What is Business continuity plan, and what should an ABA practice owner know before applying it? A business continuity plan (BCP) documents how a practice will continue or safely pause critical functions during a disruption and restore them in a controlled order. An ABA owner should map clinical, staffing, facility, technology, privacy, payer, payroll, vendor, and communication dependencies; assign activation, stop, and recovery authority; and exercise the plan.
The CASP Organizational Guidelines public overview groups recommendations under business, clinical, and risk management; this article relies only on that overview.
Business continuity, emergency action, and disaster recovery differ
| Plan | Primary question | Typical scope |
|---|---|---|
| Business continuity plan | What continues, pauses, and recovers? | Care, people, facilities, vendors, finance, and communications |
| Emergency action plan | What do workers do in an emergency? | Reporting, evacuation or shelter, accountability, duties, and training |
| IT contingency or disaster recovery plan | How are systems and data restored? | Backups, alternatives, recovery sequence, and testing |
| Incident response plan | How is an incident handled? | Detection, containment, evidence, mitigation, notification, and lessons |
OSHA says 29 CFR 1910.38 applies when another OSHA standard requires an EAP. Plans are generally written and available; employers with 10 or fewer employees may communicate them orally. OSHA recommends EAPs for all employers. Verify federal or state-plan rules plus site-specific fire, building, licensing, and local requirements.
Build the plan from impact and risk analysis
A business impact analysis identifies critical functions and outage impacts; a hazard or risk assessment identifies causes and controls. Record each function's owner, systems, records, qualified staff, vendors, deadlines, dependencies, fallback, and safe-stop condition.
Use standard terms:
- Maximum tolerable downtime (MTD): total time a process can be disrupted before impacts become unacceptable.
- Recovery time objective (RTO): planned maximum time to restore a function or system within its process MTD.
- Recovery point objective (RPO): pre-disruption point to which data must be recovered; it expresses tolerated data loss.
- Minimum safe operating mode (practice-defined): reduced services allowed with available information, qualified staff, controls, and approvals.
Targets guide design rather than guarantee recovery. NIST SP 800-34 Rev. 1, updated in November 2010, is final federal information-system guidance covering impact analysis, recovery, exercises, and maintenance. Private practices may adapt it; it is not a general private-provider mandate unless a contract or other governing requirement incorporates it.
Minimum fields for an ABA continuity register
| Field | What to capture |
|---|---|
| Function and accountable owner | Role with activation and recovery authority |
| Safety and clinical gate | Required client information, qualified decision-maker, supervision, setting, and stop rule |
| Dependencies | People, facilities, systems, vendors, devices, connectivity, transportation, and data |
| Time and data targets | MTD, RTO, RPO, and deadline clocks |
| Fallback | Approved alternate process and stored materials |
| Privacy and security | Authorized role-based access, secure storage and transmission, device rules, audit trail, and incident routing |
| Communication | Audience, message owner, primary and backup channels, and timing |
| Recovery validation | Reconciliation, acceptance evidence, backlog owner, and return-to-normal approval |
Keep a secured, current, approved contact and escalation tree outside the affected system; test authorized access.
Clinical continuity has hard gates
Safe care remains the governing condition during an outage. Follow site emergency procedures and contact emergency services for an immediate threat. Before a session proceeds, confirm a safe setting; access to the client-specific safety, health, and communication/AAC information needed for care; staff qualified for assigned duties; and required clinical supervision.
Changes to clinical risk controls, dosage, goals, or treatment require an appropriately qualified clinician acting within scope, with client or authorized-representative involvement and applicable consent. Administrative tools may flag missing information or deadlines; they do not make clinical decisions.
Alternative locations, telehealth, substitute staff, changed service codes, or schedule shifts may trigger payer, authorization, enrollment, licensing, labor, consent, and contract rules. The BCP should identify verification sources, owners, and hold or stop decisions. These requirements remain in force during disruption.
HIPAA contingency planning has a defined scope
For a HIPAA covered entity or business associate, current 45 CFR 164.308(a)(7) requires policies and procedures for emergencies or other occurrences that damage systems containing electronic protected health information. Data backup, disaster recovery, and emergency-mode operation are required implementation specifications. Testing and revision procedures and applications-and-data criticality analysis are addressable specifications.
HHS explains that “addressable” does not mean optional. A regulated entity must assess whether the specification is reasonable and appropriate, implement it if so, or document why not and implement an equivalent alternative when that alternative is reasonable and appropriate.
This standard covers ePHI security contingency planning, not the practice's entire clinical, payroll, payer, facility, or family-communication continuity program. Separately map applicable state privacy, health-record, consumer-health, breach, payer, contract, labor, facility, insurance, and professional requirements.
During downtime, use approved forms and devices and protect records. Record the actual service time and actual entry or addendum time; preserve authorship, corrections, and the original audit trail; and reconcile each temporary record. Follow applicable documentation rules. Prohibit silent overwrite or any false representation of when care or documentation occurred.
A fictional outage walkthrough
At 7:35 a.m., a fictional multi-site practice loses its scheduling and clinical-record platform. The incident lead records BCP activation at 7:45, ten minutes after detection. Site leaders use an approved offline roster marked with its as-of time to verify each client's safety and communication information, staff, supervision, service, location, and downtime-documentation path.
Eight of 11 scheduled sessions meet every gate and proceed; three are postponed because current client-specific safety information cannot be verified. The practice reaches the designated contact for each affected visit by 8:25 (11/11). Staff record time in the approved backup tool. Billing places all eight potential charges on hold (8/8) until the authenticated downtime record, schedule, authorization, staff, code, units, and later system entry reconcile.
The platform returns at 2:10 p.m. Recovery remains open until operations account for all visits (11/11), reconcile all expected session records (8/8), validate access logs and platform integrity against defined acceptance checks, resolve payroll entries, and document all postponements (3/3). Platform availability is a technical milestone; controlled recovery ends when the required evidence is complete.
Test decisions and recovery evidence
Run tabletop exercises and technical recovery tests across sites, shifts, and scenarios with an unavailable leader. Test activation, safe-stop decisions, backup access, communication, privacy, clinical escalation, deadline preservation, recovery acceptance, and return-to-normal authority.
Useful measures include:
- activation latency: elapsed time from the defined detection event to the recorded activation decision.
- required communications completed by target / required communications, with completion defined as sent, delivered, acknowledged, or reached.
- affected critical functions restored and accepted by RTO / affected critical functions.
- successful test restores / attempted restores, plus reconciled records / expected records.
- applicable safety, payer, payroll, privacy, or regulatory deadlines met / applicable deadlines due in the scenario.
- unreconciled downtime records: count and oldest age.
- corrective actions closed by due date / corrective actions due.
For every duration, state the start and end events; for every proportion, state the numerator and denominator. Report the scenario, target, exclusions, owner, and time window, and use N/A rather than 0% when no item was eligible. Speed and completeness are separate: lost records or bypassed clinical gates fail acceptance even when time targets are met.
The Ready.gov Business Continuity Plan template offers a general structure that practices must adapt to healthcare, ABA, state, payer, and contract requirements.
Related terms
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview
- Ready.gov, Business Continuity Plan template
- National Institute of Standards and Technology, SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems
- Electronic Code of Federal Regulations, 45 CFR 164.308, Administrative Safeguards
- Occupational Safety and Health Administration, Emergency Preparedness and Response: Getting Started
- U.S. Department of Health and Human Services, Addressable and Required Implementation Specifications FAQ
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni