ABA practice privacy and data breach requirements in Montana combine HIPAA, Montana's computer-security-breach law, record-destruction rules, Medicaid requirements and, for some organizations, the Montana Consumer Data Privacy Act. Montana's breach statute expressly includes medical-record information. It calls for notice without unreasonable delay when its acquisition-and-injury test is met and requires a simultaneous electronic copy of the resident notice to the Attorney General's consumer-protection office.

Start with the information families actually share

The first private details often arrive before a Montana ABA practice calls someone a client. A parent may explain a diagnosis, a school problem, insurance coverage and a difficult week in one voicemail. Those facts can spread into a callback sheet, email, calendar, intake platform and clinical record, each with a different owner and retention rule.

Build a living data map around the family journey rather than around product names. Note the legal entity, purpose, people, fields, system, export, vendor, payer and eventual deletion point. The HIPAA Privacy Rule governs covered entities and PHI, while Montana law can reach medical, identity and financial information in other places. Seeing both layers early makes privacy work feel practical instead of abstract.

Montana's breach definition expressly reaches medical records

Under Montana Code Annotated 30-14-1704, personal information includes a person's first name or initial and last name combined with an unencrypted Social Security number, government identification, qualifying financial-access data, taxpayer identifier, IRS identity-protection PIN or medical-record information. Medical-record information is therefore not merely a HIPAA concern in this state analysis.

Do not treat every health-related fact as automatically covered by that exact state definition, and do not assume information outside it is safe to ignore. A treatment summary can still be PHI, confidential under professional duties or restricted by contract. A billing export may hold names, diagnoses, member numbers and refund-account details. Map the actual fields before deciding which rule applies.

The older identity-theft definition belongs in a separate drawer

Montana Code Annotated 30-14-1702 defines personal information for the broader identity-theft part somewhat differently, including a person's name, signature, address or telephone number combined with listed identity, insurance or financial information, while a Social Security number qualifies by itself. The computer-breach section has its own more specific definition.

That difference matters during retention and destruction planning. A practice should not copy one list into every policy and call the work finished. Label the rule, version and business process beside each data field. Counsel can then see whether an intake record, old paper form, credentialing file or incident export falls under the destruction rule, the breach rule, HIPAA, a payer term or several of them.

Acquisition, material compromise and injury all need facts

Montana defines a breach as unauthorized acquisition of computerized data that materially compromises the security, confidentiality or integrity of covered information and causes, or is reasonably believed to cause, loss or injury to a Montana resident. An alert, policy violation or suspicious login is important, but it is not a complete statutory conclusion by itself.

Open a decision record while evidence is fresh. Preserve login history, device state, file events, exports, message forwarding, encryption, resident information and what the person could actually obtain. Record why reviewers believe acquisition, material compromise and loss or injury are present, absent or still unknown. A careful analysis is more useful than either an instant declaration or a month of unrecorded uncertainty.

A good-faith internal mistake is not a free pass

The statute's good-faith exclusion is narrow: it can apply to an employee or agent's acquisition for the business only if the information is neither used nor disclosed again without authorization. A therapist who opens the wrong chart, closes it and reports the mistake is different from an employee who exports a caseload to a personal drive before resigning.

Investigate purpose, duration, copying, forwarding, later access and disclosure. Thanking staff for prompt reporting can preserve facts that would otherwise disappear. Keep the person's explanation with objective evidence, and do not punish uncertainty. The practice still may need a HIPAA analysis, mitigation, access correction, training or contract review even when Montana's state-breach exception ultimately applies.

Montana uses a reasonableness clock, not a universal day count

When the Montana resident-notice test is met, disclosure is due without unreasonable delay. Legitimate law-enforcement needs and measures necessary to determine scope and restore reasonable system integrity can affect timing. The statute does not give every private ABA incident a single numbered resident-notice deadline.

Internal dates are still valuable. Set short targets for containment, field mapping, resident matching, legal review and notice drafting. Document the work that consumes time and why it changes the decision. Waiting for evidence that determines who was affected is different from waiting for a convenient leadership meeting. The HIPAA Breach Notification Rule has its own federal clock and recipients, so track the two analyses separately.

The Attorney General receives a copy whenever resident notice is required

Montana requires a person or business issuing resident notice under section 30-14-1704 to submit an electronic copy of the notice and a statement with the date and method of distribution simultaneously to the Attorney General's consumer-protection office. The filing excludes personally identifying information. If more than one person receives notice, one copy states the number of Montana recipients.

There is no affected-person threshold in that provision. Prepare resident communication and the state submission as one coordinated workstream, then retain transmission evidence. For a multistate event, use a jurisdiction matrix rather than assuming Montana's recipient follows another state's population threshold. A small Montana cohort can still create the state-copy obligation.

Vendors should report facts immediately, not wait for certainty

A person or business maintaining computerized covered information it does not own must notify the owner or licensee immediately after discovery when the information was or is reasonably believed to have been acquired by an unauthorized person. In an ABA practice, that relationship can involve scheduling, billing, recruiting, payroll, storage, messaging or clinical vendors.

Contract for a monitored incident address, after-hours escalation, evidence preservation and continuing updates. The first report should identify systems, dates, people, data, acquisition evidence, containment and unknowns. It does not need a polished root-cause analysis. The HHS business-associate guidance helps identify separate HIPAA obligations when a vendor creates, receives, maintains or transmits PHI on behalf of a covered entity.

Substitute notice has a precise channel structure

Montana allows substitute notice when direct notice would cost more than $250,000, the affected class exceeds 500,000 people or contact information is insufficient. The statute calls for email where the business has addresses and then either conspicuous website posting, when it maintains a site, or notice to applicable local or statewide media. The exact connectors matter.

Do not turn substitute notice into a quiet webpage by habit or import an all-channel formula from another state. Preserve the facts supporting the route, complete the applicable components and have counsel verify the wording. Accessible language, translations and a staffed contact line may be wise even when the statute does not prescribe every usability detail.

A maintained notification policy can help only if the practice follows it

Montana recognizes a business's own notification procedures when they are part of an information-security policy, the business does not unreasonably delay notice and it notifies people according to those procedures. The provision is conditional. A forgotten template or an aspirational policy is not the same as maintained, usable response practice.

Give the policy owners, backups and tested communication routes. Rehearse a modest scenario and capture what failed. The HHS risk-analysis guidance can organize ePHI risks, but a Montana exercise should also include state-covered tax, financial and identity data outside the clinical chart. One evidence plan can support several legal decisions without merging them.

Record destruction should follow a retention map

Montana Code Annotated 30-14-1703 requires a business to take reasonable steps to destroy customer records containing personal information that are no longer necessary to retain by shredding, erasing or otherwise making the information unreadable or undecipherable. The phrase “no longer necessary” requires a defensible retention decision before deletion.

Create a schedule by record type, not a universal delete date. Clinical records, Medicaid support, payroll, credentialing, corporate documents and incident evidence can have different floors and holds. Include backups, downloads, paper files and vendor copies. During an incident, preserve evidence and continuity records first. A legal hold, payer appeal, audit or professional duty may require keeping information beyond an ordinary schedule.

Montana's consumer privacy act requires a role-and-scope check

The Montana Consumer Data Privacy Act applicability section generally reaches a person that does business in Montana or intentionally targets Montana residents and controls or processes at least 25,000 consumers' personal data, excluding data used solely to complete a payment transaction. A second path applies at 15,000 consumers when the person also derives more than 25% of gross revenue from selling personal data. Its exemptions section excludes a HIPAA covered entity or business associate, among other entities and data. That is broader than a PHI-only data exemption, but it still depends on the actual legal entity and role.

Do not assume every management company, recruiting affiliate, website, analytics flow or vendor shares the clinical practice's status. Map common branding, legal control, contracts, data and purpose. If an entity is in scope, the act's controller duties include privacy notice, security, minimization and consent-related requirements. Qualified counsel should resolve the edge cases before public claims or workflows are built around an exemption.

Medicaid records need more than a retention number

The current Montana General Information for Providers Manual says Medicaid-related medical and financial records must be kept for six years and three months after the date of service. It identifies signed and dated entries, service dates and times, provider identity, treatment detail, prior authorization, claims, payments and other supporting data. The site also warns that policy changes and providers must use the version effective for the service.

The Montana Applied Behavior Analysis Services Manual adds program context. Connect authorization, assessment, plan, rendering professional, supervision, session, units and claim. Retain longer when an audit, appeal, investigation, contract, professional duty or legal hold requires it. A defensible record is both protected and understandable after the original employee leaves.

Security should be tested where work really happens

The HIPAA Security Rule summary and current risk-analysis guidance point toward administrative, physical and technical safeguards appropriate to the practice's risks. A young ABA organization does not need theatrical controls. It does need to know where ePHI lives, who can reach it, what happens when someone leaves and whether backups and incident contacts work.

Test a few ordinary moments. Remove a departed employee across the EHR, email, scheduling, payroll and shared storage. Recover a file without exposing another family. Inspect whether a school-session device shows data on its lock screen. Findings from real workflows often improve security faster than adding another page to a policy binder.

A fictional lost-laptop incident shows the order of work

Big Sky Learning Collective is fictional. A supervisor leaves a laptop in a vehicle overnight. Full-disk encryption is enabled, but the practice does not yet know whether the device was awake, whether a clinical session remained open or whether a locally saved billing file included Montana names, diagnoses, taxpayer identifiers and refund information.

The response team preserves device-management, identity and application logs, disables risky sessions and protects upcoming care. Reviewers map residents and fields, test unauthorized acquisition, material compromise and injury, and keep HIPAA, Montana, Medicaid, payer, insurer, vendor and workforce tracks separate. They prepare communication routes without claiming that a breach or notice duty exists until the evidence supports it.

Families deserve a calm explanation, not legal theater

The BACB Ethics Code reinforces confidentiality and record responsibilities, while legal and privacy leaders decide notice. Staff should know how to report a mistake without diagnosing the law. A culture that thanks people for raising a concern quickly is more likely to receive the next important report.

If notice is required, use ordinary language. Explain what happened, what information was involved, what the practice has done, what a person can do and where a human will answer questions. Avoid unsupported reassurance, blame and jargon. Montana privacy and breach work becomes easier to manage when preparation serves both accurate decisions and respectful communication.

Related resources

Sources