To publish ABA clinical records to a client portal safely, define which source records and versions may appear, when release occurs, who can see each item, and which restriction, representative, or client-choice rules apply. Render content accessibly, protect AAC and communication, verify notifications and downloads, preserve corrections, and log every access. A portal copy is a controlled view of the source record, not a separate clinical truth.
Define Felix's portal publication release file
Felix separates record finalization, clinical review, legal or privacy release, portal publication, notification, user access, download, and client response. One release switch never proves every gate. The unit identifies the client and record, source, purpose, version, system, custodian, accountable owner, downstream use, open exception, and acceptance evidence before any completion rate is reported.
Build Felix's page-specific evidence record
Felix records source class and version, client and encounter, author and correction state, publication rule, release delay or event, decision owner, portal audience and capability, personal representative or delegate source, restrictions, sensitive segments, accessibility and language, rendering, attachment and media behavior, notification channel, preview, publish event, access and download log, failed delivery, client question or disagreement, amendment and correction route, removal or supersession, outage behavior, vendor custody, retention, incident response, and validation. Drafts and incomplete records remain blocked.
Put Felix's transport control into practice
Felix tests the intended record with each real portal role before enabling a class. The preview shows the same rendering, attachment, source date, author, and correction label the client will receive. Release rules account for current federal and state requirements, while clinical staff do not use a delay to hide an accurate final record. Notifications contain minimal information and follow confidential-channel settings. The portal provides an accessible way to ask a question, request access in another format, or challenge content. A correction links the prior view to the current record and alerts affected users as required. Removal from routine view does not erase the source or audit trail. Felix checks mobile sessions, shared devices, delegate revocation, adulthood transitions, and downloads. When the portal is unavailable, another approved access route remains available. Metrics distinguish publication, notification, access, understanding, disagreement, and amendment.
Protect clinical meaning and client access for Felix
Felix preserves accessible communication, AAC, language and disability access, consent and assent when applicable, dissent, privacy, safety, source attribution, and qualified clinical judgment. Transport, storage, receipt, and technical validation never create clinical authority, payer approval, claim acceptance, or payment.
Work through Felix's fictional example
Felix reviews 28 portal releases. Twenty-three publish correctly. Two go to expired delegates, one attachment fails, one inaccessible graph has no alternate text, and one superseded note appears current. All five are removed or contained pending correction. This fictional cohort teaches traceability and denominator discipline. It does not set a clinical, technical, legal, privacy, retention, payer, or accessibility requirement.
Keep Felix's denominator tied to the locked population
Publication integrity is 23 of 28 releases, or 82.1%. Notification delivery and client access use their own eligible populations. A record the client never opens is not recoded as a failed publication or successful understanding.
Assign Felix's decisions to accountable roles
Records and privacy leaders approve release rules. Qualified clinicians own source content. Clients and applicable representatives receive scoped access. Accessibility roles test rendering. Technical teams publish approved versions and cannot decide clinical meaning.
Address Felix's main transport risk
Portal transparency can still fail when content is unreadable, context-free, or delivered to the wrong role. Test audience, rendering, and correction together.
Test Felix's full source-to-target path
Felix tests note, plan, graph, attachment, media reference, correction, superseded version, delegate, restriction, adulthood transition, confidential notification, download, outage, and accessible alternate format.
Check Felix's release or acceptance packet
Felix confirms the approved source population, exact produced objects, identity and encounter links, authorship and versions, attachments, access roles, security evidence, exceptions, responsible recipient, and downstream validation before handoff or acceptance. The portal publication release file retains manifests, counts, timestamps, transformation or transfer controls, reviewer findings, client communication, correction links, unresolved work, and the next recheck date. Felix also tests client logout and notification removal.
Anchor Felix's workflow in accountable practice governance
Felix uses the CASP public overview for high-level organizational context only. The BACB Ethics Code applies to BCBA and BCaBA certificants and applicants as defined by the Code; BACB has no separate jurisdiction over organizations or corporations. These sources support role, documentation, confidentiality, correction, client involvement, and continuity boundaries without prescribing this technical design.
Keep Felix's medical-review source narrow
Felix uses current CMS Program Integrity Manual Chapter 3 as Medicare medical-review guidance. It supports source-based documentation review and currently says services are expected to be documented when rendered; delayed or corrected entries may occur; date and author should be identifiable; and a change or addendum should be clearly and permanently noted. It does not create one universal ABA migration, scanning, payer, or state rule.
Apply Felix's security controls to the real environment
Felix uses the current HHS Security Rule overview, 45 CFR 164.308, and 45 CFR 164.312 for regulated ePHI safeguards. Covered entities and business associates must apply the current rule to their actual role and environment. A backup, encryption feature, contract, or certification does not by itself complete risk analysis, risk management, access control, integrity, transmission, incident, and contingency duties.
Map Felix's vendor and cloud roles accurately
Felix uses HHS cloud guidance and HHS business-associate guidance to identify actual covered-entity, business-associate, subcontractor, and cloud-service-provider roles. A regulated customer and its business associate retain duties for their roles. Contract language, return or destruction clauses, shared responsibility, and vendor tools must be tested against actual custody, access, copies, and services.
Preserve Felix's recovery, access, and communication boundaries
Felix treats NIST SP 800-34 Rev. 1 Update 1 as federal information-system contingency guidance that a private practice may adapt, not a general private-provider mandate. HHS access guidance remains relevant to usable record delivery. The DOJ Title III overview supports effective communication and reasonable modifications for covered public accommodations, while ASHA's AAC portal says AAC users should always have access to their tools or devices.
Choose Felix's next review trigger
Felix reopens the portal publication release file after a new record class, system, interface, format, mapping, vendor, subprocessor, access role, portal, key, backup, archive, request pathway, correction, incident, outage, audit finding, or law and contract change. The review records affected people and records, immediate safeguard, owner, deadline, source correction, target propagation, communication, and validation.
Close Felix's lifecycle without losing open work
Review the portal publication release file with affected clients and authorized people, qualified clinicians, health-information, privacy, security, and technical leaders, and the specialists named in the manifest. Confirm source, identity, version, transformation, authority, access, destination, exception, correction, downstream state, and independent validation. Keep this page draft and noindex until every required external review is complete.
Related resources
- Reconcile ABA Clinical Record Exports, Deliveries, and Acknowledgments.
- Test ABA Archived Record Search, Retrieval, Rendering, and Correction.
- Exit an ABA Clinical Data Vendor and Verify Return or Destruction.
- Validate ABA Clinical Record Backup, Restore, and Recovery Evidence.
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview.
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts.
- Centers for Medicare & Medicaid Services, Medicare Program Integrity Manual, Chapter 3.
- U.S. Department of Health and Human Services, HIPAA Security Rule.
- Electronic Code of Federal Regulations, 45 CFR 164.308.
- Electronic Code of Federal Regulations, 45 CFR 164.312.
- U.S. Department of Health and Human Services, Guidance on HIPAA and Cloud Computing.
- U.S. Department of Health and Human Services, Business Associates.
- U.S. Department of Health and Human Services, Individuals' Right Under HIPAA to Access Their Health Information.
- National Institute of Standards and Technology, SP 800-34 Rev. 1 Update 1.
- U.S. Department of Justice, Businesses That Are Open to the Public.
- American Speech-Language-Hearing Association, Augmentative and Alternative Communication.