An ABA privacy incident tracker for families can preserve what a family directly observed, what the responsible organization said and what follow-up occurred after a suspected information-handling problem. It creates a chronology without asking the family to investigate devices or decide whether the event meets a legal definition.
Use one copy for one event or closely connected series of events. Save the original message, envelope, screenshot, notice or other source separately. Record only the sensitive details needed to identify the event and use the provider's approved private route for protected information.
This ABA privacy incident tracker for families is a family-owned facts and follow-up log. It is not a breach assessment, security investigation, HIPAA complaint, incident report, grievance, clinical record, law-enforcement report or legal claim.
Families and Caregivers / Progress, Quality, Rights and Ethical Care.
What this log can and cannot establish
The log can preserve dates, direct observations, source materials, information possibly involved, people or systems named by a source, immediate family actions, responsible contacts, acknowledgements, attributed investigation updates, notices, mitigation described and questions. It can keep corrections visible when early information changes.
Important boundary: This log cannot decide whether information is protected, whether HIPAA or another law applies, or whether an impermissible use or disclosure occurred. It cannot determine whether an event is a breach, exception or cybersecurity incident; whether information was acquired or viewed; or the risk, notification duties or deadlines. It also cannot decide security adequacy, fault, harm, fraud, retaliation, remedy or legal compliance. Do not use it to inspect a device, test an account, contact an unintended recipient, expose more sensitive information or replace emergency, provider, privacy, security, payer, regulator or legal routes.
The BACB Ethics Code for Behavior Analysts addresses confidentiality, documentation, communication and applicable requirements within its professional scope. A family log cannot determine whether a practitioner or organization complied with the code.
Stabilize the situation before documenting it
If there is an immediate threat to a person's physical safety, use the appropriate emergency route. If an account appears compromised, use the organization's official security instructions rather than experimenting with passwords, links or devices. A tracker should not delay urgent help.
First record whether an immediate safety concern is present and which urgent route was used, if any. Note the official privacy or security contact, the original item retained, any account or device action directed by a responsible source, sensitive details kept out of ordinary channels and family accessibility support needed.
Do not forward a suspicious message merely to show someone what happened. Do not click a link to “confirm” it. Ask the responsible organization where to send evidence safely.
Record direct observations before conclusions
Event fieldFamily entryDate and time observed or receivedChannel, location or systemWhat the family directly saw, heard or receivedSource item retained and stored atInformation visibly involvedPerson, address or account shownWhat is unknownWho else directly observed it
Use neutral language: “an email addressed to another family arrived” is more precise than “the provider leaked records.” Separate a direct observation from an inference. If a screenshot contains another person's information, do not circulate it beyond the approved reporting route.
Preserve the original timestamp and sender address. Label notes written later with their own date. Do not alter metadata or search a device for evidence unless a qualified responsible source directs that work.
Keep different incident routes separate
Possible routeWhat it may addressResponsible source to confirmReference or statusPrivacy concernQuestion about use, access or disclosureInternal privacy or security incidentOrganization's investigation processHIPAA breach assessment, if applicableCovered entity or business associate analysisCybersecurity or account eventSystem, credential or device responseUnauthorized recording concernPhoto, audio or video issueClinical or safety incidentCare event involving health or safetyProvider grievanceOrganization's complaint processPayer or school processRecord held by another institutionRegulator complaint or legal claimExternal process
One event may lead to more than one route, but the routes do not prove one another. A privacy office may review an email while a clinical leader separately reviews care. Keep the case numbers and responses separate.
Do not call an event a “breach” merely because it is upsetting or unexpected. Do not call a response “cleared” merely because the organization acknowledged it.
Understand why breach status requires a responsible assessment
The HHS Breach Notification Rule overview explains that the HIPAA Breach Notification Rule applies to covered entities and business associates after a breach of unsecured protected health information. It summarizes a risk assessment that considers the information involved, the unauthorized person, whether information was actually acquired or viewed and mitigation. It also describes exceptions.
The current 45 CFR 164.402 eCFR text contains the regulatory definitions used for that analysis. Those definitions require facts that a family may not have and a legal framework that the tracker cannot apply.
Record the responsible organization's attributed determination if it provides one. Do not turn a family observation into a legal breach conclusion or assume that “not a reportable breach” means nothing happened.
Report through the responsible route
Report fieldEntryOrganization contactedPrivacy, security or other officeApproved reporting channelDate and time reportedFactual description submittedEvidence referenced, not broadly copiedDelivery confirmationCase or reference number
Use the provider's or plan's official contact. Ask how to transmit a source item safely. If the event involves information belonging to another person, avoid adding that person's details to an ordinary email or voicemail.
Keep the report bounded to what the family knows. It is reasonable to say, “I do not know whether anyone opened the attachment.” Preserve questions rather than filling gaps with assumptions.
Track acknowledgement and investigation updates
Follow-up eventDateSource and exact responseOwnerNext question or statusReport receivedAdditional facts requestedInvestigation or review acknowledgedInterim safety or account instructionScope clarifiedDetermination or explanation suppliedFormal notice suppliedCase closed or transferred
Copy the organization's wording. “Security team is reviewing” is different from “incident confirmed.” Note who said it and when. If the organization corrects an early statement, keep both entries and label the correction.
The family can ask who owns the next update and where questions belong. This log does not set an investigation timeline.
Review any formal notice without expanding its claims
The current 45 CFR 164.404 eCFR text is the notification provision used here. It describes individual notification after discovery of a breach of unsecured protected health information when the rule applies. It addresses timing, method and content of the notice. The covered entity is responsible for applying those requirements.
Notice-review fieldEntryNotice title and senderDate receivedEvent and discovery dates statedInformation types describedProtective steps suggestedInvestigation or mitigation describedContact route suppliedFamily question
An ordinary email response is not automatically the formal notice described by the rule. A formal notice does not itself prove every fact beyond what it states. Preserve the original and route questions to the named contact.
Record mitigation as attributed action
Mitigation or follow-up itemSourceDate promisedDate confirmedEvidence or open questionMessage recalled or access removedRecipient contacted by organizationAccount credentials resetCorrect recipient received informationMonitoring or protective step offeredProcess change describedFamily communication corrected
Write “provider stated the link was disabled,” not “the information is safe.” The tracker cannot verify a technical action or eliminate risk. Do not ask an unintended recipient to delete information unless the responsible organization or qualified adviser directs that contact.
Wrong family contact information should be updated through the official process. That correction is separate from the organization's incident assessment.
Protect the learner and family during follow-up
Record the preferred update channel, language or interpreter support, accessible format and learner communication preference. Add the person confirmed for case updates, any care-continuity question, the route for retaliation or access concerns and where sensitive details are stored outside this log.
Privacy follow-up should not require the family to retell unrelated clinical history. Ask the responsible office what minimum identifying information it needs. Keep ordinary care questions with the care team and privacy-investigation questions with the designated contact.
A family concern about retaliation or disrupted care should be recorded and routed through the responsible organization or qualified adviser. The tracker cannot determine retaliation or guarantee continuity.
Close one tracking cycle without deciding the case
Closure fieldEntryFinal response or notice receivedOrganization's stated determinationMitigation describedFamily action completedSeparate complaint or grievance openedRecords stored atUnanswered questionNext review, if needed
Closing the log means the family has completed this round of documentation. It does not certify breach status, security, compliance, harm or remedy. A regulator, payer, school or legal process may have its own forms and deadlines; use the responsible source for those requirements.
Fictional example: a misdirected portal message
This fictional example describes no real learner, family, provider, system or incident.
Observation. Sam receives a portal message from fictional Meadowline ABA. The subject references Sam's child, Luis, but the attachment's first page displays a different first name. Sam does not open additional pages or forward the file. Sam records the timestamp, preserves the message and uses the portal's privacy contact.
Report. Sam states exactly what was visible and says he does not know whether the attachment contains more information. The privacy office supplies case number P-104 and asks him not to access the attachment while it reviews the event.
Follow-up. The office later states that the attachment link was disabled and provides a written explanation. Sam copies that statement with attribution. He does not contact the other family or conclude that the event is a HIPAA breach.
Closure. A corrected document for Luis arrives through the portal. Sam stores the explanation and corrected document separately and records one open question about whether his own information went elsewhere. The privacy office opens a second inquiry for that question.
The example does not establish protected status, impermissible disclosure, acquisition or viewing, breach, exception, notification duty, technical security, fault, harm, fraud, retaliation, remedy or compliance.
Sources
Finni resources