ABA practice privacy and data breach requirements in New Hampshire combine HIPAA with separate state rules for computerized personal-information incidents, medical records, patient information, consumer data and Medicaid records. New Hampshire's general breach definition is narrower than a clinical-record definition: it centers on a name paired with a Social Security number, government identification number or financial account access information. A clinical incident can still trigger HIPAA, professional, medical-record, payer, contract or program duties even when that particular state definition is not met.
Privacy lives in ordinary moments
A New Hampshire ABA practice can receive a diagnosis, insurance card, school report and a family's description of daily life before anyone has met a clinician. Care then adds assessments, behavior data, photographs, schedules, supervision records, authorizations, claims and messages. The HIPAA Privacy Rule gives covered providers an important federal framework, but families experience privacy through everyday conversations, handoffs and systems.
Choose one fictional family and trace its information from the first inquiry through discharge. Include personal inboxes, intake forms, mobile devices, paper, shared workspaces, payer portals, vendor backups and exported reports. For every copy, ask why it exists, who needs it, how it is protected and when it should leave. This practical walk-through often uncovers more than a policy read alone.
Start with the organization, not the logo
Many ABA providers that conduct standard electronic insurance transactions are HIPAA covered entities. The conclusion should be documented for the actual legal organization, services and transactions. A provider practice, management company, independent clinician, staffing affiliate and software company can share branding without sharing the same legal role.
Revisit that map after an acquisition, new consumer product, cash-pay offering or structural change. Employment records and marketing leads are not automatically PHI because a healthcare company holds them. A single event may therefore need a HIPAA analysis for one entity and a New Hampshire consumer or employment-data analysis for another.
The general breach definition is deliberately specific
RSA 359-C:19 defines personal information for the general security-breach chapter as a person's name paired with an unencrypted Social Security number, driver's license or other government identification number, or financial account, credit-card or debit-card number together with information that permits access. The definition does not itself list a diagnosis, treatment record or insurance member number.
That difference matters. Do not tell families that a clinical file is outside privacy protection simply because it misses this state-law definition. It may still be PHI, confidential patient information or a record governed by a payer, program, contract or professional duty. At the same time, do not rewrite the statute by treating every clinical field as the chapter's personal information.
Mixed files can open more than one response track
An ABA intake packet may hold a diagnosis and treatment history beside a parent's payment information or a scanned government identification document. A payroll export may contain Social Security numbers with no clinical information. When a suspicious event touches either file, list the actual fields rather than using the vague label “sensitive data.”
Record the resident, data subject, legal entity, data owner, system, readable elements and evidence of acquisition. Then evaluate HIPAA, New Hampshire's general breach chapter, medical-record duties, Medicaid or payer requirements, contracts and cyber coverage separately. Parallel review is more reliable than forcing every obligation into one yes-or-no breach box.
Uncertainty is part of the misuse decision
RSA 359-C:20 directs an in-scope person to promptly investigate whether misuse of covered personal information has occurred. Notice follows when misuse occurred, is reasonably likely to occur or cannot be determined after a prompt, good-faith and reasonable investigation. “We could not tell” is therefore not the same as “nothing happened.”
Preserve login history, downloads, mailbox records, device state, payment activity and vendor evidence before short-lived records disappear. Write down known facts, missing evidence, investigative steps, likely misuse and mitigation. Keep this state conclusion distinct from the HIPAA Breach Notification Rule, which uses its own exceptions and documented four-factor assessment.
Resident notice is prompt, not tied to a fixed number
When the general New Hampshire route requires notice, affected people must be notified as soon as possible. The statute does not give the ordinary route a 30-, 45- or 60-day outside limit. Law-enforcement needs can delay notice under defined conditions, but an open-ended internal investigation is not a substitute for prompt work.
Create a clock register when the event becomes credible. Record discovery, evidence preservation, population work, legal decisions, drafting, accessibility, translation and delivery. HIPAA can permit up to 60 days in some circumstances, while a payer, contract, insurance policy or another resident's state may require something different. Use the shortest verified clock for each population rather than inventing a universal deadline.
The regulator notice follows the organization's status
New Hampshire directs a person subject to RSA 358-A:3, I to notify its primary regulator. A person without that regulatory route notifies the Attorney General. The notice includes the anticipated date of consumer notice and the approximate number of New Hampshire residents affected. The statute says names or other personal information are not required in that regulator notice.
Identify the correct recipient before an incident, and have counsel confirm the route for the particular organization. Keep a clean resident estimate and preserve what was submitted, by whom and when. A regulator package should be useful without carrying unnecessary clinical details, speculation or privileged strategy.
A data maintainer has an immediate cooperation duty
An in-scope person that maintains computerized covered information it does not own must notify and cooperate with the owner or licensee immediately when the information was acquired by an unauthorized person. In ABA operations, a billing company may maintain a practice's files, while a practice may hold records for a school, network or affiliated organization.
Contracts should identify data ownership, the incident channel, evidence-preservation duties, investigation access, resident mapping and notice responsibilities. Test the contact path rather than trusting a general support address. Cooperation is useful only if the owner receives enough timely evidence to make its own federal, state, payer and contract decisions.
The consumer notice and large-event route have defined pieces
A New Hampshire consumer notice under the general chapter includes a general description of the incident, its approximate date, the personal information obtained and a telephone number for further information and assistance. If notice goes to more than 1,000 consumers, the person generally also informs nationwide consumer reporting agencies without unreasonable delay about timing, distribution and content.
Count notified consumers carefully and keep state residents distinct from the full incident population. A credit-agency threshold is not the same thing as the regulator notice described elsewhere in the statute. Test the assistance line before notices leave and equip the team with an approved factual explanation. A hurried call center can compound a family's worry with contradictory answers.
A regulated procedure needs a written fit analysis
RSA 359-C:20 includes routes for people whose primary or functional regulators maintain security-breach procedures, and for HIPAA-subject people that follow applicable notification requirements. The wording should be applied to the actual organization and incident, not reduced to a broad statement that healthcare providers are exempt from New Hampshire law.
Document which subsection, regulator and procedure apply, how the entity qualifies and what notice was completed. A mixed corporate structure or file can leave another entity, data set or duty outside that route. Qualified New Hampshire and HIPAA reviewers should confirm the fit before the practice closes its state analysis.
Patients have concrete rights in New Hampshire records
RSA 332-I:1 treats medical information in a provider's or health facility's records as the patient's property while the physical record remains with its owner. It connects copy rights to HIPAA, calls for an electronic format when available and generally uses a 30-day access period. It also provides a faster, no-cost provider-to-provider transfer route in specified circumstances.
The companion patient-information section addresses confidential communications and allows a patient to request a report from the electronic-record audit trail for a named provider during the preceding three years. Map the statute's provider and record definitions to the practice, then make access, identity verification, family authority, electronic delivery and audit-log retrieval workable before a real request arrives.
Consumer privacy exclusions need a close reading
RSA 507-H:3 contains healthcare-related exclusions for certain covered entities, business associates, protected health information and other specified data. Those provisions can be important, but an entity-level exclusion, a data-level exclusion and a function-specific exclusion are not interchangeable.
Review websites, recruiting tools, analytics, consumer apps, nonclinical affiliates and data collected outside treatment separately from PHI workflows. Record the exact exclusion and facts supporting it. The right conclusion may be that the chapter does not apply to a defined activity; it should not become a slogan that an ABA business has no state privacy responsibilities.
Medicaid records need longevity and controlled access
New Hampshire Medicaid's current General Billing Manual says electronic and paper claim records generally must be kept for at least six years from the date of service, or until a pending audit, investigation or litigation is resolved, whichever is longer. It calls for complete records supporting services and access by authorized state, federal and Attorney General representatives. The state also maintains a current manual library for program updates.
Tie retention to the correct service, agreement and pending matter rather than setting one deletion date for every file. If the practice closes, follow the manual's direction about telling the state where records will be stored. Access for an authorized audit should be documented and controlled; it is not permission to expose the same folder broadly inside the organization.
Vendor oversight should work on a difficult day
HHS uses its business associate guidance to describe which relationships need a business associate agreement and how protections reach subcontractors. The Security Rule summary and risk-analysis guidance put administrative, physical and technical safeguards on top of an accurate view of actual risks. A signed agreement is only one part of that operating system.
Maintain a vendor register with the data handled, legal role, contract owner, access method, notice promise, log-retention period, backups, export process and termination plan. Ask how the vendor will identify New Hampshire residents and preserve evidence. Test one escalation path and one restoration scenario. The exercise can reveal that the promised evidence disappears before the practice's own review even begins.
A billing-file incident makes the separate lanes visible
Granite Coast Behavior Services is fictional. A billing supervisor receives a genuine-looking file request, sends an export and then learns the recipient's account had been taken over. The file contains New Hampshire families' names, diagnoses, insurance information and some guarantor payment details. The practice recalls the link, preserves email and download records, contacts the vendor and verifies that current care documentation remains available.
The response lead maps each field and opens HIPAA, New Hampshire breach, medical-record, Medicaid, payer, contract and insurance reviews. Qualified reviewers decide whether the state chapter's defined elements were acquired, whether misuse can be determined and which regulator route fits. Family communication, if required, should plainly explain known facts, involved information, protective steps and where to ask questions. A calm voice should make uncertainty understandable rather than disguising it.
Related resources
- How to Start an ABA Practice in New Hampshire
- ABA Practice Licensing Requirements in New Hampshire
- How to Scale an ABA Practice in New Hampshire
- ABA Practice Telehealth Readiness Checklist
Sources
- HHS, HIPAA Privacy Rule
- HHS, Summary of the HIPAA Security Rule
- HHS, HIPAA Breach Notification Rule
- HHS OCR, Guidance on HIPAA Risk Analysis
- HHS, Business Associate Guidance
- New Hampshire RSA 359-C:19, Security Breach Definitions
- New Hampshire RSA 359-C:20, Security Breach Notification
- New Hampshire RSA 359-C:21, Security Breach Enforcement
- New Hampshire RSA 332-I:1, Medical Records
- New Hampshire RSA 332-I:2, Patient Information
- New Hampshire RSA 507-H:3, Consumer Data Privacy Exclusions
- New Hampshire Medicaid, Current Provider Manuals
- New Hampshire Medicaid General Billing Manual, August 2026
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- Finni, Provider Program