ABA practice privacy and data breach requirements in North Dakota combine HIPAA with Century Code Chapter 51-30, Medicaid policy, professional duties and contracts. North Dakota expressly covers medical and health-insurance information, along with identity, financial and other listed data. Resident notice is due in the most expedient time possible without unreasonable delay after covered acquisition, while a breach exceeding 250 individuals adds notice to the Attorney General by mail or email.
Privacy begins before the intake packet is complete
A North Dakota parent may describe a child's diagnosis, medication, school history and insurance difficulty while asking whether the practice has openings. Those details can land in a phone note, email, scheduling platform and intake form before a clinician sees them. A practice that protects only its formal EHR has already missed much of the real information flow.
Trace a representative family from first inquiry through services, billing, closure and archive. Record the legal entity, purpose, people, data, systems, vendors, exports and deletion point. The HIPAA Privacy Rule governs covered entities and PHI, while North Dakota's breach law reaches a defined set of resident information. The two maps should connect without becoming one vague “confidential” label.
North Dakota's list is unusually relevant to health care
North Dakota Century Code Chapter 51-30 includes a resident's first name or initial and last name paired with unencrypted Social Security, government-identification or qualifying financial-access information. It also includes date of birth, mother's maiden name, employer-assigned identification with required credentials, an electronic signature, medical information and health-insurance information.
Medical information covers medical history, mental or physical condition, treatment or diagnosis by a health care professional. Health-insurance information includes a policy or subscriber number and a unique identifier used by an insurer. For an ABA practice, an intake export, eligibility file, authorization packet or billing reconciliation may therefore contain several state-covered fields as well as PHI.
The incident definition turns on unauthorized acquisition
A North Dakota breach means unauthorized acquisition of computerized data when personal information was not secured by encryption or another method that makes the electronic material unreadable or unusable. The statute does not add a separate likelihood-of-harm exception to the resident-notice trigger. An unexplained alert still requires facts about acquisition and data, not an automatic conclusion.
Preserve identity, device, application, download, forwarding and key evidence. Ask what the person could read and obtain, not merely whether the vendor labels a database encrypted. Encryption at rest, an unlocked application session and a copied decryption key present different facts. Write known, unknown and disputed points separately so reviewers can update the analysis without rewriting history.
Good-faith employee access depends on what happens next
North Dakota's exclusion turns on what follows an employee or agent's good-faith acquisition: no subsequent use and no additional unauthorized disclosure. A billing employee who opens the wrong member record, reports it and does nothing else presents a different case from one who sends member information to a personal account to finish work at home.
Review purpose, scope, duration, copies, later use and disclosure. Keep the person's account with objective logs. Even when the state exception fits, HIPAA, payer terms, professional duties or internal mitigation may still require action. A narrow state conclusion should never become permission to skip the rest of the response.
Resident notice has a reasonableness clock
An owner or licensee notifies a North Dakota resident whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. Notice must be made in the most expedient time possible and without unreasonable delay, consistent with legitimate law-enforcement needs and measures necessary to determine scope and restore integrity.
There is no universal numbered resident deadline in the chapter. Create internal milestones for containment, resident matching, legal review and drafting, then record why any interval was necessary. The HIPAA Breach Notification Rule has its own presumptions, assessment and timing. Put both tracks in the incident record rather than choosing whichever clock feels easier.
More than 250 individuals changes the Attorney General route
North Dakota requires disclosure to the Attorney General by mail or email when a breach exceeds 250 individuals. “Exceeds” means more than 250, so a cohort of exactly 250 does not meet that numeric wording. Resident notice remains a separate obligation and does not disappear below the state-filing threshold.
Count the people in the breach carefully and document how duplicates, household records and uncertain identities were handled. Counsel should confirm whether the relevant count is the full event or the North Dakota portion on the actual facts. Prepare state and resident communications together when the threshold may be crossed, and preserve proof of what was sent and when.
A vendor's immediate notice should carry useful facts
A person maintaining computerized data it does not own must notify the owner or licensee immediately after discovery when covered information was or is reasonably believed to have been acquired by an unauthorized person. That duty can matter when a scheduling, revenue-cycle, payroll, recruiting, communications or clinical service discovers the event first.
Vendor contracts should identify a continuously monitored reporting route, after-hours escalation, evidence preservation and update cadence. Ask for affected systems, dates, fields, people, acquisition evidence, encryption and containment. The HHS business-associate guidance governs a separate role analysis when PHI is involved. A vendor can be central to both tracks without controlling the practice's final legal decision.
Substitute notice is a demanding alternative
The North Dakota chapter permits substitute notice when direct notice would cost more than $250,000, the affected class exceeds 500,000 people or the organization lacks sufficient contact information. Substitute notice consists of email where addresses are available, conspicuous website posting and notification to major statewide media.
That is not a shortcut for avoiding individual communication. Preserve the evidence supporting the threshold and complete every required component. Consider accessibility, translations and how a person will confirm whether they are affected without disclosing more information. Qualified counsel should review the route before it is used.
HIPAA can satisfy the state chapter, but only for the right role and conduct
Chapter 51-30 says a covered entity, business associate or subcontractor that is subject to the HIPAA breach-notification requirements in 45 C.F.R. Part 164 Subpart D is considered in compliance with the state chapter. This is important, but it is not a blanket exemption for every company associated with an ABA practice or for every data flow.
Confirm the legal entity, HIPAA role, information and whether the event actually falls under the federal breach-notification requirements. A management company, marketing site or workforce platform may not share the clinical practice's status. Document federal compliance rather than merely citing a HIPAA policy. Counsel should test the state route against the real organizational structure.
One evidence file can support separate legal questions
HIPAA asks whether there was an impermissible use or disclosure of unsecured PHI and, absent an exception, uses a documented four-factor risk assessment. North Dakota asks whether its listed unencrypted information was acquired without authorization. A single authorization packet may include diagnosis, insurer identifiers, date of birth and clinical notes, but the tests are still not interchangeable.
Maintain one trustworthy evidence repository with a matrix for each law, payer, insurer and contract. Record definitions, roles, people, fields, exceptions, recipients and deadlines on separate rows. This structure helps the team update one conclusion without accidentally changing another.
Medicaid's seven-year rule is a floor, not a deletion command
The current North Dakota Medicaid Provider Requirements generally requires records to be retained for at least seven years from creation or the date the record was last in effect, whichever is later, while recognizing that other law may require longer. Records must be complete, legible, signed or authenticated and confidential, with prompt completion.
The policy describes service, rendering-provider, time-based, plan, authorization, claim, payment and financial support that an audit may need. Keep information longer when an appeal, investigation, contract, professional rule or legal hold requires it. A retention floor does not authorize deletion on the anniversary without checking every other duty and the current policy.
ABA documentation is part of both care and recovery
North Dakota's Autism ABA Service Policy describes assessments, care plans, periodic updates, monitoring, provider qualifications, signatures and detailed documentation. The state's current provider-policy index is the better starting point for changes because general and service-specific materials can be updated independently.
Connect the approval period, plan, qualified professional, supervision, date, duration, setting, progress and claim. If an incident disrupts a system, restore enough verified information to support safe care and defensible billing. Do not delete questionable records during containment. Preserve an original, document corrections and separate recovery work from retrospective editing.
Security controls should match ordinary ABA work
The HIPAA Security Rule summary calls for administrative, physical and technical safeguards, while the HHS risk-analysis guidance expects a practice to understand its ePHI risks. Start with real workflows: home sessions, school visits, remote supervision, family messages, shared devices, billing exports and employee departures.
Test access removal across every application, not just the clinical system. Verify whether a lost device can be locked, whether a backup restores readable records and whether staff know whom to call on a weekend. A smaller practice can use straightforward controls, but “small” does not mean “unplanned.”
A fictional email compromise makes the sequence visible
Prairie Lantern Behavior Services is fictional. A coordinator's email account begins sending unusual messages. The mailbox contains authorization attachments with North Dakota names, dates of birth, diagnoses, insurer identifiers and electronic signatures. Sign-in logs show a suspicious session, but the team does not yet know which messages were opened or downloaded.
The practice resets access, preserves mailbox and identity evidence and protects upcoming services. Reviewers map residents and fields, analyze acquisition, HIPAA, the more-than-250 Attorney General threshold, Medicaid, payer, insurer, vendor and workforce duties, and prepare communication routes. They do not call the event a reportable breach until the facts and qualified review support that conclusion.
Staff need a report path that welcomes uncertainty
The BACB Ethics Code reinforces confidentiality and record responsibilities, but it does not make every clinician an incident lawyer. Staff should report a wrong attachment, lost device or suspicious login quickly, say what they know and preserve the message or screen. They should not decide notice at the point of discovery.
Thanking someone for an early report is good risk management. It keeps evidence available and makes the next person more likely to speak up. Training should use ordinary examples, name the response contacts and explain what not to do, including deleting evidence, warning a suspected actor or making promises to families before the facts are reviewed.
Clear communication protects trust without overpromising
If notice is required, write for a worried person rather than for a policy file. Explain the confirmed event, information involved, dates if known, steps taken, actions the reader can consider and a staffed contact route. Avoid blame, unsupported reassurance and technical filler.
ABA practice privacy and data breach requirements in North Dakota become more manageable when the practice has already decided who gathers evidence, who keeps care running, who obtains qualified advice and who speaks with families. Preparation does not guarantee an easy incident. It gives the team room to be accurate, prompt and humane when uncertainty is high.
Related resources
- How to Start an ABA Practice in North Dakota
- ABA Practice Licensing Requirements in North Dakota
- How to Scale an ABA Practice in North Dakota
- ABA Practice Telehealth Readiness Checklist
Sources
- HHS, HIPAA Privacy Rule
- HHS, Summary of the HIPAA Security Rule
- HHS, HIPAA Breach Notification Rule
- HHS OCR, Guidance on HIPAA Risk Analysis
- HHS, Business Associate Guidance
- North Dakota Century Code Chapter 51-30, security-breach notice
- North Dakota Medicaid, current provider policies and manuals
- North Dakota Medicaid, Provider Requirements
- North Dakota Medicaid, Autism Applied Behavior Analysis Service Policy
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- Finni, Provider Program