To respond to AI errors data exposure and unsafe actions in ABA practices, protect people and continuity first, then stop the affected action path while preserving evidence. Reconstruct every exposed record, output, recipient, decision, and downstream effect; route privacy, security, clinical, payer, billing, employment, and legal questions to their owners; correct affected work; validate recovery; and monitor the repaired path for recurrence.
Recognize more than one incident type
Juno distinguishes an inaccurate output, unsafe recommendation, wrong-client content, unauthorized disclosure, prompt-injection success, prohibited tool action, inaccessible interaction, biased pattern, model or source drift, missing approval, logging failure, and vendor outage. One event may enter several response routes. The internal AI incident label helps coordination; it does not decide whether an event is a HIPAA security incident, breach, clinical safety event, payer issue, or legal violation.
Protect people and continuity first
Address immediate danger through the practice's emergency and safety procedures. Give clinicians accurate source information needed for safe care. Stop the affected model, prompt, retrieval source, tool, integration, user group, or action while an approved fallback continues. Preserve accessible communication and AAC. Technical staff can contain systems; an appropriately qualified clinician decides whether and how clinical services proceed after a material failure.
Preserve evidence without spreading it
Capture timestamps, reporter, use case, user, client or record reference, model and prompt version, retrieved sources, input provenance, output, tool calls, approvals, edits, logs, recipients, downstream actions, and current containment. When a vendor performs functions involving PHI, current HHS business-associate guidance informs the role and agreement analysis. Restrict the evidence to authorized responders. Do not paste PHI or secrets into an unapproved ticket, chat, or model. Avoid destructive reimaging or log deletion until the response lead authorizes it.
Lock the exposure cohort
Query every case that could share the model, configuration, prompt, corpus, date range, user, vendor route, attack pattern, or downstream action. Record included, excluded, unknown, and unresolved cases with reasons. Trace each output to records, plans, messages, authorizations, claims, schedules, payments, and other decisions that used it. A spot check of the originally reported record cannot establish the full exposure.
Classify privacy and security duties
Current 45 CFR 164.308 requires a regulated entity to identify and respond to suspected or known security incidents, mitigate known harmful effects to the extent practicable, and document incidents and outcomes. The HHS Breach Notification Rule concerns breaches of unsecured PHI and includes its definition, exceptions, and low-probability assessment route. Apply each federal, state, contract, payer, insurer, licensing, and vendor clock separately while response continues.
Correct records and downstream work
The qualified author corrects a clinical or business record under the applicable policy, preserving original content, authorship, dates, reason, and audit trail. Other owners determine authorization, claim, refund, disclosure, employment, or contract consequences. Notify affected recipients and people through the required or approved route. A corrected AI output does not silently rewrite a signed record or prove that every downstream effect is resolved.
Coordinate accurate communications
Build one event timeline and one approved fact set for internal leaders, staff, affected people, vendors, payers, insurers, regulators, and other recipients. Each owner determines whether communication is required, permitted, or useful under the applicable source. State what happened, what remains unknown, immediate protections, available support, and the next update time. Preserve accessibility, language, confidential-contact, and representative requirements. Avoid speculation about cause or impact before the evidence supports it, while meeting every applicable notice clock. Use a communication log to record the audience, authority, approved content, channel, accessibility support, delivery state, owner, and next update. Record unsuccessful delivery attempts, escalation, and resolution.
Find the control failure
Test source data, retrieval, prompt, model behavior, vendor change, interface, access, tool validation, approval, workload, monitoring, and training. Separate initiating event from conditions that allowed impact. NIST's final SP 800-61 Rev. 3 integrates incident response across CSF 2.0 functions. Its scope is general cybersecurity guidance; AI, HIPAA, and ABA requirements remain separate. The voluntary AI RMF Manage Playbook adds AI-specific response and recovery suggestions.
Validate return to service
Recovery requires more than technical availability. Reproduce the defect, show that the repair blocks it, run ordinary and adjacent failure cases, verify access and logs, reconcile affected records and actions, and confirm the fallback can end safely. An independent reviewer checks the evidence. Known limitations, temporary controls, open corrections, and monitoring thresholds stay visible after release.
Work through a locked incident cohort
Juno locks 16 fictional AI incidents due for initial containment review. Twelve meet the defined target with the affected action stopped, evidence preserved, exposure query opened, owners assigned, and continuity protected: 12 of 16, or 75%. One wrong-client event continued through a retry, one vendor event lacks raw logs, one unsafe action has no identified stop owner, and one incident was mislabeled as a harmless model error before privacy review.
Measure response and recurrence
Report time from detection to triage, containment, affected-cohort lock, correction, required communication, recovery acceptance, and closure. Count incidents due, contained, reopened, recurred, and overdue. Keep people, records, outputs, recipients, actions, and notifications as separate denominators. Close only when required evidence, corrections, communications, recovery tests, residual decisions, and monitoring are complete.
Support affected people through correction
An incident response should give affected clients, families, staff, or partners a usable route to ask questions, correct information, report additional impact, and request accessible communication. Juno separates what the practice knows from what remains under review and gives a named contact plus the next update time. Clinical, privacy, security, payer, employment, and legal owners approve statements within their authority while the response team keeps one consistent event timeline.
Correction may require more than sending a notice. A person may need an amended record, a repeated authorization review, a restored appointment, a billing explanation, language assistance, or a different communication channel. Record the requested remedy, authority, owner, due date, delivery evidence, and unresolved concern. The incident cannot be closed merely because the technical system is available again.
Maintain a post-incident action register
Translate each root cause and contributing condition into a specific action with an accountable owner, evidence requirement, deadline, validation method, and recurrence measure. Distinguish immediate containment, permanent control repair, affected-work reconciliation, training, vendor action, contract change, monitoring, and accepted residual risk. A broad promise to improve AI governance is not a testable corrective action.
At the closure review, an independent participant samples completed actions and traces them back to the event. Verify that temporary controls have either ended safely or received a new approved expiry, and that similar workflows were assessed for the same weakness. Keep open actions visible after the incident record moves out of active response so overdue remediation cannot disappear from leadership review.
Ask closure questions before ending active response
- Is every affected person, record, output, recipient, decision, and action accounted for?
- Did each qualified owner complete the required classification and correction?
- Were required communications delivered through accessible, approved routes?
- Does the repaired path pass the original failure plus neighboring cases?
- Are residual risks, temporary controls, open actions, and recurrence signals assigned?
- Can the practice explain the event and response from preserved evidence?
If any answer remains unknown, classify the open state and keep an owner and due date. Closure can occur in phases, but uncertainty should remain visible to the leaders and affected roles responsible for the residual work.
Related resources
- Build an ABA AI Use-Case Inventory and Risk-Tiering System
- Secure AI Agents and Autonomous Actions in ABA Operations
- Validate an AI Model or Vendor Before ABA Production Use
- Govern AI Model, Prompt, and Retrieval Changes in ABA Systems
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview
- National Institute of Standards and Technology, AI Risk Management Framework
- National Institute of Standards and Technology, AI RMF Core
- National Institute of Standards and Technology, AI RMF Playbook Manage function
- National Institute of Standards and Technology, Generative AI Profile
- National Institute of Standards and Technology, SP 800-61 Rev. 3 Incident Response Recommendations
- Electronic Code of Federal Regulations, 45 CFR 164.308 Administrative Safeguards
- U.S. Department of Health and Human Services, Breach Notification Rule
- U.S. Department of Health and Human Services, Business Associates