HIPAA BinderGet my forms

Do I need HIPAA forms for my eye care practice?

Almost certainly yes. Your practice needs HIPAA forms if it is a covered entity, and it becomes one when any claim or eligibility check moves electronically (45 CFR 160.103), and vision-plan claims to VSP or EyeMed count the same as medical claims. Most eye care practices bill at least one channel electronically.

Not sure your practice meets the test? Walk the covered-entity test, profession by profession, then come back for the checklist below.

Researched and written by Larry Osakwe · Last verified July 15, 2026

Checked against the current 45 CFR text. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.

How we research thisReport an error

The eight documents your eye care practice needs

This is the HIPAA compliance checklist for an optometry or eye care practice: the same document set every covered practice must be able to produce, flavored with the vendors and records an eye care practice actually has, optical side included. Each item cites the rule that requires it, so you can verify any of it against the regulation.

One trap worth naming: eyewear and contact-lens orders flow to outside optical labs through ordering portals, and a lab or portal that receives patient information on your behalf generally needs a BAA. It is easy to overlook because it feels like ordering product, not sharing records. The full annotated table of contents is on the HIPAA binder template page.

Are optometrists HIPAA covered entities?

Almost always. An eye care practice becomes a covered entity when it transmits any covered transaction electronically (45 CFR 160.103): claims, eligibility checks, or remittance, whether the channel is a vision plan or medical insurance. Since most optometry practices electronically bill at least one of those channels, it is unusual for a modern practice to fall outside HIPAA. The theoretical exception is a purely retail optical shop that never transmits a covered transaction, which is atypical for a practice that examines patients.

The covered-entity test, profession by profession

Do vision-plan claims (VSP, EyeMed) count as HIPAA covered transactions?

Yes. A claim filed electronically with a vision plan is a covered transaction the same as a claim filed with medical insurance; the covered-entity test in 45 CFR 160.103 turns on the electronic transaction, not on which kind of plan receives it. “We only bill vision plans” is the assumption that most often catches eye care practices. It also means dual-channel practices have a wider vendor web: two claim paths, two clearinghouses, and more places a BAA can be missing.

Do my opticians and front-desk staff need HIPAA training?

Yes. The training requirement in 45 CFR 164.530(b) covers all members of your workforce, and opticians and dispensing staff routinely access prescriptions and patient records to fill frame and contact-lens orders, which is protected health information. The same goes for the Security Rule's awareness program (45 CFR 164.308(a)(5)), which explicitly includes management. Train everyone who can see patient information, and log it; an undocumented training never happened as far as an auditor is concerned.

Where can I get HIPAA forms for an optometry practice?

The AOA publishes a HIPAA compliance manual and sample forms for optometrists, with much of it offered as a member benefit behind the AOA login. If you are a member, use it. This page's checklist and citations are open to everyone regardless: you can verify every requirement against the eCFR links below, generate a Notice of Privacy Practices and see the finished document before paying, or order the complete binder built for your practice with no membership involved.

Does RevolutionEHR or Eyefinity make my practice HIPAA compliant?

No. Your EHR is a business associate: it should sign a BAA and secure the clinical and optical records it holds, but it does not supply your Notice of Privacy Practices, your written policies, a Security Risk Analysis spanning every system that touches patient data (EHR, imaging, lab portals, email), your training log, or your breach procedure. The software manages the records; the compliance documentation layer is yours to produce and maintain.

Don’t skip the training log

Two rules make training a documentation requirement, not a nice-to-have. The Privacy Rule (45 CFR 164.530(b)) requires you to train all members of your workforce on your privacy policies: new hires within a reasonable period after they join, and everyone affected within a reasonable period after a material policy change, with the training documented. The Security Rule (45 CFR 164.308(a)(5)) separately requires a security awareness and training program for the entire workforce, management included, with periodic security updates.

Neither rule names a fixed interval, so an annual all-hands pass, logged with names and dates, is how small practices evidence both: it catches new hires, refreshes everyone else, and pairs naturally with the annual review of your Security Risk Analysis. In an eye care practice the log must cover everyone who touches patient information, which means opticians, dispensing staff, and the front desk, not just the doctors and techs.

Sources

Last verified July 15, 2026. Educational self-help information, not legal advice and not a covered-entity determination for any specific practice. Whether HIPAA applies to your practice turns on its actual billing arrangements; confirm with the sources above and, where appropriate, a qualified attorney. State law may add stronger requirements.

Every HIPAA document your eye care practice needs, done for you

The complete binder, built to order for your practice and state, with every policy citing the rule that requires it.

See the optometry binder and pricing