HIPAA forms for dietitians and nutritionists
A registered dietitian or nutritionist in private practice is generally a HIPAA covered entity only if the practice itself transmits health information electronically in connection with a HIPAA standard transaction: typically filing insurance claims, checking eligibility, or receiving electronic remittance. Many nutrition practices are cash-pay or fully out-of-network, which makes covered-entity status a genuinely live question rather than a given. HHS/CMS offer a covered-entity decision tool; confirm your own status.
Researched and written by Larry Osakwe · Last verified June 30, 2026
Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
Are you even a covered entity?
The trigger is who electronically transmits the claim. A dietitian who only hands the client a printed superbill, and the client submits it to their own insurer, is generally NOT transmitting electronically, so not a covered entity on that basis. But the moment you bill insurance directly, run electronic eligibility checks, or submit claims yourself or via a billing service/clearinghouse, you generally become a covered entity. An unlicensed nutrition coach who never touches a covered transaction often falls outside HIPAA, though state privacy law can still apply.
The test (45 CFR 160.103) is whether you electronically transmit a HIPAA covered transaction, not your job title. HHS and CMS publish a free covered-entity decision tool; when in doubt, run it or ask an attorney. This page is educational, not legal advice.
New to the vocabulary? See plain-language definitions in the HIPAA glossary, starting with covered entity and business associate.
HIPAA considerations specific to dietitians and nutritionists
Vendors dietitians and nutritionists usually need a BAA with
If you’re a covered entity, any vendor that can create, receive, maintain, or transmit your patients’ PHI needs a signed Business Associate Agreement before it touches that data. For dietitians and nutritionists, that commonly includes:
Using a “HIPAA-compliant” tool does not by itself make your practice compliant. The signed BAA, your policies, and your Security Risk Analysis are still yours to maintain.
Weighing your options? Compare us honestly against a standalone NPP generator and against monthly compliance software, or see what HIPAA compliance actually costs a small practice.
The HIPAA documents a covered dietitian / nutritionist practice needs
Notice of Privacy Practices
The notice you must give patients and post in your office and online.
45 CFR 164.520
Business Associate Agreements
Required with every vendor that can access patient data: EHR, billing, cloud, email.
45 CFR 164.502(e)
Security Risk Analysis
The most-cited deficiency in OCR enforcement: required, annual, and documented.
45 CFR 164.308(a)(1)(ii)(A)
Privacy & security policies
Your written rulebook for access, minimum-necessary use, sanctions, and incidents.
Privacy & Security Rules
Patient-rights & authorization forms
Access, amendment, accounting of disclosures, and release forms.
45 CFR 164.508
Breach procedure & Privacy Officer docs
A breach-notification procedure and log, plus the Privacy/Security Officer designation.
Breach Notification Rule
See what you actually get
Not a checklist or a link to a free template: a finished, formatted document set, cited to the rule. A page from a dietitian / nutritionist binder:
Your Rights. When it comes to your health information, you have the right to:
- Get a copy of your records, usually within 30 days (§ 164.524).
- Ask us to correct information you believe is incomplete (§ 164.526).
- Ask us to limit what we use or share (§ 164.522).
- File a complaint with us or the HHS Office for Civil Rights; we will not retaliate.
Generate your Notice of Privacy Practices now →Generate your BAA →Document your risk analysis →See the full sample binder →
Free 2-minute HIPAA gap check
Answer 10 questions and see where a dietitian / nutritionist practice most often has gaps. Educational, not legal advice.
The binder is hand-prepared and customized to your dietitian / nutritionistpractice, with the same documents, organized to your specialty’s records and vendors.
Lock in founding pricing
Every document is made to order at locked-in founding pricing, built from your practice details and delivered within 30 days, with a full refund anytime before then. Each binder is built by hand, so founding pricing is limited to the first 25 practices; after that the Complete Binder is $249. Preview any document free before you decide.
Opening a dental office? HIPAA + OSHA Binder Bundle: $299 $328 separately
Add the OSHA binder: exposure control plan, hazard communication, sharps and training documentation, every policy citing the regulation that requires it.
Founding price · $449 after the first 25 practices
Your documents are built to order and delivered within 30 days, with a full refund anytime before delivery. The subscription then keeps every document current as HIPAA rules change and reminds you when your annual risk assessment is due. Cancel anytime.
HIPAA FAQ for dietitians and nutritionists
HIPAA forms for other professions
Sources
- www.hhs.gov/hipaa/for-professionals/covered-entities/index.html
- www.cms.gov/regulations-and-guidance/administrative-simplification/hipaa-aca/areyouacoveredentity
- www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160
Reviewed June 30, 2026. Educational self-help information about HIPAA documentation, not legal advice and not a covered-entity determination for any specific practice. The binder is a document layer; it never handles patient information (PHI) and does not by itself make a practice HIPAA compliant. Confirm your status with HHS/CMS resources and, where appropriate, a qualified attorney. State law may add stronger requirements.