To build ABA identity matching and duplicate record controls, define the identifiers and demographic fields used for each context, preserve their sources, and route exact, possible, and conflicting matches differently. Require trained review before a merge, protect clinical and legal distinctions, retain both original record identities and change history, and provide an unmerge or correction route. Reconcile schedules, notes, authorizations, claims, portal access, consents, and reports after every approved resolution.
Define Ximena's identity-match and duplicate-resolution register
Ximena distinguishes two errors. A false positive joins different people, while a false negative leaves one person split across records. A duplicate candidate is evidence for review, not permission to merge. Matching thresholds vary by source quality, purpose, system, and consequence, so the register keeps the score, attributes, conflicts, and reviewer decision visible.
Build a decision-ready record
The identity-match and duplicate-resolution register records candidate ID, record IDs, systems, match trigger, algorithm and version, compared attributes, source and freshness, exact matches, conflicts, missing fields, score, threshold, risk class, reviewer, authority evidence, client or representative contact when appropriate, decision, surviving field source, linked records, merge steps, preserved history, downstream propagation, access effect, unmerge route, validation, incident link, and closure. Structured fields support routing, comparison, alerts, expiry, and validation. Narrative preserves workflow context, client and family experience, clinical and operational impact, uncertainty, disagreements, source limits, failed tests, and why the accountable owner approved, restricted, repaired, deferred, or rejected the item.
Run the operating workflow
Ximena improves collection and lookup before changing thresholds. New registrations search current and historical identifiers without forcing a match. Candidate pairs enter a work queue with no automated clinical or legal conclusion. Reviewers compare source evidence and relevant context, resolve field ownership, and approve link, merge, separate, or defer. Post-action checks cover every dependent system and user-facing portal.
Keep authority and technical capability separate
ONC describes patient matching as identifying and linking one person's data within and across systems and emphasizes multiple demographic fields. Its framework supplies general healthcare methods rather than a universal algorithm or threshold. Legal names, preferred names, family relationships, payer identities, and portal authority remain separate facts with separate sources.
Protect care, communication, and required records
Ximena maps any effect on client safety, health information, clinical work, communication and AAC, access, records, authorizations, claims, payroll, and family contact. Technical work proceeds beside emergency and incident duties. A qualified clinician decides whether care can proceed after a material technology failure; other accountable owners decide within their domains.
Keep failures and unknowns in view
Ximena records every failed or skipped test, unknown asset or route, workaround, vendor case, dependency, owner, due date, escalation, retest, and expiry. Conditional approval states the exact scope, safeguard, restriction, evidence, and stop condition. Open work stays in the locked denominator.
Work through a fictional practice example
Ximena locks 36 fictional candidate pairs. Twenty-eight have source fields, algorithm version, conflicts, reviewer, decision, preserved history, downstream checks, and correction route. One pair shares a twin's birth date, one legal-name change fragments a record, one household phone joins two clients, and five candidates lack current source evidence. Three resolve; five remain open. This synthetic scenario tests workflow and denominator logic. It establishes no clinical, privacy, security, legal, accessibility, payer, employment, contract, or product conclusion for a real practice or person.
Measure the locked cohort
Ximena's initial readiness is 28 of 36, or 77.8%. Report all 36 candidate record pairs due, the review date, unresolved reasons, and age of open work. Systems, records, fields, users, events, attempts, tests, findings, and remediation actions retain separate denominators.
Test the hard failure modes
Ximena tests twins, shared household contact, legal-name change, preferred name, transposed birth date, reused email, payer ID change, foster placement, deceased duplicate, cross-clinic record, merge reversal, and downstream correction. Each case preserves the system and version, starting state, data, user or process, expected control, observed result, evidence, defect, owner, retest, and disposition. Passage applies only to the named configuration and conditions.
Address the main operating risk
An aggressive merge can place another person's clinical information, billing, messages, or portal access into the wrong record. A timid process can hide fragmented history and duplicate services or claims.
Require independent acceptance
Ximena gives an independent reviewer the locked scope, source map, configuration, raw evidence, tests, failures, approvals, monitoring, remediation, and closure proof. The reviewer reproduces one ordinary case and one failure. A changed cohort, missing record, hidden manual repair, or result dependent on an undocumented step fails acceptance.
Anchor the workflow in current healthcare duties
Ximena uses the CASP public organizational overview only for high-level business, clinical-operations, and risk context. HHS risk-analysis guidance covers all ePHI a regulated entity creates, receives, maintains, or transmits. The current Security Rule page still labels the January 2025 cybersecurity update proposed, so operative requirements and future readiness ideas stay separate.
Distinguish binding duties from voluntary frameworks
Current 45 CFR 164.308 supplies administrative-safeguard duties and 45 CFR 164.312 supplies technical-safeguard duties. The HHS Healthcare Cybersecurity Performance Goals are voluntary healthcare priorities, and NIST CSF 2.0 is a voluntary outcome framework. Ximena cites each additional source within its actual scope.
Apply the page-specific sources within their scope
Ximena's additional sources are Office of the National Coordinator for Health Information Technology, Patient Identity and Patient Record Matching, Office of the National Coordinator for Health Information Technology, Patient Demographic Data Quality Framework: Data Quality Assessment, Office of the National Coordinator for Health Information Technology, Patient Demographic Data Quality Framework: Data Lifecycle Management, National Institute of Standards and Technology, SP 800-53 Rev. 5 Security and Privacy Controls. They support the page's architecture, data, software, identity, remote-access, network, protocol, or capacity boundaries. Federal and consensus guidance can inform a private practice, while current law, contracts, professional duties, vendor terms, and deployed facts control their own domains.
Resolve a possible duplicate without guessing
Ximena routes uncertain matches to trained human review and keeps both records restricted from destructive merging until identity is supported. The reviewer compares approved demographic and contextual evidence, records which fields agree or conflict, and avoids using a convenient but unreliable attribute as a universal identifier. A qualified clinical or records owner decides how conflicting care information should be reconciled; the matching tool does not make that judgment. Merge approval names the surviving identity, fields retained, relationships moved, downstream systems, notifications, and rollback or correction path. The original records and audit trail remain recoverable according to applicable rules. After resolution, Ximena verifies permissions, schedules, authorizations, notes, billing, portals, communications, and integrations for both identities. False-positive and false-negative samples are measured separately, with the reviewed population and time window stated, because one overall accuracy percentage can conceal the more harmful failure mode.
Maintain the control after release
Ximena assigns a review cadence and triggers for systems, data, versions, configurations, users, vendors, subprocessors, workflows, integrations, incidents, law, contracts, and ownership. Urgent response proceeds immediately. This page remains draft until the named technology, privacy, security, clinical, accessibility, records, and legal reviewers complete their work.
Related resources
- Control Remote Vendor Support Access to ABA Systems
- Validate ABA Data Imports Before Release
- Plan ABA Technology Maintenance Windows and Change Freezes
- Manage ABA Software Technical Debt and End-of-Life Risk
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview
- U.S. Department of Health and Human Services, Guidance on Risk Analysis
- U.S. Department of Health and Human Services, HIPAA Security Rule
- Electronic Code of Federal Regulations, 45 CFR 164.308 Administrative Safeguards
- Electronic Code of Federal Regulations, 45 CFR 164.312 Technical Safeguards
- U.S. Department of Health and Human Services, Healthcare Cybersecurity Performance Goals
- National Institute of Standards and Technology, Cybersecurity Framework 2.0
- Office of the National Coordinator for Health Information Technology, Patient Identity and Patient Record Matching
- Office of the National Coordinator for Health Information Technology, Patient Demographic Data Quality Framework: Data Quality Assessment
- Office of the National Coordinator for Health Information Technology, Patient Demographic Data Quality Framework: Data Lifecycle Management
- National Institute of Standards and Technology, SP 800-53 Rev. 5 Security and Privacy Controls