When you discover wrong ABA portal access, contact the provider's privacy or security route promptly, identify the account and records involved, and ask for immediate containment. Preserve screenshots, dates, alerts, and messages without forwarding protected records. Change your own credentials when advised and avoid shared passwords. Ask the provider to investigate scope, classify the event, protect ongoing communication, and give written closure evidence.

Contain access and preserve facts

Record how the problem appeared, the account name, approximate first and last access, records visible, downloads or messages observed, device, and provider contacts. Capture enough evidence to explain the issue while limiting further copies. Use the provider's urgent privacy or security route rather than a routine clinical message.

If another person's records appear in your account, stop viewing once you recognize the error. Avoid saving, printing, or sharing them except as the provider's secure incident process directs.

Secure the account

Follow the provider's instructions to reset credentials, sign out other sessions, review multi-factor authentication, remove unknown devices, update recovery methods, and check delegated users. Preserve access to necessary communication through a verified backup route while the portal is held or corrected.

For HIPAA regulated entities, 45 CFR 164.308 includes security-management, access, and security-incident procedures. The provider determines its incident response within the applicable rule and facts.

Ask for incident scope and classification

Request the affected account, people, record types, access window, actions taken, remaining risk, and owner. A portal error can be a security incident without automatically being a reportable breach. HHS breach guidance explains the rule for breaches of unsecured PHI, its exceptions, and the low-probability assessment path.

State, payer, licensing, contract, and insurance rules can add duties. The provider should classify the event under every applicable source.

Protect clinical and family continuity

Ask how appointments, care questions, invoices, forms, and urgent notices will reach the intended person during remediation. The BACB Ethics Code addresses confidentiality, documentation, continuity, and professional responsibilities for covered people. Clinical staff can maintain care communication while privacy and security owners handle the incident.

The CASP public summary concerns ABA treatment and does not replace incident law or technical investigation.

Verify closure

Ravi's incident checklist has six items: access disabled, password reset, unknown device removed, record scope confirmed, backup messaging established, and written closure received. Five are complete; the scope report remains pending. Closure is 5 of 6 controls. He keeps the incident open until the final evidence arrives.

Build the wrong-portal-access incident record

Use the wrong-portal-access incident record to contain unauthorized ABA portal access quickly, preserve evidence, protect care continuity, and route privacy, security, and breach decisions to the responsible organization. Lock the person, request or event, document version, and review period before calculating any rate. Give each row a source, current state, owner, next action, due date, and closure artifact. Keep a family-facing summary linked to the restricted operational record without copying sensitive narrative into broadly visible queues.

Collect only the evidence needed for this decision: reporter; discovered time; affected account and person; unauthorized identity; access method; active sessions; recovery contacts; information exposed; actions viewed, downloaded, changed, or sent; audit logs; containment; credential reset; corrected authority; safety impact; privacy and security owners; breach assessment; notices; and family support. Label who created or issued each item, when it took effect, what it covers, and where the authoritative copy lives. A portal flag, call note, signed document, clinical record, legal instrument, vendor report, and audit log answer different questions. Preserve conflicts until the responsible role resolves them.

Follow a sequence that can be explained later. Report the access through the provider's urgent privacy or security route. Ask the provider to disable the wrong access, protect the correct user's recovery route, preserve logs, and prevent further disclosure without destroying evidence. Verify clinical and scheduling integrity, then let qualified privacy and security owners classify the incident and any notification duties. Keep the original record when a correction occurs and add the new state with its author, date, reason, and scope. Use approved systems and role-based access for health, identity, authority, and incident information.

Keep privacy, clinical, and family decisions distinct

Write the decision owner beside every open field. The family reports facts and immediate safety concerns. The covered entity or business associate investigates within its duties. Privacy and security leaders determine impermissible access, risk assessment, and breach response; legal and state-law owners assess additional rules. A family member should not be asked to negotiate directly with the unauthorized user. Administrative staff and software may collect evidence, calculate dates, flag conflicts, and route work. They should not invent authorization, personal-representative authority, clinical judgment, legal conclusions, breach status, or the person's preference.

Turn the record into a real choice. Ask which information and functions were accessible, whether anything changed, how the correct account will be restored, and when updates will arrive. Request a safe channel for sensitive details. Avoid deleting messages, screenshots, or devices that may help the investigation unless the response lead directs otherwise. Explain confirmed facts, provisional facts, consequences, alternatives, and the next review in accessible language. Keep AAC, interpretation, disability access, and a private question route available. Record the person's own message separately from family, staff, and clinician interpretations.

Ask focused questions: Who has access and how was it discovered? Is access active now? Which sessions and recovery routes exist? What information or functions were exposed? Were records changed? Who owns privacy, security, clinical integrity, and notices? What evidence shows containment across every session? Read back the answers, source, owner, and date. When the contact cannot answer, route the question to the privacy, security, legal, clinical, payer, vendor, or records role that actually controls it.

Use a release gate and an incident plan

The wrong-portal-access incident record needs a release gate. Containment needs wrong access disabled, active sessions and tokens addressed, recovery ownership verified, evidence preserved, information and actions scoped, clinical and scheduling integrity checked, privacy and security cases opened, family contact established, and each notification clock assigned without waiting for perfect certainty. A cleared gate applies only to the named person, requester, recipient, information, purpose, system, and time period. Recheck fields that can change before recording, disclosure, portal access, communication, signature, service, or delivery occurs.

Prepare for realistic failure. Risk increases when staff merely change a password, leave sessions active, reuse compromised recovery email, erase logs, contact the wrong person through the exposed portal, assume no download means no access, delay clinical corrections, or tell the family that every unauthorized view automatically is or is not a reportable breach. Record the observed condition instead of guessing intent. Protect immediate health and safety, preserve evidence, contain the affected action, maintain applicable deadlines, and tell the family what remains available while review continues.

Give each high-impact wrong-portal-access incident record failure a written fallback with the trigger, authorized decision-maker, immediate action, information needed, safe family contact, alternate route, and update time. Privacy or security review should continue alongside urgent clinical, medical, emergency, mandated-reporting, or protective action when those duties apply.

Work through a realistic complication

Evan reports a former caregiver can still enter the portal. The provider disables the role, revokes three active sessions, preserves logs, and restores Evan's mother's account. Logs show two pages viewed and no changes. Technical containment is complete, while privacy classification and notice remain open decisions. State the numerator, denominator, unit, eligibility rule, time window, and status of every open or excluded item. A completion rate does not establish legal compliance, clinical quality, confidentiality, or lack of harm.

Add a later complication to the wrong-portal-access incident record. New authority evidence, a corrected document, a changed recipient, a returned message, a vendor finding, a portal log, or the person's new preference may invalidate the earlier state. Link the new evidence to every downstream action that relied on the old record. Keep history visible so reviewers can see what was known at each point.

Verify implementation and close the loop

Reconcile account roles, audit logs, messages, record views, downloads, appointments, forms, billing, and recovery contacts. Apply corrective action to the source of stale access, test removal across web and mobile sessions, and provide the family a final explanation permitted by the investigation. Monitor for renewed login attempts and confirm that alerts go to a verified safe contact rather than the compromised route. A sent form, portal status, password reset, staff promise, or signed document can be an intermediate artifact. Close the wrong-portal-access incident record only when the expected real-world result, system state, and family-facing record agree.

Define wrong-portal-access incident record measures before reporting them. Name start and end events for durations and every eligible item in a denominator. Report pending items by count and oldest age. Keep people, documents, authorizations, recipients, systems, messages, sessions, files, and incidents as separate units. Pair percentages with raw counts and material exceptions.

Finish the wrong-portal-access incident record workflow with a narrow retrospective. Ask which fact was hardest to verify, which handoff or access control failed, whether the person and family could communicate and participate, and which control should change. Test the correction in the workflow where the miss occurred. The examples on this page support planning and questions; they do not determine another person's rights, clinical need, breach status, or legal outcome.

Related resources

Sources

Finni resources

Ready for the next step?

Find ABA care near you