What should a family do about an ABA privacy concern? Protect immediate privacy and safety, record what happened, preserve relevant evidence, and report the issue through the provider's privacy or complaint route. Share only what the reviewer needs. Ask who owns the review, which interim safeguards apply, when the family will receive an update, and how the provider will document correction, required notices, and prevention.
Protect the person first
Move a conversation to a private space, close an exposed screen, retrieve a misdirected document when safe, stop an unauthorized recording, or limit further disclosure through the appropriate staff route. If another family received information, ask them to stop viewing or sharing it and follow the provider’s secure return or deletion instructions. Avoid investigating through wider disclosure.
Preserve the facts without altering the original record. Deleting a message, editing an audit trail, factory-resetting a device, or confronting everyone who might be involved can destroy useful evidence. Immediate safety, medical, protective, and legal reporting duties remain active while the privacy review proceeds.
Tell the person what happened in an accessible, age-appropriate way when authorized and appropriate. Ask what support they want, who may join the conversation, and whether the event affected their willingness to use a device, attend a session, or share information. A privacy response should account for the person’s experience alongside the technical review.
Identify what happened without deciding the law yourself
Privacy concerns take many forms. Examples include records sent to the wrong caregiver, a session discussed in a public space, an unlocked tablet, a portal account showing another client, a photograph posted without a valid route, or staff accessing information outside their role. Some events involve poor practice without meeting a particular legal definition. Others may trigger several laws, contracts, payer rules, or licensing duties.
HIPAA applies only to covered entities and certain business associates. HHS explains that covered entities include health plans, clearinghouses, and health care providers that transmit health information electronically in connection with a transaction for which HHS has adopted a standard. Provider status alone does not answer the question. State health, consumer-health, education, minor, biometric, recording, and breach laws may apply on different terms.
A family can report the facts without labeling the event a “HIPAA breach.” Ask the provider’s privacy or legal owner to determine the applicable rules, event classification, required mitigation, documentation, and notice. Keep clinical care and urgent safety support moving through authorized routes while that analysis occurs.
Record facts without spreading them
Write the date, time, place, people, information or device involved, who may have received it, how it was discovered, immediate action, and current risk. Include the account, page, message, attachment, or physical record involved and whether access may still be open. Preserve messages or screenshots in an approved secure location. Do not forward sensitive material widely to prove the concern.
Separate direct observation from what another person reported. A useful note might say, “At 3:10 p.m., I opened my child’s portal and saw another client’s appointment summary. I closed the page at 3:12, called the privacy number at 3:18, and did not download or forward the document.” This gives the reviewer a timeline without copying the exposed content into a new channel.
Ask for a case or reference number and keep the provider’s instructions. If you are asked to send evidence, confirm the approved destination and the minimum information needed. Regular email, text, or social media may create another exposure when the organization has a secure route.
Find the responsible review route
Ask for the provider's privacy contact, complaint process, response timing, and escalation route. A frontline clinician or scheduler can help route the report, while the privacy or legal owner should handle classification and notice decisions within authority. Different laws, contracts, payers, licensing bodies, and credentialing rules can apply. A family member should not have to decide legal reportability alone.
The CASP public guideline summary describes organizational recommendations across risk management and operations.
Request these basics in writing:
- confirmation that the report was received
- the named owner and contact route
- immediate containment steps affecting the family
- information the reviewer still needs
- the expected update date
- where to report continued access, retaliation, or new harm
- how the family can correct inaccurate records or preferences
An internal review may involve access logs, device status, recipients, the information involved, contracts, and interviews. The family may not receive every internal detail because another person’s privacy, workforce rules, security, or legal restrictions can limit disclosure. The provider can still communicate the family-facing finding, safeguards, notices, and open items.
Understand the breach-review boundary
For covered entities and business associates, the HHS Breach Notification Rule guidance explains that an impermissible use or disclosure of unsecured protected health information is presumed to be a breach unless an exception applies or a documented assessment of at least four regulatory factors demonstrates a low probability of compromise. An organization can choose to notify without performing that assessment. This analysis belongs to the regulated entity, not the family or the treating clinician acting alone.
The four factors address the nature and extent of the information, the unauthorized person, whether information was actually acquired or viewed, and mitigation. They are legal-review inputs. A family can supply facts relevant to them without trying to calculate its own score.
Notice rules depend on the recipient, event size, entity role, and other governing sources. A “60-day rule” should not be treated as permission to wait. HHS describes individual notice without unreasonable delay and no later than 60 days after discovery for a HIPAA breach, while other recipients and other laws may have different timing. Ask which clock and rule the organization is applying.
Protect communication and confidentiality
Offer a private way for the client to describe impact, ask questions, choose a supporter, or correct the record. The ASHA AAC portal supports continual AAC access.
The BACB Ethics Code addresses confidentiality, privacy, communication, documentation, risk, and professional responsibilities for covered behavior analysts.
Do not require the person to repeat a sensitive account to every layer of the organization. Record who has already received the information and arrange a consented handoff where appropriate. Use a private setting, role-limited access, interpreters or communication support as needed, and a clear option to pause.
Ask whether contact preferences or portal permissions need temporary changes. Verify authority before adding or removing a person’s access. A caregiver, emergency contact, and legally authorized representative may have different roles, and a privacy incident does not create new authority.
Know the external complaint option
Families may choose an external route in addition to, or instead of, an internal complaint. The appropriate destination depends on the entity, facts, jurisdiction, and issue. It may include a regulator, licensing board, payer, school process, law enforcement, or another authority. Filing internally does not necessarily extend an outside deadline.
For HIPAA-covered complaints, the current HHS complaint process says anyone can submit a written complaint to the Office for Civil Rights about a covered entity or business associate. It generally must be filed within 180 days of when the person knew of the act or omission, although OCR may extend the period for good cause. HHS also states that HIPAA prohibits retaliation for filing a complaint. This is general information, and OCR can investigate only entities and conduct within its authority.
Preserve the entity’s name, dates, description, prior correspondence, and any case number if an external complaint is being considered. Families can seek qualified legal advice for deadlines, state-law rights, damages, or case-specific strategy.
A fictional privacy-response tracker
A fictional family opens its child’s portal and sees another client’s appointment summary. The parent closes the page, notes the time, and calls the posted privacy contact. The provider disables the incorrect access without deleting the audit trail and gives both affected families separate communication routes.
The family records six defined response actions after the exposure. Four are complete within the stated period: access removed, privacy owner assigned, family contacted, and evidence preserved. Scope review and written resolution remain open. Completion is 4 of 6, or 66.7%.
The two open items stay in the denominator with owners and due dates. The 4/6 ratio measures response tasks. It cannot classify the event under any law, prove that mitigation was sufficient, establish whether notice is required, or measure the family’s trust.
Close the loop with evidence
Ask what the review found, which information and people were involved, what safeguard changed, whether records need correction, what notices apply, and how recurrence will be checked. Keep open items aged until final disposition.
Use a closure checklist:
- Containment is verified, including access, devices, recipients, and copies.
- The family-facing scope and finding are documented.
- The client received an accessible explanation and support when appropriate.
- Required record corrections, notices, and external reports are tracked separately.
- Contact and portal permissions are accurate.
- The responsible safeguard has been changed and tested.
- Staff or vendor follow-up has an owner and date.
- The family knows where to report recurrence or retaliation.
- Evidence is retained under the applicable policy.
An ABA privacy concern deserves a traceable response. A verbal assurance can support immediate communication, while documented ownership, qualified review, correction, and prevention show whether the issue was actually resolved.
Sources
- Council of Autism Service Providers, ABA Practice Guidelines Version 3.0
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- American Speech-Language-Hearing Association, Augmentative and Alternative Communication
- U.S. Department of Health and Human Services, Covered Entities and Business Associates
- U.S. Department of Health and Human Services, Breach Notification Rule
- U.S. Department of Health and Human Services, How to File a Health Information Privacy or Security Complaint
Finni resources