me/speech-pathologists-at-the-heart-of-outreach/</guid>

					<description><![CDATA[<p>Ready to make an impact for National Speech-Language-Hearing Month? Learn how to provide valuable resources, educate the public, and advocate for better media representation. What's one communication disorder you wish more people understood?</p>
<p>The post <a href="https://mrsspeechonline.com/slp-community-outreach/">Speech-Pathologists at the Heart of Outreach</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Hey there, fellow speech-pathologists! <a href="https://www.asha.org/national-speech-language-hearing-month/" target="_blank" rel="noopener">National Speech-Language-Hearing Month</a>&nbsp;(NSLHM) is less than a month away! Today, let&#8217;s dive into how we can be rock stars in our communities, providing essential support and resources for those in need. Whether you&#8217;re just starting out or a seasoned pro, there&#8217;s always something new to learn. This involves reaching out and making a difference. So, grab your coffee, and let&#8217;s get started!</p>



<h2 class="wp-block-heading" id="h-reaching-out-to-our-community">Reaching Out to Our Community</h2>



<p>First things first, let&#8217;s talk about reaching out to our community. Whether it&#8217;s through local schools, community centers, or even social media, there are tons of ways we can spread the word about what we do. Hosting workshops, giving talks, or even just setting up a booth at a local event can go a long way in raising awareness. Letting people know we&#8217;re here to help is invaluable. So many people don&#8217;t know about the wonderful things you do every day. This is your time to shine!</p>



<h2 class="wp-block-heading" id="h-providing-a-variety-of-resources">Providing a Variety of Resources</h2>



<figure class="wp-block-image alignleft size-large is-resized"><img fetchpriority="high" decoding="async" width="1024" height="1024" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/chat-5000695_1280-1024x1024.webp" alt="A laptop displaying a simple online interface with user icons and text blocks, surrounded by social media-style icons (like, heart, speech bubbles, thumbs down), symbolizing the variety of online resources speech-language pathologists can provide." class="wp-image-364" style="width:240px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/chat-5000695_1280-1024x1024.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/07/chat-5000695_1280-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/chat-5000695_1280-150x150.webp 150w, https://mrsspeechonline.com/wp-content/uploads/2025/07/chat-5000695_1280-768x768.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/07/chat-5000695_1280.webp 1280w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">This image represents the multitude of online resources, from websites to social media, that speech-language pathologists can leverage to provide support and information to their community.</figcaption></figure>



<p>As speech-pathologists, we have a host of resources at our fingertips, and it&#8217;s up to us to share them with our community. From brochures and handouts to online guides and toolkits, there&#8217;s no shortage of ways we can support individuals and families affected by communication disorders. Even a list of links is infinitely helpful for those looking for more information! Let&#8217;s not forget about collaborating with other professionals and organizations, because this provides even more comprehensive care.</p>



<h2 class="wp-block-heading" id="h-educating-others-on-disorders">Educating Others on Disorders</h2>



<p>Educating others about communication disorders is a big part of what we do. It&#8217;s super important in breaking down barriers and fostering understanding. Whether we&#8217;re giving a presentation at a local school or hosting a webinar for parents, every opportunity to spread knowledge and awareness is a step in the right direction. Plus, by empowering others with information, we&#8217;re helping them make informed decisions. Access to the support they need is crucial. The general public simply isn&#8217;t aware of all the options available!</p>



<h2 class="wp-block-heading" id="h-making-a-difference-in-media-representation">Making a Difference in Media Representation</h2>



<figure class="wp-block-image alignright size-large is-resized"><img decoding="async" width="1024" height="682" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/icon-2764666_1280-1024x682.webp" alt="An abstract network of colorful lines connecting various spheres, each containing a different media or communication icon (e.g., camera, microphone, social media logos), symbolizing the interconnectedness of media and the wide reach of communication." class="wp-image-413" style="width:306px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/icon-2764666_1280-1024x682.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/07/icon-2764666_1280-300x200.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/icon-2764666_1280-768x512.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/07/icon-2764666_1280.webp 1280w" sizes="(max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">This image represents the intricate web of media and communication platforms, underscoring the importance of accurate and respectful portrayals of communication disorders across all forms of media.</figcaption></figure>



<p>Last but not least, let&#8217;s talk about making a difference in media representation. From movies to TV shows, how communication disorders are portrayed in the media can have a big impact on how people perceive them. There&#8217;s nothing more frustrating to me than seeing communication impairments misrepresented!&nbsp; By working with writers, filmmakers, and other media professionals, we can help ensure that these portrayals are accurate, respectful, and free from harmful stereotypes. It&#8217;s all about advocating for better representation. This helps give a voice to those who need it most.</p>



<p>In a nutshell, being a speech-pathologist isn&#8217;t just about helping individuals—it&#8217;s about being an active and engaged member of our community. By reaching out, providing resources, educating others, and advocating for better representation, we can make a real difference in the lives of those affected by communication disorders. So, let&#8217;s keep up the amazing work and continue being the superheroes our communities need!</p>



<figure class="wp-block-image alignleft size-full is-resized"><img decoding="async" width="350" height="270" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/original-4503366-1.webp" alt="" class="wp-image-428" style="width:278px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/original-4503366-1.webp 350w, https://mrsspeechonline.com/wp-content/uploads/2025/07/original-4503366-1-300x231.webp 300w" sizes="(max-width: 350px) 100vw, 350px" /></figure>



<p>If you&#8217;d like a jumpstart on educating your community on communication impairments, check out my <a href="https://www.teacherspayteachers.com/Product/BSHM-Informative-Posters-Google-Slides-11376727" target="_blank" rel="nofollow noopener">BSHM packet</a> on TPT!&nbsp; It is 41 pages of SLP information in an easy to edit Google Slides format!</p>



<p>Keep rockin&#8217; the world!</p>



<h4 class="wp-block-heading" id="h-links-for-more-information-nbsp"><b>Links for more information:&nbsp;</b></h4>



<ul class="wp-block-list">
<li><strong><a href="https://www.asha.org/public/" target="_blank" rel="noreferrer noopener">American Speech-Language Hearing Association</a></strong></li>



<li><strong><a href="https://www.cdc.gov/ncbddd/disabilityandhealth/materials/factsheets/fs-communicating-with-people.html" target="_blank" rel="noreferrer noopener">Centers for Disease Control and Prevention &#8211; Communication with People</a></strong></li>



<li><strong><a href="https://www.nidcd.nih.gov/" target="_blank" rel="noreferrer noopener">National Institute on Deafness and Other Communication Disorders</a></strong></li>



<li><strong><a href="https://www.mayoclinichealthsystem.org/hometown-health/speaking-of-health/help-is-available-for-speech-and-language-disorders" target="_blank" rel="noreferrer noopener">Mayo Clinic</a></strong></li>



<li><strong><a href="https://www.nidcd.nih.gov/health/statistics/quick-statistics-voice-speech-language" target="_blank" rel="noreferrer noopener">NIDCD Statistics</a></strong></li>
</ul>



<div class="wp-block-group is-layout-constrained wp-block-group-is-layout-constrained">
<figure class="wp-block-image aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="810" height="169" src="https://i0.wp.com/vmx.erb.mybluehost.me/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp?fit=810%2C169&amp;ssl=1" alt="Mrs. Speech Signature" class="wp-image-804" style="width:364px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp 810w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-300x63.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-768x160.webp 768w" sizes="auto, (max-width: 810px) 100vw, 810px" /></figure>



<div class="wp-block-group is-content-justification-center is-nowrap is-layout-flex wp-container-core-group-is-layout-23441af8 wp-block-group-is-layout-flex">
<figure class="wp-block-image size-full is-resized"><a href="https://www.facebook.com/profile.php?id=61556892726241" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="388" height="398" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp" alt="facebook icon" class="wp-image-815" style="width:48px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp 388w, https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918-292x300.webp 292w" sizes="auto, (max-width: 388px) 100vw, 388px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.instagram.com/mrs.speechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="418" height="408" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp" alt="Instagram Icon" class="wp-image-818" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp 418w, https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939-300x293.webp 300w" sizes="auto, (max-width: 418px) 100vw, 418px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.pinterest.com/mrsspeechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="413" height="410" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp" alt="pinterest icon" class="wp-image-816" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp 413w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-300x298.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-150x150.webp 150w" sizes="auto, (max-width: 413px) 100vw, 413px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.linkedin.com/in/jennifer-tillock-821999287/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="402" height="402" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp" alt="LinkedIn Icon" class="wp-image-821" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp 402w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-150x150.webp 150w" sizes="auto, (max-width: 402px) 100vw, 402px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="http://www.youtube.com/@Mrs.Speech-wk4mr" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="429" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp" alt="YouTube icon" class="wp-image-817" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp 429w, https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232-300x291.webp 300w" sizes="auto, (max-width: 429px) 100vw, 429px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.teacherspayteachers.com/store/mrs-speech" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="423" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp" alt="TeachersPayTeachers Icon" class="wp-image-822" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp 423w, https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756-300x295.webp 300w" sizes="auto, (max-width: 423px) 100vw, 423px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="414" height="413" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp" alt="Mrs. Speech Books Icon" class="wp-image-1322" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp 414w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-150x150.webp 150w" sizes="auto, (max-width: 414px) 100vw, 414px" /></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="387" height="377" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp" alt="MailTo Icon" class="wp-image-1326" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp 387w, https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307-300x292.webp 300w" sizes="auto, (max-width: 387px) 100vw, 387px" /></figure>
</div>
</div>



<p class="icon-attribution" style="font-size: 0.6em; font-style: italic;">
    Social Media Icons: <a href="https://www.freepik.com" target="_blank" rel="noopener">designed by rawpixel.com &#8211; Freepik.com</a>
</p>



<div style="height:47px" aria-hidden="true" class="wp-block-spacer"></div>


<div style="color:#db820e;font-style:normal;font-weight:300" class="taxonomy-post_tag has-text-align-center has-link-color wp-elements-e81afc2be6272024545412bcb750c79c wp-block-post-terms has-text-color"><a href="https://mrsspeechonline.com/tag/collaboration/" rel="tag">Collaboration</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/communication-disorder/" rel="tag">Communication disorder</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/community/" rel="tag">Community</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/national-speech-language-hearing-month/" rel="tag">National Speech-Language-Hearing Month</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/slp-advocacy/" rel="tag">SLP Advocacy</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/tpt/" rel="tag">TPT</a></div><p>The post <a href="https://mrsspeechonline.com/slp-community-outreach/">Speech-Pathologists at the Heart of Outreach</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://mrsspeechonline.com/slp-community-outreach/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Conquer your Continuing Education (CEUs): A Stress-Free Guide for SLPs</title>
		<link>https://mrsspeechonline.com/asha-ceus-guide-for-slps/</link>
					<comments>https://mrsspeechonline.com/asha-ceus-guide-for-slps/#respond</comments>
		
		<dc:creator><![CDATA[Jennifer]]></dc:creator>
		<pubDate>Tue, 12 Aug 2025 17:22:28 +0000</pubDate>
				<category><![CDATA[Clinical]]></category>
		<category><![CDATA[Compliance & Ethics]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[ASHA]]></category>
		<category><![CDATA[CEUs]]></category>
		<category><![CDATA[Documentation]]></category>
		<category><![CDATA[Tips]]></category>
		<guid isPermaLink="false">https://vmx.erb.mybluehost.me/conquer-your-continuing-education-ceus-a-stress-free-guide-for-slps/</guid>

					<description><![CDATA[<p>Stressed about ASHA CEUs and CCCs? You're not alone! Learn how to make your 3-year renewal stress-free with a clear checklist and tips for earning your 30 hours. What's your favorite way to earn CEUs?</p>
<p>The post <a href="https://mrsspeechonline.com/asha-ceus-guide-for-slps/">Conquer your Continuing Education (CEUs): A Stress-Free Guide for SLPs</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Are ASHA CEUs, PDHs, and CCCs stressing you out? You&#8217;re not alone! But fret no more! Maintaining your Certificate of Clinical Competence (CCC) is crucial for keeping your skills sharp and providing the best possible care to your clients.&nbsp;</p>



<p>This guide will break down the process into a stress-free experience, making CCC renewal a breeze. Keep reading for a link to a treasure trove of free and low-cost CEU opportunities!</p>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:31% auto"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="1024" height="731" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/checklist-7325314_1280-edited.webp" alt="Cartoonish illustration of a hand holding a pen and checking off items on a list displayed on a clipboard, symbolizing task completion and checklist management." class="wp-image-1421 size-full" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/checklist-7325314_1280-edited.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/07/checklist-7325314_1280-edited-300x214.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/checklist-7325314_1280-edited-768x548.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure><div class="wp-block-media-text__content">
<h2 class="wp-block-heading" id="h-staying-sharp-your-3-year-ccc-renewal-checklist">Staying Sharp: Your 3-Year CCC Renewal Checklist</h2>



<p>Every 3 years, you&#8217;ll need to complete specific requirements to maintain your CCC. Here&#8217;s a handy checklist to keep you on track:</p>
</div></div>



<h3 class="wp-block-heading" id="h-earn-30-hours-of-continuing-education">Earn 30 Hours of Continuing Education:</h3>



<p>This is where ASHA CEUs and PDHs come in.</p>



<ul class="wp-block-list">
<li><strong>2 hours</strong>&nbsp;must focus on cultural competency, diversity, equity, or inclusion to ensure you&#8217;re providing inclusive care for all clients.</li>



<li><strong>1 hour&nbsp;</strong>Ethics training is also required.</li>
</ul>



<h3 class="wp-block-heading" id="h-keep-track">Keep track</h3>



<p>You must keep track of your <strong>PDHs</strong> since you can&#8217;t submitted them to the registry.  I would suggest to keep track of all courses, even CEUs, in case they aren&#8217;t submitted properly.</p>



<ul class="wp-block-list">
<li>&nbsp;ASHA offers a&nbsp;<a href="https://www.asha.org/siteassets/ce/ce-calculation-worksheets.xlsx" target="_blank" rel="noreferrer noopener">free PDH tracking spreadsheet</a>&nbsp;to help you track your PDHs.&nbsp;</li>



<li>You will need a certificate of completion for each course or a college transcript if they are not submitted to the registry, in the case of an audit.
<ul class="wp-block-list">
<li>If a certificate of completion is not offered, then you can fill out a&nbsp;<a href="https://www.asha.org/siteassets/uploadedfiles/verificationofattendance.pdf" target="_blank" rel="noreferrer noopener">Verification of Attendance</a>&nbsp;form.</li>
</ul>
</li>
</ul>



<h3 class="wp-block-heading" id="h-submit-a-compliance-form">Submit a Compliance Form</h3>



<p>When you renew, you simple check that you completed your Continuing Education. This is just you verifying that you completed all hours.</p>



<ul class="wp-block-list">
<li>&nbsp;ASHA doesn&#8217;t require courses to be listed, or supporting documentation, unless you are Audited. Here is the&nbsp;<a href="https://www.asha.org/siteassets/uploadedfiles/certification/certrecordkeepingform.pdf" target="_blank" rel="noreferrer noopener">official compliance audit form</a>.</li>
</ul>



<h3 class="wp-block-heading" id="h-pay-nbsp-annual-dues-or-fee">Pay&nbsp;<a href="https://www.asha.org/renew/new-dues-information/" target="_blank" rel="noreferrer noopener">Annual Dues or Fee</a></h3>



<ul class="wp-block-list">
<li> Maintain your ASHA membership, increased to $250 for 2025.</li>



<li><strong>Uphold the ASHA Code of Ethics</strong>: Stay professional and ethical in your practice.</li>
</ul>



<h2 class="wp-block-heading" id="h-understanding-asha-ceus">Understanding ASHA CEUs</h2>



<figure class="wp-block-image alignright size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="682" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/working-6636355_1280-1024x682.webp" alt="Stock stylized illustration of a man sitting at a desk with a large monitor, leaning back in an office chair with hands behind his head and a calm, smiling expression, symbolizing relaxed achievement or stress-free work." class="wp-image-568" style="width:243px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/working-6636355_1280-1024x682.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/07/working-6636355_1280-300x200.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/working-6636355_1280-768x512.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/07/working-6636355_1280.webp 1280w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Understanding ASHA CEUs can be a calm and straightforward process when you know the standards and how to earn them.</figcaption></figure>



<ul class="wp-block-list">
<li><strong>The Standard Unit</strong>
<ul class="wp-block-list">
<li><strong>1 CEU = 10 hours</strong> of participation, excluding breaks.</li>
</ul>
</li>



<li><strong>How to Get Them:</strong>&nbsp;Attend an ASHA-approved course and request CEUs. The provider will submit your information to the ASHA CE Registry, which awards the credits and updates your transcript.&nbsp;</li>



<li><strong>Important:</strong>&nbsp;CEUs can only be earned through the ASHA CE Registry, which is an additional fee on top of the renewal fee.</li>
</ul>



<h2 class="wp-block-heading" id="h-pdhs-beyond-asha-ceus">PDHs: Beyond ASHA CEUs</h2>



<p>PDHs track your participation in various learning activities beyond ASHA-approved CEUs. These activities can still enhance your knowledge and skills as an SLP and count toward the continuing education requirement.</p>



<ul class="wp-block-list">
<li><strong>1 PDH = 60 minutes</strong>&nbsp;of active learning or participation.  
<ul class="wp-block-list">
<li><strong>Non-ASHA CEU Activities</strong></li>



<li>PDHs for activities that aren&#8217;t ASHA courses but approved but contribute to your development (e.g., conferences, workshops, teacher professional development, self-study).  Find the full list here:  <a href="https://www.asha.org/certification/pdhs-for-asha-certification/">https://www.asha.org/certification/pdhs-for-asha-certification/</a></li>
</ul>
</li>



<li><strong>Academic Coursework:</strong>&nbsp;PDHs can also be earned through coursework (check conversion rates for semesters and quarters).</li>
</ul>



<h2 class="wp-block-heading" id="h-benefits-of-asha-ceu-registry">Benefits of ASHA CEU registry:</h2>



<ul class="wp-block-list">
<li><strong>Convenience:</strong>&nbsp;Track your progress easily and securely through the ASHA CE Registry.</li>



<li><strong>State Licensure:</strong>&nbsp;Most state boards accept the ASHA CE transcript for license renewal
<ul class="wp-block-list">
<li><strong>Important!</strong>&nbsp;The requirements&nbsp;<strong>may be different</strong>&nbsp;(check your&nbsp;<a href="https://www.asha.org/advocacy/state/" target="_blank" rel="noreferrer noopener">state&#8217;s specifics</a>).</li>
</ul>
</li>



<li><strong>CCC Maintenance</strong>: ASHA CEUs fulfill the 30-hour requirement for maintaining your CCC without any further documentation.</li>



<li><strong>ACE Award (see more below)</strong>: requires CE Registry</li>
</ul>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:31% auto"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://mrsspeechonline.com/wp-content/uploads/2024/07/1-1024x1024.webp" alt="Cover image for the 'Multi-State &amp; Organization CE Tracker' TPT product, showing the title overlaid on a collage background of various tables, tracking dials, and Google Sheet interface elements from the resource, symbolizing CEU progress monitoring." class="wp-image-1420 size-full" srcset="https://mrsspeechonline.com/wp-content/uploads/2024/07/1-1024x1024.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2024/07/1-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2024/07/1-150x150.webp 150w, https://mrsspeechonline.com/wp-content/uploads/2024/07/1-768x768.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2024/07/1.webp 1080w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure><div class="wp-block-media-text__content">
<p>Have multiple licensure dates and requirements to worry about?  No problem with this <strong><a href="https://www.teacherspayteachers.com/Product/Multi-State-Organization-CE-Tracker-Visual-Google-Sheet-12794697"><strong></strong></a><strong><a href="https://www.teacherspayteachers.com/Product/Multi-State-Organization-CE-Tracker-Visual-Google-Sheet-12794697">Multi-State &amp; Organization CE Tracker | Visual Google Sheet</a></strong></strong>.  Designed for SLPs and other professionals, this intuitive tool simplifies compliance with one-time data entry, at-a-glance progress gauges, and smart expiration alerts. Transform your CE tracking from a chore into a simple, stress-free process, saving you invaluable time and boosting compliance.</p>
</div></div>



<h2 class="wp-block-heading" id="h-free-and-low-cost-ceu-resources-to-the-rescue">Free and Low-Cost CEU Resources to the Rescue!</h2>



<figure class="wp-block-image alignright size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="682" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/wallet-3548021_1280-1024x682.webp" alt="Stock photo of hands holding an open brown leather wallet that is visibly empty, symbolizing financial constraint or the need for budget-friendly options." class="wp-image-560" style="width:243px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/wallet-3548021_1280-1024x682.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/07/wallet-3548021_1280-300x200.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/wallet-3548021_1280-768x512.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/07/wallet-3548021_1280.webp 1280w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Conquer your CEU renewal without breaking the bank, with a little help from free and low-cost resources!</figcaption></figure>



<p>Conquer your CCC renewal without breaking the bank! We&#8217;ve compiled a comprehensive list of free and low-cost CEU resources. Check out my&nbsp;<a href="https://mrsspeechonline.com/free-low-cost-ceus/">Free CEUs</a>&nbsp;page for a mix of valuable options to fit your learning preferences and budget.</p>



<h2 class="wp-block-heading" id="h-the-asha-award-for-continuing-education-ace-going-the-extra-mile">The ASHA Award for Continuing Education (ACE): Going the Extra Mile</h2>



<figure class="wp-block-image alignleft size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="778" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/certificate-23399_1280-1024x778.webp" alt="Cartoonish illustration of a generic award, featuring a gold star and a ribbon, symbolizing recognition and achievement." class="wp-image-502" style="width:197px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/certificate-23399_1280-1024x778.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/07/certificate-23399_1280-300x228.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/certificate-23399_1280-768x584.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/07/certificate-23399_1280.webp 1280w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Going the extra mile: Earn the prestigious ASHA Award for Continuing Education (ACE) for your dedication to lifelong learning.</figcaption></figure>



<p><strong>The ASHA Award for Continuing Education (ACE)</strong>&nbsp;recognizes SLPs who go above and beyond by completing<strong>&nbsp;70 hours (7.0 CEUs)&nbsp;</strong>of ASHA-approved continuing education courses within 3 years. This prestigious award demonstrates your dedication to lifelong learning and excellence in the field.&nbsp; However, this only includes courses on the CE Registry.</p>



<p>Note that ASHA says to allow at least 90 days from the date you completed your last course before receiving your notification of the ACE award.&nbsp; &nbsp;In my experience, courses show up on my CE transcript months before they show up on my ACE transcript.&nbsp;&nbsp;</p>



<p>Benefits of the ACE Award include recognition on the ASHA website, award documentation, name submission to the state association, and 10% discount on ASHA&#8217;s professional liability insurance.</p>



<h2 class="wp-block-heading" id="h-you-got-your-asha-ceus-handled">You Got Your ASHA CEUs Handled!</h2>



<p>By staying up-to-date with these guidelines and taking advantage of the available resources, you can ensure your CCC remains active and your skills remain sharp! This allows you to continue providing top-notch care to your clients. </p>



<p>Feeling overwhelmed? Share this post with your fellow SLPs, and don&#8217;t hesitate to ask any questions in the comments below!</p>



<div class="wp-block-group is-layout-constrained wp-block-group-is-layout-constrained">
<figure class="wp-block-image aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="810" height="169" src="https://i0.wp.com/vmx.erb.mybluehost.me/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp?fit=810%2C169&amp;ssl=1" alt="Mrs. Speech Signature" class="wp-image-804" style="width:364px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp 810w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-300x63.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-768x160.webp 768w" sizes="auto, (max-width: 810px) 100vw, 810px" /></figure>



<div class="wp-block-group is-content-justification-center is-nowrap is-layout-flex wp-container-core-group-is-layout-23441af8 wp-block-group-is-layout-flex">
<figure class="wp-block-image size-full is-resized"><a href="https://www.facebook.com/profile.php?id=61556892726241" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="388" height="398" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp" alt="facebook icon" class="wp-image-815" style="width:48px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp 388w, https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918-292x300.webp 292w" sizes="auto, (max-width: 388px) 100vw, 388px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.instagram.com/mrs.speechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="418" height="408" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp" alt="Instagram Icon" class="wp-image-818" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp 418w, https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939-300x293.webp 300w" sizes="auto, (max-width: 418px) 100vw, 418px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.pinterest.com/mrsspeechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="413" height="410" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp" alt="pinterest icon" class="wp-image-816" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp 413w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-300x298.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-150x150.webp 150w" sizes="auto, (max-width: 413px) 100vw, 413px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.linkedin.com/in/jennifer-tillock-821999287/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="402" height="402" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp" alt="LinkedIn Icon" class="wp-image-821" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp 402w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-150x150.webp 150w" sizes="auto, (max-width: 402px) 100vw, 402px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="http://www.youtube.com/@Mrs.Speech-wk4mr" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="429" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp" alt="YouTube icon" class="wp-image-817" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp 429w, https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232-300x291.webp 300w" sizes="auto, (max-width: 429px) 100vw, 429px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.teacherspayteachers.com/store/mrs-speech" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="423" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp" alt="TeachersPayTeachers Icon" class="wp-image-822" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp 423w, https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756-300x295.webp 300w" sizes="auto, (max-width: 423px) 100vw, 423px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="414" height="413" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp" alt="Mrs. Speech Books Icon" class="wp-image-1322" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp 414w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-150x150.webp 150w" sizes="auto, (max-width: 414px) 100vw, 414px" /></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="387" height="377" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp" alt="MailTo Icon" class="wp-image-1326" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp 387w, https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307-300x292.webp 300w" sizes="auto, (max-width: 387px) 100vw, 387px" /></figure>
</div>
</div>



<p class="icon-attribution" style="font-size: 0.6em; font-style: italic;">
    Social Media Icons: <a href="https://www.freepik.com" target="_blank" rel="noopener">designed by rawpixel.com &#8211; Freepik.com</a>
</p>



<div style="height:47px" aria-hidden="true" class="wp-block-spacer"></div>


<div style="color:#db820e;font-style:normal;font-weight:300" class="taxonomy-post_tag has-text-align-center has-link-color wp-elements-e81afc2be6272024545412bcb750c79c wp-block-post-terms has-text-color"><a href="https://mrsspeechonline.com/tag/asha/" rel="tag">ASHA</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/ceus/" rel="tag">CEUs</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/documentation/" rel="tag">Documentation</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/tips/" rel="tag">Tips</a></div>


<p></p>
<p>The post <a href="https://mrsspeechonline.com/asha-ceus-guide-for-slps/">Conquer your Continuing Education (CEUs): A Stress-Free Guide for SLPs</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://mrsspeechonline.com/asha-ceus-guide-for-slps/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI &#038; SLPs Series, Part 1:  Clinical Data Privacy</title>
		<link>https://mrsspeechonline.com/ai-slps-part-1-client-data-privacy/</link>
					<comments>https://mrsspeechonline.com/ai-slps-part-1-client-data-privacy/#respond</comments>
		
		<dc:creator><![CDATA[Jennifer]]></dc:creator>
		<pubDate>Tue, 12 Aug 2025 17:22:19 +0000</pubDate>
				<category><![CDATA[Clinical]]></category>
		<category><![CDATA[Compliance & Ethics]]></category>
		<category><![CDATA[Business Associate Agreement]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<guid isPermaLink="false">https://mrsspeechonline.com/ai-slps-part-1-client-data-privacy/</guid>

					<description><![CDATA[<p>Worried about AI and PHI? This guide explains why general-purpose AI tools are a HIPAA violation for SLPs, even with de-identified notes, and why you need a BAA to use them compliantly. What's one of your biggest concerns about using AI in your practice?</p>
<p>The post <a href="https://mrsspeechonline.com/ai-slps-part-1-client-data-privacy/">AI &amp; SLPs Series, Part 1:  Clinical Data Privacy</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" id="h-ai-models-client-data-amp-hipaa-compliance-what-slps-need-to-know">AI Models, Client Data, &amp; HIPAA Compliance: What SLPs Need to Know</h2>



<p>Welcome back! Are you ready to dig deep in to AI and client privacy? In our recent &#8216;<a href="https://mrsspeechonline.com/hipaa-compliance-at-home" target="_blank" rel="noreferrer noopener">HIPAA Compliance At Home</a>&#8216; article, safeguarding protected health information (PHI) is key. It&#8217;s not just a professional guideline; it&#8217;s a fundamental ethical responsibility and a legal imperative under laws like HIPAA. Now we narrow our focus on HIPAA and the use of AI tools.</p>



<h3 class="wp-block-heading" id="h-the-critical-importance-of-client-data-privacy-hipaa">The Critical Importance of Client Data Privacy (HIPAA)</h3>



<figure class="wp-block-image alignleft size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="571" src="https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-data-privacy-security-risk-1024x571.jpg" alt="A hooded silhouette figure against a dark blue background with binary code, overlaid with circuit lines and a prominent blue padlock, representing the critical need for AI &amp; data privacy and cybersecurity in clinical settings." class="wp-image-2877" style="width:258px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-data-privacy-security-risk-1024x571.jpg 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-data-privacy-security-risk-300x167.jpg 300w, https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-data-privacy-security-risk-768x428.jpg 768w, https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-data-privacy-security-risk.jpg 1280w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">This image powerfully symbolizes the challenges of AI &amp; data privacy for SLPs. It&#8217;s a stark reminder of the digital security risks when handling Protected Health Information (PHI) with AI tools.</figcaption></figure>



<p>Now, we&#8217;ll examine one of the most critical concerns for us as clinicians when dealing with AI: HIPPA and PHI. Specifically, our clients&#8217; sensitive health information must be kept private and secure when interacting with AI tools. As Speech-Language Pathologists, safeguarding protected health information (PHI) is a fundamental ethical and legal responsibility under laws like HIPAA.</p>



<p>The rapid rise of AI brings with it questions about how these models learn from vast datasets.  What are the implications for the confidentiality and security of the clinical data we manage daily? Is any interaction with any AI tool a HIPAA violation? How can we ensure our client&#8217;s trust isn&#8217;t compromised?&nbsp;</p>



<p>In this post, we&#8217;ll unpack these crucial issues of AI and HIPPA for SLPs. We&#8217;ll examine how AI actually learns from massive amounts of text and data. Then we&#8217;ll tackle how to keep PHI data private and secure with AI use.&nbsp;&nbsp;</p>



<p><strong>Don&#8217;t forget to take our poll at the end!&nbsp;</strong>&nbsp;Results will be shared in Part 8.</p>



<h3 class="wp-block-heading" id="h-the-human-brain-and-clinical-data-processing-a-parallel-perspective">The Human Brain and Clinical Data Processing: A Parallel Perspective</h3>



<figure class="wp-block-image alignright size-large is-resized"><img loading="lazy" decoding="async" width="1024" height="576" src="https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-human-learning-parallel-comparison-1024x576.png" alt="An orange segmented human brain (representing human learning) with a background of text and a circuit board/AI chip (representing AI models) with a background of computer code, connected by the &quot;approximately equal&quot; symbol (≈)." class="wp-image-2878" style="width:447px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-human-learning-parallel-comparison-1024x576.png 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-human-learning-parallel-comparison-300x169.png 300w, https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-human-learning-parallel-comparison-768x432.png 768w, https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-human-learning-parallel-comparison-1536x864.png 1536w, https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-human-learning-parallel-comparison-1320x743.png 1320w, https://mrsspeechonline.com/wp-content/uploads/2025/09/slp-ai-human-learning-parallel-comparison.png 1920w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">A visual parallel: How the pattern-recognition learning of AI models compares to the language learning of the human brain.</figcaption></figure>



<p>As Speech-Language Pathologists, we constantly process and learn from clinical information. From graduate school to continuing education, supervision, and countless client interactions, our brains process vast clinical data.  We are immersed in a sea of de-identified case studies, research articles, diagnostic reports, and therapy session data. We absorb this input, identify patterns, recognize clinical presentations, and synthesize effective intervention strategies.</p>



<p>This exposure allows us to develop our clinical judgment, personalize therapy plans, and communicate professionally about our clients&#8217; needs. We don&#8217;t memorize every detail of every case. Instead, we internalize the underlying principles and relationships, allowing us to generate our own unique, ethical, and individualized clinical insights. This human learning process involves drawing inferences from numerous, often sensitive, pieces of information.</p>



<h3 class="wp-block-heading" id="h-how-ai-learns-pattern-recognition-on-a-massive-scale">How AI Learns: Pattern Recognition on a Massive Scale</h3>



<figure class="wp-block-image alignleft size-medium is-resized"><img loading="lazy" decoding="async" width="300" height="200" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/digitization-5180477_1280-300x200.webp" alt="A close-up view of a digital screen filled with glowing blue binary code (zeros and ones), representing data processing and AI learning relating to PHI" class="wp-image-147" style="width:346px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/digitization-5180477_1280-300x200.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/digitization-5180477_1280-768x512.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/06/digitization-5180477_1280.webp 1024w" sizes="auto, (max-width: 300px) 100vw, 300px" /></figure>



<p>While humans and AI language models learn differently, they both rely on an immense quantity of input. AI language models are trained on enormous datasets of text and code – encompassing millions of books, articles, websites, and more. </p>



<h4 class="wp-block-heading" id="h-ai-training-leveraging-vast-datasets">AI Training:  Leveraging Vast Datasets</h4>



<p>Healthcare AI datasets include anonymized data. This covers research, journals, guidelines, and de-identified clinical records. It&#8217;s like they&#8217;ve &#8220;read&#8221; the entire internet and a specialized library of medical and clinical literature.</p>



<h4 class="wp-block-heading" id="h-beyond-memorization-the-art-of-pattern-synthesis">Beyond Memorization:  The Art of Pattern Synthesis</h4>



<p>However, during this training process, the AI doesn&#8217;t typically &#8220;download&#8221; and store individual client records or copyrighted works. Instead, AI analyzes data for patterns. It identifies word probabilities, grammar, and style.</p>



<p>It&#8217;s not directly copying and regurgitating.  Instead, it is learning the underlying rules of language and the common ways information is conveyed, though without real meaning. When text is generated (e.g., a SOAP note), it&#8217;s not pulling verbatim from a specific client&#8217;s file. Instead, it&#8217;s using patterns to construct new sequences of words that are statistically probable and relevant to your prompt. It&#8217;s synthesizing information into something novel.</p>



<p>We will dive more into how AI works in Part 3 of the series.  However, the key takeaway for SLPs is that the data you input for a specific task may violate privacy and security.</p>



<h3 class="wp-block-heading" id="h-the-imperative-of-data-privacy-and-security-for-slps-hipaa-and-beyond">The Imperative of Data Privacy and Security for SLPs (HIPAA and Beyond)</h3>



<figure class="wp-block-image alignright size-medium is-resized"><img loading="lazy" decoding="async" width="813" height="513" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/cybersecurity-9302462_1280-edited.webp" alt="An illustration of a shield protecting various digital devices and login methods, representing comprehensive cybersecurity and secure data access when using ai for client data." class="wp-image-1606" style="width:366px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/cybersecurity-9302462_1280-edited.webp 813w, https://mrsspeechonline.com/wp-content/uploads/2025/07/cybersecurity-9302462_1280-edited-300x189.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/cybersecurity-9302462_1280-edited-768x485.webp 768w" sizes="auto, (max-width: 813px) 100vw, 813px" /></figure>



<p>For SLPs, the core legal and ethical imperative is HIPAA (Health Insurance Portability and Accountability Act). This legislation dictates how protected health information (PHI) must be handled, stored, and transmitted. The myth from our next post – that all AI use inherently violates HIPAA – stems from a valid concern about PHI.</p>



<p>This is why it&#8217;s crucial to differentiate the tools you use for PHI and non-PHI purposes.  Even seemingly &#8220;de-identified&#8221; notes can still be problematic with AI and HIPAA for SLPs.</p>



<h4 class="wp-block-heading" id="h-public-general-purpose-ai-tools-e-g-standard-chatgpt-google-gemini"><strong>Public/General-Purpose AI Tools (e.g., standard ChatGPT, Google Gemini)</strong></h4>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:32% auto"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="300" height="173" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/ai-generated-9106907_1280-300x173.webp" alt="A prominent red digital padlock featuring a white medical cross, set against a circuit board background, signifying critical HIPAA compliance for healthcare data when using AI" class="wp-image-151 size-full" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/ai-generated-9106907_1280-300x173.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/ai-generated-9106907_1280.webp 320w" sizes="auto, (max-width: 300px) 100vw, 300px" /></figure><div class="wp-block-media-text__content">
<p>These tools are&nbsp;<strong>NOT HIPAA compliant&nbsp;</strong>by default. They are designed for general use, not for processing sensitive health information. This AI use directly impacts client data security.  You must have a BAA to use them to protect PHI.  </p>
</div></div>



<h4 class="wp-block-heading" id="h-the-de-identification-trap"><strong>The &#8220;De-identification&#8221; Trap</strong></h4>



<p>You might believe you&#8217;ve removed all identifying information when using AI, by leaving out a name, specific dates, or location. However, HIPAA&#8217;s definition of de-identification (the &#8220;Safe Harbor&#8221; method) is incredibly stringent. It requires removing 18 specific identifiers, and crucially, &#8220;any other unique identifying number, characteristic, or code.&#8221;</p>



<h5 class="wp-block-heading" id="h-your-session-notes-even-without-a-name-contain-highly-specific-clinical-details-and-narrative-elements"><strong>Your session notes, even without a name, contain highly specific clinical details and narrative elements</strong>.</h5>



<p>For example:  </p>



<ul class="wp-block-list">
<li>&#8220;Data on /s/ blend in the initial position was 82% accurate.&#8221; </li>



<li>&#8220;Discussed pictures from her trip to Chicago.&#8221;</li>



<li>&#8220;/k/ sounds 50% accurate at word level.&#8221; </li>



<li>&#8220;Cued /k/ by saying &#8216;in your throat&#8217;.&#8221; </li>



<li>&#8220;Continues to answer &#8216;I don&#8217;t know&#8217; and look to her parent&#8221;). </li>
</ul>



<p>These specific clinical observations, unique behaviors, and personal anecdotes (like the Chicago trip)  ARE PHI.  They can, taken together, make a client potentially re-identifiable.  Look at it through the lens of someone familiar with your caseload, or who has other publicly available information.</p>



<h5 class="wp-block-heading" id="h-even-if-your-account-is-anonymous-or-you-remove-all-obvious-identifiers-you-may-still-violate-hippa"><strong>Even if your account is anonymous, or you remove all &#8220;obvious&#8221; identifiers</strong>, you may still violate HIPPA. </h5>



<p>Transmitting such detailed, potentially re-identifiable information to a non-HIPAA compliant service constitutes an impermissible disclosure. An anonymous user account doesn&#8217;t change the fact that the AI service itself is not operating under HIPAA&#8217;s legal framework.</p>



<h4 class="wp-block-heading" id="h-no-business-associate-agreement-baa"><strong>No Business Associate Agreement (BAA)</strong></h4>



<p>This is the ultimate barrier. Under HIPAA, covered entities sharing PHI with service providers need a BAA. This includes re-identifiable data. Public (free) AI models like ChatGPT and Gemini do not offer or sign BAAs.&nbsp;<strong>Without this legal contract, you are essentially exposing PHI to the AI, an unsecured third party, which is a clear HIPAA violation.</strong> </p>



<p>Learn more about BAAs in <a href="https://mrsspeechonline.com/slp-business-associate-agreement-hipaa-guide" target="_blank" rel="noreferrer noopener">Navigating Business Associate Agreements as an SLP:  Your HIPAA BAA Guide</a>.</p>



<h3 class="wp-block-heading" id="h-transparency-and-due-diligence-your-role">Transparency and Due Diligence: Your Role</h3>



<figure class="wp-block-image alignright size-full is-resized"><img loading="lazy" decoding="async" width="864" height="576" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/iphone-4699057_1280-edited.webp" alt="An illustration depicting a person using a laptop with a VPN symbol and lock icon, symbolizing the importance of secure online practices especially when dealing with PHI and AI." class="wp-image-993" style="width:354px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/iphone-4699057_1280-edited.webp 864w, https://mrsspeechonline.com/wp-content/uploads/2025/07/iphone-4699057_1280-edited-300x200.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/iphone-4699057_1280-edited-768x512.webp 768w" sizes="auto, (max-width: 864px) 100vw, 864px" /></figure>



<p>As AI evolves, so do the guidelines and expectations for its use in healthcare. There are ongoing debates and legal discussions about the broader implications of AI training data.  Legislators and leading technology experts are investigating issues of intellectual property and potential re-identification even from de-identified datasets. For SLPs, the immediate action points are:</p>



<ul class="wp-block-list">
<li><strong>NEVER input any PHI  into non-HIPAA compliant AI tools like public (free) ChatGPT or Google Gemini.</strong>&nbsp; This is because even your best efforts at de-identification are unlikely to meet HIPAA&#8217;s stringent standards for PHI.  Therefore, the lack of a BAA creates an immediate compliance risk.</li>



<li><strong>Exercise extreme due diligence</strong>&nbsp;when considering specialized AI tools for your practice. Ask critical questions about security protocols, data handling, BAAs, and data storage and use policies. To help you, in upcoming parts of this series (see below), we&#8217;ll delve deeper into finding compliant tools.  We will explore what secure AI solutions might look like for SLP practice.</li>



<li><strong>Stay informed</strong>&nbsp;about professional guidelines and emerging legal interpretations regarding AI &amp; HIPPA for SLPs from your governing professional bodies.</li>
</ul>



<p>We use predictive technology daily, with autofill, grammar checkers, and search engines. While they are are not typically thought of as AI, these tools still demonstrate pattern recognition. Full-fledged generative AI is even more advanced version of these. We must remain vigilant with data privacy and security, especially in a clinical context.</p>



<h3 class="wp-block-heading" id="h-ready-to-navigate-ai-with-confidence"><strong>Ready to Navigate AI with Confidence?</strong></h3>



<p>The potential of AI is exciting, but vetting tools for HIPAA compliance can feel like deciphering a secret code. To make it easier, I&#8217;ve created a&nbsp;<strong>free, in-depth checklist</strong>!  It can help guide you through finding and evaluating AI solutions that truly safeguard your clients&#8217; Protected Health Information (PHI).</p>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:23% auto"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="1024" height="670" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/Download.webp" alt="A red, starburst-shaped graphic with bold yellow text &quot;FREE!&quot; and green text &quot;DOWNLOAD&quot;, serving as a call to action for a free resource." class="wp-image-104 size-full" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/Download.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Download-300x196.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Download-768x503.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure><div class="wp-block-media-text__content">
<h4 class="wp-block-heading" id="h-sign-up-to-download-your-free-hipaa-compliant-ai-tool-vetting-checklist-for-slps"><strong>Sign up to Download Your Free HIPAA-Compliant AI Tool Vetting Checklist for SLPs!</strong></h4>
</div></div>


  
  
  <div class="
    mailpoet_form_popup_overlay
      "></div>
  <div
    id="mailpoet_form_2"
    class="
      mailpoet_form
      mailpoet_form_html
      mailpoet_form_position_
      mailpoet_form_animation_
    "
      >

    <style type="text/css">
     #mailpoet_form_2 .mailpoet_form {  }
#mailpoet_form_2 form { margin-bottom: 0; }
#mailpoet_form_2 p.mailpoet_form_paragraph.last { margin-bottom: 0px; }
#mailpoet_form_2 h2.mailpoet-heading { margin: -10px 0 10px 0; }
#mailpoet_form_2 .mailpoet_column_with_background { padding: 10px; }
#mailpoet_form_2 .mailpoet_form_column:not(:first-child) { margin-left: 20px; }
#mailpoet_form_2 .mailpoet_paragraph { line-height: 20px; margin-bottom: 20px; }
#mailpoet_form_2 .mailpoet_segment_label, #mailpoet_form_2 .mailpoet_text_label, #mailpoet_form_2 .mailpoet_textarea_label, #mailpoet_form_2 .mailpoet_select_label, #mailpoet_form_2 .mailpoet_radio_label, #mailpoet_form_2 .mailpoet_checkbox_label, #mailpoet_form_2 .mailpoet_list_label, #mailpoet_form_2 .mailpoet_date_label { display: block; font-weight: normal; }
#mailpoet_form_2 .mailpoet_text, #mailpoet_form_2 .mailpoet_textarea, #mailpoet_form_2 .mailpoet_select, #mailpoet_form_2 .mailpoet_date_month, #mailpoet_form_2 .mailpoet_date_day, #mailpoet_form_2 .mailpoet_date_year, #mailpoet_form_2 .mailpoet_date { display: block; }
#mailpoet_form_2 .mailpoet_text, #mailpoet_form_2 .mailpoet_textarea { width: 200px; }
#mailpoet_form_2 .mailpoet_checkbox {  }
#mailpoet_form_2 .mailpoet_submit {  }
#mailpoet_form_2 .mailpoet_divider {  }
#mailpoet_form_2 .mailpoet_message {  }
#mailpoet_form_2 .mailpoet_form_loading { width: 30px; text-align: center; line-height: normal; }
#mailpoet_form_2 .mailpoet_form_loading > span { width: 5px; height: 5px; background-color: #5b5b5b; }#mailpoet_form_2{border: 5px solid #c07000;border-radius: 40px;background: linear-gradient(180deg,rgb(255,243,214) 0%,rgb(255,255,255) 100%);color: #240002;text-align: left;}#mailpoet_form_2 form.mailpoet_form {padding: 10px;}#mailpoet_form_2{width: 100%;}#mailpoet_form_2 .mailpoet_message {margin: 0; padding: 0 20px;}
        #mailpoet_form_2 .mailpoet_validate_success {color: #00d084}
        #mailpoet_form_2 input.parsley-success {color: #00d084}
        #mailpoet_form_2 select.parsley-success {color: #00d084}
        #mailpoet_form_2 textarea.parsley-success {color: #00d084}
      
        #mailpoet_form_2 .mailpoet_validate_error {color: #cf2e2e}
        #mailpoet_form_2 input.parsley-error {color: #cf2e2e}
        #mailpoet_form_2 select.parsley-error {color: #cf2e2e}
        #mailpoet_form_2 textarea.textarea.parsley-error {color: #cf2e2e}
        #mailpoet_form_2 .parsley-errors-list {color: #cf2e2e}
        #mailpoet_form_2 .parsley-required {color: #cf2e2e}
        #mailpoet_form_2 .parsley-custom-error-message {color: #cf2e2e}
      #mailpoet_form_2 .mailpoet_paragraph.last {margin-bottom: 0} @media (max-width: 500px) {#mailpoet_form_2 {background: linear-gradient(180deg,rgb(255,243,214) 0%,rgb(255,255,255) 100%);}} @media (min-width: 500px) {#mailpoet_form_2 .last .mailpoet_paragraph:last-child {margin-bottom: 0}}  @media (max-width: 500px) {#mailpoet_form_2 .mailpoet_form_column:last-child .mailpoet_paragraph:last-child {margin-bottom: 0}} 
    </style>

    <form
      target="_self"
      method="post"
      action="https://mrsspeechonline.com/wp-admin/admin-post.php?action=mailpoet_subscription_form"
      class="mailpoet_form mailpoet_form_form mailpoet_form_html"
      novalidate
      data-delay=""
      data-exit-intent-enabled=""
      data-font-family=""
      data-cookie-expiration-time=""
    >
      <input type="hidden" name="data[form_id]" value="2" />
      <input type="hidden" name="token" value="b7980c8f49" />
      <input type="hidden" name="api_version" value="v1" />
      <input type="hidden" name="endpoint" value="subscribers" />
      <input type="hidden" name="mailpoet_method" value="subscribe" />

      <label class="mailpoet_hp_email_label" style="display: none !important;">Please leave this field empty<input type="email" name="data[email]"/></label><h3 class="mailpoet-heading  mailpoet-has-font-size" style="text-align: center; color: #240002; font-size: 36px">Want exclusive freebies?</h3>
<div class="mailpoet_paragraph "><style>input[name="data[form_field_ZTYwMWUzMTY0ZDU0X2ZpcnN0X25hbWU=]"]::placeholder{color:#5b8ba7;opacity: 1;}</style><input type="text" autocomplete="given-name" class="mailpoet_text" id="form_first_name_2" name="data[form_field_ZTYwMWUzMTY0ZDU0X2ZpcnN0X25hbWU=]" title="First Name" value="" style="width:100%;box-sizing:border-box;background-color:#ffffff;border-style:solid;border-radius:10px !important;border-width:1px;border-color:#313131;padding:4px;margin: 0 auto 0 0;font-family:&#039;Ubuntu&#039;;font-size:16px;line-height:1.5;height:auto;color:#5b8ba7;" data-automation-id="form_first_name"  placeholder="First Name" aria-label="First Name" data-parsley-errors-container=".mailpoet_error_1uwjq" data-parsley-names='[&quot;Please specify a valid name.&quot;,&quot;Addresses in names are not permitted, please add your name instead.&quot;]'/><span class="mailpoet_error_1uwjq"></span></div>
<div class="mailpoet_paragraph "><style>input[name="data[form_field_ZTU2MDYxYjE3Njk1X2VtYWls]"]::placeholder{color:#5b8ba7;opacity: 1;}</style><input type="email" autocomplete="email" class="mailpoet_text" id="form_email_2" name="data[form_field_ZTU2MDYxYjE3Njk1X2VtYWls]" title="Email Address" value="" style="width:100%;box-sizing:border-box;background-color:#ffffff;border-style:solid;border-radius:10px !important;border-width:1px;border-color:#313131;padding:4px;margin: 0 auto 0 0;font-family:&#039;Ubuntu&#039;;font-size:16px;line-height:1.5;height:auto;color:#5b8ba7;" data-automation-id="form_email"  placeholder="Email Address *" aria-label="Email Address *" data-parsley-errors-container=".mailpoet_error_ugay5" data-parsley-required="true" required aria-required="true" data-parsley-minlength="6" data-parsley-maxlength="150" data-parsley-type-message="This value should be a valid email." data-parsley-required-message="This field is required."/><span class="mailpoet_error_ugay5"></span></div>
<div class="mailpoet_paragraph "><input type="submit" class="mailpoet_submit" value="I want my freebies!" data-automation-id="subscribe-submit-button" data-font-family='Ubuntu' style="width:100%;box-sizing:border-box;background-color:#c07000;border-style:solid;border-radius:10px !important;border-width:1px;padding:4px;margin: 0 auto 0 0;font-family:&#039;Ubuntu&#039;;font-size:20px;line-height:1.5;height:auto;color:#ffffff;border-color:transparent;font-weight:bold;" /><span class="mailpoet_form_loading"><span class="mailpoet_bounce1"></span><span class="mailpoet_bounce2"></span><span class="mailpoet_bounce3"></span></span></div>
<p class="mailpoet_form_paragraph  mailpoet-has-font-size" style="text-align: center; color: #240002; font-size: 14px; line-height: 1.2"><span style="font-family:" data-font="" class="mailpoet-has-font">We don’t spam! Read our <a href="https://mrsspeechonline.com/privacy-policy/" data-type="link" data-id="https://mrsspeechonline.com/privacy-policy/">privacy policy</a> for more info.</span></p>
<p class="mailpoet_form_paragraph  mailpoet-has-font-size" style="text-align: center; font-size: 13px">See the <a href="https://mrsspeechonline.com/subscription-options-guide/" data-type="link" data-id="https://mrsspeechonline.com/subscription-options-guide/">subscription guide</a> for more information!</p>

      <div class="mailpoet_message">
        <p class="mailpoet_validate_success"
                style="display:none;"
                >Check your inbox or spam folder to confirm your subscription.
        </p>
        <p class="mailpoet_validate_error"
                style="display:none;"
                >        </p>
      </div>
    </form>

      </div>

  


<h3 class="wp-block-heading" id="h-conclusion-responsible-innovation-in-clinical-practice">Conclusion: Responsible Innovation in Clinical Practice</h3>



<p>The conversation around AI and clinical data is less about AI &#8220;stealing&#8221; in a direct sense.  Instead, it is more about responsible data governance, robust privacy protocols, and unwavering security measures. AI models learn from patterns, not by directly appropriating individual client files, but the data is still there. Therefore, the ethical and legal burden falls squarely on the SLP to ensure their tools adhere to stringent privacy regulations.</p>



<p>We have to understand how AI learns and, more importantly, prioritize HIPAA compliance and PHI security when using AI. Only then can we harness the potential of this technology while upholding our professional obligations and preserving our clients&#8217; trust.</p>



<figure class="wp-block-image alignleft size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="292" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/arrow-1538686_1280.webp" alt="Colorful arrow pointing right with the word &quot;COMMENT&quot; in bold letters." class="wp-image-102" style="width:260px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/arrow-1538686_1280.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/arrow-1538686_1280-300x86.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/arrow-1538686_1280-768x219.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<h4 class="wp-block-heading" id="h-i-want-to-know">I want to know!</h4>



<p>What are your primary strategies for ensuring client data privacy when using AI in your current practice? Do you have questions about vetting AI tools for HIPAA compliance?&nbsp;What is your take on AI &amp; client privacy for SLPs?</p>



<p><strong>Share your thoughts in the comments below, and then share your perspective in our quick poll!</strong>&nbsp;Results will be shared at the end of the series!</p>



<h3 class="wp-block-heading" id="h-ai-amp-client-privacy-part-1-poll"><a href="https://docs.google.com/forms/d/e/1FAIpQLSfFxnJDWwioy_I3f8InpFManjUY34GVEL-9VMf2rGwNak64tw/viewform?usp=header" target="_blank" rel="noreferrer noopener">AI &amp; Client Privacy Part 1 Poll</a></h3>



<p><strong>To keep the poll fair and ensure unique responses, a Google account sign-in is required</strong>.  <strong>Be assured, however, your email address is neither collected nor visible to me.</strong></p>



<h3 class="wp-block-heading" id="h-the-ai-amp-slps-series-your-comprehensive-guide">The AI &amp; SLPs Series: Your Comprehensive Guide</h3>



<p>Welcome to the AI &amp; SLPs Series! Over the next eight weeks, we&#8217;ll delve deep into how Artificial Intelligence is shaping the world of speech-language pathology. Here’s what you can expect:</p>



<ul class="wp-block-list">
<li><strong>Part 1: AI &amp; Clinical Data Privacy</strong>
<ul class="wp-block-list">
<li>This foundational post explores AI training data, client privacy, and HIPAA compliance for SLPs, including the non-negotiable role of BAAs.</li>
</ul>
</li>



<li><strong><a href="https://mrsspeechonline.com/ai-slps-part-2-truth-vs-myth" target="_blank" rel="noreferrer noopener">Part 2: Separating AI Truth vs Myth</a></strong>&nbsp;
<ul class="wp-block-list">
<li>We debunk common AI myths in SLP practice. Get a realistic understanding of AI&#8217;s true role and capabilities.</li>
</ul>
</li>



<li><a href="https://mrsspeechonline.com/ai-slps-part-3-how-ai-works/"><strong>Part 3: How AI Tools Work</strong>&nbsp;</a>
<ul class="wp-block-list">
<li>Get a clear, jargon-free explanation of how large language models function. Understand their capabilities and limitations.</li>
</ul>
</li>



<li><strong><a href="https://mrsspeechonline.com/part-4-ai-for-clinical-efficiency-slps-guide/">Part 4: AI for Clinical Spark &amp; Efficiency</a></strong>
<ul class="wp-block-list">
<li>Discover ethical ways to use AI. Brainstorm, overcome planning hurdles, and refine non-clinical communications.</li>
</ul>
</li>



<li><a href="https://mrsspeechonline.com/prompt-writing-ai-slps-part-5/"><strong>Part 5: Mastering AI Prompts</strong> </a>
<ul class="wp-block-list">
<li>Learn prompt engineering. Communicate effectively with AI models to get tailored, useful results for SLP needs.</li>
</ul>
</li>



<li><strong>Part 6: Compliant AI Platforms &amp; Tools</strong>
<ul class="wp-block-list">
<li>This post guides you through AI tools. Learn key factors for ethically and compliantly selecting platforms for your SLP practice.</li>
</ul>
</li>



<li><strong>Part 7: Ethical &amp; Responsible AI Use</strong>
<ul class="wp-block-list">
<li>This crucial post delves into broader ethical responsibilities for SLPs using AI. It covers principles beyond data privacy.</li>
</ul>
</li>



<li><strong>Part 8: The Future of AI</strong>
<ul class="wp-block-list">
<li>This concluding post explores emerging AI trends and future possibilities in Speech-Language Pathology. Prepare to adapt, innovate, and lead responsible AI integration.</li>
</ul>
</li>
</ul>



<p>Stick around as we keep figuring out this whole AI thing together. By the end of the series, I hope to give SLPs the knowledge they need to help us all find a balance. There is a lot of gray area and strong opinions on this topic. I hope I can provide some facts to help you make informed choices that correspond with your own values.</p>



<p>Keep on clickin&#8217;!</p>



<div class="wp-block-group is-layout-constrained wp-block-group-is-layout-constrained">
<figure class="wp-block-image aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="810" height="169" src="https://i0.wp.com/vmx.erb.mybluehost.me/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp?fit=810%2C169&amp;ssl=1" alt="Mrs. Speech Signature" class="wp-image-804" style="width:364px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp 810w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-300x63.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-768x160.webp 768w" sizes="auto, (max-width: 810px) 100vw, 810px" /></figure>



<div class="wp-block-group is-content-justification-center is-nowrap is-layout-flex wp-container-core-group-is-layout-23441af8 wp-block-group-is-layout-flex">
<figure class="wp-block-image size-full is-resized"><a href="https://www.facebook.com/profile.php?id=61556892726241" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="388" height="398" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp" alt="facebook icon" class="wp-image-815" style="width:48px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp 388w, https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918-292x300.webp 292w" sizes="auto, (max-width: 388px) 100vw, 388px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.instagram.com/mrs.speechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="418" height="408" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp" alt="Instagram Icon" class="wp-image-818" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp 418w, https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939-300x293.webp 300w" sizes="auto, (max-width: 418px) 100vw, 418px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.pinterest.com/mrsspeechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="413" height="410" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp" alt="pinterest icon" class="wp-image-816" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp 413w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-300x298.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-150x150.webp 150w" sizes="auto, (max-width: 413px) 100vw, 413px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.linkedin.com/in/jennifer-tillock-821999287/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="402" height="402" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp" alt="LinkedIn Icon" class="wp-image-821" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp 402w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-150x150.webp 150w" sizes="auto, (max-width: 402px) 100vw, 402px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="http://www.youtube.com/@Mrs.Speech-wk4mr" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="429" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp" alt="YouTube icon" class="wp-image-817" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp 429w, https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232-300x291.webp 300w" sizes="auto, (max-width: 429px) 100vw, 429px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.teacherspayteachers.com/store/mrs-speech" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="423" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp" alt="TeachersPayTeachers Icon" class="wp-image-822" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp 423w, https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756-300x295.webp 300w" sizes="auto, (max-width: 423px) 100vw, 423px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="414" height="413" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp" alt="Mrs. Speech Books Icon" class="wp-image-1322" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp 414w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-150x150.webp 150w" sizes="auto, (max-width: 414px) 100vw, 414px" /></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="387" height="377" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp" alt="MailTo Icon" class="wp-image-1326" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp 387w, https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307-300x292.webp 300w" sizes="auto, (max-width: 387px) 100vw, 387px" /></figure>
</div>
</div>



<p class="icon-attribution" style="font-size: 0.6em; font-style: italic;">
    Social Media Icons: <a href="https://www.freepik.com" target="_blank" rel="noopener">designed by rawpixel.com &#8211; Freepik.com</a>
</p>



<div style="height:47px" aria-hidden="true" class="wp-block-spacer"></div>


<div style="color:#db820e;font-style:normal;font-weight:300" class="taxonomy-post_tag has-text-align-center has-link-color wp-elements-e81afc2be6272024545412bcb750c79c wp-block-post-terms has-text-color"><a href="https://mrsspeechonline.com/tag/business-associate-agreement/" rel="tag">Business Associate Agreement</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/hipaa-security/" rel="tag">HIPAA Security</a></div>


<p></p>
<p>The post <a href="https://mrsspeechonline.com/ai-slps-part-1-client-data-privacy/">AI &amp; SLPs Series, Part 1:  Clinical Data Privacy</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://mrsspeechonline.com/ai-slps-part-1-client-data-privacy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>HIPAA Compliance At Home: Cloud, Schools, Teletherapy &#038; PHI Security</title>
		<link>https://mrsspeechonline.com/hipaa-compliance-at-home/</link>
					<comments>https://mrsspeechonline.com/hipaa-compliance-at-home/#respond</comments>
		
		<dc:creator><![CDATA[Jennifer]]></dc:creator>
		<pubDate>Tue, 12 Aug 2025 17:22:19 +0000</pubDate>
				<category><![CDATA[Clinical]]></category>
		<category><![CDATA[Compliance & Ethics]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Business Associate Agreement]]></category>
		<category><![CDATA[De-identification]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[Home Office]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Teletherapy]]></category>
		<guid isPermaLink="false">https://mrsspeechonline.com/hipaa-compliance-at-home/</guid>

					<description><![CDATA[<p>Working from home? This post breaks down how to stay HIPAA compliant by securing your devices, understanding Business Associate Agreements (BAAs) with cloud services, and responsibly handling PHI. What’s one step you've taken to ensure your home workspace is HIPAA compliant?</p>
<p>The post <a href="https://mrsspeechonline.com/hipaa-compliance-at-home/">HIPAA Compliance At Home: Cloud, Schools, Teletherapy &amp; PHI Security</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" id="h-hipaa-in-your-pjs-or-post-school-hours">HIPAA in Your PJs (or Post-School Hours)</h2>



<p>Hey SLP fam!</p>



<figure class="wp-block-image alignright size-large is-resized"><img loading="lazy" decoding="async" width="999" height="1024" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/Special-Elite-e1752258619631-999x1024.webp" alt="Top secret document with 'DECLASSIFIED' stamp and black redaction bars over text, illustrating information that has been partially obscured.&quot;" class="wp-image-1643" style="width:276px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/Special-Elite-e1752258619631-999x1024.webp 999w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Special-Elite-e1752258619631-293x300.webp 293w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Special-Elite-e1752258619631-768x787.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Special-Elite-e1752258619631.webp 1317w" sizes="auto, (max-width: 999px) 100vw, 999px" /><figcaption class="wp-element-caption">Even with extensive redactions like those seen here, simply blacking out information may not be enough to meet HIPAA&#8217;s stringent de-identification requirements.</figcaption></figure>



<p>Let&#8217;s talk about HIPAA compliance at home.  I know it&#8217;s something that might make your brain do a little loop-de-loop! Whether you&#8217;re rocking the teletherapy life from your home office, hustling in a school building, or bringing a stack of papers (or digital files!) home to tackle after hours, you&#8217;re dealing with sensitive information.</p>



<p>I remember grad school, taking out the black Sharpie to strike through names and addresses on stacks of papers. It&#8217;s what we did, back in the day, to share ideas about goals and treatment plans without breaking client confidentiality. Even with extensive redactions like those seen here, simply blacking out information may not be enough to meet HIPAA&#8217;s stringent de-identification requirements. And in the digital age&#8230; well, let me share with you.</p>



<h4 class="wp-block-heading" id="h-my-hipaa-compliance-wake-up-call"><b>My HIPAA Compliance wake-up call:</b></h4>



<p>I recently had a bit of an &#8220;aha!&#8221; moment (or maybe more of an &#8220;uh-oh!&#8221; moment) for HIPAA compliance at home.  I don&#8217;t even remember how I found out, but I realized my free Google account wasn&#8217;t exactly HIPAA-compliant for handling student info. And that got me thinking&#8230; if I was a bit fuzzy on this, how many of us are? Especially when we step outside the secure walls of our schools or clinics?</p>



<p>It turns out, even when you&#8217;re comfy in your PJs or working from your kitchen table after school, you&#8217;re still 100% responsible for protecting your clients&#8217; Protected Health Information (PHI), even from your family members (who could probably care less). HIPAA doesn&#8217;t care if you&#8217;re in a fancy clinic, a bustling school, or your spare bedroom – the rules are the same for how you handle that information.</p>



<p>To help you navigate this essential topic, I&#8217;ve even created a&nbsp;<strong>free worksheet</strong>&nbsp;to guide you in developing your own HIPAA policies and procedures for your home-based work environment!&nbsp; Let&#8217;s break down some key areas, with a special spotlight on those cloud services many of us use daily.</p>



<h3 class="wp-block-heading" id="h-hipaa-compliance-in-the-cloud-google-microsoft-365-and-the-baa">HIPAA Compliance In The Cloud: Google, Microsoft 365, and the BAA</h3>



<figure class="wp-block-image alignleft is-resized"><img loading="lazy" decoding="async" width="1024" height="853" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/lock-3216823_1280.webp" alt="A 3D illustration of a blue and white cloud icon with a key inserted into a keyhole on its side, symbolizing secure cloud access." class="wp-image-162" style="width:281px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/lock-3216823_1280.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/lock-3216823_1280-300x250.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/lock-3216823_1280-768x640.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Unlocking secure and HIPAA-compliant cloud data management.</figcaption></figure>



<p>This is where it gets real. Many of us use Google Workspace (Gmail, Docs, Drive) or Microsoft 365 (Outlook, Word, OneDrive) for our personal lives, and our schools or districts often use them too. They&#8217;re super convenient, right? </p>



<p>But here&#8217;s the kicker: your&nbsp;<strong>personal Google or Microsoft account is NOT HIPAA compliant for handling PHI.</strong>&nbsp;Full stop.</p>



<p>Why? HIPAA compliance when dealing with PHI requires a&nbsp;<strong>Business Associate Agreement (BAA)</strong> with third parties (like Google). A BAA is a legally binding contract that outlines how a third-party service provider will protect PHI on your behalf. Without one, you&#8217;re on shaky ground.</p>



<h3 class="wp-block-heading" id="h-districts-using-cloud-services-a-critical-distinction"><strong>Districts Using Cloud Services: A Critical Distinction</strong></h3>



<p><strong>So, what about districts using Google Workspace or Microsoft 365?&nbsp;</strong></p>



<p>This is a critical point. While most paid educational plans (often covered by FERPA – the Family Educational Rights and Privacy Act, which governs educational records) offer robust privacy,&nbsp;<strong>FERPA compliance doesn&#8217;t automatically mean HIPAA compliance for you.</strong>&nbsp;</p>



<p>PHI in a school setting often includes health diagnoses, medical history, or therapy notes related to health conditions.  While these are typically considered education records under FERPA,&nbsp;<strong>as an SLP, if you bill Medicaid or other health plans, you are a HIPAA Covered Entity.</strong>&nbsp;This means the specific health information you handle is subject to HIPAA regulations, even within a FERPA-governed school environment.</p>



<p>For a district’s Google Workspace or Microsoft 365 environment to be HIPAA compliant for PHI, they need to have specifically configured their accounts for HIPAA. Crucially, they need a signed BAA with Google or Microsoft for that specific enterprise-level service.</p>



<figure class="wp-block-pullquote"><blockquote><p>Administrators must <a href="https://support.google.com/a/answer/2888485" target="_blank" rel="noreferrer noopener"><strong>review and accept a BAA</strong></a> before using Google services with PHI. See what Google Workspace products can be used for HIPAA compliance in the <a href="https://workspace.google.com/terms/2015/1/hipaa_functionality.html" target="_blank" rel="noreferrer noopener">HIPAA Included Functionality</a>.</p><cite><a href="https://support.google.com/a/answer/3407054?hl=en#:~:text=Under%20HIPAA%2C%20certain%20information%20about,Google%20Workspace%20and%20Cloud%20Identity" target="_blank" rel="noreferrer noopener">Google HIPAA Compliance with Google Workspace and Cloud Identity</a></cite></blockquote></figure>



<h4 class="wp-block-heading" id="h-your-hipaa-compliance-at-home-takeaway">Your HIPAA Compliance at Home Takeaway:</h4>



<p>Don&#8217;t assume. If you&#8217;re using a district&#8217;s cloud services for anything that involves PHI (even if it&#8217;s just student names and health-related goals within an IEP), it&#8217;s your responsibility to confirm that the district has a BAA in place with their cloud provider for that specific service.&nbsp;</p>



<p><strong>And critically, confirm that the specific features and services you use are explicitly covered by that BAA.&nbsp;</strong>If they are not, or if no BAA is in place,&nbsp;you need to adjust your practices.&nbsp; This might mean only using district-approved, HIPAA-compliant EHRs,&nbsp;&nbsp;purchasing your own subscription, or secure local storage, such as the free LibreOffice Suite (See Technical Safeguards below).</p>



<p>Fortunately, I&#8217;d been super cautious and hadn&#8217;t used my personal accounts frequently for student information, but it was a good wake-up call!</p>



<h3 class="wp-block-heading" id="h-beyond-the-cloud-other-key-considerations-for-hipaa-happiness">Beyond the Cloud: Other Key Considerations for HIPAA Happiness</h3>



<p>While cloud services are a big piece of the puzzle, let&#8217;s not forget the other vital aspects of keeping PHI safe, whether you&#8217;re working at school or from home.</p>



<h4 class="wp-block-heading" id="h-core-pillars-for-hipaa-compliance-at-home">Core Pillars for HIPAA Compliance at Home</h4>



<figure class="wp-block-image alignright size-medium is-resized"><img loading="lazy" decoding="async" width="300" height="200" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/binding-contract-948442_1280-300x200.webp" alt="A closed padlock and a set of keys resting on an open book titled &quot;Professional Standards Committee,&quot; with a pen nearby." class="wp-image-164" style="width:347px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/binding-contract-948442_1280-300x200.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/binding-contract-948442_1280-768x512.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/06/binding-contract-948442_1280.webp 1024w" sizes="auto, (max-width: 300px) 100vw, 300px" /><figcaption class="wp-element-caption">Locking down your home practice with strong HIPAA compliance policies and procedures.</figcaption></figure>



<h5 class="wp-block-heading" id="h-risk-analysis-aka-playing-detective-with-your-practice">Risk Analysis (aka &#8220;Playing Detective with Your Practice&#8221;)</h5>



<p>Before you even start working remotely or bringing files home, take a good look at your home setup. Where are the potential weak spots? Is your home Wi-Fi secure? Are your personal devices encrypted? Could your nosy family member or roommate accidentally see your screen? Identify these risks and make a plan to fix them. Document everything!</p>



<h5 class="wp-block-heading" id="h-workforce-training-yes-you-re-the-workforce">Workforce Training (Yes, You&#8217;re the Workforce!)</h5>



<p>Even if it&#8217;s just you, train yourself! Stay up-to-date on HIPAA and your own policies. And guess what? Document that training too!</p>



<h5 class="wp-block-heading" id="h-policies-and-procedures-your-personal-hipaa-rulebook">Policies and Procedures (Your Personal HIPAA Rulebook)</h5>



<p>You&#8217;re the boss of your home workspace, so write down your rules! How do you handle PHI on your personal devices? Where do you store it? What&#8217;s your plan if something goes wrong (a &#8220;breach&#8221;)? Having these written policies keeps you consistent and gives you a roadmap in a pinch. You should also be intimately familiar with your employer&#8217;s HIPAA policies, if applicable.</p>



<h5 class="wp-block-heading" id="h-business-associate-agreements-baas">Business Associate Agreements (BAAs)</h5>



<p>We talked about this with cloud services, but it applies to almost any third-party service you independently contract that touches PHI. Your teletherapy platform (if you use one), your EHR, your billing service, even encrypted email services – they all need a BAA. Beware of &#8220;free&#8221; or even personal versions of platforms; they usually do NOT offer BAAs.</p>



<h5 class="wp-block-heading" id="h-incident-response-plan-your-oh-crap-protocol">Incident Response Plan (Your &#8220;Oh Crap&#8221; Protocol)</h5>



<p>What if your personal laptop gets stolen? What if you accidentally email PHI to the wrong person? Have a clear plan for what to do: contain the issue, investigate, notify affected individuals (and potentially HHS), and prevent it from happening again. Your district should also have a plan; know it!</p>



<figure class="wp-block-image aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="341" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/smartphone-4562985_1280.webp" alt="A hand reaching towards a smartphone screen that displays a prominent blue fingerprint graphic, indicating biometric security or digital access." class="wp-image-166" style="width:411px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/smartphone-4562985_1280.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/smartphone-4562985_1280-300x100.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/smartphone-4562985_1280-768x256.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Securing Protected Health Information with robust digital safeguards.</figcaption></figure>



<h4 class="wp-block-heading" id="h-physical-amp-technical-considerations-for-hipaa-compliance-at-home">Physical &amp; Technical Considerations for HIPAA Compliance At Home</h4>



<h5 class="wp-block-heading" id="h-physical-safeguards-lock-it-up">Physical Safeguards (Lock it Up!)</h5>



<ul class="wp-block-list">
<li>Ensure your home workspace is private.</li>



<li>Close the door and position your screen away from prying eyes.</li>



<li>Lock up any physical paper records containing PHI.</li>



<li>Shred unneeded documents securely when done.</li>



<li>Never leave PHI visible or accessible to others in your home.</li>



<li></li>
</ul>



<h5 class="wp-block-heading" id="h-technical-safeguards-your-digital-fort-knox">Technical Safeguards (Your Digital Fort Knox)</h5>



<ul class="wp-block-list">
<li><strong>Encrypt EVERYTHING:</strong> All devices (laptops, desktops, external drives, mobile devices) storing or accessing PHI must be encrypted. This is crucial if a device is lost or stolen.</li>



<li><strong>Strong Passwords &amp; MFA:</strong> Use complex, unique passwords. Enable multi-factor authentication (MFA) everywhere possible for accounts with PHI.</li>



<li><strong>Antivirus/Firewall:</strong> Keep your software updated and firewalls active.</li>



<li><strong>Secure Network:</strong> Use a strong, secure home Wi-Fi connection. NEVER handle PHI on public Wi-Fi. If connecting to your school&#8217;s network from home, always use their provided VPN if available.</li>



<li><strong>HIPAA-Compliant Platforms:</strong> For teletherapy, use platforms specifically designed for HIPAA compliance, with end-to-end encryption and a BAA.</li>



<li><strong>Secure Communication:</strong> Stick to secure messaging within your EHR/school system or encrypted email for PHI. Avoid regular email, WhatsApp, or FaceTime for anything confidential.</li>
</ul>



<h3 class="wp-block-heading" id="h-a-crucial-note-on-de-identification-and-ai-tools">A Crucial Note on &#8220;De-identification&#8221; and AI Tools</h3>



<figure class="wp-block-image alignleft is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/Untitled-20design-20-14-.webp" alt="The letters &quot;AI&quot; in white on a black rectangle, overlaid on a blue circuit board background, surrounded by three large red question marks." class="wp-image-168" style="width:211px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/Untitled-20design-20-14-.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Untitled-20design-20-14--300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Untitled-20design-20-14--150x150.webp 150w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Untitled-20design-20-14--768x768.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Here&#8217;s a big one that&#8217;s becoming more relevant with the rise of AI&#8230;</p>



<h5 class="wp-block-heading" id="h-simply-removing-a-client-s-or-student-s-name-or-a-few-obvious-identifiers-does-not-make-the-information-safe-to-use">**<strong>Simply removing a client&#8217;s or student&#8217;s name or a few obvious identifiers does NOT make the information safe to use.</strong>**</h5>



<p>General-purpose, free AI tools like Gemini or ChatGPT, or even education tools like MagicSchool.ai, are <strong>NOT </strong>HIPPA compliant.  Even if you pay for Gemini Pro, there is no BAA unless it comes with a Workspace plan.</p>



<h4 class="wp-block-heading" id="h-hipaa-de-identification-is-stringent">HIPAA De-identification is Stringent</h4>



<p>HIPAA has very specific and stringent rules for what constitutes truly &#8220;de-identified&#8221; information. It&#8217;s far more complex than just deleting a name. If you use PHI, even seemingly &#8220;de-identified,&#8221; with a service that doesn&#8217;t have a BAA and isn&#8217;t designed for PHI, you&#8217;re risking a breach. This means:</p>



<p><strong>Do NOT copy/paste session notes, IEP sections, or any other PHI, even with names removed, into general AI tools</strong>&nbsp;like Gemini, ChatGPT, or other free online summarizers to help you write notes, develop goals, or for any other purpose. These services do not typically offer BAAs and are not designed to protect PHI.</p>



<p>The data you input into these tools can become part of their training data, meaning your client&#8217;s potentially re-identifiable information could be exposed or used in ways you can&#8217;t control.</p>



<p><strong>When in doubt, don&#8217;t put it in a service without a BAA!&nbsp;</strong>This applies whether you&#8217;re trying to draft a progress note at home or summarize a student&#8217;s history.</p>



<h3 class="wp-block-heading" id="h-ready-to-hipaa-happy-your-home-office"><strong>Ready to HIPAA-Happy Your Home Office?</strong></h3>



<figure class="wp-block-image alignleft size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="670" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/Download.webp" alt="A red, starburst-shaped graphic with bold yellow text &quot;FREE!&quot; and green text &quot;DOWNLOAD&quot;, serving as a call to action for a free resource." class="wp-image-104" style="width:260px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/Download.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Download-300x196.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Download-768x503.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Developing comprehensive HIPAA policies and procedures for home can feel daunting, but it&#8217;s a crucial step in safeguarding your clients&#8217;/students&#8217; PHI. To make it easier, I&#8217;ve created a free, actionable worksheet to guide you through identifying your unique risks and writing down your specific policies for working from home.</p>



<h4 class="wp-block-heading" id="h-sign-up-to-download-your-free-hipaa-compliance-home-office-policies-amp-procedures-worksheet"><strong>Sign up to Download Your Free HIPAA Compliance Home Office Policies &amp; Procedures Worksheet!</strong></h4>


  
  
  <div class="
    mailpoet_form_popup_overlay
      "></div>
  <div
    id="mailpoet_form_2"
    class="
      mailpoet_form
      mailpoet_form_html
      mailpoet_form_position_
      mailpoet_form_animation_
    "
      >

    <style type="text/css">
     #mailpoet_form_2 .mailpoet_form {  }
#mailpoet_form_2 form { margin-bottom: 0; }
#mailpoet_form_2 p.mailpoet_form_paragraph.last { margin-bottom: 0px; }
#mailpoet_form_2 h2.mailpoet-heading { margin: -10px 0 10px 0; }
#mailpoet_form_2 .mailpoet_column_with_background { padding: 10px; }
#mailpoet_form_2 .mailpoet_form_column:not(:first-child) { margin-left: 20px; }
#mailpoet_form_2 .mailpoet_paragraph { line-height: 20px; margin-bottom: 20px; }
#mailpoet_form_2 .mailpoet_segment_label, #mailpoet_form_2 .mailpoet_text_label, #mailpoet_form_2 .mailpoet_textarea_label, #mailpoet_form_2 .mailpoet_select_label, #mailpoet_form_2 .mailpoet_radio_label, #mailpoet_form_2 .mailpoet_checkbox_label, #mailpoet_form_2 .mailpoet_list_label, #mailpoet_form_2 .mailpoet_date_label { display: block; font-weight: normal; }
#mailpoet_form_2 .mailpoet_text, #mailpoet_form_2 .mailpoet_textarea, #mailpoet_form_2 .mailpoet_select, #mailpoet_form_2 .mailpoet_date_month, #mailpoet_form_2 .mailpoet_date_day, #mailpoet_form_2 .mailpoet_date_year, #mailpoet_form_2 .mailpoet_date { display: block; }
#mailpoet_form_2 .mailpoet_text, #mailpoet_form_2 .mailpoet_textarea { width: 200px; }
#mailpoet_form_2 .mailpoet_checkbox {  }
#mailpoet_form_2 .mailpoet_submit {  }
#mailpoet_form_2 .mailpoet_divider {  }
#mailpoet_form_2 .mailpoet_message {  }
#mailpoet_form_2 .mailpoet_form_loading { width: 30px; text-align: center; line-height: normal; }
#mailpoet_form_2 .mailpoet_form_loading > span { width: 5px; height: 5px; background-color: #5b5b5b; }#mailpoet_form_2{border: 5px solid #c07000;border-radius: 40px;background: linear-gradient(180deg,rgb(255,243,214) 0%,rgb(255,255,255) 100%);color: #240002;text-align: left;}#mailpoet_form_2 form.mailpoet_form {padding: 10px;}#mailpoet_form_2{width: 100%;}#mailpoet_form_2 .mailpoet_message {margin: 0; padding: 0 20px;}
        #mailpoet_form_2 .mailpoet_validate_success {color: #00d084}
        #mailpoet_form_2 input.parsley-success {color: #00d084}
        #mailpoet_form_2 select.parsley-success {color: #00d084}
        #mailpoet_form_2 textarea.parsley-success {color: #00d084}
      
        #mailpoet_form_2 .mailpoet_validate_error {color: #cf2e2e}
        #mailpoet_form_2 input.parsley-error {color: #cf2e2e}
        #mailpoet_form_2 select.parsley-error {color: #cf2e2e}
        #mailpoet_form_2 textarea.textarea.parsley-error {color: #cf2e2e}
        #mailpoet_form_2 .parsley-errors-list {color: #cf2e2e}
        #mailpoet_form_2 .parsley-required {color: #cf2e2e}
        #mailpoet_form_2 .parsley-custom-error-message {color: #cf2e2e}
      #mailpoet_form_2 .mailpoet_paragraph.last {margin-bottom: 0} @media (max-width: 500px) {#mailpoet_form_2 {background: linear-gradient(180deg,rgb(255,243,214) 0%,rgb(255,255,255) 100%);}} @media (min-width: 500px) {#mailpoet_form_2 .last .mailpoet_paragraph:last-child {margin-bottom: 0}}  @media (max-width: 500px) {#mailpoet_form_2 .mailpoet_form_column:last-child .mailpoet_paragraph:last-child {margin-bottom: 0}} 
    </style>

    <form
      target="_self"
      method="post"
      action="https://mrsspeechonline.com/wp-admin/admin-post.php?action=mailpoet_subscription_form"
      class="mailpoet_form mailpoet_form_form mailpoet_form_html"
      novalidate
      data-delay=""
      data-exit-intent-enabled=""
      data-font-family=""
      data-cookie-expiration-time=""
    >
      <input type="hidden" name="data[form_id]" value="2" />
      <input type="hidden" name="token" value="b7980c8f49" />
      <input type="hidden" name="api_version" value="v1" />
      <input type="hidden" name="endpoint" value="subscribers" />
      <input type="hidden" name="mailpoet_method" value="subscribe" />

      <label class="mailpoet_hp_email_label" style="display: none !important;">Please leave this field empty<input type="email" name="data[email]"/></label><h3 class="mailpoet-heading  mailpoet-has-font-size" style="text-align: center; color: #240002; font-size: 36px">Want exclusive freebies?</h3>
<div class="mailpoet_paragraph "><style>input[name="data[form_field_ZTYwMWUzMTY0ZDU0X2ZpcnN0X25hbWU=]"]::placeholder{color:#5b8ba7;opacity: 1;}</style><input type="text" autocomplete="given-name" class="mailpoet_text" id="form_first_name_2" name="data[form_field_ZTYwMWUzMTY0ZDU0X2ZpcnN0X25hbWU=]" title="First Name" value="" style="width:100%;box-sizing:border-box;background-color:#ffffff;border-style:solid;border-radius:10px !important;border-width:1px;border-color:#313131;padding:4px;margin: 0 auto 0 0;font-family:&#039;Ubuntu&#039;;font-size:16px;line-height:1.5;height:auto;color:#5b8ba7;" data-automation-id="form_first_name"  placeholder="First Name" aria-label="First Name" data-parsley-errors-container=".mailpoet_error_1xvxn" data-parsley-names='[&quot;Please specify a valid name.&quot;,&quot;Addresses in names are not permitted, please add your name instead.&quot;]'/><span class="mailpoet_error_1xvxn"></span></div>
<div class="mailpoet_paragraph "><style>input[name="data[form_field_ZTU2MDYxYjE3Njk1X2VtYWls]"]::placeholder{color:#5b8ba7;opacity: 1;}</style><input type="email" autocomplete="email" class="mailpoet_text" id="form_email_2" name="data[form_field_ZTU2MDYxYjE3Njk1X2VtYWls]" title="Email Address" value="" style="width:100%;box-sizing:border-box;background-color:#ffffff;border-style:solid;border-radius:10px !important;border-width:1px;border-color:#313131;padding:4px;margin: 0 auto 0 0;font-family:&#039;Ubuntu&#039;;font-size:16px;line-height:1.5;height:auto;color:#5b8ba7;" data-automation-id="form_email"  placeholder="Email Address *" aria-label="Email Address *" data-parsley-errors-container=".mailpoet_error_101wp" data-parsley-required="true" required aria-required="true" data-parsley-minlength="6" data-parsley-maxlength="150" data-parsley-type-message="This value should be a valid email." data-parsley-required-message="This field is required."/><span class="mailpoet_error_101wp"></span></div>
<div class="mailpoet_paragraph "><input type="submit" class="mailpoet_submit" value="I want my freebies!" data-automation-id="subscribe-submit-button" data-font-family='Ubuntu' style="width:100%;box-sizing:border-box;background-color:#c07000;border-style:solid;border-radius:10px !important;border-width:1px;padding:4px;margin: 0 auto 0 0;font-family:&#039;Ubuntu&#039;;font-size:20px;line-height:1.5;height:auto;color:#ffffff;border-color:transparent;font-weight:bold;" /><span class="mailpoet_form_loading"><span class="mailpoet_bounce1"></span><span class="mailpoet_bounce2"></span><span class="mailpoet_bounce3"></span></span></div>
<p class="mailpoet_form_paragraph  mailpoet-has-font-size" style="text-align: center; color: #240002; font-size: 14px; line-height: 1.2"><span style="font-family:" data-font="" class="mailpoet-has-font">We don’t spam! Read our <a href="https://mrsspeechonline.com/privacy-policy/" data-type="link" data-id="https://mrsspeechonline.com/privacy-policy/">privacy policy</a> for more info.</span></p>
<p class="mailpoet_form_paragraph  mailpoet-has-font-size" style="text-align: center; font-size: 13px">See the <a href="https://mrsspeechonline.com/subscription-options-guide/" data-type="link" data-id="https://mrsspeechonline.com/subscription-options-guide/">subscription guide</a> for more information!</p>

      <div class="mailpoet_message">
        <p class="mailpoet_validate_success"
                style="display:none;"
                >Check your inbox or spam folder to confirm your subscription.
        </p>
        <p class="mailpoet_validate_error"
                style="display:none;"
                >        </p>
      </div>
    </form>

      </div>

  


<h3 class="wp-block-heading" id="h-the-bottom-line">The Bottom Line</h3>



<p>HIPAA compliance in the cloud or at home can feel overwhelming, but it&#8217;s crucial for protecting our clients/students and our professional integrity. Take it step-by-step. Conduct that risk analysis, get those BAAs in place for any services you control, and secure your devices and workspace. Always defer to and understand your district&#8217;s policies first and foremost.</p>



<figure class="wp-block-image alignright size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/Your-20paragraph-20text-20-7-.webp" alt="Silver shield icon with 'HIPAA &amp; BAAs' in bold white text and a red heart showing a white heartbeat line, symbolizing HIPAA compliance and data security." class="wp-image-107" style="width:202px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/Your-20paragraph-20text-20-7-.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Your-20paragraph-20text-20-7--300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Your-20paragraph-20text-20-7--150x150.webp 150w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Your-20paragraph-20text-20-7--768x768.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>It&#8217;s a journey, not a destination, so stay informed and don&#8217;t be afraid to consult legal counsel or your district&#8217;s HIPAA compliance officer if you have specific questions about your practice.</p>



<p><strong>Want to know more?&nbsp; Check out&nbsp;</strong><a href="https://mrsspeechonline.com/slp-business-associate-agreement-hipaa-guide/">Navigating Business Associate Agreements as an SLP:  Your HIPAA BAA Guide</a>.</p>



<h4 class="wp-block-heading" id="h-what-are-your-biggest-hipaa-challenges-as-an-slp-whether-in-a-school-or-teletherapy-setting-is-there-anything-you-d-like-to-know-more-about-nbsp-share-your-thoughts-in-the-comments-below"><em>What are your biggest HIPAA challenges as an SLP, whether in a school or teletherapy setting? Is there anything you&#8217;d like to know more about?&nbsp; Share your thoughts in the comments below!</em></h4>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:30% auto"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="1024" height="579" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/ai-slps-series-banner-1024x579.webp" alt="Stylized illustration of a female SLP working at a laptop, with a glowing, translucent AI figure behind her, symbolizing AI as a supportive assistant. Text reads: 'AI &amp; SLPs'." class="wp-image-2188 size-full" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/ai-slps-series-banner-1024x579.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/07/ai-slps-series-banner-300x170.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/ai-slps-series-banner-768x434.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/07/ai-slps-series-banner-1536x868.webp 1536w, https://mrsspeechonline.com/wp-content/uploads/2025/07/ai-slps-series-banner-2048x1158.webp 2048w, https://mrsspeechonline.com/wp-content/uploads/2025/07/ai-slps-series-banner-1320x746.webp 1320w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure><div class="wp-block-media-text__content">
<div class="wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-6c531013 wp-block-group-is-layout-flex">
<h3 class="wp-block-heading" id="h-coming-up-next-an-8-part-series-on-nbsp-ai-amp-slps"><strong>Coming up next &#8211; an 8-part series on&nbsp;<a href="https://mrsspeechonline.com/part-1-ai-clinical-data-navigating-privacy-security-for-slps/">AI &amp; SLPs!</a></strong></h3>
</div>
</div></div>



<p>Remember, you are awesome because you do the best with what you know – and taking steps toward HIPAA compliance at home is truly doing your best for your clients. </p>



<p>Keep up the amazing work!</p>



<div class="wp-block-group is-layout-constrained wp-block-group-is-layout-constrained">
<figure class="wp-block-image aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="810" height="169" src="https://i0.wp.com/vmx.erb.mybluehost.me/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp?fit=810%2C169&amp;ssl=1" alt="Mrs. Speech Signature" class="wp-image-804" style="width:364px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp 810w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-300x63.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-768x160.webp 768w" sizes="auto, (max-width: 810px) 100vw, 810px" /></figure>



<div class="wp-block-group is-content-justification-center is-nowrap is-layout-flex wp-container-core-group-is-layout-23441af8 wp-block-group-is-layout-flex">
<figure class="wp-block-image size-full is-resized"><a href="https://www.facebook.com/profile.php?id=61556892726241" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="388" height="398" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp" alt="facebook icon" class="wp-image-815" style="width:48px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp 388w, https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918-292x300.webp 292w" sizes="auto, (max-width: 388px) 100vw, 388px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.instagram.com/mrs.speechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="418" height="408" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp" alt="Instagram Icon" class="wp-image-818" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp 418w, https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939-300x293.webp 300w" sizes="auto, (max-width: 418px) 100vw, 418px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.pinterest.com/mrsspeechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="413" height="410" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp" alt="pinterest icon" class="wp-image-816" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp 413w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-300x298.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-150x150.webp 150w" sizes="auto, (max-width: 413px) 100vw, 413px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.linkedin.com/in/jennifer-tillock-821999287/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="402" height="402" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp" alt="LinkedIn Icon" class="wp-image-821" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp 402w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-150x150.webp 150w" sizes="auto, (max-width: 402px) 100vw, 402px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="http://www.youtube.com/@Mrs.Speech-wk4mr" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="429" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp" alt="YouTube icon" class="wp-image-817" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp 429w, https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232-300x291.webp 300w" sizes="auto, (max-width: 429px) 100vw, 429px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.teacherspayteachers.com/store/mrs-speech" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="423" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp" alt="TeachersPayTeachers Icon" class="wp-image-822" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp 423w, https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756-300x295.webp 300w" sizes="auto, (max-width: 423px) 100vw, 423px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="414" height="413" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp" alt="Mrs. Speech Books Icon" class="wp-image-1322" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp 414w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-150x150.webp 150w" sizes="auto, (max-width: 414px) 100vw, 414px" /></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="387" height="377" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp" alt="MailTo Icon" class="wp-image-1326" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp 387w, https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307-300x292.webp 300w" sizes="auto, (max-width: 387px) 100vw, 387px" /></figure>
</div>
</div>



<p class="icon-attribution" style="font-size: 0.6em; font-style: italic;">
    Social Media Icons: <a href="https://www.freepik.com" target="_blank" rel="noopener">designed by rawpixel.com &#8211; Freepik.com</a>
</p>



<div style="height:47px" aria-hidden="true" class="wp-block-spacer"></div>


<div style="color:#db820e;font-style:normal;font-weight:300" class="taxonomy-post_tag has-text-align-center has-link-color wp-elements-e81afc2be6272024545412bcb750c79c wp-block-post-terms has-text-color"><a href="https://mrsspeechonline.com/tag/business-associate-agreement/" rel="tag">Business Associate Agreement</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/de-identification/" rel="tag">De-identification</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/google/" rel="tag">Google</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/hipaa-security/" rel="tag">HIPAA Security</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/home-office/" rel="tag">Home Office</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/microsoft/" rel="tag">Microsoft</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/teletherapy/" rel="tag">Teletherapy</a></div>


<p></p>
<p>The post <a href="https://mrsspeechonline.com/hipaa-compliance-at-home/">HIPAA Compliance At Home: Cloud, Schools, Teletherapy &amp; PHI Security</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://mrsspeechonline.com/hipaa-compliance-at-home/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Navigating Business Associate Agreements as an SLP:  Your HIPAA BAA Guide</title>
		<link>https://mrsspeechonline.com/slp-business-associate-agreement-hipaa-guide/</link>
					<comments>https://mrsspeechonline.com/slp-business-associate-agreement-hipaa-guide/#respond</comments>
		
		<dc:creator><![CDATA[Jennifer]]></dc:creator>
		<pubDate>Tue, 12 Aug 2025 17:22:17 +0000</pubDate>
				<category><![CDATA[Clinical]]></category>
		<category><![CDATA[Compliance & Ethics]]></category>
		<category><![CDATA[Business Associate Agreement]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[Home Office]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Schools]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Teletherapy]]></category>
		<guid isPermaLink="false">https://mrsspeechonline.com/slp-business-associate-agreement-hipaa-guide/</guid>

					<description><![CDATA[<p>Navigating HIPAA can be tricky! This post demystifies the Business Associate Agreement (BAA), explaining what it is, why SLPs need one, and who requires one to ensure client data is safe and sound. What's one service provider you're now double-checking for a BAA?</p>
<p>The post <a href="https://mrsspeechonline.com/slp-business-associate-agreement-hipaa-guide/">Navigating Business Associate Agreements as an SLP:  Your HIPAA BAA Guide</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" id="h-what-they-are-why-you-need-them-and-who-needs-one-with-you-for-phi-compliance">What They Are, Why You Need Them, and Who Needs One With You for PHI Compliance</h2>



<p>In my last post, <a href="https://mrsspeechonline.com/hipaa-compliance-at-home" target="_blank" rel="noreferrer noopener">HIPAA Compliance At Home: Cloud, Schools, Teletherapy &amp; PHI Security</a>, we got real about HIPAA compliance for home offices and personal devices. We covered that many of us are HIPAA Covered Entities and how crucial it is to safeguard <strong>Protected Health Information (PHI)</strong> wherever we practice, even at home. Navigating Business Associate Agreements as SLPs is an important piece of that compliance.</p>



<p>Today, we&#8217;re zooming in on one of the most critical, yet often overlooked, pieces of that HIPAA puzzle: the&nbsp;<strong>Business Associate Agreement (BAA).</strong>&nbsp;Think of it as your golden ticket to legally sharing PHI with necessary service providers, while ensuring that data stays locked down.</p>



<p>I&#8217;ll be the first to tell you, this is a new topic for me. I was unaware of most of this information just a few weeks ago! My eyes have really been opened and I&#8217;m changing the way I work based on this new information. Especially as a teletherapy contractor, I&#8217;ve been working to upgrade my services to business grade. (You can read all about it here: <a href="https://mrsspeechonline.com/personal-hipaa-compliance-journey" target="_blank" rel="noreferrer noopener">My Personal HIPAA Compliance Journey: Steps to Secure Data</a>)</p>



<h5 class="wp-block-heading"><strong>Disclaimer:</strong></h5>



<p class="has-small-font-size"><span style="font-size: x-small;"><em>The information provided in this blog post is for informational and educational purposes only and is not intended to constitute legal or professional advice. HIPAA compliance is complex and constantly evolving. While efforts have been made to ensure the accuracy of the information presented, it may not reflect the most current legal developments, nor is it guaranteed to be complete or applicable to your specific situation.As a healthcare professional, it is your responsibility to understand and comply with all applicable federal, state, and local laws and regulations, including HIPAA. This content should not be used as a substitute for seeking qualified legal counsel from an attorney specializing in healthcare law, particularly concerning your individual practice, specific vendor relationships, or unique circumstances. Reliance on any information provided in this post is solely at your own risk.</em></span></p>



<h3 class="wp-block-heading">What Exactly IS a Business Associate Agreement (BAA)?</h3>



<figure class="wp-block-image alignleft size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="507" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/hand-853188_1280.webp" alt="Cartoon illustration of two hands shaking, representing a formal business agreement or contract, like a Business Associate Agreement." class="wp-image-109" style="width:318px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/hand-853188_1280.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/hand-853188_1280-300x149.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/hand-853188_1280-768x380.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">A Business Associate Agreement offers compliance in safeguarding Protected Health Information.</figcaption></figure>



<p>At its core, a&nbsp;<strong>Business Associate Agreement (BAA)</strong>&nbsp;is a formal, legally binding contract between you (the<strong>&nbsp;Covered Entity</strong>) and any person or entity (the&nbsp;<strong>Business Associate</strong>) that performs services for you that involve the creation, receipt, maintenance, or transmission of Protected Health Information (PHI).</p>



<h4 class="wp-block-heading" id="h-why-do-i-need-a-baa-as-an-slp-nbsp">Why do I need a BAA as an SLP?&nbsp;</h4>



<p>The BAA is HIPAA&#8217;s way of extending the privacy and security obligations beyond just your practice. It legally obligates your Business Associates to:</p>



<ul class="wp-block-list">
<li><strong>Safeguard PHI:</strong>&nbsp;They must implement their own administrative, physical, and technical safeguards to protect PHI, just like you do.</li>



<li><strong>Limit Use/Disclosure:</strong>&nbsp;They can only use or disclose PHI as permitted by the BAA and HIPAA regulations.</li>



<li><strong>Report Breaches:</strong>&nbsp;They must notify you if they discover a breach of unsecured PHI.</li>



<li><strong>Cooperate with Audits/Investigations:&nbsp;</strong>They may be subject to direct enforcement actions by the Department of Health and Human Services (HHS).</li>



<li><strong>Flow-Down Rule</strong>: If they use subcontractors who access PHI, they must have a BAA with their subcontractors too!</li>
</ul>



<p><strong>In short: No BAA, No PHI Exchange</strong>. You cannot share PHI with a service provider unless you have a signed BAA in place, or that provider falls under a very narrow exception. Failing to get a required BAA can lead to significant fines and penalties for your practice if a breach occurs.</p>



<h3 class="wp-block-heading">What Does a BAA Actually Look Like? Key Sections to Expect</h3>



<figure class="wp-block-image alignright size-full is-resized"><img loading="lazy" decoding="async" width="660" height="660" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/business-4576778_1280-edited.webp" alt="Illustration of hands holding a document, with a magnifying glass examining text, symbolizing due diligence and review of Business Associate Agreement terms." class="wp-image-1003" style="width:263px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/business-4576778_1280-edited.webp 660w, https://mrsspeechonline.com/wp-content/uploads/2025/07/business-4576778_1280-edited-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/business-4576778_1280-edited-150x150.webp 150w" sizes="auto, (max-width: 660px) 100vw, 660px" /><figcaption class="wp-element-caption">Careful review of BAA terms with a magnifying glass symbolizes the essential due diligence required for HIPAA compliance.</figcaption></figure>



<p>While the exact wording of a BAA can vary between vendors, they generally follow a standard structure and include specific clauses mandated by&nbsp;<strong>HIPAA regulations, as outlined by the U.S. Department of Health &amp; Human Services (HHS)</strong>.&nbsp;When you receive one, here&#8217;s what you can expect to see:</p>



<h4 class="wp-block-heading"><strong>I. Core Agreement Details</strong></h4>



<p>These sections lay out the basic framework and definitions of the Business Associate Agreement.</p>



<ul class="wp-block-list">
<li><strong>Introduction &amp; Parties:</strong>
<ul class="wp-block-list">
<li><strong>Purpose:</strong> States the agreement&#8217;s goal (to comply with HIPAA by protecting PHI).</li>



<li><strong>Effective Date:</strong> When the BAA officially begins.</li>



<li><strong>Parties Involved:</strong> Clearly identifies you (the Covered Entity) and the vendor (the Business Associate) by their full legal names and addresses.</li>
</ul>
</li>



<li><strong>Definitions:</strong>
<ul class="wp-block-list">
<li>This section will define key HIPAA terms as they apply to the agreement, such as &#8220;Protected Health Information (PHI),&#8221; &#8220;Electronic PHI (ePHI),&#8221; &#8220;Covered Entity,&#8221; &#8220;Business Associate,&#8221; &#8220;Breach,&#8221; &#8220;Security Incident,&#8221; and the &#8220;HIPAA Rules&#8221; (Privacy, Security, and Breach Notification Rules). This ensures both parties are on the same page legally.</li>
</ul>
</li>
</ul>



<h4 class="wp-block-heading"><strong>II. PHI Usage &amp; Protection Obligations</strong></h4>



<p>This crucial category outlines how the Business Associate is permitted to use PHI and the safeguards they must have in place.</p>



<ul class="wp-block-list">
<li><strong>Permitted and Required Uses and Disclosures of PHI by the Business Associate:</strong>
<ul class="wp-block-list">
<li>This is a core section. It specifies exactly how the Business Associate is allowed to use and disclose PHI to perform the services for which you hired them. For example, an EHR vendor&#8217;s BAA would permit them to store, process, and transmit PHI for your charting and billing.</li>



<li>It will also outline any disclosures required by law (e.g., to the Secretary of HHS for compliance investigations).</li>



<li>Crucially, it will state that the BA cannot use or disclose PHI in any way that would violate HIPAA if done by you, the Covered Entity.</li>
</ul>
</li>



<li><strong>Obligations of the Business Associate (Safeguards):</strong>
<ul class="wp-block-list">
<li>This section details the security measures the Business Associate must implement to protect PHI. It often references the HIPAA Security Rule and its requirements for administrative, physical, and technical safeguards.</li>



<li>Key phrases you&#8217;ll see include commitments to:
<ul class="wp-block-list">
<li>&#8220;Implement appropriate safeguards to prevent unauthorized use or disclosure of PHI.&#8221;</li>



<li>&#8220;Comply with the HIPAA Security Rule with respect to electronic PHI.&#8221;</li>



<li>&#8220;Ensure the confidentiality, integrity, and availability of ePHI.&#8221;</li>
</ul>
</li>
</ul>
</li>
</ul>



<h4 class="wp-block-heading"><strong>III. Breach Reporting &amp; Compliance Provisions</strong></h4>



<p>This category covers what happens in case of a security incident or breach.  It also describes how the Business Associate handles relationships with their own subcontractors.</p>



<ul class="wp-block-list">
<li><strong>Reporting Obligations (Breaches and Security Incidents):</strong>
<ul class="wp-block-list">
<li>A critical component. The BAA will clearly define the Business Associate&#8217;s responsibility to report any &#8220;Security Incidents&#8221; (e.g., failed login attempts, malware attacks that might affect PHI) and, more importantly, any confirmed &#8220;Breaches of Unsecured PHI.&#8221;</li>



<li>It will specify the timeframe for reporting (e.g., &#8220;without unreasonable delay,&#8221; often 10-15 business days from discovery) and what information they must provide in the breach notification.</li>
</ul>
</li>



<li><strong>Subcontractors:</strong>
<ul class="wp-block-list">
<li>This clause is essential. It requires the Business Associate to ensure that any of their subcontractors who create, receive, maintain, or transmit PHI on behalf of the Business Associate also agree in writing to the same HIPAA restrictions and conditions that apply to the Business Associate. This is often called the &#8220;flow-down&#8221; provision.</li>
</ul>
</li>
</ul>



<h4 class="wp-block-heading"><strong>IV. Client Rights &amp; Agreement Management</strong></h4>



<p>These sections ensure client rights regarding their PHI are upheld and define the terms for the BAA&#8217;s lifespan.</p>



<ul class="wp-block-list">
<li><strong>Access, Amendment, and Accounting of Disclosures:</strong>
<ul class="wp-block-list">
<li>The BAA will ensure that the Business Associate cooperates with your obligations to individuals regarding their PHI, such as allowing individuals to access, amend, or receive an accounting of disclosures of their PHI.</li>
</ul>
</li>



<li><strong>Termination:</strong>
<ul class="wp-block-list">
<li>Outlines the conditions under which the agreement can be terminated (e.g., for material breach of contract).</li>



<li>Crucially, it details the Business Associate&#8217;s responsibilities upon termination, which typically include returning or securely destroying all PHI received from or created on behalf of the Covered Entity, if feasible. If not feasible, they must continue to protect the PHI.</li>
</ul>
</li>



<li><strong>Miscellaneous Provisions:</strong>
<ul class="wp-block-list">
<li>Standard legal clauses like governing law (which state&#8217;s laws apply), notices, and how amendments to the BAA will be made.</li>
</ul>
</li>
</ul>



<p><strong>Important Note:&nbsp;</strong>You won&#8217;t usually&nbsp;<em>negotiate</em>&nbsp;a BAA provided by a large vendor like Google or an EHR. Their BAAs are standardized. Your role in a BAA as an SLP is to read it&nbsp;<em>carefully</em>&nbsp;to ensure it meets HIPAA&#8217;s requirements and your understanding of the service. If you have any concerns or complex situations, consulting an attorney specializing in healthcare law is always advisable.</p>



<ul class="wp-block-list">
<li>Google has a publicly available <a href="https://support.google.com/a/answer/3407054?hl=en" target="_blank" rel="noreferrer noopener nofollow">HIPAA Compliance help page</a> with a link to their BAA.</li>
</ul>



<h3 class="wp-block-heading" id="h-who-do-you-need-a-baa-with-the-access-to-phi-rule">Who Do You Need a BAA With? The &#8220;Access to PHI&#8221; Rule</h3>



<figure class="wp-block-image alignleft size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="682" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/social-media-6721926_1280.webp" alt="An intricate network diagram with glowing teal icons for cloud, email, social media, and communication apps on a dark blue background, symbolizing digital services potentially requiring a BAA." class="wp-image-113" style="width:334px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/social-media-6721926_1280.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/social-media-6721926_1280-300x200.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/social-media-6721926_1280-768x512.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">This interconnected digital landscape highlights the various online platforms and services that may necessitate a Business Associate Agreement for HIPAA compliance.</figcaption></figure>



<p>This is the million-dollar question! The key is whether a service provider, in the course of performing services for you, has&nbsp;<strong>&#8220;access to&#8221; PHI</strong>. This &#8220;access&#8221; is much broader than just storing or directly viewing the data. It includes any service that processes, handles, or routinely interacts with PHI.</p>



<p>Here are common service categories where you absolutely need a Business Associate Agreement as an SLP:</p>



<h4 class="wp-block-heading" id="h-services-directly-managing-client-data-amp-communication">Services Directly Managing Client Data &amp; Communication</h4>



<h5 class="wp-block-heading" id="h-electronic-health-record-ehr-practice-management-systems"><strong>Electronic Health Record (EHR) / Practice Management Systems:</strong></h5>



<ul class="wp-block-list">
<li><em>Why:</em> These are the central hubs for all your client data, including diagnoses, treatment plans, notes, and billing information. The vendor maintains and processes all this PHI.</li>



<li><em>Examples:</em> SimplePractice, TherapyNotes, TheraPlatform, ClinicSource, or any specialized EHR/PM system you use.</li>
</ul>



<h5 class="wp-block-heading" id="h-telehealth-video-conferencing-platforms"><strong>Telehealth / Video Conferencing Platforms:</strong></h5>



<ul class="wp-block-list">
<li><em>Why:</em> When you conduct teletherapy sessions, PHI (audio, video, screen shares, chat messages) is transmitted through and processed by the platform&#8217;s servers. Even if they don&#8217;t store the video, the transmission involves access.</li>



<li><em>Examples:</em> Zoom for Healthcare, Doxy.me, SimplePractice Telehealth, or any specific HIPAA-compliant telehealth solution.</li>



<li><em>Crucial Note:</em> Free, consumer versions of platforms like standard Zoom, Google Meet, or FaceTime are <strong>NOT HIPAA compliant</strong> and will not sign a BAA. Never use these for PHI.</li>
</ul>



<h5 class="wp-block-heading" id="h-cloud-storage-amp-productivity-suites"><strong>Cloud Storage &amp; Productivity Suites:</strong></h5>



<ul class="wp-block-list">
<li><em>Why:</em> If you save any client notes, reports, scanned documents, or other files containing PHI to a cloud drive, or use cloud-based email/document services where PHI might reside or pass through.</li>



<li><em>Examples:</em> Google Workspace (formerly G Suite), Microsoft 365 (formerly Office 365), Dropbox Business.</li>



<li><em>Crucial Note:</em> You must have the <strong>business or enterprise versions</strong> of these services, and you must specifically request and sign their BAA. Standard consumer accounts (e.g., free Gmail, personal Dropbox) <strong>do NOT offer BAAs and are not HIPAA compliant</strong> for PHI.</li>
</ul>



<h5 class="wp-block-heading" id="h-email-marketing-amp-communication-platforms-if-used-for-client-communications"><strong>Email Marketing &amp; Communication Platforms (if used for client communications):</strong></h5>



<ul class="wp-block-list">
<li><em>Why:</em> If you use an email service to send appointment reminders, share resources, or communicate anything with clients that could be considered PHI (even indirectly), your email provider needs a BAA. Your personal Gmail or Outlook.com accounts are out!</li>



<li><em>Examples:</em> Certain secure email providers often bundled with EHRs or business productivity suites.</li>



<li><em>Crucial Note:</em> Again, consumer email services are generally not <strong>HIPAA compliant for handling PHI</strong>, as they typically do not provide the necessary Business Associate Agreements. Ensure your email provider offers a BAA.</li>
</ul>



<h5 class="wp-block-heading" id="h-billing-amp-claims-processing-services"><strong>Billing &amp; Claims Processing Services:</strong></h5>



<ul class="wp-block-list">
<li><em>Why:</em> These services handle all the financial PHI related to your clients, including diagnoses, procedure codes, and personal identifying information.</li>



<li><em>Examples:</em> Any third-party billing company or clearinghouse you use to submit claims.</li>
</ul>



<h4 class="wp-block-heading" id="h-infrastructure-amp-support-services-with-phi-access"><strong>Infrastructure &amp; Support Services with PHI Access</strong></h4>



<p>These services may not directly process your core client notes.  However, they have access to the underlying systems, devices, or physical records that contain PHI.  This makes a BAA essential for SLPs that use them.</p>



<h5 class="wp-block-heading" id="h-antivirus-and-endpoint-security-solutions"><strong>Antivirus and Endpoint Security Solutions:</strong></h5>



<ul class="wp-block-list">
<li><em>Why:</em> This one often surprises people! Antivirus software constantly scans and interacts with all files on your hard drive, including those that may temporarily contain PHI. It monitors network traffic where PHI is transmitted. Many also send telemetry data back to their servers, potentially including fragments of PHI. Because of this <strong>direct and persistent access</strong> to data on devices that handle PHI, the antivirus vendor becomes a Business Associate.</li>



<li><em>Examples:</em> Business-grade versions of solutions like Trend Micro Apex One, Bitdefender GravityZone, ESET Endpoint Security, CrowdStrike, or Symantec Endpoint Protection.</li>



<li><em>Crucial Note:</em> Most free or consumer-grade antivirus products (like the version of Avast we discussed) are <strong>not suitable for devices handling PHI</strong> because they typically do not offer BAAs.  (I&#8217;m having trouble finding one that offers a BAA for a sole entity.)</li>
</ul>



<h5 class="wp-block-heading" id="h-it-support-managed-service-providers-msps"><strong>IT Support / Managed Service Providers (MSPs):</strong></h5>



<ul class="wp-block-list">
<li><em>Why:</em> If an IT professional accesses your computer systems, servers, or network to perform maintenance, updates, or troubleshooting, and those systems contain or access PHI, they are a Business Associate. They have access to the underlying infrastructure that houses your PHI.</li>



<li><em>Examples:</em> Any company or individual you hire to manage your practice&#8217;s technology infrastructure.</li>
</ul>



<h5 class="wp-block-heading" id="h-physical-document-shredding-disposal-services"><strong>Physical Document Shredding/Disposal Services:</strong></h5>



<ul class="wp-block-list">
<li><em>Why:</em> If you use a third-party service to shred or dispose of paper records containing PHI, they are handling and destroying that PHI on your behalf.</li>



<li><em>Examples:</em> Shred-it or local shredding services.</li>
</ul>



<h3 class="wp-block-heading">Who Doesn&#8217;t Need a BAA? The &#8220;Conduit Exception&#8221;</h3>



<p>Not every single service you deal with as an SLP needs a BAA (Whew!). The most common exception is for entities that merely act as a &#8220;conduit.&#8221;  This is a principle often referred to as the <strong>&#8220;Conduit Exception Rule,&#8221;</strong> as further detailed by the HIPAA Journal..</p>



<ul class="wp-block-list">
<li><strong>Internet Service Providers (ISPs):</strong>&nbsp;Your home internet provider (e.g., Comcast, AT&amp;T, Spectrum) typically does NOT need a BAA with you. Their role is limited to transmitting information, like a digital postal service. Any access they might have to the content of your data is transient and incidental, simply for the purpose of moving the data. They aren&#8217;t storing or processing the PHI itself.
<ul class="wp-block-list">
<li><strong>Important Caveat</strong>: While the ISP itself doesn&#8217;t need a BAA, you are still responsible for securing your own home network (strong Wi-Fi passwords, updated router firmware, firewalls). The data you send should be encrypted by the services you&#8217;re using (EHR, telehealth, etc.) before it travels across the internet.</li>
</ul>
</li>



<li><strong>The U.S. Postal Service (USPS) or other mail couriers (e.g., FedEx, UPS)</strong>: If you mail physical documents containing PHI (securely, of course!), these services are considered conduits.</li>
</ul>



<h3 class="wp-block-heading" id="h-the-school-slp-baas-amp-educational-platforms-google-workspace-microsoft-365-etc-deep-dive">The School SLP, BAAs &amp; Educational Platforms (Google Workspace, Microsoft 365, etc.) Deep Dive:</h3>



<figure class="wp-block-image alignright size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/classroom-8407932_1280.webp" alt="An illustration of an online classroom on a laptop screen, showing a teacher presenting to eight students at desks, symbolizing educational tech platforms requiring BAAs." class="wp-image-115" style="width:306px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/classroom-8407932_1280.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/classroom-8407932_1280-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/classroom-8407932_1280-150x150.webp 150w, https://mrsspeechonline.com/wp-content/uploads/2025/06/classroom-8407932_1280-768x768.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Online classroom platforms used by SLPs may require a Business Associate Agreement to ensure HIPAA-compliant handling of student PHI.</figcaption></figure>



<p>If you&#8217;re an SLP working with a school district that uses&nbsp;<strong>Google Workspace for Education or Microsoft 365 Education</strong>&nbsp;(or similar educational platforms), here&#8217;s your specific action plan for BAAs and handling PHI:</p>



<ul class="wp-block-list">
<li><strong>The School&#8217;s BAA with the Platform Provider:</strong> Your absolute first step is to confirm with the school district&#8217;s IT department or administration if they have a BAA in place. Both Google and Microsoft do offer BAAs for their education editions (from what I could find).  However, the school administrator must specifically enable HIPAA compliance settings and accept the BAA for it to be active. Without this, the platform is NOT HIPAA compliant for PHI.</li>



<li><strong>Your Use within Their System:</strong> IYou might be covered under your school&#8217;s HIPAA umbrella, provided these conditions are met:
<ul class="wp-block-list">
<li>The school has a Business Associate Agreement (BAA) with the platform provider.</li>



<li>Your use of their provided account (e.g., your school district Google or Microsoft account) falls under their defined, HIPAA-compliant policies. It&#8217;s crucial that you adhere strictly to the school&#8217;s internal policies and procedures for handling student health information within these platforms.</li>
</ul>
</li>



<li><strong>No BAA from School?</strong>&nbsp;Big Problem! If the school district does not have a BAA in place with Google, Microsoft, or any other cloud service they&#8217;re making you use for PHI, you cannot legally use those services for PHI. You would need to advocate strongly for them to become compliant or use alternative, secure methods for your PHI handling that are sanctioned by the school and meet HIPAA standards. Using non-compliant platforms for PHI, even if mandated by a school, could put your personal license and practice at risk if you are a Covered Entity.</li>
</ul>



<h3 class="wp-block-heading" id="h-working-at-home-slp-security-beyond-a-baa">Working At Home: SLP Security Beyond a BAA</h3>



<h4 class="wp-block-heading" id="h-taking-work-home-using-personal-devices">Taking Work Home/Using Personal Devices</h4>



<p>This is a common scenario and a significant HIPAA risk. If you take work home that involves PHI (e.g., student health records, IEPs with medical details, notes with diagnoses) and use personal devices or home networks:</p>



<ul class="wp-block-list">
<li><strong>No PHI on Personal Devices (Unless Controlled):</strong>&nbsp;Ideally, avoid storing or processing any PHI on your personal computer, tablet, or phone unless these devices are explicitly managed by the school&#8217;s IT department with appropriate security configurations (encryption, remote wipe capabilities, etc.) and covered under their HIPAA compliance program.</li>



<li><strong>Secure Remote Access</strong>: If you must access school-based PHI from home, you should only do so via secure, encrypted channels provided by the school (e.g., a Virtual Private Network (VPN) connection to the school&#8217;s server, or accessing cloud-based platforms directly through a web browser on a school-managed or properly secured device).</li>



<li><strong>Physical Security:</strong>&nbsp;If you bring physical documents containing PHI home, they must be stored securely (e.g., in a locked filing cabinet) and never left visible or accessible to others in your household. Any physical PHI you need to dispose of at home must be shredded securely, not just thrown in the trash.</li>



<li><strong>Home Network Security</strong>: Ensure your home Wi-Fi network is password-protected with a strong, unique password and that your router firmware is up to date.</li>
</ul>



<h4 class="wp-block-heading" id="h-your-personal-private-practice-billing-if-applicable"><strong>Your Personal Private Practice/Billing (if applicable)</strong></h4>



<p>If you, as an individual SLP, have a private practice, even a few hours a month, and bill Medicaid or other health plans electronically, you are unequivocally a HIPAA Covered Entity. If you use any Google Workspace or Microsoft 365 features (even if provided by the school) for your private practice PHI that isn&#8217;t part of the school&#8217;s &#8220;education record&#8221; (e.g., your own private therapy notes for direct billing, your own client contact lists), you need to be very clear about how that PHI is handled. It&#8217;s often safest and most advisable to maintain entirely separate, fully BAA-covered systems for your SLP work to avoid commingling data and potential compliance issues.</p>



<h3 class="wp-block-heading" id="h-the-risks-of-skipping-a-baa-for-slps-why-it-matters-to-you">The Risks of Skipping a BAA for SLPs: Why It Matters to YOU</h3>



<figure class="wp-block-image alignleft size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="757" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/cybersecurity-6949298_1280.webp" alt="Illustration of a masked hacker emerging from a laptop screen with a bag of digital data and an unlocked padlock, symbolizing a cybersecurity breach and the critical need for a BAA." class="wp-image-117" style="width:319px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/cybersecurity-6949298_1280.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/cybersecurity-6949298_1280-300x222.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/cybersecurity-6949298_1280-768x568.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Without a BAA, you lack contractual assurance against data breaches and face severe consequences if PHI is compromised.</figcaption></figure>



<p>You might be thinking, &#8220;This is a lot of paperwork! It&#8217;s just little ole me!&#8221; But the consequences of not having a required BAA can be severe:</p>



<ul class="wp-block-list">
<li><strong>Hefty Fines &amp; Penalties:</strong>&nbsp;The HHS Office for Civil Rights (OCR) can impose significant civil monetary penalties for HIPAA violations. Failing to have a BAA is a direct violation. Fines range from hundreds to hundreds of thousands of dollars per violation, potentially reaching millions annually.
<ul class="wp-block-list">
<li><strong>Real-World Example:</strong>&nbsp;Reports from sources like Paubox highlight documented cases of covered entities facing substantial fines (e.g., hundreds of thousands to millions of dollars) for failing to execute BAAs with vendors who then experienced a breach. For instance, in one case, a medical center paid $240,000 for HIPAA Security Rule failures, including issues with a Business Associate Agreement. Another entity paid $500,000 for PHI exposure due to the absence of a BAA with a medical billing contractor.</li>
</ul>
</li>



<li><strong>Legal Liability:</strong>&nbsp;If a Business Associate mishandles PHI and you don&#8217;t have a BAA in place, you (the Covered Entity) can be held directly liable for their actions. This could lead to lawsuits from affected clients.</li>



<li><strong>Increased Data Breach Vulnerability:</strong>&nbsp;Without a BAA, you have no contractual assurance that your vendor is implementing the necessary security safeguards. This leaves your clients&#8217; sensitive information vulnerable.</li>



<li><strong>Reputational Damage:</strong>&nbsp;A data breach or HIPAA violation severely erodes client trust and can lead to significant reputational harm, impacting your ability to attract and retain clients.</li>



<li><strong>Audit Red Flag:</strong>&nbsp;During an OCR audit or investigation, one of the first things they&#8217;ll check for is signed BAAs. Missing BAAs are an immediate red flag that can trigger deeper scrutiny and more severe penalties, as discussed by Secureframe and other compliance resources.</li>
</ul>



<h3 class="wp-block-heading">Best Practices for Managing Your BAAs</h3>



<p>Once you start collecting BAAs, effective management is key:</p>



<figure class="wp-block-image alignright size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="1024" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/list-2828012_1280.webp" alt="A stylized illustration of a clipboard with a checklist, two items checked, and a yellow pencil, symbolizing essential steps for managing Business Associate Agreements." class="wp-image-119" style="width:306px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/list-2828012_1280.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/list-2828012_1280-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/list-2828012_1280-150x150.webp 150w, https://mrsspeechonline.com/wp-content/uploads/2025/06/list-2828012_1280-768x768.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption class="wp-element-caption">Effectively managing your BAAs involves a systematic checklist to ensure ongoing HIPAA compliance.</figcaption></figure>



<ul class="wp-block-list">
<li><strong>Create a Vendor Inventory:</strong>&nbsp;Maintain a clear, organized list of all your service providers. For each, note:
<ul class="wp-block-list">
<li>Vendor Name</li>



<li>Service Provided</li>



<li>PHI Accessed (e.g., clinical notes, billing data, demographics)</li>



<li>BAA Status (Yes/No)</li>



<li>Date BAA Signed</li>



<li>Date for Next Review (e.g., annually, or upon contract renewal)</li>



<li>Location of Signed BAA (digital file path or physical folder)</li>
</ul>
</li>



<li><strong>Due Diligence is Key:</strong>&nbsp;Don&#8217;t just get a signed BAA; conduct basic due diligence. While you don&#8217;t need to perform a full security audit, ask questions about their security practices (e.g., do they encrypt data? do they have strong access controls? do they perform their own risk assessments?). A good BAA means they&#8217;ve agreed to protect PHI, but you should still have a reasonable assurance that they can and do.</li>



<li><strong>Regular Review and Update:</strong>&nbsp;Your practice and the services you use will evolve. Review your vendor inventory and all BAAs annually, or whenever:
<ul class="wp-block-list">
<li>You change a service provider.</li>



<li>A vendor changes the services they provide.</li>



<li>HIPAA regulations are updated.</li>



<li>There&#8217;s a significant change in your practice operations.</li>
</ul>
</li>



<li><strong>Document Everything:</strong>&nbsp;Keep all signed BAAs, vendor communications about security, and your internal review notes meticulously organized. In the event of an audit, documentation is your best friend.</li>
</ul>



<h3 class="wp-block-heading" id="h-your-action-steps-for-baa-compliance-as-an-slp">Your Action Steps for BAA Compliance as an SLP:</h3>



<ol class="wp-block-list">
<li><strong>Inventory Your Vendors:</strong>&nbsp;Make a list of every service provider (including software and online platforms) that interacts with PHI in your practice.</li>



<li><strong>Assess &#8220;Access to PHI&#8221;:</strong>&nbsp;For each vendor, ask: &#8220;Does this service create, receive, maintain, or transmit PHI on my behalf, or does it have persistent access to PHI?&#8221;</li>



<li><strong>Request a BAA:</strong>&nbsp;If the answer to #2 is &#8220;yes,&#8221; contact the vendor and request their BAA. Most legitimate business-grade services for healthcare will have one ready.</li>



<li><strong>Read and Understand:</strong>&nbsp;Don&#8217;t just sign! Read the BAA carefully to understand your and their responsibilities.</li>



<li><strong>Document:&nbsp;</strong>Keep all signed BAAs on file as part of your HIPAA compliance documentation.</li>



<li><strong>Regular Review:</strong>&nbsp;Revisit your vendor list and BAAs annually, or whenever you add a new service or there&#8217;s a significant change in your practice or technology.</li>
</ol>



<h3 class="wp-block-heading" id="h-you-can-do-it">You can do it!</h3>



<p>Navigating Business Associate Agreements as an SLP can feel overwhelming, but it&#8217;s a critical aspect of being a responsible and compliant healthcare provider. By taking these proactive steps, you&#8217;re building a strong foundation of trust and security for your clients and your practice.</p>



<p>Want to know more?  Check out these posts!</p>



<ul class="wp-block-list">
<li><a href="https://mrsspeechonline.com/my-personal-hipaa-compliance-journey-steps-to-secure-data/">My Personal HIPAA Compliance Journey: Steps to Secure Data</a></li>



<li><a href="https://mrsspeechonline.com/slp-hipaa-compliance-cloud-schools-teletherapy-phi-security/">HIPAA Compliance At Home: Cloud, Schools, Teletherapy &amp; PHI Security</a></li>
</ul>



<h4 class="wp-block-heading" id="h-what-other-hipaa-questions-are-on-your-mind-share-in-the-comments">What other HIPAA questions are on your mind? Share in the comments!</h4>



<figure class="wp-block-image alignleft size-full is-resized"><img loading="lazy" decoding="async" width="1024" height="670" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/Download.webp" alt="A red, starburst-shaped graphic with bold yellow text &quot;FREE!&quot; and green text &quot;DOWNLOAD&quot;, serving as a call to action for a free resource." class="wp-image-104" style="width:197px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/Download.webp 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Download-300x196.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/06/Download-768x503.webp 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p>Don&#8217;t forget to download your&nbsp;<strong>free HIPAA Home Office Policies &amp; Procedures Worksheet</strong>&nbsp;to help you get started on your internal documentation! Sign up below for Exclusive access to my Subscriber Freebies page, newsletter, blog updates, and special announcements!</p>


  
  
  <div class="
    mailpoet_form_popup_overlay
      "></div>
  <div
    id="mailpoet_form_2"
    class="
      mailpoet_form
      mailpoet_form_html
      mailpoet_form_position_
      mailpoet_form_animation_
    "
      >

    <style type="text/css">
     #mailpoet_form_2 .mailpoet_form {  }
#mailpoet_form_2 form { margin-bottom: 0; }
#mailpoet_form_2 p.mailpoet_form_paragraph.last { margin-bottom: 0px; }
#mailpoet_form_2 h2.mailpoet-heading { margin: -10px 0 10px 0; }
#mailpoet_form_2 .mailpoet_column_with_background { padding: 10px; }
#mailpoet_form_2 .mailpoet_form_column:not(:first-child) { margin-left: 20px; }
#mailpoet_form_2 .mailpoet_paragraph { line-height: 20px; margin-bottom: 20px; }
#mailpoet_form_2 .mailpoet_segment_label, #mailpoet_form_2 .mailpoet_text_label, #mailpoet_form_2 .mailpoet_textarea_label, #mailpoet_form_2 .mailpoet_select_label, #mailpoet_form_2 .mailpoet_radio_label, #mailpoet_form_2 .mailpoet_checkbox_label, #mailpoet_form_2 .mailpoet_list_label, #mailpoet_form_2 .mailpoet_date_label { display: block; font-weight: normal; }
#mailpoet_form_2 .mailpoet_text, #mailpoet_form_2 .mailpoet_textarea, #mailpoet_form_2 .mailpoet_select, #mailpoet_form_2 .mailpoet_date_month, #mailpoet_form_2 .mailpoet_date_day, #mailpoet_form_2 .mailpoet_date_year, #mailpoet_form_2 .mailpoet_date { display: block; }
#mailpoet_form_2 .mailpoet_text, #mailpoet_form_2 .mailpoet_textarea { width: 200px; }
#mailpoet_form_2 .mailpoet_checkbox {  }
#mailpoet_form_2 .mailpoet_submit {  }
#mailpoet_form_2 .mailpoet_divider {  }
#mailpoet_form_2 .mailpoet_message {  }
#mailpoet_form_2 .mailpoet_form_loading { width: 30px; text-align: center; line-height: normal; }
#mailpoet_form_2 .mailpoet_form_loading > span { width: 5px; height: 5px; background-color: #5b5b5b; }#mailpoet_form_2{border: 5px solid #c07000;border-radius: 40px;background: linear-gradient(180deg,rgb(255,243,214) 0%,rgb(255,255,255) 100%);color: #240002;text-align: left;}#mailpoet_form_2 form.mailpoet_form {padding: 10px;}#mailpoet_form_2{width: 100%;}#mailpoet_form_2 .mailpoet_message {margin: 0; padding: 0 20px;}
        #mailpoet_form_2 .mailpoet_validate_success {color: #00d084}
        #mailpoet_form_2 input.parsley-success {color: #00d084}
        #mailpoet_form_2 select.parsley-success {color: #00d084}
        #mailpoet_form_2 textarea.parsley-success {color: #00d084}
      
        #mailpoet_form_2 .mailpoet_validate_error {color: #cf2e2e}
        #mailpoet_form_2 input.parsley-error {color: #cf2e2e}
        #mailpoet_form_2 select.parsley-error {color: #cf2e2e}
        #mailpoet_form_2 textarea.textarea.parsley-error {color: #cf2e2e}
        #mailpoet_form_2 .parsley-errors-list {color: #cf2e2e}
        #mailpoet_form_2 .parsley-required {color: #cf2e2e}
        #mailpoet_form_2 .parsley-custom-error-message {color: #cf2e2e}
      #mailpoet_form_2 .mailpoet_paragraph.last {margin-bottom: 0} @media (max-width: 500px) {#mailpoet_form_2 {background: linear-gradient(180deg,rgb(255,243,214) 0%,rgb(255,255,255) 100%);}} @media (min-width: 500px) {#mailpoet_form_2 .last .mailpoet_paragraph:last-child {margin-bottom: 0}}  @media (max-width: 500px) {#mailpoet_form_2 .mailpoet_form_column:last-child .mailpoet_paragraph:last-child {margin-bottom: 0}} 
    </style>

    <form
      target="_self"
      method="post"
      action="https://mrsspeechonline.com/wp-admin/admin-post.php?action=mailpoet_subscription_form"
      class="mailpoet_form mailpoet_form_form mailpoet_form_html"
      novalidate
      data-delay=""
      data-exit-intent-enabled=""
      data-font-family=""
      data-cookie-expiration-time=""
    >
      <input type="hidden" name="data[form_id]" value="2" />
      <input type="hidden" name="token" value="b7980c8f49" />
      <input type="hidden" name="api_version" value="v1" />
      <input type="hidden" name="endpoint" value="subscribers" />
      <input type="hidden" name="mailpoet_method" value="subscribe" />

      <label class="mailpoet_hp_email_label" style="display: none !important;">Please leave this field empty<input type="email" name="data[email]"/></label><h3 class="mailpoet-heading  mailpoet-has-font-size" style="text-align: center; color: #240002; font-size: 36px">Want exclusive freebies?</h3>
<div class="mailpoet_paragraph "><style>input[name="data[form_field_ZTYwMWUzMTY0ZDU0X2ZpcnN0X25hbWU=]"]::placeholder{color:#5b8ba7;opacity: 1;}</style><input type="text" autocomplete="given-name" class="mailpoet_text" id="form_first_name_2" name="data[form_field_ZTYwMWUzMTY0ZDU0X2ZpcnN0X25hbWU=]" title="First Name" value="" style="width:100%;box-sizing:border-box;background-color:#ffffff;border-style:solid;border-radius:10px !important;border-width:1px;border-color:#313131;padding:4px;margin: 0 auto 0 0;font-family:&#039;Ubuntu&#039;;font-size:16px;line-height:1.5;height:auto;color:#5b8ba7;" data-automation-id="form_first_name"  placeholder="First Name" aria-label="First Name" data-parsley-errors-container=".mailpoet_error_da2wr" data-parsley-names='[&quot;Please specify a valid name.&quot;,&quot;Addresses in names are not permitted, please add your name instead.&quot;]'/><span class="mailpoet_error_da2wr"></span></div>
<div class="mailpoet_paragraph "><style>input[name="data[form_field_ZTU2MDYxYjE3Njk1X2VtYWls]"]::placeholder{color:#5b8ba7;opacity: 1;}</style><input type="email" autocomplete="email" class="mailpoet_text" id="form_email_2" name="data[form_field_ZTU2MDYxYjE3Njk1X2VtYWls]" title="Email Address" value="" style="width:100%;box-sizing:border-box;background-color:#ffffff;border-style:solid;border-radius:10px !important;border-width:1px;border-color:#313131;padding:4px;margin: 0 auto 0 0;font-family:&#039;Ubuntu&#039;;font-size:16px;line-height:1.5;height:auto;color:#5b8ba7;" data-automation-id="form_email"  placeholder="Email Address *" aria-label="Email Address *" data-parsley-errors-container=".mailpoet_error_hmnqx" data-parsley-required="true" required aria-required="true" data-parsley-minlength="6" data-parsley-maxlength="150" data-parsley-type-message="This value should be a valid email." data-parsley-required-message="This field is required."/><span class="mailpoet_error_hmnqx"></span></div>
<div class="mailpoet_paragraph "><input type="submit" class="mailpoet_submit" value="I want my freebies!" data-automation-id="subscribe-submit-button" data-font-family='Ubuntu' style="width:100%;box-sizing:border-box;background-color:#c07000;border-style:solid;border-radius:10px !important;border-width:1px;padding:4px;margin: 0 auto 0 0;font-family:&#039;Ubuntu&#039;;font-size:20px;line-height:1.5;height:auto;color:#ffffff;border-color:transparent;font-weight:bold;" /><span class="mailpoet_form_loading"><span class="mailpoet_bounce1"></span><span class="mailpoet_bounce2"></span><span class="mailpoet_bounce3"></span></span></div>
<p class="mailpoet_form_paragraph  mailpoet-has-font-size" style="text-align: center; color: #240002; font-size: 14px; line-height: 1.2"><span style="font-family:" data-font="" class="mailpoet-has-font">We don’t spam! Read our <a href="https://mrsspeechonline.com/privacy-policy/" data-type="link" data-id="https://mrsspeechonline.com/privacy-policy/">privacy policy</a> for more info.</span></p>
<p class="mailpoet_form_paragraph  mailpoet-has-font-size" style="text-align: center; font-size: 13px">See the <a href="https://mrsspeechonline.com/subscription-options-guide/" data-type="link" data-id="https://mrsspeechonline.com/subscription-options-guide/">subscription guide</a> for more information!</p>

      <div class="mailpoet_message">
        <p class="mailpoet_validate_success"
                style="display:none;"
                >Check your inbox or spam folder to confirm your subscription.
        </p>
        <p class="mailpoet_validate_error"
                style="display:none;"
                >        </p>
      </div>
    </form>

      </div>

  


<p><strong>Disclaimer:</strong></p>



<p class="has-small-font-size"><em>The information provided in this blog post is for informational and educational purposes only and is not intended to constitute legal or professional advice. HIPAA compliance is complex and constantly evolving. While efforts have been made to ensure the accuracy of the information presented, it may not reflect the most current legal developments, nor is it guaranteed to be complete or applicable to your specific situation.  As a healthcare professional, it is your responsibility to understand and comply with all applicable federal, state, and local laws and regulations, including HIPAA. This content should not be used as a substitute for seeking qualified legal counsel from an attorney specializing in healthcare law, particularly concerning your individual practice, specific vendor relationships, or unique circumstances. Reliance on any information provided in this post is solely at your own risk.</em></p>



<h3 class="wp-block-heading">References:</h3>



<ul class="wp-block-list">
<li><strong>U.S. Department of Health &amp; Human Services (HHS).</strong><em>Business Associate Contracts.</em>&nbsp;Retrieved from&nbsp;<a href="https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html" target="_blank" rel="noreferrer noopener nofollow">https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html</a></li>



<li><strong>U.S. Department of Health &amp; Human Services (HHS).</strong><em>Business Associates.</em>&nbsp;Retrieved from&nbsp;<a href="https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html" target="_blank" rel="noreferrer noopener nofollow">https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html</a></li>



<li><strong>HIPAA Journal.</strong><em> HIPAA Conduit Exception Rule and Transmission of PHI: 2025 Update.</em>&nbsp;(Updated January 2, 2025). Retrieved from&nbsp;<a href="https://www.hipaajournal.com/hipaa-conduit-exception-rule/" target="_blank" rel="noreferrer noopener nofollow">https://www.hipaajournal.com/hipaa-conduit-exception-rule/</a></li>



<li><strong>Paubox.</strong><em> HIPAA lessons learned: A review of HHS resolution agreements.</em>&nbsp;(Updated January 23, 2025). Retrieved from&nbsp;<a href="https://www.paubox.com/blog/hipaa-lessons-learned-a-review-of-hhs-resolution-agreements" target="_blank" rel="noreferrer noopener nofollow">https://www.paubox.com/blog/hipaa-lessons-learned-a-review-of-hhs-resolution-agreements</a></li>



<li><strong>Secureframe.</strong><em> HIPAA Violations: Examples, Fines + 5 Cases to Learn From.</em>&nbsp;Retrieved from&nbsp;<a href="https://secureframe.com/hub/hipaa/violations" target="_blank" rel="noreferrer noopener nofollow">https://secureframe.com/hub/hipaa/violations</a></li>
</ul>



<div class="wp-block-group is-layout-constrained wp-block-group-is-layout-constrained">
<figure class="wp-block-image aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="810" height="169" src="https://i0.wp.com/vmx.erb.mybluehost.me/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp?fit=810%2C169&amp;ssl=1" alt="Mrs. Speech Signature" class="wp-image-804" style="width:364px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp 810w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-300x63.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-768x160.webp 768w" sizes="auto, (max-width: 810px) 100vw, 810px" /></figure>



<div class="wp-block-group is-content-justification-center is-nowrap is-layout-flex wp-container-core-group-is-layout-23441af8 wp-block-group-is-layout-flex">
<figure class="wp-block-image size-full is-resized"><a href="https://www.facebook.com/profile.php?id=61556892726241" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="388" height="398" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp" alt="facebook icon" class="wp-image-815" style="width:48px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp 388w, https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918-292x300.webp 292w" sizes="auto, (max-width: 388px) 100vw, 388px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.instagram.com/mrs.speechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="418" height="408" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp" alt="Instagram Icon" class="wp-image-818" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp 418w, https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939-300x293.webp 300w" sizes="auto, (max-width: 418px) 100vw, 418px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.pinterest.com/mrsspeechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="413" height="410" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp" alt="pinterest icon" class="wp-image-816" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp 413w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-300x298.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-150x150.webp 150w" sizes="auto, (max-width: 413px) 100vw, 413px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.linkedin.com/in/jennifer-tillock-821999287/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="402" height="402" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp" alt="LinkedIn Icon" class="wp-image-821" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp 402w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-150x150.webp 150w" sizes="auto, (max-width: 402px) 100vw, 402px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="http://www.youtube.com/@Mrs.Speech-wk4mr" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="429" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp" alt="YouTube icon" class="wp-image-817" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp 429w, https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232-300x291.webp 300w" sizes="auto, (max-width: 429px) 100vw, 429px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.teacherspayteachers.com/store/mrs-speech" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="423" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp" alt="TeachersPayTeachers Icon" class="wp-image-822" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp 423w, https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756-300x295.webp 300w" sizes="auto, (max-width: 423px) 100vw, 423px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="414" height="413" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp" alt="Mrs. Speech Books Icon" class="wp-image-1322" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp 414w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-150x150.webp 150w" sizes="auto, (max-width: 414px) 100vw, 414px" /></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="387" height="377" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp" alt="MailTo Icon" class="wp-image-1326" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp 387w, https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307-300x292.webp 300w" sizes="auto, (max-width: 387px) 100vw, 387px" /></figure>
</div>
</div>



<p class="icon-attribution" style="font-size: 0.6em; font-style: italic;">
    Social Media Icons: <a href="https://www.freepik.com" target="_blank" rel="noopener">designed by rawpixel.com &#8211; Freepik.com</a>
</p>



<div style="height:47px" aria-hidden="true" class="wp-block-spacer"></div>


<div style="color:#db820e;font-style:normal;font-weight:300" class="taxonomy-post_tag has-text-align-center has-link-color wp-elements-e81afc2be6272024545412bcb750c79c wp-block-post-terms has-text-color"><a href="https://mrsspeechonline.com/tag/business-associate-agreement/" rel="tag">Business Associate Agreement</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/google/" rel="tag">Google</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/hipaa-security/" rel="tag">HIPAA Security</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/home-office/" rel="tag">Home Office</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/microsoft/" rel="tag">Microsoft</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/schools/" rel="tag">Schools</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/technology/" rel="tag">Technology</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/teletherapy/" rel="tag">Teletherapy</a></div><p>The post <a href="https://mrsspeechonline.com/slp-business-associate-agreement-hipaa-guide/">Navigating Business Associate Agreements as an SLP:  Your HIPAA BAA Guide</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://mrsspeechonline.com/slp-business-associate-agreement-hipaa-guide/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>My Personal HIPAA Compliance Journey: Steps to Secure Data</title>
		<link>https://mrsspeechonline.com/personal-hipaa-compliance-journey/</link>
					<comments>https://mrsspeechonline.com/personal-hipaa-compliance-journey/#respond</comments>
		
		<dc:creator><![CDATA[Jennifer]]></dc:creator>
		<pubDate>Tue, 12 Aug 2025 17:22:16 +0000</pubDate>
				<category><![CDATA[Clinical]]></category>
		<category><![CDATA[Compliance & Ethics]]></category>
		<category><![CDATA[Business Associate Agreement]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Workspace]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[Home Office]]></category>
		<category><![CDATA[Insights]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Personal Journey]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Teletherapy]]></category>
		<category><![CDATA[Tips]]></category>
		<guid isPermaLink="false">https://mrsspeechonline.com/personal-hipaa-compliance-journey/</guid>

					<description><![CDATA[<p>Ready to build a HIPAA-compliant practice? This post details one SLP's personal journey of securing her home-based teletherapy setup, from choosing the right tech like Google Workspace to implementing strict Data Loss Prevention (DLP) rules. What’s one step you plan to take to secure your own practice?</p>
<p>The post <a href="https://mrsspeechonline.com/personal-hipaa-compliance-journey/">My Personal HIPAA Compliance Journey: Steps to Secure Data</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading" id="h-how-i-m-making-my-solo-practice-hipaa-happy">How I&#8217;m Making My Solo Practice HIPAA-Happy!</h2>



<p>Hey fellow SLPs and healthcare pros! Today, I want to share some insights from my personal journey towards HIPAA compliance.</p>



<p>In my last two posts, we delved into the crucial topic of&nbsp;<strong>HIPAA compliance for telepractice</strong>.  They covered the &#8220;what&#8221; and the &#8220;why.&#8221;</p>



<ul class="wp-block-list">
<li><a href="https://mrsspeechonline.com/hipaa-compliance-at-home" target="_blank" rel="noreferrer noopener">HIPAA Compliance At Home: Cloud, Schools, Teletherapy &amp; PHI Security</a></li>



<li><a href="https://mrsspeechonline.com/slp-business-associate-agreement-hipaa-guide/" target="_blank" rel="noreferrer noopener">Navigating Business Associate Agreements as an SLP:  Your HIPAA BAA Guide</a></li>
</ul>



<p>Today, I want to share the &#8220;how&#8221; – my personal journey of putting these principles into practice! I’ve been diving deep into my tech setup to make sure it&#8217;s not just functional, but also rock-solid HIPAA compliant. <em><strong> </strong></em>For example, as a teletherapist, some of my schools don&#8217;t invite me into their workspace. This leaves it up to me to securely manage all my client notes and materials. This kind of gap is precisely what drove me to build a truly robust system.</p>



<p>It might sound daunting, but trust me, it&#8217;s all about peace of mind for both you and your clients. I wanted to share a rundown of what I&#8217;ve done.  More importantly, I want to share why I&#8217;ve done it, in case it helps you level up your practice too!</p>



<h3 class="wp-block-heading" id="h-the-why-behind-my-personal-hipaa-compliance-journey">The &#8220;Why&#8221; Behind My Personal HIPAA Compliance Journey</h3>



<p>My biggest drive was simple. I needed to know, without any doubt, that I was protecting my clients&#8217; sensitive information to the highest standard. HIPAA isn&#8217;t just a checkbox; it&#8217;s about building trust. First, conducted a&nbsp;<strong>thorough risk analysis</strong>&nbsp;of my setup to identify any potential vulnerabilities.</p>



<p>I&#8217;ve now meticulously created and am maintaining a detailed&nbsp;<strong>&#8220;Security Policies and Procedures&#8221; document</strong>&nbsp;that guides all my practices. Plus, having everything clearly documented helps me sleep better at night!</p>



<p>Honestly, it wasn&#8217;t that long ago, a few weeks, that I wasn&#8217;t even aware of all of this.  I didn&#8217;t know about Business Associate Agreements (BAAs), or their critical role.  My previous security stance of &#8220;just don&#8217;t share client info&#8221; felt sufficient.  Since then, I&#8217;ve realized how&nbsp;<strong>nebulous and insufficient</strong>&nbsp;that really was for both cloud-based and desktop information.&nbsp;</p>



<h3 class="wp-block-heading" id="h-how-it-all-started">How It All Started</h3>



<p>So, if I wasn&#8217;t born with this wealth of knowledge, and it wasn&#8217;t covered in grad school, what happened?  Well, I discovered that simply removing what I thought was identifying information was&nbsp;<strong>not sufficient for HIPAA de-identification</strong>.  That realization truly sent me down this &#8220;rabbit hole&#8221; of learning and implementing everything you&#8217;re about to read!</p>



<p>Honestly, as a single user, all this might seem like&nbsp;<strong>overkill</strong>&nbsp;at times.  That is, until I really think about the potential&nbsp;<strong>cost and repercussions of a HIPAA violation</strong>. That quickly puts things into perspective!</p>



<p>Here&#8217;s information and tips I&#8217;ve learned on this individual HIPAA compliance trek.  <em><strong>(No, I&#8217;m not affiliated with, or sponsored by, Google in any way, it was just easier to work with.)</strong></em></p>



<h3 class="wp-block-heading" id="h-the-secure-foundation-my-google-workspace-enterprise-standard">The Secure Foundation: My Google Workspace Enterprise Standard</h3>



<figure class="wp-block-image alignleft size-full"><img loading="lazy" decoding="async" width="320" height="213" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/network-3866435_1280.webp" alt="Three modern computer monitors with blank screens, digitally connected to a glowing blue global network sphere covered in white binary code, set against a blue background with radiating lines." class="wp-image-77" title="Securing Cloud Data and Professional Networks" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/network-3866435_1280.webp 320w, https://mrsspeechonline.com/wp-content/uploads/2025/06/network-3866435_1280-300x200.webp 300w" sizes="auto, (max-width: 320px) 100vw, 320px" /><figcaption class="wp-element-caption">Establishing a secure digital foundation for Protected Health Information in the cloud.</figcaption></figure>



<p>Before even setting up my specific security rules, choosing the right Google Workspace edition was crucial. There are several tiers, and it&#8217;s not just about how many emails you can send! For me, picking&nbsp;<strong>Enterprise Standard</strong>&nbsp;was absolutely essential because of the level of HIPAA security I was comfortable with.</p>



<ul class="wp-block-list">
<li><strong>Pro-Tip on Choosing a Platform:</strong>&nbsp;I actually considered Microsoft 365 Business plans, as they also offer BAAs. However, I was already using and familiar with Google&#8217;s interface. More importantly,&nbsp;<strong>I found it much easier to get clear information about Google&#8217;s BAA and HIPAA-included functionality upfront.</strong>&nbsp;Microsoft seems to hide their BAA documentation behind a subscriber wall, making it difficult to fully vet before committing. This ease of information access, combined with my familiarity, ultimately swayed my decision towards Google.&nbsp; Basically, it looks like any paid workspace can have a BAA:&nbsp; &nbsp;<a href="https://support.google.com/a/answer/2888485?sjid=14092164238884574583-NC" target="_blank" rel="noreferrer noopener">https://support.google.com/a/answer/2888485?sjid=14092164238884574583-NC</a></li>
</ul>



<p>Here’s why I landed on it during my own HIPAA compliance trip, and what foundational elements it provides:</p>



<h4 class="wp-block-heading" id="h-the-non-negotiable-baa"><strong>The Non-Negotiable BAA</strong></h4>



<p>This was the top priority. Enterprise Standard definitely comes with a&nbsp;<strong>Business Associate Agreement (BAA)</strong>. This gives me that crucial legal agreement with Google to handle Protected Health Information. This is absolutely non-negotiable for anyone handling PHI with Google Workspace. (You can find Google&#8217;s BAA here:&nbsp;<em><a href="https://workspace.google.com/terms/2015/1/hipaa_baa/" target="_blank" rel="noreferrer noopener">https://workspace.google.com/terms/2015/1/hipaa_baa/</a></em>).</p>



<ul class="wp-block-list">
<li><strong>Pro-Tip on Choosing a Tier</strong> &#8211;&nbsp;I actually started with the cheapest business tier (Business Starter $7/mo), which I can confirm offers a BAA. However, after really digging into the features, I chose to upgrade to Enterprise Standard. It offered&nbsp;<strong>much better control over information and more robust policy enforcement options</strong>.  These ultimately felt essential for protecting client PHI effectively.&nbsp;&nbsp;<a href="https://workspace.google.com/pricing.html?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=1710046-Workspace-DR-NA-US-en-Google-BKWS-sitelink&amp;utm_content=c-Hybrid+%7C+BKWS+-+MIX+%7C+Txt-Google+Workspace-Top-43700076441559576&amp;utm_term=google%20workspace%20cost&amp;gad_source=1&amp;gad_campaignid=20159848972&amp;gclid=Cj0KCQjwmqPDBhCAARIsADorxIYo7rdIj7qMVbdiL1ouVc1tXhZGsD0qfIzDt2J21ImymFsCjBe18s0aAgLjEALw_wcB&amp;gclsrc=aw.ds" target="_blank" rel="noreferrer noopener nofollow">Google Tiers &amp; Pricing</a>&nbsp;</li>



<li><strong>Don&#8217;t Forget Your Domain Name!&nbsp;</strong>A domain name is an additional, but necessary, cost for any Google Workspace Business account. While Google offers to sell you one directly, I opted to buy my domain&nbsp;through Cloudflare for just $10.44/year. This was a cost-effective choice since I already used Cloudflare for other services.</li>
</ul>



<h4 class="wp-block-heading" id="h-serious-pooled-storage">Serious Pooled Storage</h4>



<p>Enterprise Standard offers a massive&nbsp;<strong>5 TB of pooled storage per user</strong>. (Just a heads-up: This pooled storage gets released in stages after payments, so my Drive initially showed less!). This is more than enough space for all my therapy materials and client files.</p>



<div class="wp-block-media-text has-media-on-the-right is-stacked-on-mobile" style="grid-template-columns:auto 25%"><div class="wp-block-media-text__content">
<h4 class="wp-block-heading" id="h-google-vault-for-ironclad-data-retention">Google Vault for Ironclad Data Retention</h4>



<p>This was a game-changer! Enterprise Standard includes&nbsp;<strong>Google Vault</strong>, which allows me to set an&nbsp;<strong>indefinite retention policy</strong>&nbsp;for all my Google data. This ensures I meet and exceed HIPAA&#8217;s minimum six-year data retention requirement. It’s like a super-secure, always-on backup for everything.</p>
</div><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="866" height="1024" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/strongbox-154022_1280-1-866x1024.webp" alt="A large, grey, rectangular safe with a circular combination dial and heavy bolted door, casting a shadow on a light grey floor." class="wp-image-724 size-full" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/06/strongbox-154022_1280-1-866x1024.webp 866w, https://mrsspeechonline.com/wp-content/uploads/2025/06/strongbox-154022_1280-1-254x300.webp 254w, https://mrsspeechonline.com/wp-content/uploads/2025/06/strongbox-154022_1280-1-768x908.webp 768w, https://mrsspeechonline.com/wp-content/uploads/2025/06/strongbox-154022_1280-1.webp 1083w" sizes="auto, (max-width: 866px) 100vw, 866px" /></figure></div>



<h4 class="wp-block-heading" id="h-advanced-data-loss-prevention-dlp">Advanced Data Loss Prevention (DLP)</h4>



<p>This tier gives me access to advanced DLP rules for Gmail and Drive, which are central to my security strategy. These are the powerful rules that can warn me if I try to share sensitive files externally.</p>



<h4 class="wp-block-heading" id="h-comprehensive-security-controls">Comprehensive Security Controls</h4>



<p>Enterprise Standard unlocks a lot of the granular administrative controls I needed. This allowed me to configure things like forcing 2FA, setting strong password policies, and disabling third-party apps.</p>



<p>Basically, for handling PHI and needing robust, auditable security features, Enterprise Standard provided the comprehensive toolkit I needed to feel confident and stay compliant. It&#8217;s an investment at $27/mo, but one that’s absolutely worth it for peace of mind and professional responsibility.</p>



<h3 class="wp-block-heading" id="h-the-core-pillars-of-my-personal-hipaa-compliance-policy">The Core Pillars of My Personal HIPAA Compliance Policy:</h3>



<p>Here&#8217;s a look at the specific configurations I implemented (See Google&#8217;s HIPAA Implementation Guide:&nbsp;&nbsp;<a href="https://services.google.com/fh/files/misc/gsuite_cloud_identity_hipaa_implementation_guide.pdf" target="_blank" rel="noreferrer noopener">https://services.google.com/fh/files/misc/gsuite_cloud_identity_hipaa_implementation_guide.pdf</a>):</p>



<h4 class="wp-block-heading">1. Bulletproof Access Control (Who Gets In? Only Me!)</h4>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:35% auto"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="1920" height="1373" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/secure-access-2fa.png" alt="A digital illustration of a hand touching a &quot;Login&quot; button on a smartphone. The screen shows two password fields filled with asterisks and a shield icon at the top, indicating a secure login process." class="wp-image-2384 size-full" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/secure-access-2fa.png 1920w, https://mrsspeechonline.com/wp-content/uploads/2025/07/secure-access-2fa-300x215.png 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/secure-access-2fa-1024x732.png 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/07/secure-access-2fa-768x549.png 768w, https://mrsspeechonline.com/wp-content/uploads/2025/07/secure-access-2fa-1536x1098.png 1536w, https://mrsspeechonline.com/wp-content/uploads/2025/07/secure-access-2fa-1320x944.png 1320w" sizes="auto, (max-width: 1920px) 100vw, 1920px" /></figure><div class="wp-block-media-text__content">
<ul class="wp-block-list">
<li><strong>2-Step Verification (2FA) is Mandatory:</strong>&nbsp;No exceptions! I enforced 2FA for all account access. This is your absolute best defense against unauthorized logins.</li>



<li><strong>Strong Passwords, Always:</strong>&nbsp;My system enforces strong password policies, requiring a&nbsp;<strong>minimum length of 16 characters</strong>&nbsp;and prompting for a refresh every&nbsp;<strong>180 days</strong>. No weak links here!</li>
</ul>
</div></div>



<ul class="wp-block-list">
<li><strong>Third-Party Apps? Deny by Default!</strong>&nbsp;My policy is strict: all third-party app access is blocked by default. If I ever need an app, it goes through a security review and is force-installed by me, the admin. This prevents unvetted apps from touching my client data.</li>



<li><strong>Strictly BAA-Covered Services Only:</strong>&nbsp;As part of my setup, I went into my Google Admin Console and literally turned&nbsp;<strong>OFF</strong>&nbsp;any Google services that aren&#8217;t explicitly covered by the BAA (like Google Photos, YouTube, etc.). Why? To make sure no PHI accidentally ends up in a non-compliant service. (You can find a list of Google&#8217;s HIPAA Included Functionality and BAA-covered services here:&nbsp;<em><a href="https://workspace.google.com/terms/2015/1/hipaa_functionality/" target="_blank" rel="noreferrer noopener">https://workspace.google.com/terms/2015/1/hipaa_functionality/</a></em>).</li>
</ul>



<h4 class="wp-block-heading">2. Smart Data Protection (No Accidental Leaks!)</h4>



<figure class="wp-block-image alignright size-full is-resized"><img loading="lazy" decoding="async" width="200" height="172" src="https://mrsspeechonline.com/wp-content/uploads/2025/06/data-2998180_1280.webp" alt="A bright blue digital folder icon with an orange padlock placed in front of it, symbolizing secure or locked digital files." class="wp-image-83" style="width:252px;height:auto"/><figcaption class="wp-element-caption">Locking down your digital files to prevent accidental data leaks.</figcaption></figure>



<ul class="wp-block-list">
<li><strong>Gmail Content Compliance:</strong>&nbsp;I set up an automated rule in Gmail that quarantines any outbound email containing PHI-related keywords if it&#8217;s addressed to a domain not on my pre-approved &#8220;Trusted School Districts&#8221; list. It&#8217;s a huge safety net!</li>



<li><strong>Drive DLP (Data Loss Prevention) Rule:</strong>&nbsp;For Google Drive, I have a rule that gives me a real-time warning if I ever try to externally share a file containing PHI keywords. It&#8217;s an extra &#8220;Are you sure?&#8221; before a potential mishap.</li>



<li><strong>Always Use Secure Communication Channels:</strong>&nbsp;Beyond these automated rules, I always ensure that any direct client communication involving PHI occurs only through secure, HIPAA-compliant platforms (like my employer&#8217;s therapy portal).  I now&nbsp;<strong>avoid using regular email, text messages, or consumer video calls for sensitive information</strong>.</li>
</ul>



<h4 class="wp-block-heading">3. Endpoint &amp; Browser Security (My Laptop &amp; Chrome)</h4>



<ul class="wp-block-list">
<li><strong>My Laptop is Encrypted &amp; Protected:</strong>&nbsp;My main computer has full-disk encryption (BitLocker/FileVault) and a robust antivirus solution. I&#8217;m currently using&nbsp;<strong>Norton Small Business ($59/1st year with $119/year renewal)</strong>&nbsp;for this, primarily for its strong endpoint protection. While I&#8217;m actively looking into BAA-covered antivirus and endpoint detection &amp; response (EDR) solutions, it&#8217;s been a real challenge to find providers willing to work with a single user. For now, Norton Business helps secure my device itself.  I had to specifically&nbsp;<strong>disable its cloud backup features</strong>&nbsp;to prevent any PHI from being stored on non-BAA servers.&nbsp; I&#8217;ve also upgraded my mouse to use&nbsp;<strong>Logi Bolt technology</strong>&nbsp;for a more secure wireless connection.</li>



<li><strong>Physical Security for My Home Office:</strong>&nbsp;Beyond digital protection, I also ensure any limited physical PHI (like printed notes) is kept in a&nbsp;<strong>locked file box when unattended</strong>, and my work area is secured to prevent unauthorized access. I&#8217;ve even rearranged my office so that my&nbsp;<strong>computer screen is not visible from the doorway</strong>, even though I always make sure to close the door when I&#8217;m with clients.</li>



<li><strong>Dedicated Chrome Profiles:</strong>&nbsp;This is a big one! I have separate Chrome browser profiles. One just for&nbsp;<strong>my professional W</strong>orkspace&nbsp;(where I handle PHI), and others for personal stuff or employer-provided Outlook/therapy portals. This completely isolates data and workflows.
<ul class="wp-block-list">
<li>Updated to add &#8211; I&#8217;ve now gone a step farther and added another Windows user to my computer.  This way all therapy stuff stays in the therapy user.</li>
</ul>
</li>



<li><strong>Chrome Policies Enforced:</strong>&nbsp;My professional Google Workspace Chrome profile has Enhanced Safe Browse, &#8220;Always use secure connections&#8221; (HTTPS), and strict extension blocking enforced by policy. This means my browser is secured from the top down.</li>



<li><strong>Windows Settings Tuned:</strong>&nbsp;Beyond the basics, I dove into Windows settings to ensure my device is locked down. Strong PIN/Windows Hello, Dynamic Lock (locks when I walk away), automatic screen lock, firewall active, and app permissions reviewed app-by-app.</li>
</ul>



<h4 class="wp-block-heading">4. Tackling Existing Data &amp; Migration</h4>



<p>This was a big project, especially for older files, and probably the hardest part in my HIPAA compliance trek!</p>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:39% auto"><figure class="wp-block-media-text__media"><img loading="lazy" decoding="async" width="1280" height="1280" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/data-migration-cloud-consolidation.png" alt="An illustration of multiple yellow digital folders connected via lines to a central white cloud icon, with additional symbols for Wi-Fi, data sharing, and bidirectional data transfer, all on a grey background." class="wp-image-2385 size-full" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/data-migration-cloud-consolidation.png 1280w, https://mrsspeechonline.com/wp-content/uploads/2025/07/data-migration-cloud-consolidation-300x300.png 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/data-migration-cloud-consolidation-1024x1024.png 1024w, https://mrsspeechonline.com/wp-content/uploads/2025/07/data-migration-cloud-consolidation-150x150.png 150w, https://mrsspeechonline.com/wp-content/uploads/2025/07/data-migration-cloud-consolidation-768x768.png 768w" sizes="auto, (max-width: 1280px) 100vw, 1280px" /></figure><div class="wp-block-media-text__content">
<ul class="wp-block-list">
<li><strong>Consolidating All My Data (PHI &amp; Non-PHI):</strong>&nbsp;I meticulously went through&nbsp;<strong>all my files, both on my computer&#8217;s desktop and in my Drive</strong>.  I identified any possible PHI or general therapy materials. That data was then securely moved to&nbsp;<strong>my professional Drive</strong>, ensuring it was consolidated into my compliant environment.</li>



<li><strong>No More OneDrive Sync:</strong>&nbsp;I&#8217;ve also&nbsp;<strong>disabled Microsoft OneDrive&#8217;s automatic PC folder backup</strong>.  I&#8217;m in the process of moving those files from the OneDrive synced location back to my local user&#8217;s root folders. This ensures no client data is inadvertently stored or synced to a non-BAA cloud service.</li>
</ul>
</div></div>



<h5 class="wp-block-heading" id="h-google-drive-settings-and-workarounds">Google Drive Settings and Workarounds</h5>



<ul class="wp-block-list">
<li><strong>Google Drive for Desktop (Strategically!):</strong>&nbsp;I used Google Drive for Desktop for efficiency with many files, but with a key rule. I keep it on&nbsp;<strong>&#8220;stream files&#8221; mode</strong>. This means files are only downloaded when I open them, minimizing PHI stored locally on my hard drive. I also keep its &#8220;offline access&#8221; feature for PHI files disabled in the Admin Console to prevent local copies, unless absolutely necessary and then with extreme care.</li>



<li><strong>Native Google Docs/Sheets/Slides:</strong>&nbsp;This was tricky! I learned you can&#8217;t just drag-and-drop native Google files between different accounts using Drive for Desktop. For these, especially if they contained PHI, I had to&nbsp;<strong>download them in Microsoft Office format</strong>&nbsp;from my personal Drive.  Then I&nbsp;<strong>re-uploaded them</strong>&nbsp;to&nbsp;<strong>my professional Google Workspace Drive</strong>. This ensured ownership transferred correctly and, crucially, kept the PHI handling within my secured processes.</li>



<li><strong>Unzipping Files:</strong>&nbsp;Since Google Drive doesn&#8217;t have a built-in unzipper, I securely downloaded ZIP files to my local, encrypted computer.  I unzipped them using Windows&#8217; built-in function, and then re-uploaded the extracted files to&nbsp;<strong>my professional Google Workspace Drive</strong>.</li>



<li><strong>Disconnecting My Personal Drive:</strong>&nbsp;Once the transfer was done, I disconnected my personal Google Drive account from Google Drive for Desktop. Why? Fewer accounts connected equals less potential risk.</li>



<li><strong>Cleaning Up My Personal Drive (Carefully!):</strong>&nbsp;After moving all PHI, I used a cloud cleaner like Norton Cloud Cleaner on my&nbsp;<em>personal</em>&nbsp;Google Drive to remove duplicates and old non-PHI files. <strong>NEVER</strong>&nbsp;use such a tool on&nbsp;any PHI files or folders due to compliance risks, if it&#8217;s not covered by a BAA.</li>
</ul>



<h5 class="wp-block-heading" id="h-involving-others-in-my-personal-hippa-journey">Involving Others in My Personal HIPPA Journey</h5>



<ul class="wp-block-list">
<li><strong>Dealing with Shared PHI from Others:</strong>&nbsp;I found some old PHI-containing files in my personal Gmail&#8217;s &#8220;Shared with me&#8221; section, shared by a school district. I immediately downloaded these to&nbsp;<strong>my professional Google Workspace Drive</strong>,&nbsp;<strong>securely deleted them from my personal Drive and my local computer</strong>. Then I reached out to the owner (politely!) asking them to remove my personal Gmail from the access list. This is an&nbsp;<strong>active and ongoing effort</strong>&nbsp;where I&#8217;m proactively contacting owners to ensure my access is removed.  I&#8217;m&nbsp;<strong>documenting all my attempts</strong>&nbsp;as part of my due diligence, especially if I encounter non-responsive contacts or technical difficulties.</li>



<li><strong>Updating My Employer:</strong>&nbsp;I proactively contacted my employer to update my email address for all Google Drive file sharing.  I specifically requested that anything with sensitive client info go to&nbsp;<strong>my new, secure professional email address (e.g., your.professional.email@yourdomain.com)</strong>. This helps them send things to the right place from the start.</li>
</ul>



<h3 class="wp-block-heading">My Ongoing Commitment:</h3>



<p>This isn&#8217;t a one-and-one project! I&#8217;ve also built in:</p>



<ul class="wp-block-list">
<li><strong>Annual Policy Review:</strong>&nbsp;I&#8217;ll review my entire security policy document at least once a year.</li>



<li><strong>Self-Education:</strong>&nbsp;Staying informed about HIPAA and cybersecurity is an ongoing task. I&#8217;ve even been learning about specific processes like the&nbsp;<strong>HIPAA de-identification process</strong>.</li>



<li><strong>Basic Incident Response:</strong>&nbsp;I have a plan for what to do if something ever goes wrong, including who to notify.</li>



<li><strong>Learning Curve:</strong>&nbsp;I won&#8217;t lie, all these tech skills required some serious reading up and a lot of help (shout out to Gemini! ?). It&#8217;s a journey, not a sprint, but totally doable!</li>
</ul>



<p>Setting all this up has been a journey, but it&#8217;s given me immense confidence in my practice&#8217;s security. If you&#8217;re an SLP (or any healthcare professional) using tech in your practice, I highly encourage you to take a look at your own setup. It&#8217;s worth every bit of effort for your peace of mind and, most importantly, for your clients&#8217; privacy!</p>



<p>Here&#8217;s to HIPAA Happiness!</p>



<div class="wp-block-group is-layout-constrained wp-block-group-is-layout-constrained">
<figure class="wp-block-image aligncenter size-full is-resized"><img loading="lazy" decoding="async" width="810" height="169" src="https://i0.wp.com/vmx.erb.mybluehost.me/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp?fit=810%2C169&amp;ssl=1" alt="Mrs. Speech Signature" class="wp-image-804" style="width:364px;height:auto" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent.webp 810w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-300x63.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/Mrs.-Speech-signature-transparent-768x160.webp 768w" sizes="auto, (max-width: 810px) 100vw, 810px" /></figure>



<div class="wp-block-group is-content-justification-center is-nowrap is-layout-flex wp-container-core-group-is-layout-23441af8 wp-block-group-is-layout-flex">
<figure class="wp-block-image size-full is-resized"><a href="https://www.facebook.com/profile.php?id=61556892726241" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="388" height="398" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp" alt="facebook icon" class="wp-image-815" style="width:48px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918.webp 388w, https://mrsspeechonline.com/wp-content/uploads/2025/07/1-e1751811762918-292x300.webp 292w" sizes="auto, (max-width: 388px) 100vw, 388px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.instagram.com/mrs.speechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="418" height="408" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp" alt="Instagram Icon" class="wp-image-818" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939.webp 418w, https://mrsspeechonline.com/wp-content/uploads/2025/07/4-e1751812074939-300x293.webp 300w" sizes="auto, (max-width: 418px) 100vw, 418px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.pinterest.com/mrsspeechonline/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="413" height="410" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp" alt="pinterest icon" class="wp-image-816" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435.webp 413w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-300x298.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/2-e1751811897435-150x150.webp 150w" sizes="auto, (max-width: 413px) 100vw, 413px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.linkedin.com/in/jennifer-tillock-821999287/" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="402" height="402" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp" alt="LinkedIn Icon" class="wp-image-821" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224.webp 402w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/5-e1751812160224-150x150.webp 150w" sizes="auto, (max-width: 402px) 100vw, 402px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="http://www.youtube.com/@Mrs.Speech-wk4mr" target="_blank" rel=" nofollow noopener noreferrer"><img loading="lazy" decoding="async" width="429" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp" alt="YouTube icon" class="wp-image-817" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232.webp 429w, https://mrsspeechonline.com/wp-content/uploads/2025/07/3-e1751811991232-300x291.webp 300w" sizes="auto, (max-width: 429px) 100vw, 429px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><a href="https://www.teacherspayteachers.com/store/mrs-speech" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="423" height="416" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp" alt="TeachersPayTeachers Icon" class="wp-image-822" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756.webp 423w, https://mrsspeechonline.com/wp-content/uploads/2025/07/6-e1751812225756-300x295.webp 300w" sizes="auto, (max-width: 423px) 100vw, 423px" /></a></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="414" height="413" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp" alt="Mrs. Speech Books Icon" class="wp-image-1322" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319.webp 414w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-300x300.webp 300w, https://mrsspeechonline.com/wp-content/uploads/2025/07/social-icons-1-e1751812692319-150x150.webp 150w" sizes="auto, (max-width: 414px) 100vw, 414px" /></figure>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" width="387" height="377" src="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp" alt="MailTo Icon" class="wp-image-1326" style="width:50px" srcset="https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307.webp 387w, https://mrsspeechonline.com/wp-content/uploads/2025/07/7-e1751813665307-300x292.webp 300w" sizes="auto, (max-width: 387px) 100vw, 387px" /></figure>
</div>
</div>



<p class="icon-attribution" style="font-size: 0.6em; font-style: italic;">
    Social Media Icons: <a href="https://www.freepik.com" target="_blank" rel="noopener">designed by rawpixel.com &#8211; Freepik.com</a>
</p>



<div style="height:47px" aria-hidden="true" class="wp-block-spacer"></div>


<div style="color:#db820e;font-style:normal;font-weight:300" class="taxonomy-post_tag has-text-align-center has-link-color wp-elements-e81afc2be6272024545412bcb750c79c wp-block-post-terms has-text-color"><a href="https://mrsspeechonline.com/tag/business-associate-agreement/" rel="tag">Business Associate Agreement</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/google/" rel="tag">Google</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/google-workspace/" rel="tag">Google Workspace</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/hipaa-security/" rel="tag">HIPAA Security</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/home-office/" rel="tag">Home Office</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/insights/" rel="tag">Insights</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/microsoft/" rel="tag">Microsoft</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/personal-journey/" rel="tag">Personal Journey</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/technology/" rel="tag">Technology</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/teletherapy/" rel="tag">Teletherapy</a><span class="wp-block-post-terms__separator">, </span><a href="https://mrsspeechonline.com/tag/tips/" rel="tag">Tips</a></div><p>The post <a href="https://mrsspeechonline.com/personal-hipaa-compliance-journey/">My Personal HIPAA Compliance Journey: Steps to Secure Data</a> appeared first on <a href="https://mrsspeechonline.com">Mrs. Speech Online</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://mrsspeechonline.com/personal-hipaa-compliance-journey/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
