Do I need HIPAA forms as a dietitian or nutritionist?
Only if you transmit electronically. Your practice needs HIPAA forms if it is a covered entity, and it becomes one when a claim, eligibility check, or remittance moves electronically between you and a health plan (45 CFR 160.103). Handing a client a superbill does not do it. Your software quietly running an eligibility check does.
Nutrition is one of the genuinely split fields, so the table below shows which facts flip the test before the checklist.
Researched and written by Larry Osakwe · Last verified August 1, 2026
Checked against the current 45 CFR text. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
What actually makes a nutrition practice a covered entity
The test is narrow and mechanical. It is not about how sensitive your records are, whether you are licensed, or how many clients you see. It is about whether a covered transaction moves electronically between you and a health plan.
| If this is true of your practice | Covered entity? | Why |
|---|---|---|
| You are cash-pay and hand clients a printed superbill to submit themselves | No | The client transmits the claim to their own insurer, not you. 45 CFR 160.103 asks whether YOU transmit health information electronically in connection with a covered transaction. |
| You take card, HSA, or FSA payments | No | Payment is not a HIPAA standard transaction. How a client pays has nothing to do with the test. |
| You are an unlicensed nutrition coach who never bills a plan | No | HIPAA does not turn on your credential. With no covered transaction there is no covered-entity status, though state law and platform terms still apply. |
| You submit claims to insurance, Medicare, or Medicaid electronically | Yes | The classic covered transaction. Medical Nutrition Therapy billed to Medicare Part B counts. |
| Your platform runs electronic eligibility or benefits checks for you | Yes | Eligibility verification is itself a covered transaction, and transmission on your behalf counts as yours. This is the most common accidental trigger in nutrition practice. |
| A billing service files even one claim for one client | Yes | One covered transaction makes you a covered entity, and the rules then reach all of your client information, including your cash clients' records. |
Note the asymmetry in the last two rows: one covered transaction makes the whole practice covered, including the records of clients you never billed.
Do dietitians and nutritionists have to comply with HIPAA?
Only if the practice transmits health information electronically in connection with a covered transaction, which in practice means electronic claims, eligibility checks, or remittance with a health plan (45 CFR 160.103). Nutrition is one of the genuinely split fields: a large share of practices are cash-pay or fully out-of-network and never do any of that, so they are not covered entities. A dietitian who bills insurance electronically is. Your credential is irrelevant to the test, which surprises people who assume RDN status carries HIPAA obligations that a coaching practice does not.
The covered-entity test, profession by professionDoes giving clients a superbill make me a covered entity?
Generally no, on its own. A superbill is documentation you hand the client so they can seek out-of-network reimbursement from their own insurer. The client is the one submitting it, and you have not transmitted anything electronically to a health plan. This matters because superbills are the standard workaround for cash-pay nutrition practices, and a lot of compliance marketing implies that issuing them pulls you into HIPAA. It generally does not. What would is you or your software filing the claim or checking eligibility electronically on the client's behalf.
How do cash practices become covered entities by accident?
Almost always through a setting inside software rather than a decision anyone made. The most common route is switching on electronic eligibility or benefits verification in Practice Better, Healthie, or similar, often because it is presented as a convenience feature rather than as a regulatory event. Eligibility verification is itself a covered transaction. The second route is a billing service or a single insurance-paying client. Both make you a covered entity, and once you are, the Privacy and Security Rules apply to all of your client information, not only to the clients you billed. Write down the answer you reached and the date, and revisit it whenever your billing setup changes.
Is there a difference between a registered dietitian and a nutritionist for HIPAA?
No. HIPAA does not look at credentials, licensure, or scope of practice. It looks at whether you transmit covered transactions electronically. An RDN billing Medicare for Medical Nutrition Therapy is a covered entity; an unlicensed health coach taking cash and never filing a claim generally is not. The two can hold nearly identical client information and sit on opposite sides of the line. State licensure and title-protection laws are a separate matter and do turn on credential, but they are not HIPAA.
If I'm not covered, should I still have privacy documents?
HIPAA will not require them, but the information you hold argues for them anyway. Nutrition records routinely include weight history, eating-disorder history, lab values, medications, GI and fertility issues, and diet recalls that read like a diary. State confidentiality statutes, your licensing board's ethics rules, and consumer-protection law reach that data whether or not HIPAA does, and clients assume it is protected. A written privacy practice, access-controlled storage, and agreements with the platforms holding your notes are worth having on their own terms. Just do not buy a HIPAA compliance program on the premise that HIPAA applies when it does not.
If you are covered: the eight documents
If the table above put you on the covered side, this is the document set you must be able to produce. It is the same set every covered practice needs, flavored with the vendors and records a nutrition practice actually has. Each item cites the rule that requires it, so you can verify any of it against the regulation.
Notice of Privacy Practices
The notice you give every client, post in a clear and prominent place, and publish on your website, describing how the practice uses and discloses client information.
45 CFR § 164.520
NPP acknowledgment of receipt
The form documenting your good-faith effort to obtain each client's written acknowledgment that they received the notice; it belongs in the intake packet at the first session.
45 CFR § 164.520(c)(2)
Client authorization + rights request forms
The written-permission form for disclosures HIPAA does not already permit, plus request forms for access, amendment, restrictions, and an accounting of disclosures. Referring physicians, therapists, and eating-disorder treatment teams generate these constantly.
45 CFR § 164.508; §§ 164.522–164.528
Business Associate Agreements + vendor register
A signed BAA with every vendor that touches client data, tracked in a register. For a nutrition practice that usually means your platform (Practice Better, Healthie, Kalix, Nutrium), any meal-planning or food-logging app you connect, a billing service, cloud backup, and email.
45 CFR § 164.502(e); § 164.504(e)
Security Risk Analysis
The documented, accurate and thorough assessment of risks to electronic client data across every system that holds it: your platform, connected apps, lab results, body-composition data, email, backups, devices. The most-cited deficiency in OCR enforcement.
45 CFR § 164.308(a)(1)(ii)(A)
Privacy & security policies with a training log
Your written rulebook for access, minimum-necessary use, and safeguards, plus documented training and a sanctions policy. Solo practices still need this in writing, and it has to cover any VA or billing help you use.
45 CFR § 164.530(b); § 164.308(a)(5); § 164.316
Breach notification procedure + breach log
What to do when something goes wrong: notification without unreasonable delay and no later than 60 calendar days after discovery, plus your state's breach statute answered specifically.
45 CFR §§ 164.400–414
Privacy Official & Security Official designation
Names, in writing, the person responsible for your privacy policies and the person responsible for security. In a solo nutrition practice both are you, and the designation still has to be written down.
45 CFR § 164.530(a); § 164.308(a)(2)
The full annotated table of contents, with what each document does and an honest binder-vs-software comparison, is on the HIPAA binder template page.
The connected-app problem
Nutrition practice runs on integrations in a way most small clinical practices do not. Food and photo logging, continuous glucose data, wearable syncs, lab-ordering portals, meal-plan generators, and group-program platforms all end up holding client health information, and each one you connect is a vendor that needs to be in your register and, if you are covered, under a signed BAA.
The two that get missed most often are the ones that do not feel clinical. A meal-planning tool holding allergy and condition data is handling PHI. A scheduling or group-course platform that captures intake answers is handling PHI. Neither presents itself as a medical system, which is exactly why they stay off the vendor list.
Your Security Risk Analysis has to span all of it, not just the primary platform. The practical version of that is keeping an actual list of every integration you have switched on, because most practices cannot produce one from memory.
Get the documents done
Settle the question first
The covered-entity test, profession by profession, before you buy anything.
The nutrition binder
Every document above, built to order for your practice, state, and software.
Generate your NPP
Build your Notice of Privacy Practices now and see it before you pay.
See a sample first
Real excerpts from a delivered binder, citations included.
Sources
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-162/subpart-L
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- www.cms.gov/priorities/key-initiatives/burden-reduction/administrative-simplification/hipaa/covered-entities
Last verified August 1, 2026. Educational self-help information, not legal advice and not a covered-entity determination for any specific practice. Whether HIPAA applies to your practice turns on its actual billing arrangements; confirm with the sources above and, where appropriate, a qualified attorney. State law may add stronger requirements.
Covered after all? Get every document your nutrition practice needs
The complete binder, built to order for your practice and state, with every policy citing the rule that requires it.
See the nutrition binder and pricing