ABA practice privacy and data breach requirements in Louisiana combine HIPAA with state database security law and payer records duties. The state breach definition is narrower than PHI and generally requires unauthorized acquisition and access to listed identity, financial, passport or authentication data. Resident notice is prompt and no later than 60 days after discovery, while an administrative rule generally places Attorney General notice within ten days after resident notices. A documented no-harm decision is retained for five years, and Medicaid records have a separate program floor.
The record begins moving before treatment begins
A Louisiana family may send an evaluation, insurance card and availability information before the practice decides whether it can offer services. Those details may travel through intake, scheduling, credentialing, authorization and billing systems. Once care begins, skill data, supervision notes, texts and claims add more copies. The HIPAA Privacy Rule can govern a covered practice's clinical information, but the real privacy experience stretches across the whole journey.
Walk that journey with one fictional record. Name the legal entity, purpose, users, integrations, copies, retention and exit method at every step. This is the practical beginning of ABA practice privacy and data breach requirements in Louisiana. It finds the forgotten mailbox or vendor workspace that a tidy diagram may leave out.
Louisiana's general breach list is narrower than PHI
Louisiana Revised Statutes Section 51:3073 defines personal information through a Louisiana resident's name combined with listed data, including Social Security, driver's-license or state-identification, financial access, passport and biometric information used to authenticate the individual. It does not generally add diagnosis, treatment or health-insurance information to that list merely because the information is private.
A treatment note can still raise HIPAA, professional, payer and contractual concerns without meeting this state definition. A mixed enrollment export may contain both clinical and listed identity data. Build a field-level inventory and evaluate each legal lane. Calling the whole file “medical” or “PII” hides exactly the distinctions the response team needs.
The state definition asks about acquisition and access
Louisiana describes a breach as a compromise that results in, or is reasonably likely to result in, unauthorized acquisition of and access to personal information. A good-faith acquisition by an employee or agent for legitimate purposes is excluded only when the information is not used for an unlawful purpose or subjected to further unauthorized disclosure.
Preserve login history, export events, mailbox rules, device evidence and vendor statements. Separate a blocked attempt, an unauthorized view and a completed download. Record the source of every conclusion and what remains unknown. Containment can begin immediately, while the legal determination waits for enough evidence to apply both parts of the definition honestly.
Reasonable security and destruction are ongoing duties
Section 51:3074 requires an entity conducting business in Louisiana to maintain reasonable security procedures and practices appropriate to the nature of the information and to protect it from unauthorized access, destruction, use, modification or disclosure. It also requires reasonable steps to destroy or arrange for destruction when a record will no longer be retained.
For an ABA practice, that means access control, offboarding, protected devices, authentication, vendor oversight, tested recovery and defensible disposal. Reasonable does not mean identical for every organization, but it should be visible in decisions and tests. Deleting a shortcut or returning a laptop without verifying the data is not the same as making a record unreadable or undecipherable.
Resident notice is prompt with a 60-day outside limit
An owner or licensee with a qualifying event must notify affected Louisiana residents in the most expedient time possible and without unreasonable delay, consistent with law-enforcement needs and measures needed to determine scope, prevent further disclosures and restore reasonable system integrity. The statute also says notice must be made no later than 60 days from discovery.
Treat 60 days as an outside boundary, not a standard project duration. Assign evidence, population, drafting, translation and call-support work early. Keep discovery, containment and decision dates distinguishable. HIPAA may use a separate framework and measurement, while residents of other states bring their own laws. One calendar entry cannot stand in for the full routing matrix.
A delayed state notice needs written reasons
When notification is delayed beyond 60 days because the entity needs more time to determine scope, prevent further disclosures or restore integrity, Louisiana requires written reasons to the Attorney General within the 60-day period. The Attorney General may allow a reasonable extension. That is a documented exception, not an internal decision to move the deadline quietly.
Engage qualified counsel and incident leaders early if the evidence suggests the outside limit may be difficult. Preserve work completed, barriers, recovery actions and the proposed path. Never let a technical vendor's slow response become invisible. The practice remains responsible for understanding what information it needs and escalating missing evidence promptly.
The Attorney General route follows citizen notice closely
Louisiana's administrative breach-notice rule requires an entity that notifies Louisiana citizens under the statute to provide written details to the Attorney General's Consumer Protection Section. The rule says that notice is timely when received within ten days after the distribution of notices to citizens and calls for information about the breach, notifications and affected Louisiana citizens.
This ten-day period is not the resident-notice deadline. Put the two events on separate lines in the response record. Coordinate sensitive population information through a secure, current submission method and confirm receipt. Other state residents, HIPAA, payers and insurers may create additional routes, so the Louisiana filing should not become a substitute for the full matrix.
A no-harm conclusion must remain reviewable
Louisiana permits a no-notice result when, after a reasonable investigation, the entity determines there is no reasonable likelihood of harm to residents. The determination must be documented in writing and the supporting materials retained for five years. If the Attorney General asks for the determination and evidence, the entity generally provides it within 30 days.
Keep the fields, access and acquisition evidence, mitigation, population, harm reasoning, reviewers and authority in the file. A sentence saying “no risk” cannot explain why the conclusion was reasonable. Protect the investigation from unnecessary access, but leave it usable if later logs or a regulator's question require the team to revisit the decision.
A maintainer must tell the information owner
A person maintaining computerized data that includes personal information it does not own must notify the owner or licensee after discovery of a qualifying breach. Louisiana calls for the most expedient time possible and without unreasonable delay, consistent with the same law-enforcement, scope, prevention and restoration needs.
Vendor contracts should set a faster practical escalation and name the evidence expected. Ask for affected systems, dates, fields, access and acquisition facts, encryption, people, containment and log windows. A covered practice cannot complete its HIPAA, Louisiana, payer and family analyses with a ticket that says only “security event under review.”
HIPAA begins from a different trigger
The HIPAA Breach Notification Rule focuses on an impermissible use or disclosure of unsecured PHI and presumes a breach unless an exception applies or a documented assessment supports a low probability of compromise. Louisiana focuses on its listed personal information and unauthorized acquisition and access. Medical facts can sit squarely in one analysis while outside the other's data list.
Use separate status fields for security incident, impermissible use or disclosure, HIPAA breach, Louisiana breach and contractual incident. Link each to the same evidence and qualified reviewer. This structure prevents an early “not Louisiana personal information” conclusion from being mistaken for a finding that no privacy problem exists.
Medicaid creates a five-year statutory records floor
Louisiana Revised Statutes Section 46:437.12 requires a Medicaid provider agreement to include orderly records, confidentiality and access for authorized state and federal reviewers. It provides a five-year period for Medicaid-related records, subject to the statute's exact trigger and any longer requirement.
That five-year floor is not automatically the end date for every clinical record. A professional rule, current provider manual, managed-care contract, audit, appeal, investigation, litigation hold or other law may require more. Record the payer, service, payment and authority next to the retention period so staff do not destroy a record based on a context-free number.
The ABA manual can require a longer program period
Louisiana Medicaid's current services page and provider-manual index are the control points for live program material. A published ABA provider requirements section states that ABA records and data are maintained for at least six years unless law requires longer. Because manuals and contracts change, the practice should verify the current effective section for the actual date of service before relying on that period.
Save the version used, not just a bookmarked URL. Managed-care requirements, professional obligations and open reviews may extend access further. If a historic training slide, statute and current manual appear to conflict, do not average the numbers. Route the specific record and service to the program or qualified reviewer for a written answer.
A release process should be easy without becoming careless
Families should be able to request their information without navigating an obstacle course. A useful workflow verifies identity, legal authority, record scope, format and destination, then tracks fulfillment. It also gives staff a clear route when a request involves a minor's separate authority, psychotherapy notes, school records, substance-use information or another specially protected category.
Use plain language and accessible forms. Do not send a broad chart simply because the requester can name the client, and do not withhold ordinary access because an account has a balance. Qualified privacy and legal reviewers should resolve the hard cases. The ordinary path should remain understandable enough that families and staff can use it correctly.
Security includes restoring usable care
HHS risk-analysis guidance asks a covered entity to assess risks and vulnerabilities to ePHI. Confidentiality is only part of that work. Corrupted skill data or inaccessible support plans can affect clinical continuity even when the team has not confirmed that anyone outside the practice viewed them.
Choose recovery priorities before an emergency. Test restoration for current schedules, contact routes, authorized caregivers and active plans. Give staff an approved downtime method and reconcile temporary records afterward. Ask vendors how they isolate tenants, preserve logs and return clean data. The first successful restoration should not occur during the practice's first serious outage.
A fictional folder incident shows the overlapping lanes
Bayou Learning Works is fictional. A reconciliation export is placed in the wrong vendor folder. It contains member names and bank-access details, and a linked directory may expose progress notes. The vendor removes access but initially cannot say whether the recipient opened or downloaded either file.
The clinic preserves folder and identity evidence, protects ongoing billing and maps each field and resident. Louisiana acquisition-and-access and harm questions, HIPAA, payer, insurer, contract and professional lanes receive separate reviewers. The team does not call the event harmless merely because the recipient promises deletion, and it does not announce a statutory breach before the available evidence supports that conclusion.
The best communication is candid and humane
If the practice must contact families, begin with the known event, the information involved, steps already taken and a reliable help route. Explain what is still being investigated. Say whether appointments, contact channels and records remain available. Avoid burying the answer under statute names or making assurances that a regulator, insurer or monitoring product has not made.
Prepare accessible and translated versions, a call guide and a correction process. The BACB Ethics Code reinforces confidentiality and records responsibilities for certificants, while qualified reviewers determine the legal communication. Listen to repeated family questions and improve the explanation. Clear, warm language is part of a responsible response, not an alternative to accuracy.
Related resources
- How to Start an ABA Practice in Louisiana
- ABA Practice Licensing Requirements in Louisiana
- How to Scale an ABA Practice in Louisiana
- ABA Practice Telehealth Readiness Checklist
Sources
- HHS, HIPAA Privacy Rule
- HHS, Summary of the HIPAA Security Rule
- HHS, HIPAA Breach Notification Rule
- HHS OCR, Guidance on HIPAA Risk Analysis
- HHS, Business Associate Guidance
- Louisiana Revised Statutes Section 51:3073, Database Security Definitions
- Louisiana Revised Statutes Section 51:3074, Database Security Duties and Notice
- Louisiana Administrative Code Title 16 Part III Section 701, Breach Notice to Attorney General
- Louisiana Revised Statutes Section 46:437.12, Medicaid Provider Agreements
- Louisiana Medicaid, Current Services and Program Resources
- Louisiana Medicaid, Current Provider Manuals
- Louisiana Medicaid, ABA Provider Requirements Section 4.4
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- Finni, Provider Program