An ABA practice subcontractor and fourth-party risk register identifies organizations a direct vendor relies on to deliver the practice's service. It records each dependency's service, data, access, location, contractual flow-downs, evidence, change notice, monitoring, incidents, concentration, continuity, replacement, and approval. The practice uses the register to understand extended risk while keeping its direct vendor accountable under the actual agreement.
Define material fourth-party dependencies
Elena distinguishes the practice's direct vendor, that vendor's subcontractor, and deeper service dependencies. She maps only relationships relevant to the scoped service rather than assuming every company in a vendor's supply chain touches practice data or operations. The extended-vendor dependency register has a named owner, purpose, audience, scope, sources, qualified decision boundaries, version, effective date, evidence, feedback route, change trigger, and retirement state.
Record service, data, access, location, and flow-down fields
Elena records direct vendor and service, fourth party and legal entity, dependency type, supplied function, systems and integrations, data classes and purposes, access and locations, onward providers, regulated role and contract flow-down, direct-vendor oversight, evidence and attestations, security and privacy controls, accessibility effect, service levels, change-notice terms, incident reporting, concentration and common dependency, continuity and alternatives, export and deletion, owner and risk tier, approval condition, exception, review, replacement, and exit evidence.
Use the register for scoped dependency decisions
Elena determines which dependency changes require notice, approval, diligence, configuration, contract action, client communication, or scope restriction. The direct vendor's use of a provider does not automatically make that provider the practice's direct contractor. Entity and business-associate relationships depend on actual roles and facts. Contract flow-downs and assurances support governance while the practice still evaluates operational consequence and its own duties.
Validate disclosures against observed dependencies
Elena reconciles vendor lists, contract schedules, product documentation, network and integration evidence, incident reports, support responses, data locations, and change notices. She tests whether the direct vendor can identify affected dependencies, provide required evidence, coordinate incidents, support export, and complete deletion. Common providers across several vendors receive concentration analysis. Unknown or changed fourth parties remain open until the responsible owner accepts, restricts, replaces, or exits the relationship.
Track changes, incidents, concentration, and exit
The register links every extended dependency to the direct vendor-service row and records evidence dates. Elena avoids claiming full visibility when the contract permits only categories or limited notice. Gaps receive a consequence-based decision. Monitoring watches material ownership, service, data, location, security, incident, and continuity changes. When a fourth party exits or fails, the practice validates the direct vendor's replacement and checks data return, deletion, access removal, integrations, and historical records.
Keep fourth-party evidence current
Elena assigns a source, owner, due date, acceptance result, and recheck trigger to every open condition. The record shows which service, people, data, systems, and downstream work are affected so the subcontractor and fourth-party risk register can be updated without broad assumptions.
Protect client access, continuity, and qualified authority
Elena keeps AAC, interpreters, accessible workflows, privacy, security, safety, continuity, and effective reporting routes within the design. Clients and workers can identify barriers and harmful effects. Clinical, payer, procurement, privacy, security, accessibility, insurance, contract, and legal decisions stay attributable to qualified roles. A vendor workflow never delays urgent action through an authorized emergency or reporting route.
Work through Elena's fictional example
Elena reviews 28 extended-dependency rows. Twenty have service, data, access, location, flow-down, evidence, notice, incident, continuity, and exit details. Two omit data locations, one lacks incident flow-down, two have stale evidence, one common dependency is unassessed, and two changes arrived late. Six rows are repaired. Two remain restricted. The scenario is synthetic. It tests scope, source, role, contract, access, data, version, use, evidence, and denominator logic without establishing clinical quality, legal compliance, payer approval, security, safe performance, vendor fitness, client satisfaction, or outcome.
Calculate the example measures
Initial extended-risk integrity is 20 of 28, or 71.4%. Twenty-six validate, or 92.9%. Direct vendors, services, fourth parties, data flows, locations, notices, incidents, and replacements keep separate counts.
Focus on dependencies that matter to the practice
A long subprocessor list can obscure which dependencies matter to the practice. Elena maps each one to the actual service, data, access, and failure consequence.
Test undisclosed services, late changes, incidents, and exit
Elena tests hosting provider, support contractor, analytics service, identity provider, data location change, late notice, incident flow-down, shared dependency, replacement, export, deletion, and direct-vendor exit. Each case states the source, qualified owner, affected users, access and safety conditions, expected evidence, exception, immediate safeguard, correction, validation, and next review.
Close review with unresolved work visible
Elena confirms scope, source currency, owners, qualified authority, contract, data and access, distribution, training, actual use, exceptions, incidents, continuity, validation, exit evidence, and open work. The subcontractor and fourth-party risk register remains draft until every named reviewer completes the required review.
Place dependency registers within organizational guidance
Elena uses the CASP Organizational Guidelines public overview for high-level business, clinical-operations, and risk-management context. CASP sells the detailed guidance. The public page does not prescribe this subcontractor and fourth-party risk register, approve a vendor, or establish clinical or legal authority.
Treat compliance guidance as voluntary control context
Elena treats the OIG General Compliance Program Guidance as voluntary and nonbinding. Its discussions of risk assessment, policies, training, reporting, auditing, corrective action, incentives, and oversight can inform vendor controls. Current law, program rules, contracts, and qualified owners control actual duties.
Preserve professional accountability
Elena applies the current BACB Ethics Code to covered people and professional activities. The Code addresses competence, responsibility, client involvement, documentation, supervision, risk, evaluation, billing, and reporting. BACB has no separate corporate jurisdiction. Vendor tools can support work while qualified professionals retain applicable judgment and accountability.
Classify HIPAA relationships before choosing agreements
Elena first uses HHS covered-entity guidance to classify the practice's role. HHS business-associate guidance explains that qualifying contractors and subcontractors handling PHI require appropriate agreements and safeguards. The classification depends on actual functions and data, so a vendor label or signed template alone cannot decide scope.
Apply cloud and agreement guidance to the actual service
HHS cloud guidance says a cloud provider that creates, receives, maintains, or transmits ePHI for a covered entity or business associate can be a business associate even without the decryption key. HHS sample agreement provisions illustrate permitted uses, safeguards, reporting, subcontractors, access, amendment, return or destruction, and termination terms. Elena still verifies the actual service, contract, configuration, and shared responsibilities.
Connect vendor controls to supply-chain risk
Elena uses the current HHS Security Rule page only for covered entities, business associates, and ePHI within scope. NIST SP 800-161 Rev. 1 Update 1 is federal cybersecurity supply-chain risk guidance that private practices may adapt. The FTC small-business cybersecurity guidance offers practical risk-reduction orientation. None of these sources certifies a vendor, service, outcome, or complete compliance.
Related resources
- Audit ABA Practice Vendor and Third-Party Governance
- ABA Practice Vendor Continuity and Exit Plan: Avoid Operational Lock-In
- ABA Practice Vendor Inventory: Services, Data, Access, and Owners
- ABA Practice Vendor Incident and Notification Playbook
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview
- HHS Office of Inspector General, General Compliance Program Guidance
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- U.S. Department of Health and Human Services, Covered Entities and Business Associates
- U.S. Department of Health and Human Services, Business Associates
- U.S. Department of Health and Human Services, Guidance on HIPAA and Cloud Computing
- U.S. Department of Health and Human Services, Sample Business Associate Agreement Provisions
- U.S. Department of Health and Human Services, The Security Rule
- National Institute of Standards and Technology, SP 800-161 Rev. 1 Update 1
- Federal Trade Commission, Cybersecurity for Small Business