When a private ABA provider receives school records by mistake, stop routine access and use, secure the message and attachments, limit internal recipients, and report the event through the provider and school's privacy routes. Preserve minimal evidence, identify sender and intended recipient, follow authorized return or deletion instructions, correct contact and workflow sources, review payer and clinical effects separately, and keep the correct student's care, AAC, and safety supports available.
Stop access and secure the material
For Theo's provider, keep the message and attachments in a restricted incident location and prevent further clinical, billing, training, or administrative use. Record who already accessed the material. Avoid adding another student's information to Theo's chart, copying it into a general ticket, or forwarding it widely for help.
Notify both accountable privacy routes
Contact the ABA practice's privacy owner and the school's published records or privacy contact. Preserve sender, intended recipient, actual recipient, time, subject, attachment names, and school direction. Let the authorized owners decide evidence preservation, return, deletion, and notification duties under the applicable rules.
Separate record, clinical, and payer effects
Check whether any wrong information reached Theo's chart, treatment planning, authorization, claim, family message, or staff instruction. A qualified clinician corrects clinical records and decisions within scope. Billing and privacy owners handle payer and disclosure effects. Preserve original and corrected histories.
Repair the sending and intake workflow
Verify the school's recipient source and the provider's intake routing, client matching, attachment preview, restricted quarantine, duplicate-name handling, and escalation path. Test with harmless synthetic information. Close each affected record and workflow field only after its acceptance condition passes.
Prepare Theo's privacy-incident review
Bring Theo's misdirected school-record provider file, the school's current privacy and security contacts, annual FERPA notice, incident messages, minimal evidence, record and account categories, access needs, service-continuity concerns, and a short decision list. Also bring school and vendor responses, correction history, complaint questions, current deadlines, and requested outcomes. End with owners, dates, and a representative validation test.
Build Theo's source-attributed incident record
Create a restricted misdirected school-record provider file for Theo's sender, intended recipient, actual recipient, record, access, internal use, school direction, return, deletion, evidence, payer, care, correction, and validation. Give every field a source, version, holder, sender, recipient, time, authority, status, owner, next action, due date, correction, and closure evidence. Attribute student communication, family report, school statement, vendor notice, system evidence, clinical information, and legal conclusion separately.
Protect Theo's safety, access, and dignity
Give Theo and family participants understandable, accessible information, privacy, realistic update times, and a reliable way to ask questions, disagree, correct, accept, decline, pause, and request help. Keep AAC, interpreters, schoolwork, health and safety information, mobility, food, water, bathroom access, prescribed care, rest, and emergency help available during the response.
Ask eight incident-response questions for Theo
Use these questions in the misdirected school-record provider file:
- Which alert, event, record, account, device, product, holder, sender, recipient, and time apply?
- What is known, unknown, disputed, contained, corrected, or still exposed?
- Which FERPA, IDEA, HIPAA, state, school, contract, security, complaint, or other source governs the step?
- Who may classify, contain, investigate, communicate, notify, correct, restore, and close each field?
- Which immediate safety, identity, health, disability, bullying, financial, or access risk needs action?
- What did Theo communicate directly, and what did family, school, vendor, or a professional report separately?
- Which evidence supports the exposure, containment, notice, correction, continuity, or recovery state?
- Which representative test will show that the repaired path works?
Classify fields as complete, failed, pending, declined, disputed, false positive, suspected, confirmed, contained, superseded, or inapplicable with a reason.
A fictional school-data incident example for Theo
In this fictional example, a private ABA practice serving Theo receives another student's IEP and evaluation attachment from a school. Reviewers freeze 30 sender, recipient, record, access, use, return, deletion, payer, care, and correction fields and complete 20 of 30 by the checkpoint. A missing event, record, holder, recipient, data, exposure, containment, account, communication, correction, continuity, or validation field remains in Theo's denominator with an owner, age, and next action.
The misdirected school-record provider file measures evidence completion. Legal compliance, notification duty, security effectiveness, service quality, student understanding, harm, family experience, and recovery remain separate questions. Concurrent changes limit causal conclusions.
Use compatible incident denominators for Theo
For Theo's misdirected school-record provider file, report alerts triaged divided by alerts due; confirmed incidents contained divided by confirmed incidents due; affected accounts secured divided by accounts due; required communications completed divided by communications due; affected records corrected divided by records due; and recovery tests passed divided by tests attempted.
Publish raw counts with percentages and age every open item. Keep discovery, triage, classification, containment, evidence preservation, exposure analysis, notice review, communication, correction, continuity, complaint, and recovery as distinct measures.
Apply the federal privacy and security boundaries for Theo
For Theo, current 34 CFR Part 99 governs FERPA within its stated scope, and the Education Department's FERPA hub provides public guidance. The Department's data-security page explains that FERPA does not prescribe specific security controls, while security failures can create privacy risk. Its older breach checklist is general best-practice guidance, and current scenario trainings support planning exercises.
No cited federal source creates one universal family notification rule for every school data incident. Verify current state, district, vendor, contract, insurance, law-enforcement, record-holder, and student-specific duties.
Apply complaint, health, and professional boundaries for Theo
The current SPPO complaint page describes the federal complaint route and its 180-day timeliness rule. IdentityTheft.gov offers a federal recovery-plan route when identity theft facts support it. Federal school health-record guidance and joint FERPA-HIPAA guidance explain why record holder and entity status matter. ASHA addresses AAC; the BACB Ethics Code and CASP overview remain limited to their professional and organizational scope for Theo page 8.
Close Theo's loop with an incident test
Ask Theo and the relevant family participant to review the outcome through their usual language and communication methods. Test the repaired recipient list, account, device control, public-link permission, vendor path, family communication, record correction, complaint file, service-continuity route, or recovery evidence suited to the event. The defined review question for Theo is private ABA provider receives school records by mistake. Preserve every mismatch with an owner, due date, and next step.
Before closure, record what the school confirmed, what remains unknown, which source governed notice, which student access or service depended on the affected system, and how the response changed the source control. For Theo's incident review, keep incident state, family communication, record correction, safety support, and technical recovery separate. Reopen the file after a failed test, new recipient, changed exposure window, recurring alert, or inaccurate notice.
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- Electronic Code of Federal Regulations, 34 CFR Part 99, Family Educational Rights and Privacy
- U.S. Department of Education, Family Educational Rights and Privacy Act
- U.S. Department of Education, Data Security for K-12 and Higher Education
- U.S. Department of Education, Data Breach Response Checklist
- U.S. Department of Education, Data Breach Scenario Trainings
- U.S. Department of Education Student Privacy Policy Office, File a Complaint
- Federal Trade Commission, IdentityTheft.gov
- U.S. Department of Education, FERPA Guidance for School Officials on Student Health Records
- U.S. Departments of Education and Health and Human Services, Joint Guidance on FERPA and HIPAA
- American Speech-Language-Hearing Association, Augmentative and Alternative Communication
Finni resources