{"@context":"https://schema.org","@type":"Article","headline":"Confidentiality","description":"Learn how ethical confidentiality differs from HIPAA, when information may be shared, and how ABA practices protect conversations, records, access, and rights.","url":"https://finnihealth.com/resources/glossary/confidentiality","datePublished":"2026-08-14T00:00:00.000Z","dateModified":"2026-08-14T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Confidentiality","item":"https://finnihealth.com/resources/glossary/confidentiality"}]}}
Glossary term

Confidentiality

Learn how ethical confidentiality differs from HIPAA, when information may be shared, and how ABA practices protect conversations, records, access, and rights.

5
min read
Updated
August 13, 2026
Sources checked
August 13, 2026
· View sources
Also called

client confidentiality clinical confidentiality duty of confidentiality

What does Confidentiality mean for a family's rights and ethical care? Confidentiality is the duty to protect information learned through care and use or disclose it only through an authorized or permitted route. Families should know what information is collected, who can access it, why it may be shared, and how to raise a concern. Ethical confidentiality, HIPAA, state law, contracts, consent, and professional rules can overlap without being identical.

Ethical confidentiality and HIPAA differ

The BACB ethics page identifies the current Ethics Code for Behavior Analysts. The direct Code applies to BCBA and BCaBA certificants and applicants and addresses confidentiality across professional activities.

HIPAA is a federal legal framework with defined entities, information, rights, and disclosure rules. A practice may have ethical and contractual confidentiality duties even when HIPAA does not apply. Other state health, disability, education, minor, consumer-health, employment, and professional laws may add rules.

Determine whether HIPAA applies

The HHS Privacy Rule page says the rule applies to health plans, clearinghouses, and healthcare providers that conduct certain transactions electronically. It protects defined protected health information, requires safeguards, limits uses and disclosures, and gives individuals rights over their PHI.

Classify the entity and activity rather than treating every clinic as automatically covered. Business associates have specified duties for PHI handled on behalf of covered entities. A mixed organization may need to map distinct roles and data.

Authorization is one disclosure route

Some disclosures require a valid HIPAA authorization when HIPAA applies. Treatment consent, service agreement, Notice of Privacy Practices acknowledgment, and authorization are different records. Check who may sign, what information and recipient it covers, purpose, expiration, revocation, and any required statements.

HIPAA also permits some uses and disclosures without authorization. The HHS treatment, payment, and operations guidance explains those routes and their limits. Other laws or contracts may be more protective.

Family involvement has a defined boundary

A family member, caregiver, emergency contact, involved person, and legal personal representative can have different authority. Do not infer decision or record-access rights from a relationship label.

HHS’s family-involvement FAQ describes a HIPAA pathway for sharing information directly relevant to an involved person’s role when its conditions are met. When the capable person is present, agreement, an opportunity to object, or reasonably inferred non-objection can matter. In absence or incapacity, professional judgment and best interests may apply. This route does not create personal-representative authority.

Give each role the access it needs

Define which workforce roles need which records for their work. Separate clinical care, scheduling, billing, supervision, quality, legal, and employment access. Review permissions when a person changes roles or leaves.

HHS explains that minimum-necessary limits generally apply to payment and healthcare-operations requests and disclosures, while provider-to-provider treatment disclosures and requests have a specific exception. That exception does not justify unrestricted internal access.

A fictional coordination example

Fictional client Omar asks an ABA clinic to coordinate one transition routine with a school and SLP. Omar authorizes sharing the current routine, communication supports, and progress summary with named recipients for six months. Detailed family history and unrelated session notes remain outside the authorization.

The clinic audits eight coordination events. Six use the approved recipient, current scope, secure route, and disclosure log: 6 of 8, or 75%. One uses an expired authorization; one attaches an unrelated note. Both become privacy incidents for review rather than exclusions.

After role training and an attachment check, 9 of 10 later events meet every condition. The percentage measures process compliance, not proof that every disclosure was lawful or clinically appropriate.

Protect conversations and telehealth

Confirm the person’s preferred and confidential contact method. Ask who is present before discussing care, especially during home telehealth. Use headphones, private spaces, approved platforms, and accessible alternatives where appropriate.

Avoid clinical discussion in hallways, shared rides, public messaging, or broad group chats. A person’s presence in a waiting room or program should not become casual information for others.

Protect records throughout their life

Collect information for a defined purpose, store it in approved systems, limit exports, encrypt where required or appropriate, maintain audit trails, and follow retention and secure-disposal rules. Keep paper downtime records and personal devices within policy.

Record amendments rather than silently overwriting history. Give individuals the applicable access, correction, restriction, confidential-communication, and complaint processes.

Respond to a confidentiality incident

Stop ongoing exposure when safe, preserve evidence, notify the privacy or incident owner, document what happened, and continue required care. Classify the event under every applicable ethical, privacy, breach, state, payer, licensing, insurer, and contract rule.

Avoid promising that every incident is a HIPAA breach. HIPAA breach analysis has defined scope, exceptions, and assessment rules, while other duties may use different definitions and clocks.

Families can ask practical questions

Ask who can see records, how family access is verified, which apps or vendors handle information, whether sessions are recorded, how remote care is protected, what is shared with payers, and how to request access or report a concern.

Clear answers should name the responsible privacy role and complaint route. Retaliation for a good-faith privacy concern undermines ethical care and may violate applicable rules.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Find ABA care near you