If a school portal account may be compromised, use the school's official support route from a trusted device, preserve alerts and timestamps, and avoid links in unexpected messages. Reset credentials, end sessions, restore approved authentication, and review changed records and downloads with the school. Protect schoolwork, AAC, health, transport, and family communication access while privacy and security owners classify the event and determine required notices.

Confirm the official recovery channel

For Mateo, navigate through the school's published website or known support number rather than an alert link. Record the account, notification, time, device, browser, location shown, and unfamiliar activity. Do not share a password, recovery code, or full sensitive screenshot through an unverified channel.

Contain and restore access

Follow the school's steps to reset the password, revoke sessions, update recovery details, and restore multifactor authentication where offered. Ask whether connected apps or reused credentials need attention. Keep an accessible backup for assignments, communication, AAC, health instructions, and urgent school messages while the portal is unavailable.

Review actions taken through the account

Ask the school to examine login history, downloads, messages, profile changes, emergency contacts, forms, grades, attendance, health information, and other affected records within the supported audit window. Preserve original and corrected values. A successful login reset does not answer what happened before containment.

Test the restored account

Verify Mateo and authorized family users can sign in, use accessibility tools, see accurate records, send and receive a harmless test message, and recover access securely. Keep unexplained sessions, missing logs, record changes, and notification questions open with owners and due dates.

Prepare Mateo's privacy-incident review

Bring Mateo's school-portal account incident tracker, the school's current privacy and security contacts, annual FERPA notice, incident messages, minimal evidence, record and account categories, access needs, service-continuity concerns, and a short decision list. Also bring school and vendor responses, correction history, complaint questions, current deadlines, and requested outcomes. End with owners, dates, and a representative validation test.

Build Mateo's source-attributed incident record

Create a restricted school-portal account incident tracker for Mateo's account, user, alert, device, session, authentication, record change, download, containment, restoration, access support, notice, and validation. Give every field a source, version, holder, sender, recipient, time, authority, status, owner, next action, due date, correction, and closure evidence. Attribute student communication, family report, school statement, vendor notice, system evidence, clinical information, and legal conclusion separately.

Protect Mateo's safety, access, and dignity

Give Mateo and family participants understandable, accessible information, privacy, realistic update times, and a reliable way to ask questions, disagree, correct, accept, decline, pause, and request help. Keep AAC, interpreters, schoolwork, health and safety information, mobility, food, water, bathroom access, prescribed care, rest, and emergency help available during the response.

Ask eight incident-response questions for Mateo

Use these questions in the school-portal account incident tracker:

  • Which alert, event, record, account, device, product, holder, sender, recipient, and time apply?
  • What is known, unknown, disputed, contained, corrected, or still exposed?
  • Which FERPA, IDEA, HIPAA, state, school, contract, security, complaint, or other source governs the step?
  • Who may classify, contain, investigate, communicate, notify, correct, restore, and close each field?
  • Which immediate safety, identity, health, disability, bullying, financial, or access risk needs action?
  • What did Mateo communicate directly, and what did family, school, vendor, or a professional report separately?
  • Which evidence supports the exposure, containment, notice, correction, continuity, or recovery state?
  • Which representative test will show that the repaired path works?

Classify fields as complete, failed, pending, declined, disputed, false positive, suspected, confirmed, contained, superseded, or inapplicable with a reason.

A fictional school-data incident example for Mateo

Mateo is fictional. His portal shows unexpected password-reset notices, an unfamiliar session, and changed emergency-contact information. Reviewers freeze 35 account, session, record-change, containment, restoration, and validation fields and complete 24 of 35, or 68.6%, by the checkpoint. A missing event, record, holder, recipient, data, exposure, containment, account, communication, correction, continuity, or validation field remains in Mateo's denominator with an owner, age, and next action.

The school-portal account incident tracker measures evidence completion. Legal compliance, notification duty, security effectiveness, service quality, student understanding, harm, family experience, and recovery remain separate questions. Concurrent changes limit causal conclusions.

Use compatible incident denominators for Mateo

For Mateo's school-portal account incident tracker, report alerts triaged divided by alerts due; confirmed incidents contained divided by confirmed incidents due; affected accounts secured divided by accounts due; required communications completed divided by communications due; affected records corrected divided by records due; and recovery tests passed divided by tests attempted.

Publish raw counts with percentages and age every open item. Keep discovery, triage, classification, containment, evidence preservation, exposure analysis, notice review, communication, correction, continuity, complaint, and recovery as distinct measures.

Apply the federal privacy and security boundaries for Mateo

For Mateo, current 34 CFR Part 99 governs FERPA within its stated scope, and the Education Department's FERPA hub provides public guidance. The Department's data-security page explains that FERPA does not prescribe specific security controls, while security failures can create privacy risk. Its older breach checklist is general best-practice guidance, and current scenario trainings support planning exercises.

No cited federal source creates one universal family notification rule for every school data incident. Verify current state, district, vendor, contract, insurance, law-enforcement, record-holder, and student-specific duties.

Apply complaint, health, and professional boundaries for Mateo

A compromised portal may require both account containment and a records review. The current SPPO complaint page explains the federal complaint route and 180-day timeliness rule, while IdentityTheft.gov offers a recovery plan when the evidence supports identity theft. Classify exposed information using federal school health-record guidance and joint FERPA-HIPAA guidance. Preserve alternate AAC access during lockout. Apply the BACB Ethics Code and CASP overview only within their covered scopes.

Close Mateo's loop with an incident test

Ask Mateo and the relevant family participant to review the outcome through their usual language and communication methods. Test the repaired recipient list, account, device control, public-link permission, vendor path, family communication, record correction, complaint file, service-continuity route, or recovery evidence suited to the event. The defined review question for Mateo is school portal account compromised. Preserve every mismatch with an owner, due date, and next step.

Before closure, record what the school confirmed, what remains unknown, which source governed notice, which student access or service depended on the affected system, and how the response changed the source control. For Mateo's incident review, keep incident state, family communication, record correction, safety support, and technical recovery separate. Reopen the file after a failed test, new recipient, changed exposure window, recurring alert, or inaccurate notice. The tracked topic remains school portal account compromised.

Related resources

Sources

Finni resources

Ready for the next step?

Find ABA care near you