Do I need HIPAA forms for my eye care practice?
Almost certainly yes. Your practice needs HIPAA forms if it is a covered entity, and it becomes one when any claim or eligibility check moves electronically (45 CFR 160.103), and vision-plan claims to VSP or EyeMed count the same as medical claims. Most eye care practices bill at least one channel electronically.
Not sure your practice meets the test? Walk the covered-entity test, profession by profession, then come back for the checklist below.
Researched and written by Larry Osakwe · Last verified July 15, 2026
Checked against the current 45 CFR text. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
The eight documents your eye care practice needs
This is the HIPAA compliance checklist for an optometry or eye care practice: the same document set every covered practice must be able to produce, flavored with the vendors and records an eye care practice actually has, optical side included. Each item cites the rule that requires it, so you can verify any of it against the regulation.
Notice of Privacy Practices
The notice you give every patient, post in a clear and prominent place in your practice, and publish on your website, describing how the practice uses and discloses patient information.
45 CFR § 164.520
NPP acknowledgment of receipt
The form documenting your good-faith effort to obtain each patient's written acknowledgment that they received the notice; the front desk files it at the first exam.
45 CFR § 164.520(c)(2)
Patient authorization + rights request forms
The written-permission form for uses HIPAA does not already permit, plus request forms for access, amendment, restrictions, and an accounting of disclosures.
45 CFR § 164.508; §§ 164.522–164.528
Business Associate Agreements + vendor register
A signed BAA with every vendor that touches patient data, tracked in a register. For an eye care practice that typically means your EHR and practice-management software (RevolutionEHR, Eyefinity), your clearinghouses for vision-plan and medical claims, optical labs reached through ordering portals, cloud backup, and email.
45 CFR § 164.502(e); § 164.504(e)
Security Risk Analysis
The documented, accurate and thorough assessment of risks to your electronic patient data across every system that holds it: EHR, retinal and OCT imaging, the optical side's Rx and order records, and lab portals. The most-cited deficiency in OCR enforcement.
45 CFR § 164.308(a)(1)(ii)(A)
Privacy & security policies with a training log
Your written rulebook for access, minimum-necessary use, and safeguards, plus documented workforce training and a sanctions policy, covering opticians and front-of-store staff as well as the doctors and techs.
45 CFR § 164.530(b); § 164.308(a)(5); § 164.316
Breach notification procedure + breach log
What to do when something goes wrong: notification without unreasonable delay and no later than 60 calendar days after discovery, plus your state's breach statute answered specifically.
45 CFR §§ 164.400–414
Privacy Official & Security Official designation
Names, in writing, the person responsible for your privacy policies and the person responsible for security; in a small practice both are usually the owner-OD.
45 CFR § 164.530(a); § 164.308(a)(2)
One trap worth naming: eyewear and contact-lens orders flow to outside optical labs through ordering portals, and a lab or portal that receives patient information on your behalf generally needs a BAA. It is easy to overlook because it feels like ordering product, not sharing records. The full annotated table of contents is on the HIPAA binder template page.
Are optometrists HIPAA covered entities?
Almost always. An eye care practice becomes a covered entity when it transmits any covered transaction electronically (45 CFR 160.103): claims, eligibility checks, or remittance, whether the channel is a vision plan or medical insurance. Since most optometry practices electronically bill at least one of those channels, it is unusual for a modern practice to fall outside HIPAA. The theoretical exception is a purely retail optical shop that never transmits a covered transaction, which is atypical for a practice that examines patients.
The covered-entity test, profession by professionDo vision-plan claims (VSP, EyeMed) count as HIPAA covered transactions?
Yes. A claim filed electronically with a vision plan is a covered transaction the same as a claim filed with medical insurance; the covered-entity test in 45 CFR 160.103 turns on the electronic transaction, not on which kind of plan receives it. “We only bill vision plans” is the assumption that most often catches eye care practices. It also means dual-channel practices have a wider vendor web: two claim paths, two clearinghouses, and more places a BAA can be missing.
Do my opticians and front-desk staff need HIPAA training?
Yes. The training requirement in 45 CFR 164.530(b) covers all members of your workforce, and opticians and dispensing staff routinely access prescriptions and patient records to fill frame and contact-lens orders, which is protected health information. The same goes for the Security Rule's awareness program (45 CFR 164.308(a)(5)), which explicitly includes management. Train everyone who can see patient information, and log it; an undocumented training never happened as far as an auditor is concerned.
Where can I get HIPAA forms for an optometry practice?
The AOA publishes a HIPAA compliance manual and sample forms for optometrists, with much of it offered as a member benefit behind the AOA login. If you are a member, use it. This page's checklist and citations are open to everyone regardless: you can verify every requirement against the eCFR links below, generate a Notice of Privacy Practices and see the finished document before paying, or order the complete binder built for your practice with no membership involved.
Does RevolutionEHR or Eyefinity make my practice HIPAA compliant?
No. Your EHR is a business associate: it should sign a BAA and secure the clinical and optical records it holds, but it does not supply your Notice of Privacy Practices, your written policies, a Security Risk Analysis spanning every system that touches patient data (EHR, imaging, lab portals, email), your training log, or your breach procedure. The software manages the records; the compliance documentation layer is yours to produce and maintain.
Don’t skip the training log
Two rules make training a documentation requirement, not a nice-to-have. The Privacy Rule (45 CFR 164.530(b)) requires you to train all members of your workforce on your privacy policies: new hires within a reasonable period after they join, and everyone affected within a reasonable period after a material policy change, with the training documented. The Security Rule (45 CFR 164.308(a)(5)) separately requires a security awareness and training program for the entire workforce, management included, with periodic security updates.
Neither rule names a fixed interval, so an annual all-hands pass, logged with names and dates, is how small practices evidence both: it catches new hires, refreshes everyone else, and pairs naturally with the annual review of your Security Risk Analysis. In an eye care practice the log must cover everyone who touches patient information, which means opticians, dispensing staff, and the front desk, not just the doctors and techs.
Get the documents done
The optometry binder
Every document above, built to order for your practice, state, and software stack.
See the full template
The annotated binder table of contents, document by document.
Generate your NPP
Build your Notice of Privacy Practices now and see it before you pay.
See a sample first
Real excerpts from a delivered binder, citations included.
Sources
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.520
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- www.aoa.org/optometrists/tools-and-resources/hipaa-compliance
Last verified July 15, 2026. Educational self-help information, not legal advice and not a covered-entity determination for any specific practice. Whether HIPAA applies to your practice turns on its actual billing arrangements; confirm with the sources above and, where appropriate, a qualified attorney. State law may add stronger requirements.
Every HIPAA document your eye care practice needs, done for you
The complete binder, built to order for your practice and state, with every policy citing the rule that requires it.
See the optometry binder and pricing