To control vendor model training and secondary use rights for ABA clinical data, map the practice, vendor, product, and subcontractor roles; every data type and derived artifact; the service purpose; and the contract, BAA, privacy, security, and other-law terms. Confirm whether prompts, outputs, feedback, logs, metadata, or de-identified data may train or improve models. Record retention, deletion, change notice, opt-out, audit, incident, and exit evidence before use.
Define Reina's AI vendor data-rights register
Reina avoids a single no training checkbox. A vendor may distinguish foundation-model training, customer-specific tuning, service improvement, safety review, abuse monitoring, support, analytics, telemetry, and human review. The unit identifies approved use, client and event, source records, model and version, vendor, user and accountable author, output state, reviewer, downstream use, exception, and evidence needed for release or closure.
Build Reina's page-specific control record
Reina records vendor and product, entity and business-associate roles, agreement and BAA, data and record classes, prompts and files, outputs and embeddings, feedback, metadata and logs, de-identification method, linkage, service purpose, training and improvement uses, customer-specific and shared models, human access, subprocessors, locations, retention, deletion and backups, opt-in or opt-out, default, change notice, version, intellectual property, confidentiality, security, incident, audit rights, export, return or destruction, exception, owner, approval, recheck, and validation. Marketing labels never replace operative terms.
Put Reina's human-review boundary into practice
Reina traces the real data path through product documentation, contract exhibits, privacy notices, security materials, technical tests, and written vendor answers. She asks whether disabling training affects prompts, attachments, outputs, logs, support cases, feedback, and historical copies. Any de-identification claim identifies the method, responsible party, documentation, residual risk, and other restrictions. Derived artifacts receive their own analysis because an embedding or fine-tuned model may retain sensitive patterns. Contract promises align with system settings and administrator evidence. Change notices route to privacy, security, legal, clinical, and procurement owners before new terms take effect. The practice blocks casual copy-and-paste into consumer AI accounts. Vendor incidents, subprocessors, acquisitions, product migrations, and model changes reopen diligence. Exit testing confirms usable export, account and token removal, return or destruction, and any retained exception with safeguards and a final deletion date.
Protect client communication and ordinary access for Reina
Reina preserves the client's direct communication, AAC, language and disability access, consent and assent when applicable, dissent, health, safety, privacy, priorities, and correction route. AI use never makes communication, food, water, bathroom access, mobility, prescribed care, rest, or emergency help conditional on tool participation or task performance.
Work through Reina's fictional example
Reina reviews 30 diligence controls. Twenty-three validate. Two terms omit output reuse, one subprocessor list is stale, one opt-out does not cover feedback, one backup deletion window is unknown, one de-identification claim lacks a method, and one exit test fails. The cohort teaches AI governance and denominator discipline. It does not establish treatment effect, model safety, legal compliance, coding correctness, payer acceptance, accessibility, or product performance.
Keep Reina's denominator tied to the locked population
Diligence readiness is 23 of 30 controls, or 76.7%. Settings, contract terms, technical validation, and vendor attestations remain separate evidence types. Exceptions stay open with owners and review dates.
Assign Reina's decisions to accountable people
Privacy and legal leaders interpret data rights. Security validates controls. Clinicians define minimum necessary workflow inputs. Procurement manages terms. Vendors state and meet commitments. Clients retain applicable rights and communication.
Address Reina's main AI documentation risk
A vendor can honor a model-training opt-out while retaining content for another secondary purpose. Review every data category, purpose, and lifecycle stage.
Test Reina's workflow with difficult cases
Reina tests default and opt-out settings, prompts, attachments, outputs, feedback, support, logs, de-identification, subprocessors, model update, acquisition, deletion, backup expiry, export, and vendor exit.
Check Reina's release evidence
Reina confirms the exact source set and versions, client and encounter, model and configuration, approved data route, generated draft, material edits, author and reviewer decisions, accessible client communication, release destination, correction path, monitoring cohort, and known limitations. The AI vendor data-rights register retains unresolved work, owner, deadline, downstream trace, and the next revalidation trigger.
Use Reina's ABA governance sources within their scope
Reina uses the CASP public overview only for high-level organizational context. The BACB Ethics Code applies to BCBA and BCaBA certificants and applicants as defined by the Code; BACB has no separate jurisdiction over organizations or corporations. These sources support competence, documentation, confidentiality, client involvement, assessment, intervention, risk, supervision, and correction boundaries. They do not approve a tool or transfer clinical authority to software.
Keep Reina's source record and medical-review boundary visible
Reina uses current CMS Program Integrity Manual Chapter 3 as Medicare medical-review guidance. It currently says services are expected to be documented when rendered; delayed or corrected entries may occur; date and author should be identifiable; and changes or addenda clearly and permanently noted. AI output cannot supply facts that were not documented, and Medicare guidance does not become a universal payer, state, or AI rule.
Map Reina's privacy, security, and vendor roles
Reina uses the current HHS Security Rule overview, HHS cloud guidance, and HHS business-associate guidance to analyze actual covered-entity, business-associate, subcontractor, cloud, and security roles. A BAA or vendor certification does not complete purpose, permissible-use, minimum-data, configuration, risk analysis, access, incident, retention, and shared-responsibility work.
Use Reina's AI frameworks as voluntary risk tools
Reina treats the NIST AI Risk Management Framework and NIST Generative AI Profile as voluntary risk-management resources, not clinical, legal, coding, or payer authority. The profile helps teams examine generative-AI risks and actions. A framework, score, benchmark, or vendor evaluation does not prove safety, accuracy, fairness, accessibility, compliance, or fitness for this ABA use.
Protect Reina's data-purpose and communication boundaries
Reina uses HHS de-identification guidance for its two HIPAA methods and residual-risk boundary. Calling output synthetic or removing names is not itself a method. FTC staff guidance warns AI companies to honor privacy and confidentiality commitments. The OIG GCPG is voluntary and nonbinding. ASHA's AAC portal says AAC users should always have access to their tools or devices.
Choose Reina's next review trigger
Reina reopens the AI vendor data-rights register after a model, prompt, retrieval, source, template, vendor, subprocessor, setting, language, client communication method, access role, data term, payer rule, incident, complaint, correction, audit finding, or regulation changes. The review records affected people and records, immediate safeguard, owner, deadline, communication, correction, downstream propagation, and validation.
Close Reina's workflow without hiding uncertainty
Review the AI vendor data-rights register with affected clients and authorized people, qualified clinicians, health-information, privacy, security, AI-governance, accessibility, language, payer, coding, and technical leaders, and the specialists named in the manifest. Confirm source support, authorship, authority, client access, model provenance, vendor terms, errors, downstream use, correction, and independent validation. Keep this page draft and noindex until every required external review is complete.
Related resources
- Respond to an AI Documentation Error or Hallucination in ABA Records.
- Log AI Model, Prompt, Source, Output, and Reviewer Provenance for ABA Documentation.
- Audit an AI-Assisted ABA Clinical Documentation System.
- Govern AI Coding and Billing Suggestions Derived From ABA Records.
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview.
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts.
- Centers for Medicare & Medicaid Services, Medicare Program Integrity Manual, Chapter 3.
- U.S. Department of Health and Human Services, HIPAA Security Rule.
- U.S. Department of Health and Human Services, Guidance on HIPAA and Cloud Computing.
- U.S. Department of Health and Human Services, Business Associates.
- U.S. Department of Health and Human Services, Guidance Regarding Methods for De-identification of Protected Health Information.
- National Institute of Standards and Technology, AI Risk Management Framework.
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile.
- Federal Trade Commission staff, AI Companies: Uphold Your Privacy and Confidentiality Commitments.
- Office of Inspector General, General Compliance Program Guidance.
- American Speech-Language-Hearing Association, Augmentative and Alternative Communication.