To control vendor model training and secondary use rights for ABA clinical data, map the practice, vendor, product, and subcontractor roles; every data type and derived artifact; the service purpose; and the contract, BAA, privacy, security, and other-law terms. Confirm whether prompts, outputs, feedback, logs, metadata, or de-identified data may train or improve models. Record retention, deletion, change notice, opt-out, audit, incident, and exit evidence before use.

Define Reina's AI vendor data-rights register

Reina avoids a single no training checkbox. A vendor may distinguish foundation-model training, customer-specific tuning, service improvement, safety review, abuse monitoring, support, analytics, telemetry, and human review. The unit identifies approved use, client and event, source records, model and version, vendor, user and accountable author, output state, reviewer, downstream use, exception, and evidence needed for release or closure.

Build Reina's page-specific control record

Reina records vendor and product, entity and business-associate roles, agreement and BAA, data and record classes, prompts and files, outputs and embeddings, feedback, metadata and logs, de-identification method, linkage, service purpose, training and improvement uses, customer-specific and shared models, human access, subprocessors, locations, retention, deletion and backups, opt-in or opt-out, default, change notice, version, intellectual property, confidentiality, security, incident, audit rights, export, return or destruction, exception, owner, approval, recheck, and validation. Marketing labels never replace operative terms.

Put Reina's human-review boundary into practice

Reina traces the real data path through product documentation, contract exhibits, privacy notices, security materials, technical tests, and written vendor answers. She asks whether disabling training affects prompts, attachments, outputs, logs, support cases, feedback, and historical copies. Any de-identification claim identifies the method, responsible party, documentation, residual risk, and other restrictions. Derived artifacts receive their own analysis because an embedding or fine-tuned model may retain sensitive patterns. Contract promises align with system settings and administrator evidence. Change notices route to privacy, security, legal, clinical, and procurement owners before new terms take effect. The practice blocks casual copy-and-paste into consumer AI accounts. Vendor incidents, subprocessors, acquisitions, product migrations, and model changes reopen diligence. Exit testing confirms usable export, account and token removal, return or destruction, and any retained exception with safeguards and a final deletion date.

Protect client communication and ordinary access for Reina

Reina preserves the client's direct communication, AAC, language and disability access, consent and assent when applicable, dissent, health, safety, privacy, priorities, and correction route. AI use never makes communication, food, water, bathroom access, mobility, prescribed care, rest, or emergency help conditional on tool participation or task performance.

Work through Reina's fictional example

Reina reviews 30 diligence controls. Twenty-three validate. Two terms omit output reuse, one subprocessor list is stale, one opt-out does not cover feedback, one backup deletion window is unknown, one de-identification claim lacks a method, and one exit test fails. The cohort teaches AI governance and denominator discipline. It does not establish treatment effect, model safety, legal compliance, coding correctness, payer acceptance, accessibility, or product performance.

Keep Reina's denominator tied to the locked population

Diligence readiness is 23 of 30 controls, or 76.7%. Settings, contract terms, technical validation, and vendor attestations remain separate evidence types. Exceptions stay open with owners and review dates.

Assign Reina's decisions to accountable people

Privacy and legal leaders interpret data rights. Security validates controls. Clinicians define minimum necessary workflow inputs. Procurement manages terms. Vendors state and meet commitments. Clients retain applicable rights and communication.

Address Reina's main AI documentation risk

A vendor can honor a model-training opt-out while retaining content for another secondary purpose. Review every data category, purpose, and lifecycle stage.

Test Reina's workflow with difficult cases

Reina tests default and opt-out settings, prompts, attachments, outputs, feedback, support, logs, de-identification, subprocessors, model update, acquisition, deletion, backup expiry, export, and vendor exit.

Check Reina's release evidence

Reina confirms the exact source set and versions, client and encounter, model and configuration, approved data route, generated draft, material edits, author and reviewer decisions, accessible client communication, release destination, correction path, monitoring cohort, and known limitations. The AI vendor data-rights register retains unresolved work, owner, deadline, downstream trace, and the next revalidation trigger.

Use Reina's ABA governance sources within their scope

Reina uses the CASP public overview only for high-level organizational context. The BACB Ethics Code applies to BCBA and BCaBA certificants and applicants as defined by the Code; BACB has no separate jurisdiction over organizations or corporations. These sources support competence, documentation, confidentiality, client involvement, assessment, intervention, risk, supervision, and correction boundaries. They do not approve a tool or transfer clinical authority to software.

Keep Reina's source record and medical-review boundary visible

Reina uses current CMS Program Integrity Manual Chapter 3 as Medicare medical-review guidance. It currently says services are expected to be documented when rendered; delayed or corrected entries may occur; date and author should be identifiable; and changes or addenda clearly and permanently noted. AI output cannot supply facts that were not documented, and Medicare guidance does not become a universal payer, state, or AI rule.

Map Reina's privacy, security, and vendor roles

Reina uses the current HHS Security Rule overview, HHS cloud guidance, and HHS business-associate guidance to analyze actual covered-entity, business-associate, subcontractor, cloud, and security roles. A BAA or vendor certification does not complete purpose, permissible-use, minimum-data, configuration, risk analysis, access, incident, retention, and shared-responsibility work.

Use Reina's AI frameworks as voluntary risk tools

Reina treats the NIST AI Risk Management Framework and NIST Generative AI Profile as voluntary risk-management resources, not clinical, legal, coding, or payer authority. The profile helps teams examine generative-AI risks and actions. A framework, score, benchmark, or vendor evaluation does not prove safety, accuracy, fairness, accessibility, compliance, or fitness for this ABA use.

Protect Reina's data-purpose and communication boundaries

Reina uses HHS de-identification guidance for its two HIPAA methods and residual-risk boundary. Calling output synthetic or removing names is not itself a method. FTC staff guidance warns AI companies to honor privacy and confidentiality commitments. The OIG GCPG is voluntary and nonbinding. ASHA's AAC portal says AAC users should always have access to their tools or devices.

Choose Reina's next review trigger

Reina reopens the AI vendor data-rights register after a model, prompt, retrieval, source, template, vendor, subprocessor, setting, language, client communication method, access role, data term, payer rule, incident, complaint, correction, audit finding, or regulation changes. The review records affected people and records, immediate safeguard, owner, deadline, communication, correction, downstream propagation, and validation.

Close Reina's workflow without hiding uncertainty

Review the AI vendor data-rights register with affected clients and authorized people, qualified clinicians, health-information, privacy, security, AI-governance, accessibility, language, payer, coding, and technical leaders, and the specialists named in the manifest. Confirm source support, authorship, authority, client access, model provenance, vendor terms, errors, downstream use, correction, and independent validation. Keep this page draft and noindex until every required external review is complete.

Related resources

Sources