Puerto Rico ABA privacy and data breach requirements may involve both HIPAA and Puerto Rico Act 111-2005. The local law covers defined personal information of Puerto Rico residents, including HIPAA-protected medical information, and requires customer notice after a covered security breach plus a report to DACO within ten days after detection. HIPAA-covered entities and business associates must separately assess unsecured protected health information and follow federal notice rules. Contain the event, preserve evidence and run both analyses; one framework does not cancel the other.

Begin with the information your practice really holds

An ABA practice can collect far more than treatment notes. Intake forms, diagnoses, behavior data, videos, caregiver messages, school records, insurance cards, authorizations, claims, bank information, employee evaluations, credentials and payroll may travel through different systems and vendors. Privacy begins with knowing where those records live, who can reach them and why.

Follow one family's information from first inquiry through discharge and retention. Include email, text, paper, shared drives, devices, telehealth, clearinghouses and exported spreadsheets rather than documenting only the EHR. Record the owner, purpose, recipients, legal role, sensitivity, retention and deletion path for each store. The map should describe current reality, not the system the practice hopes everyone uses.

Understand what Puerto Rico's breach law protects

Puerto Rico Act 111-2005 defines a personal-information file as a name or first initial and paternal surname combined with specified readable data. The list includes Social Security and official identification numbers, financial accounts, usernames and passwords, HIPAA-protected medical information, tax information and employment evaluations. Publicly available records and postal or residential addresses alone are excluded from that definition.

The law's security-breach definition reaches unauthorized system or physical access that puts security, confidentiality or integrity in question, and certain misuse by ordinarily authorized people. Do not reduce the analysis to a hacker entering the EHR. A lost unencrypted laptop, open spreadsheet link, stolen drive or staff member's improper access can require the same disciplined fact gathering.

Know that encryption details matter

Act 111's resident-notice provision applies when the breached database contains covered personal information that was not protected with cryptographic keys beyond a password. That wording makes the actual state of the information important. A vendor's statement that its platform “uses encryption” is not enough to establish what protected the affected file, export, message or device at the relevant time.

Preserve configuration, key-management, device and access evidence before changing everything. Ask qualified privacy and security advisers to interpret the statute and the facts. Do not promise that encryption always eliminates notice, or that a password always counts as encryption. The practice bears the risk of making a conclusion from a marketing phrase instead of technical evidence.

Treat the ten-day DACO clock seriously

The local law says responsible parties must inform the Department of Consumer Affairs within an unextendable ten days after detecting the breach. It also calls for customer notice as expeditiously as possible, taking law-enforcement evidence needs and restoration measures into account. That is a different structure from HIPAA's federal notice calendar.

Record the first detection time and what was known then. Bring Puerto Rico privacy counsel and the incident lead together immediately enough to determine scope, required recipient, content and delivery. An internal ticket labeled “security question” should not quietly age while the practice waits for a perfect investigation. Fast escalation and careful analysis can coexist.

Prepare notice content before a crisis

Act 111 says a breach notice must be clear and conspicuous, describe the event in general terms and identify the type of sensitive information involved. It also calls for a toll-free number or website for more information or assistance and provides direct and substitute-notice methods under its conditions.

Maintain a reviewed template, but never fill it with guesses. Notice should tell affected people what happened, what information was involved, what the practice has done and how they can obtain help, while avoiding unnecessary exposure of another person. Qualified counsel should confirm the current statutory and regulatory details, languages, accessibility and delivery evidence for the actual event.

Run HIPAA as a parallel analysis

HHS's Breach Notification Rule guidance applies to HIPAA-covered entities and business associates when unsecured protected health information is involved. HHS describes individual notice without unreasonable delay and no later than 60 days after discovery, media notice for breaches affecting more than 500 residents of a state or jurisdiction and Secretary notice on timelines tied to size. A business associate must notify the covered entity under the federal rule.

Those federal requirements do not replace Puerto Rico's resident and DACO analysis. Nor does every ABA practice or every record automatically fall within HIPAA. Document the entity's role, the information, impermissible use or disclosure, exceptions, risk assessment, affected count and notice decision. Avoid copying a HIPAA conclusion into the local-law field.

Build security from a real risk analysis

HHS's risk-analysis guidance treats an accurate and thorough assessment of potential risks and vulnerabilities to electronic protected health information as foundational for regulated entities. Inventory systems, remote access, backups, devices, integrations, vendors, physical locations and workforce behavior. Rank practical harms and document why safeguards were chosen.

Small practices do not need theatrical security. They need reliable fundamentals: unique accounts, multi-factor authentication where available, limited administrative privileges, secure devices, tested backups, patching, logging, vendor controls and a response plan people can use. Use the HHS Security Rule guidance to keep administrative, physical and technical safeguards connected. Review the risk analysis after a new platform, office, service, acquisition or material incident instead of once at launch.

Give each person only the access the work requires

HHS's minimum-necessary guidance describes role-based limits for many uses, disclosures and requests under HIPAA. Translate that principle into practical groups: inquiry staff do not need full treatment histories, billers may not need every narrative detail and a technician should not inherit access to every client because it is convenient.

Approve access by role and assignment, review it, and remove it promptly when a person changes duties or leaves. Keep a controlled emergency-access route and inspect unusual use. Shared accounts destroy attribution. Exporting a broad roster to solve one question creates a new risk even when the recipient works for the practice.

Make vendors part of the data map

Scheduling, payroll, clearinghouse, messaging, analytics, video, storage and IT vendors can receive sensitive records. Before use, identify what the vendor receives, the practice's and vendor's legal roles, required agreements, subcontractors, storage locations, access, logging, return or deletion and incident-notification commitments. If the only person who knows how to export the records leaves, the contract language will not restore continuity by itself. A business associate agreement, when required, is a starting control rather than a guarantee.

Ask who will notify the practice, by what route and how quickly after suspected unauthorized access. Preserve a current contact outside the vendor system. Test export and offboarding before dependence grows. If the platform disappears or the contract ends, the practice still must reach current records, maintain care and meet retention and access duties.

Design telehealth privacy around homes and real life

Puerto Rico's telehealth law requires special precaution to protect records and requires documented informed consent that includes the technology's confidentiality risk. The Department of Health telemedicine page also tells professionals to consider the privacy of both physical environments and document other people present with the patient's consent.

Ask where the family can speak, who may enter the room, whether headphones or captions are needed and what happens if the connection fails. The clinician should use an approved device and private space rather than a car, café or shared account. Do not record by default. Remote care can be humane and accessible without pretending that a platform alone makes the encounter private.

Contain an event without destroying the evidence

When something goes wrong, disable the exposed link, recover a device if safe, reset affected credentials and block continuing access. At the same time, preserve logs, messages, configurations, files and the sequence of decisions. An automatic cleanup that deletes the only access history may make the legal and technical analysis harder.

Name an incident lead, technical lead and decision owner. Record discovery, containment, systems, people, information, residency, encryption, vendors, recipients and known misuse. Use qualified forensic, privacy and legal help appropriate to the event. Do not ask ordinary staff to investigate through the exposed account or send sample records to personal email.

Communicate before silence becomes another harm

A parent who learns about an exposed file from someone else may reasonably wonder whether the practice understands the event. When a notice or direct update is appropriate, use clear language, an accessible contact and honest limits. Explain current protection and next steps without minimizing the risk or promising that misuse is impossible.

Coordinate legal notice, family communication, payer or partner duties and public statements so they do not contradict one another. Keep unauthorized details out of voicemail and unverified email. Support staff should have a short approved explanation and escalation route rather than improvising technical or legal conclusions.

Learn from near misses too

A wrong autofill recipient caught before sending, an abandoned export or a former employee whose access remained active may not become a notifiable breach. It can still reveal a weak control. Capture the event without punishing good-faith reporting and examine why the safeguard depended on luck.

Choose a correction that changes the system: safer sharing defaults, better recipient verification, smaller exports, automated deprovisioning or clearer vendor ownership. Confirm that the change works and does not create an inaccessible workaround. A privacy program improves when people can report small failures before families bear the consequences.

Rehearse the two-law decision

Imagine Ceiba Learning Partners, a fictional practice, discovers that a spreadsheet containing client names, medical information and insurance identifiers was available through an unrestricted link. The team disables the link, preserves access evidence, identifies Puerto Rico residents, data elements and the file's protection and involves qualified counsel and security support.

It runs Act 111 and HIPAA analyses separately, contacts the vendor and prepares family support without deciding from the filename alone that notice is or is not required. The team records the detection clock and any DACO, individual, HHS, payer or partner decision. The example predicts no legal conclusion or agency outcome.

Make privacy part of ordinary operating quality

The practical answer to ABA practice privacy and data breach requirements in Puerto Rico is a living record of data, access, vendors, safeguards and response decisions. It should help a clinician share what a caregiver needs, a biller submit a clean claim and an owner answer an incident without distributing more information than necessary.

Before publication or reliance, obtain current review from DACO and HHS guidance as applicable, qualified Puerto Rico and federal privacy and security counsel, technical and forensic leaders, relevant plans and partners, clinical and billing leaders, owner-operators, accessibility reviewers and affected stakeholders. Recheck the statutes, federal rules, systems and vendor promises at the date of use.

Related resources

Sources