To govern ABA portal delegates involved family and personal representative access, define each role and purpose separately. A portal delegate, involved family member, emergency contact, personal representative, treatment decision-maker, record recipient, financial contact, and pickup person may have different authority. Verify the source and scope, honor capable-client choice, grant only the needed functions, set recheck triggers, and test removal across every connected system.
Define Sana's role-scoped portal access matrix
Sana builds access from capabilities rather than one family access switch. Viewing appointments, messaging, signing a service agreement, receiving records, making treatment decisions, paying a bill, and changing contact settings are independent permissions. The file identifies the person, requester, purpose, governing source, authority, record population, clock, owner, decision, downstream systems, accessible communication, unresolved work, and evidence required for closure.
Build Sana's page-specific record
Sana records client identity and preferences, user identity, relationship label, legal authority and source when applicable, involved-person disclosure route, portal-delegation instruction, consent authority, record-access authority, permitted records and functions, billing role, emergency role, restrictions, sensitive segments, effective dates, expiration, identity proofing, authentication, device and notification, access support, audit log, recheck event, removal, contested authority, professional review, and validation. Incoming information never creates disclosure authority by itself.
Put Sana's workflow into daily use
Sana presents the client with an accessible permission screen that explains each function and who will receive notifications. The system records the person's choice separately from authority supplied by law. When a personal representative acts, the practice verifies the source and actual scope rather than importing a guardian label from another system. Involved-person communication follows its own HIPAA pathway and reaches only relevant information under the applicable conditions. Portal roles cannot sign clinical content, change legal authority, or expand their own access. Sensitive messages and records receive the segmentation required by current law and system capability. New authority, revocation, endangerment concern, adulthood, divorce, custody change, death, or account compromise triggers review. Sana removes access from active sessions, tokens, mobile devices, shared links, email notifications, APIs, and downstream portals. She informs the client through the approved channel and validates that historical audit logs remain intact.
Protect client communication and clinical meaning for Sana
Sana keeps the client's own communication, AAC, language and disability access, chosen support, consent and assent when applicable, dissent, privacy, health, safety, and correction route visible. A legal or privacy pathway does not make a payer decision or a clinical recommendation. Immediate safety action and mandated duties continue through their current qualified routes.
Work through Sana's fictional example
Sana reviews 26 active delegate profiles. Twenty-one match current evidence and client direction. Two have expired authority, one grants billing access broader clinical records, one removed delegate retains a mobile session, and one involved family member is mislabeled as a representative. The cohort teaches workflow and denominator discipline rather than a legal, privacy, treatment, payer, accessibility, or technical standard.
Keep Sana's measures tied to mature work
Access-profile integrity is 21 of 26, or 80.8%. After four validate, 25 of 26 are correct, or 96.2%. The active mobile session remains open. Capability-level defects and affected-profile counts stay separate.
Assign Sana's decisions correctly
Applicable law determines personal-representative authority. The capable client directs voluntary portal delegation and involvement within applicable limits. Privacy and legal roles resolve ambiguity. Clinical staff own clinical content. Technical staff implement approved capabilities and cannot create authority.
Address Sana's main rights-workflow risk
A relationship label looks intuitive but hides scope. Store source, function, period, and restrictions as separate fields, and show the client who can do what.
Validate Sana's route end to end
Sana tests a chosen delegate, limited representative, involved family member, billing-only contact, shared device, changed phone, revoked access, expired document, adulthood transition, emergency contact, and contested authority.
Give Sana's handoff a final evidence check
Sana pauses before handoff and confirms the requester or recipient, authority source, exact record population, current versions, access needs, clock, qualified decision, approved channel, and any exception or unresolved item. The receiving role acknowledges what it owns next. The role-scoped portal access matrix retains the file manifest, decision notice, transmission or configuration evidence, client communication, open work, and recheck date. A returned message, rejected file, changed authority, incomplete search, or new downstream recipient reopens the workflow instead of becoming an informal side task.
Use Sana's professional sources within scope
Sana uses the CASP public overview only for high-level organizational context. The BACB Ethics Code applies to BCBA and BCaBA certificants and applicants as defined by the Code; BACB has no separate jurisdiction over organizations or corporations. These sources support documentation, confidentiality, client involvement, role, and correction boundaries. They do not determine HIPAA entity status, legal authority, court process, or every workforce role.
Separate Sana's access and amendment routes
Sana applies the HHS access guidance and current 45 CFR 164.524 to covered-entity access requests within their actual scope. Current 45 CFR 164.526 governs amendment requests for covered entities, including acceptance, denial, disagreement, rebuttal, future disclosure, and documentation provisions. These routes differ from an author's attributable correction and from state-law rights that may also apply.
Verify Sana's representative and involved-person evidence
Sana uses HHS personal-representative guidance for authority derived from applicable law and limited to its actual scope. Separate HHS involved-person guidance describes circumstances for directly relevant disclosure to family, friends, or others involved in care or payment. Receiving information from someone, listing an emergency contact, or sharing a household does not create personal-representative or treatment-decision authority.
Keep Sana's disclosure pathway specific
Sana uses HHS TPO guidance for applicable treatment, payment, and health-care-operations pathways and HHS court-order and subpoena guidance for its limited federal overview. Current 45 CFR 164.522 addresses certain restrictions and confidential communications. State law, Part 2, school records, contracts, court rules, licensing, payer terms, and other specialized sources may create different or additional limits.
Protect Sana's security and communication access
Sana uses the HHS Security Rule overview for current regulated ePHI safeguards. The DOJ Title III overview addresses effective communication and reasonable modifications for covered public accommodations. ASHA's AAC portal says AAC users should always have access to their tools or devices. These sources support secure and accessible operation without making one channel, device, or form universally required.
Choose Sana's next review trigger
Sana reopens the role-scoped portal access matrix after a source, law, authority, request channel, record class, client preference, representative, system, vendor, access role, disclosure pathway, court process, correction, incident, or audit finding changes. The review records affected people and records, immediate safeguard, owner, deadline, communication, source correction, downstream propagation, and validation.
Close Sana's file without hiding unresolved work
Review the role-scoped portal access matrix with affected clients and authorized people, qualified clinicians, privacy and records leaders, and the specialists named in the manifest. Confirm identity, authority, scope, source, clock, access, client message, decision, released population, secure route, exceptions, denial or disagreement, correction, downstream use, and independent validation. Keep this page draft and noindex until every required external review is complete.
Related resources
- Recheck ABA Record Authority and Access When a Client Reaches Adulthood.
- Document ABA Confidential-Communication and Disclosure-Restriction Requests.
- Share ABA Records for Provider-to-Provider Treatment Coordination.
- Process an ABA Record Amendment Request and Statement of Disagreement.
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview.
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts.
- U.S. Department of Health and Human Services, Individuals' Right Under HIPAA to Access Their Health Information.
- Electronic Code of Federal Regulations, 45 CFR 164.524.
- Electronic Code of Federal Regulations, 45 CFR 164.526.
- Electronic Code of Federal Regulations, 45 CFR 164.522.
- U.S. Department of Health and Human Services, Personal Representatives.
- U.S. Department of Health and Human Services, Communication With Family, Friends, and Others Involved in Care.
- U.S. Department of Health and Human Services, Uses and Disclosures for Treatment, Payment, and Health Care Operations.
- U.S. Department of Health and Human Services, Court Orders and Subpoenas.
- U.S. Department of Health and Human Services, HIPAA Security Rule.
- U.S. Department of Justice, Businesses That Are Open to the Public.
- American Speech-Language-Hearing Association, Augmentative and Alternative Communication.