ABA practice privacy and data breach requirements in Delaware combine HIPAA with Delaware's computer-security-breach law, consumer-privacy act, payer terms and professional duties. Delaware's breach definition expressly includes medical, health-insurance, biometric and online-account data. Required resident notice generally goes without unreasonable delay and no later than 60 days after the breach determination; more than 500 Delaware residents also triggers Attorney General notice, and a Social Security number breach generally adds one year of free credit monitoring.
Privacy starts while a family is still deciding
A Delaware parent may share a diagnosis, school concern, insurance card and family schedule while asking whether a practice can help. Before a first appointment exists, those details may be in voicemail, email, an intake form, a calendar and a referral spreadsheet. The privacy program begins with that conversation, not with a completed chart.
Trace the information through the real business. Record why it is collected, the fields, legal entity, user, system, export, vendor and intended deletion point. The HIPAA Privacy Rule applies to covered entities and PHI, while Delaware's breach law expressly reaches several medical and consumer data types. A field-level map lets the team see where those layers overlap and where they do not.
Delaware's personal-information definition is unusually broad
Delaware Code Title 6 Chapter 12B covers a person's name combined with an unencrypted Social Security number, government identification, qualifying financial information, passport number, online-account credentials, medical history, treatment or diagnosis, DNA profile, health-insurance identifier, biometric data or individual taxpayer-identification number. Some online-credential provisions work differently from the name-pairing structure.
For an ABA practice, a clinical export can therefore be relevant to both HIPAA and Delaware's state breach law. Do not assume encrypted information is automatically outside the analysis without checking whether the key or credential was affected. Map the exact fields, format and protections. A diagnosis label, insurance identifier and portal password may create distinct notice questions even when they traveled in the same file.
Reasonable security is itself part of the Delaware statute
Chapter 12B requires a person conducting business in Delaware that owns, licenses or maintains covered personal information to implement and maintain reasonable procedures and practices to prevent unauthorized acquisition, use, modification, disclosure or destruction. The requirement is not limited to the day after an incident.
Translate “reasonable” into the practice's actual risk and size with qualified advisers. Access reviews, multifactor authentication, device protection, tested backups, patching, workforce changes, vendor oversight and a usable incident route can all contribute. The HHS risk-analysis guidance offers structure for ePHI, but a Delaware review also needs online credentials, biometrics, workforce tax data and other state-covered information outside the clinical system.
A security event and a legal breach are different decisions
Delaware generally defines a breach as unauthorized acquisition of computerized data that compromises the security, confidentiality or integrity of covered personal information. Encrypted information is treated differently unless the encryption key is also compromised. A suspicious login, lost device or permission error should trigger investigation, but the first alert does not settle every statutory element.
Preserve identity logs, file activity, device and encryption state, key access, message forwarding, exports and the exact information involved. Record what an unauthorized person could acquire and what remains unknown. Qualified reviewers can then analyze Delaware law and the HIPAA team can perform its federal assessment. Shared evidence is efficient; shared conclusions are risky when the two legal tests differ.
The harm inquiry should be documented before notice is declined
Delaware does not require resident notice when, after an appropriate investigation, the business reasonably determines that the breach is unlikely to result in harm to affected residents. That exception is not satisfied by silence, a vendor's unsupported reassurance or a one-line “low risk” label.
Build a decision record describing the person or account, data sensitivity, acquisition evidence, encryption, duration, likely purpose, copying, use, mitigation and uncertainty. Identify the decision-makers and supporting evidence. Keep the state harm analysis separate from the HIPAA breach risk assessment. Similar facts can inform both, but each conclusion should show the standard actually applied and the duties that follow.
Delaware's notice clock starts after determination
When required, Delaware resident notice goes without unreasonable delay and generally no later than 60 days after the determination of a security breach. A shorter federal deadline, a law-enforcement request or circumstances in which the business could not identify affected residents within 60 days may alter the path. The outer limit is not a routine waiting period.
Track discovery, investigation, breach determination, population identification, drafting and approval as separate dates. Work on containment and communication in parallel. The HIPAA Breach Notification Rule has its own discovery rules, deadlines and recipients, so a HIPAA-covered practice needs both clocks. Counsel should resolve any timing conflict rather than choosing whichever date feels more convenient.
More than 500 Delaware residents adds Attorney General notice
When more than 500 Delaware residents are affected, the business must notify the Delaware Attorney General no later than the time resident notice is provided. The team needs a reliable Delaware population count and a coordinated package. Sending resident letters first and treating the state filing as later housekeeping can miss the statutory relationship.
For a multistate incident, maintain a jurisdiction matrix with population, method, regulator, consumer-reporting-agency rules, timing and transmission evidence. Other states use different thresholds or require regulator notice for every event. Reconcile the final resident file against each rule immediately before release, and preserve the version that supported the decision.
Social Security number incidents add a protective service
When a Delaware breach includes Social Security numbers, the statute generally calls for credit-monitoring services at no cost to affected residents for one year unless the business reasonably determines that the breach is unlikely to result in harm. That obligation requires vendor, enrollment, communication and support planning, not just a sentence inserted at the end of a letter.
Confirm the precise population and information involved, the service terms, activation steps and accessible support channel. Do not imply that credit monitoring solves every risk, particularly when medical, insurance or online credentials were also exposed. Explain which protective steps relate to which data. Counsel should review the harm exception and service package before the practice makes promises to families.
Online-account credentials need a different notice route
Delaware includes usernames or email addresses paired with passwords or security questions and answers that permit account access. If the breached account is an email account, the practice cannot rely only on sending notice to that same compromised email address. The statute provides an online or other direct communication path that directs the person to protect the account.
Treat credential response as an operational problem as well as a notice problem. Revoke sessions, reset access, review forwarding rules, preserve logs and help the person secure connected accounts. A portal credential may expose scheduling or messages without exposing the full chart, while a compromised email account can become a path into several systems. Map the actual access rather than assuming all credentials create the same risk.
Substitute notice has Delaware-specific channels
Delaware allows substitute notice when direct notice would cost more than $75,000, the affected class exceeds 100,000 residents or sufficient contact information is unavailable. The route includes email when addresses exist, conspicuous website posting, statewide media including radio and television and major social-media platforms. It is a public, multi-channel response rather than a quiet web notice.
Retain the cost, population and contact-quality facts that justify the method. Consider whether direct notice remains possible for a known subset. Draft in accessible language, prepare a staffed contact route and coordinate consistent information across channels. Qualified counsel should verify the precise statutory combination and timing, especially when the incident also involves compromised email credentials.
Vendors must notify and cooperate immediately
A person maintaining covered information on behalf of an owner or licensee must notify and cooperate with that owner immediately following determination of a security breach. Cooperation includes sharing information needed for resident notice. ABA practices often rely on billing, scheduling, recruiting, payroll, messaging and cloud vendors, so this relationship should be designed before an incident occurs.
Contracts should identify the decision point, monitored incident contact, after-hours escalation, evidence preservation, required facts and update cadence. Ask for systems, dates, fields, residents, acquisition evidence, containment and unknowns. The HHS business-associate guidance helps determine separate HIPAA duties. State owner-maintainer roles and federal covered-entity or business-associate roles both need clear accountability.
HIPAA compliance is a conditional pathway, not a blanket exemption
Delaware treats an entity regulated by HIPAA as compliant with Chapter 12B when it maintains breach procedures under the HIPAA rules, follows them and provides notice to Delaware residents in accordance with the federal framework. That pathway depends on the entity, procedures, conduct and resident notice. It should not be shortened to “HIPAA entities are exempt.”
Map each legal entity and data flow. A clinical provider, management company, recruiting affiliate, website operator or vendor may have different status even under common branding. Counsel should verify who can rely on the pathway and which Delaware-specific provisions remain relevant. The safest operating model is a response process that can produce the evidence, population and communication each applicable rule requires.
The Delaware Personal Data Privacy Act needs a separate scope review
The Delaware Personal Data Privacy Act generally applies to a controller doing business in Delaware or targeting residents that processes at least 35,000 consumers' personal data, excluding data used solely for payment transactions, or at least 10,000 consumers while deriving more than 20% of gross revenue from personal-data sales. It includes consumer rights, minimization, security, processor-contract and sensitive-data consent duties.
Its health-related exclusions are largely data-level, including PHI and certain information processed under health, research and quality pathways. Do not assume the whole legal entity is exempt merely because it is a HIPAA covered entity. Analyze website analytics, recruiting, employee, lead and management-company data separately. Nonprofits generally can be in scope, subject to specific exceptions, and current universal opt-out requirements can affect consumer-facing systems.
Medicaid retention needs a source, not a borrowed number
The current Delaware Medical Assistance Program General Policy Manual and provider portal describe provider participation, documentation and program administration. The general manual does not provide a single universal record-retention duration that an ABA owner should copy into every situation. Provider type, service, managed-care contract, audit and other law may supply the controlling period.
Build the schedule from current sources and contracts. Preserve authorization, assessment, plan, rendering professional, supervision, session detail, units and claim in an intelligible chain. Keep records longer for audits, appeals, investigations, overpayment matters, professional duties and legal holds. A cautious policy says who verifies the applicable duration and where it is recorded instead of inventing certainty that the source does not provide.
A fictional vendor export shows how the rules converge
First State Behavior Collaborative is fictional. Its billing vendor discovers that a support contractor exported a portal file to troubleshoot a failed claim batch. The file includes Delaware names, diagnoses, health-plan identifiers, Social Security numbers for a small employee subset and portal usernames. Logs show access, but copying and later use remain uncertain.
The vendor and practice preserve evidence, close access and protect billing continuity. Reviewers map residents and fields, investigate acquisition and harm, separate HIPAA from Delaware breach and consumer-privacy questions, and examine the 500-person and Social Security number duties. They prepare communication and credit-monitoring options without declaring that every statutory trigger is met before the facts and legal review support it.
Privacy should feel human even when the rules are technical
The BACB Ethics Code reinforces confidentiality and record duties, while qualified privacy and legal leaders classify incidents. Staff need a simple route for reporting a mistaken attachment, strange login, exposed screen or missing file. A respectful response to early uncertainty makes the next report more likely and the practice safer.
Delaware's privacy and breach duties become manageable when they are built into onboarding, access changes, vendor review, supervision and normal quality work. If communication is required, explain what happened, what information was involved, what the practice has done, what the reader can do and how to reach a person. Friendly writing does not minimize the event; it shows enough command of the facts to speak plainly.
Related resources
- How to Start an ABA Practice in Delaware
- ABA Practice Licensing Requirements in Delaware
- How to Scale an ABA Practice in Delaware
- ABA Practice Telehealth Readiness Checklist
Sources
- HHS, HIPAA Privacy Rule
- HHS, Summary of the HIPAA Security Rule
- HHS, HIPAA Breach Notification Rule
- HHS OCR, Guidance on HIPAA Risk Analysis
- HHS, Business Associate Guidance
- Delaware Code Title 6 Chapter 12B, computer security breaches
- Delaware Code Title 6 Chapter 12D, Personal Data Privacy Act
- Delaware Medical Assistance Program, General Policy Manual
- Delaware Medical Assistance Program, provider portal
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- Finni, Provider Program