An ABA schedule outage recovery process uses a secured, current offline roster and approved downtime workflow to continue or safely pause scheduling when the primary system fails. It limits access, verifies each visit's essential gates, records changes and actual service, communicates through approved channels, and keeps billing on hold until recovery reconciliation. Technical availability is only one recovery milestone; accepted data integrity closes the event.
Define activation and stop authority
Record outage detection, affected systems, incident owner, scheduling lead, clinical escalation, privacy and security route, activation time, services allowed in minimum operating mode, and stop conditions. Immediate safety and emergency processes remain available.
Prepare a secured offline roster
Include only current purpose-needed fields such as visit ID, client and contact route, service, time, staff, supervisor, setting, communication and safety information needed for the event, and source as-of time. Restrict access, approve storage and transmission, and test retrieval.
Apply privacy and clinical gates
For HIPAA covered entities and business associates, the HHS Security Rule page describes safeguards for electronic protected health information. The BACB Ethics Code addresses confidentiality, risk, competence, and documentation for covered professionals. Verify the applicable rules and roles.
Communicate and document downtime
Use approved channels and accessible formats informed by DOJ effective-communication guidance where applicable. Record actual service time, staff, location, changes, author, creation time, and reconciliation state. Preserve temporary records and the original schedule history.
A fictional outage
Cypress Hill ABA has 18 visits during a scheduling outage. Fourteen clear the offline gates and proceed, three are postponed because current information cannot be verified, and one is canceled by choice. Disposition completeness is 18 of 18. All 14 potential charges remain held until authenticated records reconcile.
Define recovery acceptance
Validate platform integrity and access, reconcile every expected visit and downtime record, resolve conflicts, restore notifications, verify timekeeping, and retain incident evidence. Track visits accounted for, records reconciled, open corrections, communication failures, and recovery duration from defined events.
Prepare before an outage
Inventory scheduling, clinical-record, messaging, timekeeping, authorization, identity, and access-control dependencies. Define outage scenarios, alternate tools, protected contact tree, approved devices, minimum data, owners, vendor routes, and recovery acceptance. Test access without exposing live sensitive information unnecessarily.
Keep the offline roster current through a controlled process with an as-of time, version, encryption or other approved protection, and removal schedule. A stale backup can create false confidence.
Use clear incident and visit states
Track detected, triage, activated, minimum operating mode, visit review, proceed, postpone, cancel, changed, record captured, platform restored, reconciliation, and closed. Each state needs an owner, timestamp, evidence, and next action.
Separate the technology incident from each visit disposition. A platform can return while records remain incomplete, and individual visits can be resolved before the underlying incident closes.
Define minimum safe operating mode
List the services and settings that may proceed, required client-specific safety and communication information, qualified staff, supervision, access supports, documentation route, and stop conditions. A qualified clinician decides case-specific clinical readiness within scope. Operations verifies the approved gates.
When current information cannot be verified, use the defined safe hold or postponement route. Do not reconstruct essential details from memory or an unapproved personal copy.
Control schedule changes during downtime
Assign a stable downtime event ID and record every proposed, approved, communicated, and actual change. Avoid maintaining competing spreadsheets or message threads without a reconciliation owner. Give staff and families one current source and a correction channel.
Preserve who made each operational or clinical decision. A coordinator can document and route a change without becoming the author of clinical content or payer authority.
Protect temporary records
Use approved forms and devices, role-based access, secure storage and transmission, and an audit trail. Record actual service time and actual entry time. Preserve authorship, late entries, corrections, and source reconciliation under applicable rules.
If the outage may involve a security or privacy event, activate that qualified response route in parallel. The scheduling recovery team should not delay containment or decide breach obligations on its own.
Use a recovery acceptance checklist
Account for every expected visit; reconcile schedules, downtime records, staff time, notifications, authorization usage, clinical entries, charges, and held claims; validate user access and platform integrity; resolve duplicates and conflicts; and document approval to return to normal work. Keep unresolved items open.
Technical availability is a milestone. Recovery closes when defined evidence is complete or every remaining exception has an accountable owner and approved containment.
Exercise the workflow
Run tabletop and technical tests across sites, shifts, and outage types with an unavailable leader. Test roster retrieval, role access, safe-stop decisions, accessible communication, schedule changes, downtime documentation, vendor escalation, platform recovery, and full reconciliation.
Avoid exercises that disclose real client information to unauthorized participants. Record failed steps, owners, due dates, retest results, and changes to the plan or training.
Measure outage performance
Define activation latency from detection to recorded activation, visits accounted for divided by expected visits, usable communications completed by target, reconciled records divided by expected records, and corrective actions closed by due date. State each clock and denominator.
Report safety or privacy events, service loss, paid work, claim holds, duplicate records, access failures, and oldest unresolved item. Fast restoration does not offset missing evidence or an unsafe decision.
Reconcile every offline change as an event
Give each downtime addition, change, cancellation, confirmation, outreach, staff assignment, and clinical or payer hold a temporary identifier, recorded time, effective time, source, author, affected visit, and approval evidence. Avoid editing the printed or exported starting roster without a legible event trail. If two people record conflicting changes, preserve both and hold downstream action until the assigned owner resolves the current version.
At restoration, import or enter events in controlled batches. Match temporary identifiers to system records, detect duplicates, preserve original times and authorship, and compare client-facing and staff-facing outcomes. Reconcile notices, schedules, documentation, payroll, authorization worklists, and any claim holds. A platform becoming reachable does not prove that offline work is complete or correctly represented.
Return functions in controlled layers
Define acceptance for identity, schedule read access, change entry, communications, clinical records, payer work, payroll, interfaces, reporting, and archives. Release only functions whose ordinary and failure tests pass, and keep an approved fallback for the rest. Tell staff which source controls during each layer so old offline lists and restored screens do not compete silently.
Owner outage-recovery questions
- Are activation, incident command, minimum safe mode, privacy, and stop authority clear?
- Is the offline roster current, secured, accessible to authorized roles, and usable for communication needs?
- Can every downtime event be traced without erasing or duplicating the original visit?
- Are clinical, payer, workforce, safety, and access decisions retained with their proper owners?
- Does recovery require authenticated reconciliation and domain acceptance rather than platform availability?
- Has the practice exercised loss of the primary system and communication channel together?
Related resources
- ABA Client Start-Date Forecast
- ABA Coverage Gap Aging Report
- ABA Weekly Capacity Forecast
- ABA Schedule Fairness Audit