{"@context":"https://schema.org","@type":"Article","headline":"Incident management","description":"Learn how ABA incident management connects immediate safety, neutral facts, source-specific reporting clocks, investigation, corrective action, and closure.","url":"https://finnihealth.com/resources/glossary/incident-management","datePublished":"2026-08-14T00:00:00.000Z","dateModified":"2026-08-14T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Incident management","item":"https://finnihealth.com/resources/glossary/incident-management"}]}}
Glossary term

Incident management

Learn how ABA incident management connects immediate safety, neutral facts, source-specific reporting clocks, investigation, corrective action, and closure.

7
min read
Updated
August 13, 2026
Sources checked
August 13, 2026
ยท View sources
Also called

event management incident response

What is Incident management, and what should an ABA practice owner know before applying it? Incident management is an ABA practice's process for immediate safety, neutral fact preservation, source-specific classification and reporting, qualified investigation, corrective action, and verified closure. One event can activate separate clinical, emergency, safeguarding, privacy and security, workforce, facility, payer, insurance, and legal duties. An internal label does not decide them.

One event can activate several rule sets

Incidents can involve client or staff injury, a missing person, suspected abuse or neglect, a medication, health, or crisis event, vehicle, property, or facility harm, privacy or security, documentation or workplace conduct, or service interruption. One event can enter several categories.

The CASP Organizational Guidelines public overview describes best-practice organizational guidelines across risk, clinical, and business operations; details are sold separately. This workflow is Finni editorial design, not CASP licensed content or governing law.

Internal incident, HIPAA breach or security incident, OSHA recordable or reportable event, payer or licensing report, mandated report, and insurance claim each have their own definition, scope, clock, recipient, and proof. Client injury alone is not a federal OSHA severe-event report because that rule addresses employee outcomes.

Respond without delaying emergency care

  1. Protect life and safety. For danger or a medical emergency, call 911 or go to the nearest emergency room. Use 988 for crisis support, not as a substitute for 911. Give aid within role and keep AAC, mobility, and health supports available when safe.
  2. Stop ongoing exposure. Maintain supervision and isolate the hazard through trained, authorized methods. Do not improvise restrictive procedures; follow applicable law, authorization, training, and the approved plan. Safety outranks evidence.
  3. Route duties. Notify assigned leads and make any applicable report to the named authority. Internal routing does not replace an individual's mandated report or a required external notice.
  4. Start separate clocks. Record occurrence, discovery or receipt, each responsible person or agent's knowledge, source, deadline, recipient, and owner.
  5. Preserve evidence. Retain originals, versions, logs, devices, and attributed statements; record collection and access; restrict photographs and data; use approved forensic or legal-hold processes. Alter evidence only through authorized containment.

Care and required reports do not wait for a completed internal investigation.

Distinguish record purposes and confirm placement

RecordPurpose
Clinical recordCare provided, observed client condition, clinically relevant response, communication, and follow-up
Incident recordNeutral event facts, involved people, location, timeline, witnesses, immediate actions, routing, and evidence
Investigation and action recordSource-by-source classification, analysis, findings, corrective actions, owners, verification, and closure

Treat the table as a workflow map; governing sources control storage, access, retention, and linkage. Record observed condition, care, and clinically relevant response in the clinical record; distinguish observation from an attributed statement. Route unsubstantiated conclusions and HR, security, or legal material to assigned controls. Preserve originals; use dated corrections or addenda only.

The responsible ABA clinician decides ABA treatment within competence and consent requirements; licensed medical professionals and emergency responders decide medical or emergency care within their authority. Operations coordinates clocks and actions, not clinical care, privilege, abuse substantiation, or reportability outside its role. Internal review cannot pause a duty or clock. Counsel may advise on privilege; a label alone does not create it.

Build a source-specific classification matrix

For each potential authority, capture its trigger, covered person or entity, clock, recipient, required content and method, exceptions, reviewer, evidence, and completion proof. Check applicable professional, facility, safeguarding, payer, insurance, employment, privacy, vehicle, and local sources.

Federal OSHA separates severe-event reporting from routine recording. Under 29 CFR 1904.39, employers under federal jurisdiction report an employee fatality within eight hours and an in-patient hospitalization, amputation, or loss of an eye within 24 hours. The fatality must occur within 30 days of the work-related incident; the other reportable outcomes within 24 hours. If the employer or its agent learns later of the outcome or its work-relatedness, the clock runs from that knowledge. Emergency-room treatment alone is not in-patient hospitalization, though a case may still be recordable under separate rules. Verify the governing state plan.

For a HIPAA covered entity or business associate, 45 CFR 164.308(a)(6) requires response to suspected or known security incidents, practicable mitigation, and documented outcomes. A security incident does not by itself establish a breach-notification duty. Review the Breach Notification Rule, contracts, state law, and other duties separately.

HHS says an impermissible use or disclosure of protected health information is presumed a breach unless an exception or documented four-factor low-probability assessment applies; the entity may notify without assessing. A covered entity gives individual notice without unreasonable delay and no later than 60 days; gives media notice for more than 500 affected residents of a state or jurisdiction on that schedule; reports 500 or more to HHS on that schedule; and reports fewer than 500 to HHS within 60 days after calendar-year end. A business associate notifies the covered entity without unreasonable delay and no later than 60 days. The covered entity retains individual-notice responsibility unless delegated. These are outer limits; shorter duties may control.

Investigate systems and conditions, not just people

An internal investigation separates confirmed facts, attributed statements, analysis, and unknowns; it reviews controls, staffing and supervision, communication access, environment, health referrals, technology, policies, vendors, and prior events. It identifies contributing conditions, not medical causation, legal liability, breach status, employment findings, or abuse substantiation unless the assigned qualified authority decides them.

The BACB Ethics Code applies to BCBA and BCaBA certificants and applicants and addresses roles and competence, timeliness, confidentiality and disclosure, documentation, medical referral, and source-specific self-reporting. BACB has no jurisdiction over organizations or corporations; organization controls need separate owners and governing sources.

NIST SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, was published in April 2025. It is cybersecurity guidance, not a healthcare reporting rule or universal breach classification.

A fictional lost-device event

At 3:20 p.m., a fictional technician reports that an approved work tablet is missing after a community session. The lead records discovery, confirms client safety, locks the device through the approved process, preserves logs before and after that action, checks authorized location data, and alerts privacy and security owners. A remote lock is containment, not proof that information was secured or uncompromised.

The record separates facts from unknowns and does not label the event a HIPAA breach. Assigned reviewers determine whether the device held protected health information or electronic protected health information; encryption and its key met HHS guidance; impermissible acquisition, access, use, or disclosure occurred; information was acquired or viewed; mitigation changed risk; and any external duty applies.

Quarter example: 12 incidents are discovered; all 12 meet prespecified eligibility for documented triage within two hours after designated-channel receipt, following immediate response. Eleven meet the target: 11 of 12, or 91.7%. Four meet privacy or security routing criteria; all four are classified by the assigned reviewer within a separate target: 4 of 4, or 100%. Exclude nonprivacy events. Keep the late triage visible with its contributing condition, owner, action, and due date; apply a stated discovery-period rule to later-discovered events.

Track emergency action among events requiring it, triage, and each required notice with its own eligibility and clock. Also track overdue classification, action implementation, contact, and closure. Report count, eligible denominator, deadline basis, period, and exclusions. Closure documents completion, not prevention; falling counts may reflect safety or underreporting and do not establish causation.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni