To plan record custody after selling an ABA practice, map every record class to the responsible entity, the authority supporting transfer or continued access, its location, the retention rule, the permitted users, and the process for access, amendment, audit, legal hold, incident, export, and final disposal. Separate ownership, custody, control, and access; they are not synonyms. Confirm state, payer, professional, privacy, employment, tax, and transaction duties rather than assuming HIPAA supplies one universal retention period or that the buyer automatically receives every record.
Record custody is where the sale meets years of unfinished obligations
An ABA practice may hold clinical notes, assessments, treatment plans, raw data, authorizations, claims, remittances, supervision records, incident files, employee records, contracts, tax records, and years of communication. Some are active on closing day; others may be needed later for a family request, payer audit, professional review, refund, litigation hold, or correction.
For an owner asking how to plan record custody after selling an ABA practice, the hard part is not moving folders. It is making sure the right person can preserve and retrieve the right record for the right purpose after familiar roles and entities change. A clean plan protects access and accountability without giving the former owner, buyer, vendor, or deal team more information than its role permits.
Begin with record classes and responsible entities
Create a record map by legal entity, location, client or employee population, service period, record class, system, format, custodian, responsible professional, payer relationship, retention source, active hold, access group, and disposition. Include paper, email, messaging, portals, device storage, backups, exports, and vendor-hosted data.
The SBA sale guidance tells owners to plan the transfer carefully and account for assets and liabilities. It does not decide who owns or must retain an ABA record. Transaction counsel should align the record map with the sale structure. Privacy, security, clinical, HR, payer, tax, and records leaders should verify their facts and governing sources.
Ownership, custody, control, and access are different questions
A buyer may acquire an entity that remains the legal record holder, acquire assets that include certain records, or receive custody under another arrangement. A seller may need limited access for a retained liability, tax matter, audit, claim, or legal defense. A vendor may maintain data without owning it. A clinician may have professional duties without having unilateral permission to copy the entire chart.
Write each relationship plainly. Who is accountable to the person described in the record? Who answers a regulator or payer? Who may direct a vendor? Who can amend, export, place a hold, authorize destruction, or respond to an incident? Avoid a single column called “owner” when the answer changes by action and authority.
HIPAA does not create one medical-record retention period
HHS states in its medical-record retention FAQ that the HIPAA Privacy Rule does not set a medical-record retention period and that state laws generally govern how long medical records must be kept. It also says appropriate privacy safeguards apply while the records are maintained, including through disposal.
That distinction matters. HIPAA has documentation requirements for certain HIPAA materials, but those are not a universal answer for every clinical record. Build a retention matrix from the current state, payer, contract, professional, employment, tax, accreditation, litigation-hold, and other applicable sources for the actual record and entity. When two periods differ, qualified reviewers should decide the controlling or longer defensible rule rather than relying on a slogan such as “keep everything seven years.”
The transaction pathway for PHI is bounded
The health-care-operations definition in 45 CFR 164.501 includes certain sale, transfer, merger, consolidation, and due-diligence activity when its conditions are met. That route does not make PHI an ordinary commercial asset or authorize disclosure to any recipient the parties choose.
Confirm whether the seller and buyer fit the transaction provision, what part of the covered entity is involved, which records are necessary, and what other federal or state protections apply. Preserve separate analysis for specially protected records. A purchase agreement can describe the intended transfer, but it cannot create privacy authority that the law withholds.
Client rights must survive the organization chart
The HHS Privacy Rule summary explains rights involving access and, in applicable circumstances, amendment and accounting. Plan a durable intake route for clients and personal representatives before changing domains, phone numbers, portals, addresses, or staff. Decide who receives a request, verifies identity and authority, locates the designated record set, coordinates review, communicates timing, and records the response.
Families should not have to understand the acquisition structure to find their records. If responsibility changes, prepare accurate notices and routing under qualified legal review. Keep the former route alive long enough to catch misdirected requests. A forwarding message without an accountable custodian can leave a family circulating between buyer, seller, and vendor.
Clinical and professional records need qualified stewardship
Treatment records, raw data, supervision materials, incident reviews, assessments, authorizations, and transition notes may carry different professional and organizational duties. Qualified clinical leaders should define how records remain complete, interpretable, and available for ongoing care without turning transaction personnel into clinical reviewers.
The BACB Ethics Code applies to certificants within its scope and addresses documentation, confidentiality, supervision, continuity, and client welfare. The CASP organizational-guidelines overview offers a public cross-functional frame. Neither source assigns legal custody or supplies a universal retention period. Preserve clinical authorship, corrections, late entries, version history, and decision context through the migration.
Claims and payer records do not end when the last claim is sent
Open claims, authorizations, remittances, refunds, audits, appeals, coordination-of-benefits issues, and payer correspondence can remain active for months or years. Map which entity billed, which account receives payment, who can enter each portal, who responds to a record request, and who bears each retained or assumed obligation under the documents.
CMS's current provider enrollment guidance describes federal enrollment and ownership-change reporting for providers and suppliers in its scope, while its NPI page explains identifiers at a general level. Neither source decides an ABA payer contract, claim, or record-custody question. Keep payer evidence attached to the person, entity, location, service, and date that created it.
Vendors need instructions that match the post-close relationship
EHR, billing, payroll, messaging, storage, clearinghouse, backup, scanning, and analytics vendors may hold copies or control critical exports. Inventory the contract, customer entity, user roles, subprocessor or subcontractor chain, data locations, export formats, retention behavior, termination path, and support access. Do not assume a vendor account can simply be renamed.
HHS business-associate guidance explains written safeguards for certain relationships involving PHI. Decide whether an agreement is assigned, replaced, terminated, or temporarily supports one party for another. Align permissions and instructions with that result. A vendor should not receive contradictory orders from the former owner and buyer after close.
Security planning should include the quiet months after migration
The current HHS Security Rule summary describes safeguards for electronic PHI and documentation duties within its scope. For the transaction, map identity providers, administrators, service accounts, backups, encryption, logs, device copies, incident routes, disaster recovery, and vendor access. Then remove access as each legitimate purpose ends.
Archived systems can become invisible risk. A read-only server still needs an owner, patches or isolation, authentication, monitoring, backup testing, and a retirement decision. Test retrieval from the archive before relying on it. Deleting the familiar production system before proving the export is usable can turn an orderly sale into years of manual reconstruction.
A fictional request tests the custody map
Willow Thread Behavior Services is fictional. Six months after an asset sale, a parent asks for older treatment records and a payer opens an audit on claims billed under the seller's tax ID. The buyer has current charts, the seller retained a locked archive, and the migration vendor holds an export nobody has tested. Each party initially points to another.
The custody map identifies the responsible entity, request channel, authorized reviewer, archive owner, payer response lane, and access boundary. The team retrieves the record, preserves the audit hold, and corrects its forwarding instructions. The example does not decide record ownership or retention law. It shows why custody must be testable after the deal team has gone home.
End seller access deliberately, not emotionally
A former owner may feel responsible for clients and want to keep broad access “just in case.” Good intentions are not authority. Define each retained purpose, record class, user, approval, duration, log, and termination event. Use a restricted request process where ongoing direct access is unnecessary.
The practical result of how to plan record custody after selling an ABA practice is a verified record map, retention matrix, request route, hold register, vendor instruction set, access ledger, tested archive, migration reconciliation, incident plan, and final-disposition schedule. Review it after the first request, audit, and system retirement. The plan has worked when people can retrieve what they are entitled to without recreating the old practice around the former owner's login.
Related resources
- How to Prepare Contract Assignments and Consents for an ABA Practice Sale
- Plan Technology and Data Integration for an ABA Acquisition
- How to Build a Deal Data Room for an ABA Practice Sale
- ABA Practice Change of Ownership Payer Transition Plan
Sources
- U.S. Small Business Administration, Close or Sell Your Business
- eCFR, 45 CFR 164.501 Definitions
- HHS, Business Associates
- HHS, HIPAA and Medical Record Retention FAQ
- HHS, Summary of the HIPAA Privacy Rule
- HHS, Summary of the HIPAA Security Rule
- Centers for Medicare & Medicaid Services, Become a Medicare Provider or Supplier
- Centers for Medicare & Medicaid Services, National Provider Identifiers
- HHS Office of Inspector General, General Compliance Program Guidance
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- Council of Autism Service Providers, Organizational Guidelines public overview
- Finni, Provider Program