ABA practice incident evidence preservation and chronology secure the original reports, clinical and operational records, messages, logs, images, devices, physical items, vendor artifacts, and later corrections connected to an event. The evidence index records provenance, custody, access, collection method, time basis, integrity, restrictions, gaps, and disposition. The chronology separates when something occurred, when it was observed, and when it entered the record.

Define the evidence and chronology boundary

Esme preserves the original before converting, summarizing, exporting, or annotating it. A working copy can support review while the source stays protected. She records system time zones, device clocks, delayed discovery, missing intervals, and every transformation. A late entry carries its actual entry time and reason. The evidence index and event chronology has a named owner, scope, current sources, qualified decision boundaries, version, role-limited access, evidence location, exception route, change triggers, and retention state.

Record provenance, times, integrity, custody, corrections, and gaps

The working record captures incident and evidence IDs, source, creator, custodian, format, original location, event time, observation time, received time, collection time, timezone, method, hash or integrity check when appropriate, export settings, chain of custody, access class, access log, related issue, working copy, annotation, correction, redaction authority, missing evidence, preservation notice, retention source, release, return or disposal, and reviewer. Each field supports protection, a decision, communication, measurement, or later trace. Narrative is used for context and uncertainty; structured states support queues, clocks, ownership, and reconciliation.

Preserve originals and show every correction

She builds the chronology from attributable facts and cites each source. Conflicting times stay visible until resolved. Clinical, privacy, HR, security, insurer, payer, and legal access remains role-limited. Counsel determines legal holds and privilege. The evidence file records operational preservation without promising either status.

Protect people while classification continues

Esme lets emergency, medical, crisis, protective, and immediate containment actions proceed under the applicable route. Routine approvals never delay urgent help. Temporary service or system controls stay scoped to the observed condition and retain access, communication, clinical, workforce, privacy, and continuity review.

Keep facts, hypotheses, decisions, and actions distinct

Esme labels each entry as a reported fact, direct observation, system result, hypothesis, qualified decision, assigned action, or later correction. Authorship and time remain visible. This structure allows a fast response while showing what remains uncertain.

Validate provenance, custody, chronology, and access

Esme traces sampled chronology entries back to originals, compares exports with native systems, checks access logs, tests retrieval, and confirms correction history. She includes missing video, overwritten logs, screenshots without context, changed device clocks, and vendor-held evidence.

Reconcile the incident across operating systems

Esme compares the incident record with clinical documentation, schedules, staffing, access, communications, facilities, vendors, billing, payer evidence, HR systems, privacy and security cases, insurance files, and corrective actions as authorized. Differences receive owners, effects, and resolution states.

Protect direct communication, access, and dissent

Esme gives affected people a direct, usable communication route whenever possible, keeps AAC and other supports available, allows time to respond, and records questions, corrections, refusal, pause, distress, or withdrawal. Confidentiality limits and required external routes are explained in accessible language.

Work through Esme's fictional example

Esme locks 26 evidence files. Nineteen have original source, provenance, event and record times, integrity, custody, access, chronology link, corrections, gaps, and disposition. One export omits a time zone, one screenshot lacks origin, two access logs are incomplete, one correction replaces the original, and two vendor files lack custody. Five files are repaired. Two remain incomplete. The scenario is synthetic. It tests scope, authority, access, evidence, clocks, response, and denominator logic without establishing clinical quality, legal compliance, reportability, coverage, causation, safety, satisfaction, or outcome.

Calculate the example measures

Initial evidence-file integrity is 19 of 26, or 73.1%. Twenty-four validate, or 92.3%. Incidents, evidence items, versions, chronology entries, users, gaps, corrections, and incomplete files keep separate counts.

Avoid authoritative chronologies built from unattributed material

A detailed chronology can look authoritative while depending on altered or unattributed material. Esme ties each entry to preserved evidence and shows uncertainty directly.

Test missing time zones, screenshots, logs, corrections, and custody

Esme tests late report, different time zones, EHR export, message thread, camera image, physical item, vendor log, missing video, overwritten record, corrected entry, restricted file, and disposal request. Each case states the event or signal, affected people and services, immediate protection, source, owner, evidence, communication, open route, decision, correction, validation result, and next review.

Close review with unresolved work visible

Esme confirms scope, sources, authority, access, evidence, safeguards, reporting routes, communications, decisions, recovery, corrections, and fresh validation. The incident evidence preservation and chronology stays draft until every named reviewer finishes. Open work retains its owner, age, effect, and next action.

Place evidence preservation within organizational guidance

Esme uses the CASP Organizational Guidelines public overview for high-level business, clinical-operations, and risk-management context. CASP sells the detailed guidelines. The page presents an editorial incident evidence preservation and chronology; the public overview does not prescribe this artifact, its fields, or its decision rights. The OIG General Compliance Program Guidance is voluntary and nonbinding. It supports reporting, investigation, correction, auditing, monitoring, and oversight concepts while actual duties come from the governing source.

Keep professional authority clear during response

The current BACB Ethics Code applies to BCBA and BCaBA certificants and people who completed an application for either credential. It addresses competence, client and stakeholder involvement, consent and assent when applicable, documentation, risk, delegation, evaluation, continuity, and reporting within scope. BACB has no separate jurisdiction over organizations or corporations. Esme therefore maps covered professional duties separately from entity, owner, payer, regulator, and software roles.

Separate workplace recording and urgent reports

OSHA's recordkeeping page distinguishes recording, reporting, and electronic submission. Its fatality and severe-injury page describes federal reporting routes and clocks for covered work-related events. Esme verifies event, employer, establishment, state-plan, and exception scope. Emergency response, clinical records, workers' compensation, insurance, licensing, and other reports keep their own routes.

Route privacy and security events through current sources

For HIPAA covered entities and business associates as applicable, current 45 CFR 164.308 includes security-incident procedures. HHS's Breach Notification Rule guidance explains the unsecured-PHI breach presumption, exceptions, low-probability assessment, and recipient-specific notice paths. Esme keeps alerts, security incidents, impermissible uses or disclosures, breaches, business-associate notices, and non-HIPAA events distinct.

Use cybersecurity guidance within its scope

NIST SP 800-61 Revision 3, finalized in April 2025, integrates cybersecurity incident response across the six Cybersecurity Framework 2.0 functions. It is general guidance and does not replace HIPAA, state law, contracts, payer duties, clinical authority, or emergency action. Esme adapts its preparation, detection, response, recovery, learning, and evidence concepts only where they fit the practice's systems and obligations.

Preserve usable communication throughout response

The DOJ effective-communication guidance addresses covered entities' communication with people who have communication disabilities, subject to the law's scope and standards. The ASHA AAC portal says AAC users should always have access to their communication tools or devices. Esme provides accessible intake, updates, interviews, safeguards, emergency messages, corrections, and recovery communication while keeping needed AAC available.

Related resources

Sources