ABA practice legal requirements are a linked set of entity, professional, facility, privacy, workforce, payer, billing, safety, record, insurance, and consumer obligations. The launch owner should maintain one jurisdiction-specific requirements register and release each stage only after the assigned adviser or agency confirms its evidence. State ownership, licensure, employment, privacy, facility, and payer rules can change both the sequence and the required proof.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Start with a requirements register

One owner should control the launch register while qualified specialists approve their own domains. General formation guidance from the U.S. Small Business Administration (SBA) Business Guide covers registration, permits, insurance, hiring, and ongoing compliance. An ABA practice needs additional state healthcare, professional, facility, privacy, payer, and clinical analysis.

Create one row for each requirement and keep these fields:

FieldWhat belongs in it
Requirement and sourceExact statute, regulation, agency page, board rule, payer manual, executed contract, or policy section
ScopeState, locality, entity, owner, role, location, setting, service, payer product, and client population
Owner and approverPerson doing the work and qualified person or authority accepting it
DependencyEarlier filing, decision, inspection, credential, contract, or system control
EvidenceFiled document, written opinion, license, approval, effective date, test, training record, or signed policy
TimingTrigger, submission date, deadline, effective date, renewal, and source recheck date
StatusOpen, blocked, submitted, approved with conditions, effective, or expired
Change triggerOwnership, address, service, staff role, vendor, payer, law, or workflow change that reopens the row

Keep verbal guidance as a dated note with the agency, representative, contact route, question, and response. Ask for written confirmation when a decision affects authority to practice, serve a client, represent network status, bill, or retain records.

Gate 1: approve the entity, ownership, and clinical authority

Define the proposed owners, investors, governing body, clinical decision-makers, management company, employing entity, billing entity, service locations, and states before filing. Have state healthcare and corporate counsel analyze professional-entity rules, ownership restrictions, corporate-practice principles, fee splitting, management fees, control rights, trade names, foreign qualification, tax structure, and succession.

The SBA explains that registration depends on structure and location and that an entity active in another state may need foreign qualification. Its licenses and permits guide directs businesses to state and local sources because requirements depend on the activity and location. The legal effect of a filing depends on the filing and jurisdiction. Formation or registration alone leaves professional authority, facility status, payer participation, and authority to furnish a service unresolved. Record each applicable approval separately, or preserve a source-supported decision that an approval is unnecessary.

Map each clinical role to the actual state source. The Behavior Analyst Certification Board (BACB) licensure directory identifies states that regulate behavior analysts and routes readers to boards or enacted laws. Confirm current scope, exemptions, supervision, titles, telepractice, temporary practice, disciplinary status, renewal, and the locations of both practitioner and client through the state board and governing text. BACB certification and state authority should stay as separate register rows.

Gate 1 evidence: signed structure and control analysis, filed entity documents, governance approvals, tax advice, state registration, assumed-name status, and a role-by-role authority matrix.

Gate 2: clear licenses, enrollment, contracts, and locations

Create a configuration row for every entity, tax identifier, National Provider Identifier (NPI), rendering clinician, technician role, service location, setting, service, payer, product, and effective date. The current CMS NPI standard page defines an NPI as the standard unique identifier for covered providers. The CMS NPI files page warns that issuance does not ensure or validate licensure or credentials. Treat NPI assignment, state authority, credentialing, contracting, program enrollment, roster acceptance, location approval, authorization, and payment as different decisions.

For Medicaid, use the state agency and managed-care plan sources. The CMS Medicaid provider-requirements hub shows that provider management includes enrollment, ownership and control, screening, and payments. Preserve applications, disclosures, approval letters, effective dates, roster evidence, directory checks, contract versions, fee schedules, amendments, and revalidation dates.

For each service site, record zoning and permitted use, certificate of occupancy, building and fire approvals, accessibility, local business permits, and any healthcare, childcare, school, residential, telehealth, or home-based authority triggered by the actual model. Preserve the responsible authority's or counsel's source-supported determination when an item is inapplicable.

Counsel should review payer, employment, contractor, lease, referral, vendor, software, business associate, family-service, and financial agreements. Record the parties, services, authority, payment method, data rights, audit access, record ownership, insurance, indemnity, subcontracting, renewal, termination, transition duties, and governing law. The signed agreement and incorporated manuals belong in the source record.

Gate 2 evidence: every planned client path has effective professional, entity, location, payer, and contract status, or a separately approved lawful private-pay or out-of-network path with accurate disclosures.

Gate 3: establish privacy, security, and record controls

Determine the practice's role under the Health Insurance Portability and Accountability Act (HIPAA) for each activity and data flow involving protected health information (PHI). The HHS HIPAA for Professionals portal is the federal starting point. HIPAA covers health plans, clearinghouses, and healthcare providers that conduct covered transactions electronically; specified duties also apply directly to business associates.

Build a data map for intake, care, scheduling, messaging, telehealth, video, billing, payroll, marketing, analytics, backups, paper, and disposal. A covered entity should execute a compliant agreement before a vendor creates, receives, maintains, or transmits PHI as a business associate. Business associates must obtain compliant written assurances from business-associate subcontractors. HHS explains these controls in its business-associate guidance. The agreement allocates required duties while each party retains its own obligations. Complete and maintain the documented risk analysis for all ePHI.

Treat HIPAA as a federal floor. A contrary state law is generally preempted unless an exception applies, while a more stringent state privacy provision may control. Follow both rules when both can be satisfied, and document the preemption analysis. For activities outside covered-entity or business-associate scope, separately assess the FTC Act, the FTC Health Breach Notification Rule, and applicable state consumer-health laws.

Approve access, amendment, authorization, minimum-necessary, personal-representative, complaint, sanction, incident, backup, downtime, and breach workflows. Covered providers with direct treatment relationships generally need a current, plain-language Notice of Privacy Practices and the required delivery and posting process under HHS notice guidance.

Set retention by record type and authority. HHS states that HIPAA sets no general medical-record retention period; state and other governing sources generally supply those periods. HIPAA requires covered entities and business associates to retain specified Privacy and Security Rule documentation for six years from creation or the date last in effect, whichever is later, as reflected in the HHS HIPAA Audit Protocol. Add clinical, billing, authorization, employment, corporate, tax, payer, litigation-hold, and minor-record rules. Test access, hold, export, correction, destruction, and custodian continuity before live care.

Gate 4: activate a lawful and safe workforce

Employment counsel and payroll specialists should localize worker classification, wage and hour, overtime exemption, travel, training, cancellation work, documentation time, breaks, leave, expense reimbursement, pay notices, pay frequency, final pay, personnel files, restrictive covenants, background checks, and required postings. Federal, state, local, payer, tax, and professional tests can reach different answers.

Federal wage guidance from the U.S. Department of Labor Fair Labor Standards Act (FLSA) portal covers minimum wage, overtime, hours worked, and recordkeeping. Use the current source on the decision date because rulemaking, litigation, and enforcement positions can change. For federal discrimination, accommodation, records, posting, and employment-decision material, use the U.S. Equal Employment Opportunity Commission (EEOC) Small Business Resource Center. Counsel should add applicable state and local protections and thresholds.

Review disability access in two tracks. For employment, determine whether federal ADA Title I and broader state or local hiring and accommodation duties apply. For client-facing operations, assess Title III requirements for reasonable policy modifications, effective communication, service animals, physical access, and services offered through the website. Assign remediation and a release test before marketing or intake opens.

Keep pre-service checks separate: identity and work authorization, background, professional authority, payer status, exclusion status, required health or driving evidence, competence, supervision, privacy and billing training, incident duties, and paid-work readiness. For work authorization, follow current Form I-9 timing and instructions and anti-discrimination limits on document requests. When a consumer-reporting company supplies a background report, implement the FCRA's standalone disclosure and written authorization before procurement, the pre-adverse-action copy and Summary of Rights, and the final adverse-action notice when applicable under FTC and EEOC guidance. Add state and local restrictions.

Review employee hazards by job and setting. Occupational Safety and Health Administration (OSHA) hazard-identification guidance recommends initial and periodic inspections, review of incidents and near misses, emergency and nonroutine-work analysis, prioritization, correction, and retesting. Add the applicable federal or state-plan standards and local reporting rules.

Classify each role for reasonably anticipated occupational exposure to blood or other potentially infectious materials. When exposure exists, apply OSHA's Bloodborne Pathogens Standard, including the written exposure-control plan, controls and personal protective equipment, training, hepatitis B vaccination, and post-exposure process. Map federal OSHA's severe-injury reporting rule and every state-plan deadline into the incident matrix.

Gate 5: control billing, referrals, exclusions, and public claims

Design the compliance program around the practice's actual risk. The HHS Office of Inspector General (OIG) describes its General Compliance Program Guidance as voluntary and nonbinding. Its seven-element infrastructure gives practices a useful framework for written standards, leadership, training, communication, enforcement, risk assessment and auditing, and response to detected problems.

Before a charge is released, tie the client, benefit, authorization, service, rendering person, supervisor, date, time, setting, documentation, code, modifier, unit calculation, contract, and claim field to current source evidence. Define correction, denial, credit-balance, refund, overpayment, audit-request, and disclosure routes by payer and program. A compliance lead should sample the full path from source record to remittance and report the numerator, denominator, exclusions, finding type, owner, and closure evidence.

OIG explains that Federal healthcare programs generally may not pay for items or services furnished by an excluded person or entity, or at the medical direction or on the prescription of an excluded person, regardless of who submits the claim or receives payment. Screen the List of Excluded Individuals/Entities before employment or contracting and at the approved ongoing cadence. OIG says monthly screening of employees and contractors best minimizes overpayment and civil monetary penalty exposure because the list updates monthly. OIG also says no statute or regulation independently requires an LEIE check; state Medicaid rules and payer contracts may set a cadence. Search all known names, verify possible matches with an SSN or EIN, preserve search evidence, and define contractor and subcontractor responsibility using OIG's LEIE instructions.

Route referral fees, gifts, free services, discounts, transportation, copay practices, marketing arrangements, and vendor compensation to counsel. OIG's fraud and abuse overview explains that the federal Anti-Kickback Statute addresses knowing and willful remuneration intended to induce or reward Federal healthcare-program referrals or business. State laws and payer contracts may have different or broader reach.

Approve every website, directory entry, intake script, testimonial, outcome statement, network claim, credential claim, and cost statement before use. The FTC advertising guide requires a reasonable basis for objective claims before dissemination; health or safety claims generally require competent and reliable scientific evidence matched to the express and implied claim. A testimonial cannot supply a claim the practice could not substantiate directly. Disclose unexpected material connections to endorsers clearly and conspicuously under the Endorsement Guides. The Consumer Reviews and Testimonials Rule addresses fake or false reviews, incentives conditioned on sentiment, deceptive suppression, and controlled properties presented as independent. If HIPAA applies, PHI use or disclosure for marketing generally requires authorization, subject to defined exceptions.

Gate 6: bind insurance and test incident response

Use a licensed broker, counsel, contracts, landlords, vehicle records, and the risk register to set coverage. Review professional liability, general liability, cyber and privacy, employment practices, property and business interruption, workers' compensation, hired or owned auto, directors and officers, crime or fidelity, abuse or molestation, and umbrella coverage where relevant. The SBA insurance guide describes common categories; state law, policy language, payer terms, leases, and the actual service model decide what is required and covered.

Capture named insureds, covered services and locations, exclusions, limits, deductibles or retention, defense terms, consent to settle, claims-made dates, tail needs, notice duties, certificates, renewal, and cancellation. Coverage should be effective before the related exposure begins.

Build one incident matrix across client safety, mandated reporting, employee injury, privacy and security, licensing, payer, insurer, law enforcement, and facility duties. For each event type, identify immediate protection, decision owner, recipients, deadline, evidence preservation, communication, privilege decision, correction, and restart authority. Under the HIPAA Breach Notification Rule, an impermissible PHI use or disclosure is presumed to be a breach unless an exception applies or a documented assessment of at least the four regulatory factors shows a low probability of compromise. Individual notice must be made without unreasonable delay and no later than 60 days after discovery. Determine separate timing and content rules for notice to HHS, the media, and by a business associate to a covered entity, then add any shorter state, payer, licensing, law-enforcement, and insurance clocks. Classify each event under every applicable source.

Use staged release gates

Review the ABA practice legal requirements register at every release point. The legal checklist should control the launch calendar:

ReleaseMinimum evidencePerson who can stop it
Form and contractApproved structure, ownership, governance, tax path, signing authority, and contract reviewFounders and counsel
Hire and trainEmployer registrations, worker classification, paid-work controls, insurance, screening, supervision, and safe training systemsPeople, clinical, and compliance leads
Market and intakeApproved claims, privacy intake, service and financial terms, complaint route, and accurate payer representationsCounsel, privacy, and intake leads
Schedule careClient consent, clinical readiness, professional authority, entity and location status, payer path, authorization, staffing, and safetyClinical, credentialing, and operations leads
Bill and collectSigned service evidence, code and unit rules, effective contract or payment path, claim test, refund and overpayment controlsRevenue cycle management and compliance leads

Run a fictional client, employee, vendor, incident, record request, authorization, claim, denial, refund, and discharge through the system. Use synthetic data with no real person's information.

In a fictional launch, the entity filing, center occupancy, professional licenses, privacy configuration, and commercial group agreement are complete. The commercial payer has confirmed only the home setting, Medicaid group enrollment remains pending, and one vendor has not completed the approved business-associate contract. The release sheet permits only client configurations with verified professional, location, payer, authorization, privacy, and staffing evidence. It holds center-based commercial starts, all Medicaid billing, and the vendor integration until their rows become effective. This example creates no legal or payer conclusion for another practice.

After opening, review expiring licenses, registrations, contracts, payer records, insurance, training, exclusions, access, risks, policies, marketing claims, incidents, complaints, refunds, and audits on a documented cadence. Reopen affected gates when ownership, control, location, service, population, staffing model, clinical leadership, technology, vendor, payer, or governing source changes.

Related resources

Sources