ABA practice privacy and data breach requirements in Arkansas layer HIPAA with the state's Personal Information Protection Act. Arkansas personal information includes listed medical and biometric data, as well as identity and financial data. An owner notifies residents whose unencrypted covered information was or is reasonably believed to have been acquired, without unreasonable delay, unless an investigation finds no reasonable likelihood of harm. More than 1,000 affected individuals adds an Attorney General route, and breach determinations are retained for five years.

A practice can collect sensitive information before intake is complete

An Arkansas parent may upload an evaluation, explain a safety concern and share insurance information while still deciding whether the practice feels right. Those details can land in a website form, an inbox, a callback list and a referral spreadsheet before they reach the EHR. Owners who focus only on signed clients can miss the earliest and least structured part of the information journey.

Walk through a real inquiry from first contact to deletion. Identify the legal entity, reason for collection, people, system, copies, downloads and access-removal event. The HIPAA Privacy Rule helps covered entities govern PHI, while Arkansas law adds state-specific definitions and breach decisions that should be mapped to the same workflow.

Arkansas expressly includes medical information

The official Arkansas Personal Information Protection Act defines personal information to include a person's name paired with unprotected Social Security, driver's-license or Arkansas identification, financial-access or medical information. Medical information means individually identifiable electronic or physical information about medical history, treatment or diagnosis by a healthcare professional.

That makes the state list especially relevant to ABA records. A diagnostic report or treatment detail can enter both Arkansas and HIPAA analyses, though the legal definitions and triggers remain separate. Describe the actual fields and context instead of writing “PHI” across a spreadsheet and assuming every authority asks the same question.

Biometric authentication adds another state-law path

Arkansas Act 1030 of 2019 added biometric data used to uniquely authenticate a person, including fingerprints, faceprints, retina or iris scans, hand geometry, voiceprint analysis, DNA and other qualifying biological characteristics. A fingerprint time clock or face-based login may therefore matter even when it belongs to the workforce rather than a client chart.

Inventory biometric systems, templates, backups, vendors, deletion controls and the people represented. Ask whether the technology stores an image, a transformed template or another identifier, but do not assume the label alone decides the statute. Qualified technical and legal reviewers need the implementation facts.

Unauthorized acquisition is the central breach fact

Arkansas generally defines a breach as unauthorized acquisition of computerized data that compromises the security, confidentiality or integrity of personal information. A good-faith employee or agent acquisition for the business's legitimate purpose is excluded when the information is not otherwise used or subjected to further unauthorized disclosure.

Preserve sign-ins, exports, mail routing, device state, file history and relevant interviews. A suspicious login can be serious without proving acquisition. An employee opening the wrong record and promptly reporting it is not the same as retaining a copy for a new employer. Keep the investigation factual enough to support either conclusion.

Owners notify when covered data was or likely was acquired

An owner or licensee discloses the breach to an Arkansas resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Notice is made in the most expedient time and manner possible and without unreasonable delay, while allowing law-enforcement needs and necessary scope and integrity work.

The statute does not provide a universal numbered resident deadline. Set internal milestones for evidence preservation, data mapping, resident matching, harm analysis, drafting and approval. If timing shifts, record the specific unresolved fact or restoration step. A chronology should show steady work, not a response parked until the next leadership meeting.

The harm determination can change whether notice is required

Notification is not required when a reasonable investigation supports a determination that there is no reasonable likelihood of harm to customers. This is a legal and factual conclusion, not a shortcut for calling an incident “low risk.” Medical, identity, financial and biometric information can create different kinds of harm.

Document who may have acquired the information, what they could read, whether it was used or shared, protections, mitigation, affected people and contrary evidence. Keep HIPAA's four-factor assessment distinct. A no-notice result should be reviewable later by someone who did not attend the original calls.

A custodian's owner notice is immediate

A person or business maintaining computerized personal information it does not own tells the owner or licensee immediately after discovery when the information was, or is reasonably believed to have been, acquired by an unauthorized person. A billing company, cloud service or practice-management contractor should not wait for a final forensic narrative before making the first handoff.

Use contracts and runbooks to name a monitored address, after-hours escalation, evidence-preservation duty and minimum early facts. The first report can distinguish confirmed information from open questions. Follow-up cadence matters because the owner may have resident, Attorney General, HIPAA, payer and insurer decisions moving on different clocks.

More than 1,000 affected individuals adds Attorney General notice

When a breach affects the personal information of more than 1,000 individuals, Arkansas adds Attorney General disclosure. Current statutory language ties timing to the same time the breach is disclosed to an affected individual or within 45 days after the business determines a reasonable likelihood of harm, whichever occurs first. The threshold is more than 1,000, not 1,000 exactly.

Prepare the state communication while the affected count is still being reconciled if the event may cross the line. Record the count method, first individual disclosure and harm-determination date. Ask qualified counsel to confirm who makes the filing in an owner-and-maintainer arrangement, because the current subsection's cross-reference deserves careful application to the actual roles.

The determination file stays for five years

Arkansas requires a copy of the written breach determination and supporting documentation to be retained for five years from the determination date. If the Attorney General requests it in writing, the business supplies the determination and support no later than 30 days after receiving the request. The retained material is confidential and not subject to public disclosure under the provision.

Preserve scope, evidence, field and resident maps, encryption, harm reasoning, legal analyses, communications and approvals. Include limits and contrary facts rather than polishing uncertainty away. Store the record where a future privacy leader can retrieve it even if the incident platform, outside counsel or security vendor changes.

Substitute notice requires all three channels

Arkansas allows substitute notice when ordinary notice would cost more than $250,000, the affected class exceeds 500,000 people or contact information is insufficient. The route calls for email where addresses exist, conspicuous website posting and statewide media. It is a specific alternative, not permission to use whichever channel is easiest.

Keep evidence supporting the threshold or contact problem and proof that each component occurred. Plan for accessible and translated communication when appropriate. A call guide and staffed response path can make a legally correct notice far more useful to families who are worried about clinical or identity information.

HIPAA's assessment is related but not interchangeable

The HIPAA Breach Notification Rule treats an impermissible use or disclosure of unsecured PHI as a presumed breach unless an exception applies or a documented four-factor assessment supports a low probability of compromise. Arkansas looks at unauthorized acquisition of its defined information and permits a no-notice determination based on no reasonable likelihood of harm.

Use shared logs and interviews, then write separate analyses. A printed clinical page, a lost encrypted laptop and an employee time-clock template could implicate different definitions. Neither “HIPAA compliant” nor “state breach” is an all-purpose label for every system or legal entity.

Reasonable security and destruction are ongoing duties

The Arkansas act requires reasonable security procedures and practices appropriate to the information for a business that acquires, owns or licenses personal information about a resident. It also requires reasonable destruction of customer records no longer retained by shredding, erasing or otherwise making the information unreadable or undecipherable.

Start with high-risk reality: former-worker access, shared accounts, personal downloads, remote devices, email forwarding, backups and vendor exports. The HHS risk-analysis guidance helps structure ePHI work, while Arkansas medical and biometric fields should also appear in the broader inventory. Verify destruction only after all applicable retention and hold rules are mapped.

ABA vendor relationships need more than a BAA checkbox

The HHS business-associate guidance explains when HIPAA business-associate duties apply. A BAA is important where required, but it does not itself prove that access is limited, logs are useful, deletion works or Arkansas incident handoffs will arrive on time.

Review the data and workflow for every important vendor. Test role permissions, offboarding, export controls, subcontractors, restoration and incident escalation. Put state notification cooperation beside HIPAA terms rather than assuming one paragraph covers both. Small practices benefit from choosing a manageable vendor stack whose controls they can actually understand.

Medicaid retention follows service and audit reality

Arkansas Medicaid's current provider-manual directory supplies the general and ABA-specific materials that apply to enrolled providers. General Medicaid guidance commonly requires records for five years from the ending date of service or longer while audit questions, appeals, investigations or court matters remain unresolved. The ABA manual clarification also shows why owners must watch current guidance rather than rely on an old downloaded manual.

Build a claim-to-chart trail with referral or prescription, assessment, treatment plan, rendering person, date, start and stop time where required, service detail, units, supervision and claim. Preserve the source version and service date used. A five-year Medicaid floor should not be converted into an automatic deletion instruction for every clinical, employment or corporate record.

A fictional lost tablet shows the decision points

Riverstone Behavior Clinic is fictional. A supervisor leaves a tablet in a restaurant after a home visit. Device management shows encryption and a remote lock, but the session may have remained open to a screen containing names, diagnoses, goals and caregiver contact details. A separate authentication app on the tablet used face recognition.

The practice protects upcoming sessions, preserves device and application logs and maps exactly what could be seen. Reviewers examine acquisition, Arkansas medical and biometric data, HIPAA, Medicaid, payer, insurer and vendor duties. They do not declare “encrypted, no breach” until they understand the open session and key control.

Families remember how the practice handled uncertainty

The BACB Ethics Code supports confidentiality and record stewardship, while owners remain responsible for giving staff a workable reporting path. Ask what happened, when, where and what the person did next. Thanking someone for reporting a lost device promptly can coexist with disciplined evidence preservation.

If notification is needed, tell the story in calm, direct language. Explain confirmed information, response actions, practical next steps and where a person will answer questions. Avoid blame and promises about fraud, credit, reimbursement or legal outcomes. An honest sentence about what remains unknown is often more reassuring than vague certainty.

Related resources

Sources