To revoke ABA authorization, identify the exact information-sharing form, person, recipient, purpose, date, and expiration event. Follow the provider's written revocation process and state whether you are ending the entire authorization or replacing selected terms. Ask when the change becomes effective, what action already occurred in reliance on the authorization, which systems and recipients will be updated, and how future disclosures will be handled.

Find the authorization you mean

Use the signed copy rather than a general request to “stop sharing.” Record the title, version, date, information covered, disclosing party, recipient, purpose, expiration, signer, and signer authority. Several active authorizations may exist for school coordination, another provider, billing support, research, media, or a family member.

The CASP public summary describes ABA treatment scope. It does not define authorization law or a provider's privacy workflow.

Use the written revocation route

For a HIPAA authorization under 45 CFR 164.508, an individual may revoke in writing, except to the extent the covered entity has already taken action in reliance on it and a limited insurance exception. The authorization must explain the right to revoke and how to do it.

Send the revocation through the provider's stated route. Keep the submission, delivery evidence, effective time, and provider acknowledgment. Ask whether another law, court order, payer rule, or permitted disclosure route affects the requested change.

Separate authorization from other permissions

Ending an information-sharing authorization does not automatically cancel treatment consent, a service agreement, portal access, an emergency contact, or every disclosure allowed or required through another legal pathway. Ask the privacy owner to list the exact future disclosures the revocation changes.

When a representative acts, verify current scope. HHS personal-representative guidance explains that authority generally comes from state or other applicable law and may cover only relevant PHI.

Protect client communication and clinical continuity

Explain the change to the client in an accessible form and record their questions or preferences. The BACB Ethics Code addresses consent, assent when applicable, confidentiality, stakeholder involvement, documentation, and continuity for covered professionals.

If the change affects care coordination, ask qualified team members to plan continuity within the remaining authority. Privacy staff decide disclosure routing; clinicians decide clinical recommendations within scope.

Close every affected destination

Keisha revokes an authorization that named two recipients and one shared portal folder. The provider confirms both recipients were removed from future distribution, but the folder permission remains active. Implementation is 2 of 3 affected routes complete. The request stays open until the folder is corrected and verified.

Build the authorization-revocation register

Use the authorization-revocation register to change or revoke an ABA information-sharing authorization with the right covered entity while preserving the effective scope, receipt, prior reliance, and remaining disclosure paths. Lock the person, request or event, document version, and review period before calculating any rate. Give each row a source, current state, owner, next action, due date, and closure artifact. Keep a family-facing summary linked to the restricted operational record without copying sensitive narrative into broadly visible queues.

Collect only the evidence needed for this decision: authorization copy; person or representative; issuing covered entity; information; discloser and recipient; purpose; expiration; requested change; written revocation; delivery route; receipt date and proof; actions already taken in reliance; downstream recipients; other legal permissions; confirmation; and unresolved disclosures. Label who created or issued each item, when it took effect, what it covers, and where the authoritative copy lives. A portal flag, call note, signed document, clinical record, legal instrument, vendor report, and audit log answer different questions. Preserve conflicts until the responsible role resolves them.

Follow a sequence that can be explained later. Read the existing authorization and identify the entity that may disclose, the recipient, information, purpose, and expiration. Write the requested revocation or narrower replacement, send it through the stated route, and obtain receipt. Ask what stops prospectively, what prior reliance remains, and whether another rule or permission still allows a specific disclosure. Keep the original record when a correction occurs and add the new state with its author, date, reason, and scope. Use approved systems and role-based access for health, identity, authority, and incident information.

Keep privacy, clinical, and family decisions distinct

Write the decision owner beside every open field. The individual or properly scoped personal representative may revoke the authorization. The covered entity receiving it determines implementation under the rule and its process. A recipient that already received information may have separate duties and systems. Operations may update records but cannot promise retroactive erasure or block a disclosure independently required by law. Administrative staff and software may collect evidence, calculate dates, flag conflicts, and route work. They should not invent authorization, personal-representative authority, clinical judgment, legal conclusions, breach status, or the person's preference.

Turn the record into a real choice. A family may revoke the whole authorization, replace it with a narrower one, shorten the period, remove recipients, or limit categories when a valid new form can express that scope. Ask whether refusal or revocation affects an optional service and whether any exception to conditioning applies. Explain confirmed facts, provisional facts, consequences, alternatives, and the next review in accessible language. Keep AAC, interpretation, disability access, and a private question route available. Record the person's own message separately from family, staff, and clinician interpretations.

Ask focused questions: Which authorization is changing? Which covered entity must receive the revocation? Is writing required? When does receipt occur? Which past actions relied on the authorization? Which other legal routes remain? Which systems and recipients need follow-up, and what evidence shows the change worked? Read back the answers, source, owner, and date. When the contact cannot answer, route the question to the privacy, security, legal, clinical, payer, vendor, or records role that actually controls it.

Use a release gate and an incident plan

The authorization-revocation register needs a release gate. Closure requires the correct authorization and person, verified authority, written revocation or replacement, covered-entity receipt, effective date, systems and recurring routes updated, affected owners notified, prior-reliance explanation, remaining lawful paths identified, and family confirmation. A cleared gate applies only to the named person, requester, recipient, information, purpose, system, and time period. Recheck fields that can change before recording, disclosure, portal access, communication, signature, service, or delivery occurs.

Prepare for realistic failure. Revocation fails when sent only to a third party, delivered to an unmonitored inbox, missing the authorization identity, treated as retroactive, left active in a portal or recurring export, or assumed to stop treatment, payment, operations, mandated reporting, or another permitted disclosure that did not depend on that authorization. Record the observed condition instead of guessing intent. Protect immediate health and safety, preserve evidence, contain the affected action, maintain applicable deadlines, and tell the family what remains available while review continues.

Give each high-impact authorization-revocation register failure a written fallback with the trigger, authorized decision-maker, immediate action, information needed, safe family contact, alternate route, and update time. Privacy or security review should continue alongside urgent clinical, medical, emergency, mandated-reporting, or protective action when those duties apply.

Work through a realistic complication

Rina revokes one authorization covering three recipients. The provider confirms receipt and stops two recurring disclosures. A third disclosure already occurred before receipt. Report two prospective routes stopped, one prior action preserved, and no claim that the recipient deleted information unless that recipient separately confirms it. State the numerator, denominator, unit, eligibility rule, time window, and status of every open or excluded item. A completion rate does not establish legal compliance, clinical quality, confidentiality, or lack of harm.

Add a later complication to the authorization-revocation register. New authority evidence, a corrected document, a changed recipient, a returned message, a vendor finding, a portal log, or the person's new preference may invalidate the earlier state. Link the new evidence to every downstream action that relied on the old record. Keep history visible so reviewers can see what was known at each point.

Verify implementation and close the loop

Recheck recipient lists, portal connections, automated exports, fax profiles, consent indexes, and disclosure logs after implementation. Preserve the old authorization, revocation, receipt, and effective date. Test one routine workflow to confirm the revoked route no longer sends information. Ask whether a downstream recipient needs a separate instruction, then document its response without implying that the original covered entity controls that recipient's copy. A sent form, portal status, password reset, staff promise, or signed document can be an intermediate artifact. Close the authorization-revocation register only when the expected real-world result, system state, and family-facing record agree.

Define authorization-revocation register measures before reporting them. Name start and end events for durations and every eligible item in a denominator. Report pending items by count and oldest age. Keep people, documents, authorizations, recipients, systems, messages, sessions, files, and incidents as separate units. Pair percentages with raw counts and material exceptions.

Finish the authorization-revocation register workflow with a narrow retrospective. Ask which fact was hardest to verify, which handoff or access control failed, whether the person and family could communicate and participate, and which control should change. Test the correction in the workflow where the miss occurred. The examples on this page support planning and questions; they do not determine another person's rights, clinical need, breach status, or legal outcome.

Related resources

Sources

Finni resources

Ready for the next step?

Find ABA care near you