ABA practice legal requirements are a linked set of entity, professional, facility, privacy, workforce, payer, billing, safety, record, insurance, and consumer obligations. The launch owner should maintain one jurisdiction-specific requirements register and release each stage only after the assigned adviser or agency confirms its evidence. State ownership, licensure, employment, privacy, facility, and payer rules can change both the sequence and the required proof.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
Start with a requirements register
One owner should control the launch register while qualified specialists approve their own domains. General formation guidance from the U.S. Small Business Administration (SBA) Business Guide covers registration, permits, insurance, hiring, and ongoing compliance. An ABA practice needs additional state healthcare, professional, facility, privacy, payer, and clinical analysis.
Create one row for each requirement and keep these fields:
| Field | What belongs in it |
|---|---|
| Requirement and source | Exact statute, regulation, agency page, board rule, payer manual, executed contract, or policy section |
| Scope | State, locality, entity, owner, role, location, setting, service, payer product, and client population |
| Owner and approver | Person doing the work and qualified person or authority accepting it |
| Dependency | Earlier filing, decision, inspection, credential, contract, or system control |
| Evidence | Filed document, written opinion, license, approval, effective date, test, training record, or signed policy |
| Timing | Trigger, submission date, deadline, effective date, renewal, and source recheck date |
| Status | Open, blocked, submitted, approved with conditions, effective, or expired |
| Change trigger | Ownership, address, service, staff role, vendor, payer, law, or workflow change that reopens the row |
Keep verbal guidance as a dated note with the agency, representative, contact route, question, and response. Ask for written confirmation when a decision affects authority to practice, serve a client, represent network status, bill, or retain records.
Gate 1: approve the entity, ownership, and clinical authority
Define the proposed owners, investors, governing body, clinical decision-makers, management company, employing entity, billing entity, service locations, and states before filing. Have state healthcare and corporate counsel analyze professional-entity rules, ownership restrictions, corporate-practice principles, fee splitting, management fees, control rights, trade names, foreign qualification, tax structure, and succession.
The SBA explains that registration depends on structure and location and that an entity active in another state may need foreign qualification. Its licenses and permits guide directs businesses to state and local sources because requirements depend on the activity and location. The legal effect of a filing depends on the filing and jurisdiction. Formation or registration alone leaves professional authority, facility status, payer participation, and authority to furnish a service unresolved. Record each applicable approval separately, or preserve a source-supported decision that an approval is unnecessary.
Map each clinical role to the actual state source. The Behavior Analyst Certification Board (BACB) licensure directory identifies states that regulate behavior analysts and routes readers to boards or enacted laws. Confirm current scope, exemptions, supervision, titles, telepractice, temporary practice, disciplinary status, renewal, and the locations of both practitioner and client through the state board and governing text. BACB certification and state authority should stay as separate register rows.
Gate 1 evidence: signed structure and control analysis, filed entity documents, governance approvals, tax advice, state registration, assumed-name status, and a role-by-role authority matrix.
Gate 2: clear licenses, enrollment, contracts, and locations
Create a configuration row for every entity, tax identifier, National Provider Identifier (NPI), rendering clinician, technician role, service location, setting, service, payer, product, and effective date. The current CMS NPI standard page defines an NPI as the standard unique identifier for covered providers. The CMS NPI files page warns that issuance does not ensure or validate licensure or credentials. Treat NPI assignment, state authority, credentialing, contracting, program enrollment, roster acceptance, location approval, authorization, and payment as different decisions.
For Medicaid, use the state agency and managed-care plan sources. The CMS Medicaid provider-requirements hub shows that provider management includes enrollment, ownership and control, screening, and payments. Preserve applications, disclosures, approval letters, effective dates, roster evidence, directory checks, contract versions, fee schedules, amendments, and revalidation dates.
For each service site, record zoning and permitted use, certificate of occupancy, building and fire approvals, accessibility, local business permits, and any healthcare, childcare, school, residential, telehealth, or home-based authority triggered by the actual model. Preserve the responsible authority's or counsel's source-supported determination when an item is inapplicable.
Counsel should review payer, employment, contractor, lease, referral, vendor, software, business associate, family-service, and financial agreements. Record the parties, services, authority, payment method, data rights, audit access, record ownership, insurance, indemnity, subcontracting, renewal, termination, transition duties, and governing law. The signed agreement and incorporated manuals belong in the source record.
Gate 2 evidence: every planned client path has effective professional, entity, location, payer, and contract status, or a separately approved lawful private-pay or out-of-network path with accurate disclosures.
Gate 3: establish privacy, security, and record controls
Determine the practice's role under the Health Insurance Portability and Accountability Act (HIPAA) for each activity and data flow involving protected health information (PHI). The HHS HIPAA for Professionals portal is the federal starting point. HIPAA covers health plans, clearinghouses, and healthcare providers that conduct covered transactions electronically; specified duties also apply directly to business associates.
Build a data map for intake, care, scheduling, messaging, telehealth, video, billing, payroll, marketing, analytics, backups, paper, and disposal. A covered entity should execute a compliant agreement before a vendor creates, receives, maintains, or transmits PHI as a business associate. Business associates must obtain compliant written assurances from business-associate subcontractors. HHS explains these controls in its business-associate guidance. The agreement allocates required duties while each party retains its own obligations. Complete and maintain the documented risk analysis for all ePHI.
Treat HIPAA as a federal floor. A contrary state law is generally preempted unless an exception applies, while a more stringent state privacy provision may control. Follow both rules when both can be satisfied, and document the preemption analysis. For activities outside covered-entity or business-associate scope, separately assess the FTC Act, the FTC Health Breach Notification Rule, and applicable state consumer-health laws.
Approve access, amendment, authorization, minimum-necessary, personal-representative, complaint, sanction, incident, backup, downtime, and breach workflows. Covered providers with direct treatment relationships generally need a current, plain-language Notice of Privacy Practices and the required delivery and posting process under HHS notice guidance.
Set retention by record type and authority. HHS states that HIPAA sets no general medical-record retention period; state and other governing sources generally supply those periods. HIPAA requires covered entities and business associates to retain specified Privacy and Security Rule documentation for six years from creation or the date last in effect, whichever is later, as reflected in the HHS HIPAA Audit Protocol. Add clinical, billing, authorization, employment, corporate, tax, payer, litigation-hold, and minor-record rules. Test access, hold, export, correction, destruction, and custodian continuity before live care.
Gate 4: activate a lawful and safe workforce
Employment counsel and payroll specialists should localize worker classification, wage and hour, overtime exemption, travel, training, cancellation work, documentation time, breaks, leave, expense reimbursement, pay notices, pay frequency, final pay, personnel files, restrictive covenants, background checks, and required postings. Federal, state, local, payer, tax, and professional tests can reach different answers.
Federal wage guidance from the U.S. Department of Labor Fair Labor Standards Act (FLSA) portal covers minimum wage, overtime, hours worked, and recordkeeping. Use the current source on the decision date because rulemaking, litigation, and enforcement positions can change. For federal discrimination, accommodation, records, posting, and employment-decision material, use the U.S. Equal Employment Opportunity Commission (EEOC) Small Business Resource Center. Counsel should add applicable state and local protections and thresholds.
Review disability access in two tracks. For employment, determine whether federal ADA Title I and broader state or local hiring and accommodation duties apply. For client-facing operations, assess Title III requirements for reasonable policy modifications, effective communication, service animals, physical access, and services offered through the website. Assign remediation and a release test before marketing or intake opens.
Keep pre-service checks separate: identity and work authorization, background, professional authority, payer status, exclusion status, required health or driving evidence, competence, supervision, privacy and billing training, incident duties, and paid-work readiness. For work authorization, follow current Form I-9 timing and instructions and anti-discrimination limits on document requests. When a consumer-reporting company supplies a background report, implement the FCRA's standalone disclosure and written authorization before procurement, the pre-adverse-action copy and Summary of Rights, and the final adverse-action notice when applicable under FTC and EEOC guidance. Add state and local restrictions.
Review employee hazards by job and setting. Occupational Safety and Health Administration (OSHA) hazard-identification guidance recommends initial and periodic inspections, review of incidents and near misses, emergency and nonroutine-work analysis, prioritization, correction, and retesting. Add the applicable federal or state-plan standards and local reporting rules.
Classify each role for reasonably anticipated occupational exposure to blood or other potentially infectious materials. When exposure exists, apply OSHA's Bloodborne Pathogens Standard, including the written exposure-control plan, controls and personal protective equipment, training, hepatitis B vaccination, and post-exposure process. Map federal OSHA's severe-injury reporting rule and every state-plan deadline into the incident matrix.
Gate 5: control billing, referrals, exclusions, and public claims
Design the compliance program around the practice's actual risk. The HHS Office of Inspector General (OIG) describes its General Compliance Program Guidance as voluntary and nonbinding. Its seven-element infrastructure gives practices a useful framework for written standards, leadership, training, communication, enforcement, risk assessment and auditing, and response to detected problems.
Before a charge is released, tie the client, benefit, authorization, service, rendering person, supervisor, date, time, setting, documentation, code, modifier, unit calculation, contract, and claim field to current source evidence. Define correction, denial, credit-balance, refund, overpayment, audit-request, and disclosure routes by payer and program. A compliance lead should sample the full path from source record to remittance and report the numerator, denominator, exclusions, finding type, owner, and closure evidence.
OIG explains that Federal healthcare programs generally may not pay for items or services furnished by an excluded person or entity, or at the medical direction or on the prescription of an excluded person, regardless of who submits the claim or receives payment. Screen the List of Excluded Individuals/Entities before employment or contracting and at the approved ongoing cadence. OIG says monthly screening of employees and contractors best minimizes overpayment and civil monetary penalty exposure because the list updates monthly. OIG also says no statute or regulation independently requires an LEIE check; state Medicaid rules and payer contracts may set a cadence. Search all known names, verify possible matches with an SSN or EIN, preserve search evidence, and define contractor and subcontractor responsibility using OIG's LEIE instructions.
Route referral fees, gifts, free services, discounts, transportation, copay practices, marketing arrangements, and vendor compensation to counsel. OIG's fraud and abuse overview explains that the federal Anti-Kickback Statute addresses knowing and willful remuneration intended to induce or reward Federal healthcare-program referrals or business. State laws and payer contracts may have different or broader reach.
Approve every website, directory entry, intake script, testimonial, outcome statement, network claim, credential claim, and cost statement before use. The FTC advertising guide requires a reasonable basis for objective claims before dissemination; health or safety claims generally require competent and reliable scientific evidence matched to the express and implied claim. A testimonial cannot supply a claim the practice could not substantiate directly. Disclose unexpected material connections to endorsers clearly and conspicuously under the Endorsement Guides. The Consumer Reviews and Testimonials Rule addresses fake or false reviews, incentives conditioned on sentiment, deceptive suppression, and controlled properties presented as independent. If HIPAA applies, PHI use or disclosure for marketing generally requires authorization, subject to defined exceptions.
Gate 6: bind insurance and test incident response
Use a licensed broker, counsel, contracts, landlords, vehicle records, and the risk register to set coverage. Review professional liability, general liability, cyber and privacy, employment practices, property and business interruption, workers' compensation, hired or owned auto, directors and officers, crime or fidelity, abuse or molestation, and umbrella coverage where relevant. The SBA insurance guide describes common categories; state law, policy language, payer terms, leases, and the actual service model decide what is required and covered.
Capture named insureds, covered services and locations, exclusions, limits, deductibles or retention, defense terms, consent to settle, claims-made dates, tail needs, notice duties, certificates, renewal, and cancellation. Coverage should be effective before the related exposure begins.
Build one incident matrix across client safety, mandated reporting, employee injury, privacy and security, licensing, payer, insurer, law enforcement, and facility duties. For each event type, identify immediate protection, decision owner, recipients, deadline, evidence preservation, communication, privilege decision, correction, and restart authority. Under the HIPAA Breach Notification Rule, an impermissible PHI use or disclosure is presumed to be a breach unless an exception applies or a documented assessment of at least the four regulatory factors shows a low probability of compromise. Individual notice must be made without unreasonable delay and no later than 60 days after discovery. Determine separate timing and content rules for notice to HHS, the media, and by a business associate to a covered entity, then add any shorter state, payer, licensing, law-enforcement, and insurance clocks. Classify each event under every applicable source.
Use staged release gates
Review the ABA practice legal requirements register at every release point. The legal checklist should control the launch calendar:
| Release | Minimum evidence | Person who can stop it |
|---|---|---|
| Form and contract | Approved structure, ownership, governance, tax path, signing authority, and contract review | Founders and counsel |
| Hire and train | Employer registrations, worker classification, paid-work controls, insurance, screening, supervision, and safe training systems | People, clinical, and compliance leads |
| Market and intake | Approved claims, privacy intake, service and financial terms, complaint route, and accurate payer representations | Counsel, privacy, and intake leads |
| Schedule care | Client consent, clinical readiness, professional authority, entity and location status, payer path, authorization, staffing, and safety | Clinical, credentialing, and operations leads |
| Bill and collect | Signed service evidence, code and unit rules, effective contract or payment path, claim test, refund and overpayment controls | Revenue cycle management and compliance leads |
Run a fictional client, employee, vendor, incident, record request, authorization, claim, denial, refund, and discharge through the system. Use synthetic data with no real person's information.
In a fictional launch, the entity filing, center occupancy, professional licenses, privacy configuration, and commercial group agreement are complete. The commercial payer has confirmed only the home setting, Medicaid group enrollment remains pending, and one vendor has not completed the approved business-associate contract. The release sheet permits only client configurations with verified professional, location, payer, authorization, privacy, and staffing evidence. It holds center-based commercial starts, all Medicaid billing, and the vendor integration until their rows become effective. This example creates no legal or payer conclusion for another practice.
After opening, review expiring licenses, registrations, contracts, payer records, insurance, training, exclusions, access, risks, policies, marketing claims, incidents, complaints, refunds, and audits on a documented cadence. Reopen affected gates when ownership, control, location, service, population, staffing model, clinical leadership, technology, vendor, payer, or governing source changes.
Related resources
- Parent topic: Legal, Compliance, Privacy and Risk
- Multi-State ABA Expansion Checklist
- The Complete ABA Practice Startup Checklist
- Opening an ABA Center: Facility and Operations Checklist
- The ABA Intake Workflow: From First Inquiry to First Session
Sources
- U.S. Small Business Administration, Business Guide
- HHS, HIPAA for Professionals
- U.S. Small Business Administration, Register Your Business
- U.S. Small Business Administration, Apply for Licenses and Permits
- Behavior Analyst Certification Board, U.S. Licensure of Behavior Analysts
- CMS, National Provider Identifier Standard
- CMS, NPI Files and Licensure Disclaimer
- CMS, Medicaid Provider Requirements
- HHS, Covered Entities and Business Associates
- HHS, Business Associates
- HHS, Guidance on Risk Analysis
- HHS, HIPAA Preemption of State Law
- HHS, More Stringent State Law
- FTC, Complying with the Health Breach Notification Rule
- HHS, Notice of Privacy Practices
- HHS, Medical-Record Retention FAQ
- HHS, HIPAA Audit Protocol
- U.S. Department of Labor, Fair Labor Standards Act
- U.S. Equal Employment Opportunity Commission, Small Business Resource Center
- U.S. Equal Employment Opportunity Commission, Small Employers and Reasonable Accommodation
- U.S. Department of Justice, Businesses Open to the Public
- U.S. Department of Justice, Web Accessibility and the ADA
- U.S. Citizenship and Immigration Services, Form I-9
- FTC and EEOC, Background Checks for Employers
- Occupational Safety and Health Administration, Hazard Identification and Assessment
- Occupational Safety and Health Administration, Bloodborne Pathogens Standard
- Occupational Safety and Health Administration, Severe Injury Reports
- HHS Office of Inspector General, General Compliance Program Guidance
- HHS Office of Inspector General, Exclusions Program
- HHS Office of Inspector General, Effect of Exclusion
- HHS Office of Inspector General, LEIE Quick Tips and Instructions
- HHS Office of Inspector General, Fraud and Abuse Laws
- Federal Trade Commission, Advertising FAQs for Small Business
- Federal Trade Commission, Health Products Compliance Guidance
- Federal Trade Commission, Endorsement Guides
- Federal Trade Commission, Consumer Reviews and Testimonials Rule
- HHS, Marketing and the HIPAA Privacy Rule
- U.S. Small Business Administration, Business Insurance
- HHS, Breach Notification Rule