Families can request ABA records when the client or an authorized person holds the applicable access right. For a HIPAA covered entity, the individual generally has access to PHI in a designated record set, subject to defined exclusions and procedures. State law may provide additional rights or shorter timelines. Ask which entity holds the record, who may request it, what is included, the format, fee, deadline, and review route for any denial.

Identify the requester and entity

The client, personal representative, caregiver, and involved family member may have different rights. HHS personal-representative guidance ties representative authority and scope to applicable law. Verify identity without creating unreasonable barriers.

Define the records requested

HHS access guidance covers PHI in a designated record set, including records used to make decisions about the person, while recognizing exclusions and denial rules. A provider need not create a new analysis that does not exist.

Ask for readable context

The BACB Code addresses documentation and understandable communication. Request definitions, date range, authorship, corrections, and available explanatory conversation. The CASP summary supports individualized care.

Track the request

Record received date, requester, verified authority, scope, format, delivery method, fee, deadline, status, partial production, denial basis, review rights, and completion. A portal download count does not prove the family received every responsive record.

Name the record set and the requester

Identify whether the requester is the client, a personal representative, or another authorized person, and verify the applicable scope. Ask which legal entity maintains the records. A clinic brand, billing company, and treating organization may have different record responsibilities.

For a HIPAA-covered entity, HHS access guidance explains the right to inspect or obtain PHI in a designated record set, subject to the rule's scope and procedures. State and other laws may add rights or different retention periods. Ask the provider which process and deadline it is applying.

Write a precise request

Use record categories and dates: assessments, treatment plans, session records, data summaries, consent or authorization documents, communications, claims or billing records, incident records, and amendment history. Specify the requested electronic or paper format and delivery method. Ask for an itemized response when the provider withholds or cannot locate material.

A clinical summary may be useful but does not automatically replace requested source records. HHS rules allow a summary in lieu of access only under specified advance-agreement conditions. Ask what the summary covers, any fee, and whether the source records remain available.

Protect readability and context

When the records arrive, check dates, authors, versions, legends, units, attachments, and whether electronic files open. Ask for definitions needed to interpret graphs or abbreviations. Preserve the provider's original file and create a separate working copy for notes.

If a factual error appears, use the provider's amendment or correction route rather than silently altering the record. Keep the request and response together. A disagreement about clinical judgment may be documented differently from an incorrect date, name, or service entry.

Work through a records request

Devin's representative requests six categories for the prior year in electronic form. Four categories arrive by the stated date. The incident records are missing, and one assessment file is password-protected with no password route. Usable completeness is 4 of 6 categories at that checkpoint.

The representative sends a focused follow-up listing the two incomplete categories. The practice supplies the password through a separate channel and explains the incident-record status. Keep every category in the denominator until it has a disposition such as delivered, lawfully denied, unavailable with explanation, or withdrawn by the requester.

Maintain a request tracker

Record receipt date, requester and authority, entity, scope, date range, format, delivery route, due date, extensions, fees, items delivered, denials, open questions, and appeal or complaint information. Protect identity documents and access credentials from broad operational queues.

Close the tracker after every requested category has a documented result and the requester can use the files. Record access is separate from clinical interpretation, payer authorization, and permission to disclose the records onward. Ask qualified professionals or counsel for those separate questions when needed.

Respond to delay, fees, or a partial denial

Ask the provider to identify the rule, reason, and revised date for a delay. If a fee applies, request the calculation before agreeing. If access is denied in whole or part, ask for the written basis, which records are affected, and any review or complaint route. Do not treat a portal's missing-download button as a formal denial without asking the responsible entity.

Track timing from the event the governing rule uses, such as receipt of a valid request, rather than from an informal conversation. Preserve identity-verification steps and the date the request became complete. Different laws, entities, or record types may use different procedures, so avoid one universal deadline in a family tracker.

Check whether a business closure, vendor change, or provider departure changes the records custodian. The treating professional, clinic, billing vendor, and EHR company may have different roles. Ask the legal entity to name the current custodian and future contact rather than chasing each former staff member.

A follow-up can read: “This request covered six record categories for these dates in electronic form. Four categories were delivered. Please provide the status and governing response for the incident records and assessment file, including any fee, denial basis, revised date, and review route. Keep this message with the request history.”

When every item has a result, save a request index with file names and dates. Protect the exported records, especially on shared devices or email. Decide who may receive later copies separately. A successful access request gives the requester usable records and a clear response to every category; it does not prove that the records are accurate or that another organization may lawfully receive them.

Plan for future records before the next urgent request

Ask the practice how clients can request records after staff departure, clinic closure, or a system migration. Save the current custodian, form, secure route, and complaint contact. Keep a personal index of important plan versions and dates without creating insecure duplicate clinical files.

For ongoing care, decide which records the family needs routinely and which can be requested for a specific event. A current treatment plan, communication summary, safety information, and authorization details may be useful during transitions. Billing or complaint needs may call for another set.

Review the index annually and after major changes. Delete unnecessary local copies safely, protect shared-device access, and update authorized recipients. Good record readiness reduces emergency burden while preserving the provider's responsibility to maintain and answer for its official records. Confirm that any backup can actually be opened before relying on it, with all pages and attachments present. Record the verification date too.

Related resources

Sources

Finni resources

Ready for the next step?

Find ABA care near you