ABA practice privacy and data breach requirements in Mississippi combine HIPAA with Mississippi Code Section 75-24-29. The state provision focuses on unencrypted electronic identity or financial data that was, or is reasonably believed to have been, intentionally acquired without authorization. An owner investigates and notifies affected residents without unreasonable delay unless it reasonably determines the event is not likely to cause harm. The current general statute has no routine Attorney General filing, and the maintainer provision refers specifically to acquisition for fraudulent purposes.

Privacy begins before a Mississippi family becomes a client

A parent may share a diagnostic report, insurance card and a description of an urgent home concern while asking whether a Mississippi ABA practice has room. Those details can travel through a website form, email, voicemail transcription, callback spreadsheet and payer-verification portal before anyone opens a formal chart. This early journey is easy to overlook because no treatment has started.

Follow one inquiry from collection through deletion. Record the legal entity, purpose, people, systems, copies, downloads, vendors and access-removal event. The HIPAA Privacy Rule gives covered entities a federal framework for PHI, but the Mississippi breach provision uses its own data and event definitions. A single inventory can support both reviews without pretending the two laws are identical.

Mississippi's general breach list is narrower than a clinical chart

The current Mississippi Section 75-24-29 text generally defines personal information as a Mississippi resident's first name or first initial and last name paired with an unencrypted Social Security number, driver's-license or state or tribal identification number, or financial-account, credit-card or debit-card number with a code or password that permits account access. The pairing matters.

Diagnosis, goals, behavior data and treatment notes do not enter that state list merely because they are sensitive. They can still be PHI, contract-protected information or confidential professional records. Instead of marking every field “PII,” map the specific data to each applicable rule. That work gives counsel and privacy leaders a much clearer starting point.

The state trigger asks about intentional acquisition

Mississippi describes a breach as unauthorized acquisition of electronic files, media, databases or computerized data containing personal information when it is not secured by encryption or another method that makes it unreadable or unusable. The affected-individual definition asks whether covered information was or is reasonably believed to have been intentionally acquired by an unauthorized person.

That wording makes evidence about conduct especially important. A blocked login attempt, an accidental screen view, a downloaded spreadsheet and a deliberate export are not interchangeable facts. Preserve authentication, export, email, device, file-history and interview evidence. Avoid deciding from a label such as “hacked” or “employee mistake” before the record shows what actually occurred.

Encryption is a fact pattern, not a comforting adjective

The Mississippi definition turns in part on whether the electronic information was secured by encryption or another technology that renders it unreadable or unusable. Owners should be able to explain where encryption applied, whether an active session exposed readable information, who controlled keys and whether an attachment, local export or backup existed outside the protected boundary.

Consider a stolen encrypted laptop whose browser remained signed in to a billing portal. Full-disk encryption may protect data at rest after shutdown while doing little for a live authenticated session. Preserve device-management, identity, application and key evidence. Let qualified technical and legal reviewers apply the definition to those facts rather than treating a checked encryption box as the end of the inquiry.

The owner investigates before applying the harm conclusion

A business that owns or licenses covered personal information conducts an appropriate investigation after discovery. Mississippi allows no resident notice when, after that investigation, the business reasonably determines that the breach will not likely result in harm to affected individuals. This is a conclusion supported by evidence, not a general exemption for events that look small.

Describe the fields, readability, acquisition evidence, likely recipient, use, disclosure, containment and possible identity or financial consequences. Preserve uncertainties and facts that cut against the preferred result. HIPAA has a different four-factor assessment for unsecured PHI, so a practice may need two written analyses drawing from the same underlying evidence.

Resident notice is required without unreasonable delay

When the Mississippi test is met and the harm exception is not supported, the owner discloses the breach to affected individuals without unreasonable delay. The statute allows time for the investigation and for restoring the integrity of the data system, and law enforcement may request a delay when notice would impede a criminal investigation or national security.

There is no universal numbered resident deadline in the general provision. Create internal milestones for preservation, scope, resident matching, legal analysis, drafting and approval. If notice is not yet ready, the chronology should identify the unresolved evidence or restoration work and the person accountable for the next decision. “No fixed days” should never become “whenever operations slow down.”

Maintainers have a separate, unusually worded handoff

A person or business that maintains covered personal information it does not own must notify the owner or licensee as soon as practicable after discovering a breach if the information was, or is reasonably believed to have been, acquired by an unauthorized person for fraudulent purposes. That phrase should be read carefully against the known facts and contract, not silently replaced with a broader trigger from another state.

Contracts can set an earlier operational alert than the statutory minimum. Name a monitored contact, after-hours route, evidence-preservation duties, minimum initial facts and follow-up cadence. A vendor should be able to report suspicious activity while intent remains unknown, allowing the owner to protect care and begin its own analysis without waiting for a polished forensic report.

The current general statute has no routine Attorney General filing

Mississippi's current general breach-notice text does not prescribe a routine Attorney General submission for every private breach. A 2026 bill proposed a filing when more than 100 residents were notified, but the official SB 2128 legislative history records that the measure died in committee on February 3, 2026. A proposal should not be presented as current law.

That does not mean an incident has no government or contractual reporting path. HIPAA, Medicaid, managed-care, insurer, law-enforcement, professional and other duties can still apply. Recheck the law at the time of an event because a later amendment may change recipients, thresholds, content or timing.

Substitute notice has a low cost threshold

Mississippi permits substitute notice when direct notice would cost more than $5,000, when the affected class exceeds 5,000 people or when sufficient contact information is unavailable. The route calls for email notice where addresses exist, conspicuous posting on the business's website and notification to statewide media. All of those listed components matter.

Document the cost estimate, class count or contact problem that supports the alternative. Preserve email delivery records, a copy and duration of the website notice and evidence of media distribution. A practice should also plan accessible language, translations when appropriate and a staffed response path so a worried family can understand what happened and what to do next.

HIPAA and Mississippi ask different breach questions

The HIPAA Breach Notification Rule generally presumes an impermissible use or disclosure of unsecured PHI is a breach unless an exception applies or a documented four-factor assessment supports a low probability of compromise. Mississippi focuses on its narrower identity and financial data, intentional unauthorized acquisition and likely harm.

A misdirected treatment note may demand serious HIPAA analysis without containing Mississippi's listed combination. A downloaded refund file may implicate both. Keep security incident, unauthorized access, intentional acquisition, impermissible use or disclosure, HIPAA breach and Mississippi breach as separate decision fields. Shared evidence is efficient; merged conclusions are not.

Reasonable security starts with the way work is actually done

The HHS Security Rule summary calls for reasonable and appropriate administrative, physical and technical safeguards for ePHI, and HHS risk-analysis guidance emphasizes an accurate and thorough assessment of risks and vulnerabilities. An ABA practice should connect that framework to its everyday field work.

Look closely at personal downloads, home-visit devices, shared inboxes, text messaging, former-worker accounts, remote support, spreadsheets and emergency workarounds. Limit access by job, use individual accounts, protect remote devices, preserve useful logs and test restoration. A polished policy cannot compensate for a supervisor who needs to borrow a coworker's password to finish documentation.

Vendor review should follow the data, not the sales category

The HHS business-associate guidance explains when a business associate agreement is required. A signed BAA is important where applicable, but it does not prove the vendor can detect a suspicious export, remove a departed worker, restore records or deliver Mississippi-specific incident facts quickly.

Map every material vendor to the data it receives, the people who can reach it, subcontractors, storage and backup locations, deletion, logs and incident contacts. Test the handoff before a real event. Keep contractual notice language, state-law owner-maintainer roles and HIPAA duties visible beside one another instead of expecting a generic security exhibit to answer every question.

Mississippi Medicaid records need their own retention map

The Mississippi Medicaid Administrative Code effective April 1, 2026 states in Part 200, Rule 1.3 that current and former Medicaid providers retain medical records for at least five years unless a longer period applies. Non-cost-report records are generally retained five years from the date of service or until an audit is resolved, whichever is later.

Build a claim-to-chart trail that shows the referral or order where applicable, assessment, plan, rendering person, service date, start and stop time when required, units, supervision and claim. Preserve the governing source version and payment context. The Mississippi Medicaid provider hub should be checked for current manuals and notices. A five-year Medicaid rule is not automatic permission to delete every clinical, employment or corporate record on day 1,826.

A fictional export incident shows why one label is not enough

Magnolia Pathways ABA is fictional. A departing billing specialist forwards a reconciliation workbook to a personal account. It includes resident names, member identifiers, limited service descriptions and refund-account details, but investigators do not yet know whether the account credentials in one column were current or whether the attachment was opened.

The practice disables access, protects active billing and care, preserves email and file logs and maps each field. Reviewers separately examine intentional acquisition, readability, likely harm, Mississippi's identity and financial combinations, HIPAA, Medicaid, payer, cyber-insurer and contract duties. They do not announce “breach” or “no breach” from the forwarding event alone.

A calm response depends on rehearsal

Run a tabletop exercise using a realistic incident rather than a harmless lost phone with no data. Give the team incomplete facts, an active service schedule, a vendor in another time zone and a family asking whether treatment can continue. Practice preserving evidence, separating confirmed facts from assumptions and assigning legal, technical, clinical, communications and business decisions.

The most useful after-action review is specific. Did staff know where to report? Could the practice identify affected Mississippi residents? Were payer and vendor contacts current? Could leaders restore care without destroying evidence? Improve the workflow and repeat the exercise. The goal is not theatrical speed; it is a dependable response when facts arrive in pieces.

Families need clear language and a real person

The BACB Ethics Code reinforces confidentiality and responsible record stewardship, while the practice remains accountable for a humane communication process. If notice is required, explain the known event, information involved, steps already taken, practical protective actions and how to reach someone who understands the response.

Avoid blame, dense legal recitations and promises that fraud, reimbursement or other harm cannot occur. Say what remains unknown when uncertainty is material. Train the response team to listen to a caregiver's concern about continuity of care as well as identity or financial risk. The way a practice handles a hard conversation often determines whether trust can be repaired.

Related resources

Sources