To test ABA software accessibility and communication access, identify the real tasks clients, caregivers, and workers must complete, then test them with representative users, devices, assistive technologies, languages, and settings. Cover keyboard use, screen readers, zoom, contrast, captions, forms, errors, timeouts, cognitive load, AAC, alternate channels, support, and recovery. Record barriers, severity, workaround burden, owner, remediation, retest, and any safe alternative before release.

Define Eleni's software accessibility and communication access

Eleni tests complete workflows instead of isolated screens. A portal may pass a homepage scan while consent, scheduling, payment, document upload, or help remains unusable. Communication access includes the person's AAC, interpreter or language needs, preferred channel, wait time, and ability to ask questions, dissent, correct information, and receive urgent instructions.

Build the role-based accessibility test matrix

The register captures test ID; product, version and environment; user role and task; person affected; device, browser and assistive technology; language and communication mode; keyboard path; focus; name, role and value; headings; contrast and zoom; audio, video and captions; form label, instruction and error; timeout; cognitive and sensory load; AAC and alternate channel; support; expected completion; observed barrier; severity; workaround burden; owner; target; retest; and release disposition. Structured fields support routing, comparison, evidence expiry, monitoring, alerts, and validation. Narrative preserves clinical reasoning, client and family experience, accessibility, uncertainty, disagreement, legal deferral, source limits, and why an accountable owner approved, restricted, repaired, deferred, or rejected the item.

Run Eleni's workflow

Eleni recruits and compensates representative testers where appropriate, protects test data, defines task success in advance, and observes completion without coaching that ordinary users would not receive. Automated scans supplement hands-on tests. Product, configuration, content, support, device, and workflow defects stay separately attributable.

Protect the software accessibility and communication access boundary

Accessibility duties and standards depend on the entity, setting, service, and jurisdiction. Qualified specialists and counsel assess applicability. Clinical teams protect needed communication access. A workaround that requires an unaffiliated family member, removes privacy, or turns independent access into repeated staff assistance remains a material barrier.

Keep authority and evidence attributable

Eleni assigns every clinical, privacy, security, accessibility, technical, records, financial, workforce, and operational decision to the qualified owner. Software and vendors can surface evidence, automate an approved step, or propose an action. They cannot grant professional authority, accept the practice's risk, replace client involvement, or approve their own control effectiveness.

Keep unknowns, workarounds, and failures visible

Eleni records each unknown, assumption, exception, dependency, workaround, failed or skipped test, owner, deadline, escalation, and retest. Conditional approval states the exact scope, safeguard, operating restriction, evidence, expiry, and result if remediation misses its date. Raw failures stay in the denominator.

Work through Eleni's fictional example

Eleni locks 30 fictional user-task-technology cells across intake, consent, scheduling, clinical communication, billing, and support. Twenty-one pass initially. Two forms lose focus, one error is color-only, one video lacks captions, one timeout erases work, one AAC user cannot select an attachment, and three alternate-language tasks lack support. Six repair. Three remain blocked with accessible alternatives. The scenario is synthetic and tests workflow and denominator logic. It establishes no clinical, privacy, security, accessibility, contract, payer, employment, records, financial, or legal conclusion for a real person, practice, product, or vendor.

Calculate Eleni's measures honestly

Initial task passage is 21 of 30, or 70.0%. Twenty-seven cells reach accessible completion or a validated alternative, or 27 of 30, or 90.0%. Users, tasks, technologies, attempts, barriers, workarounds, and product versions retain separate denominators.

Address the main software accessibility and communication access risk

A single automated accessibility score can miss the point where a real user loses context, cannot recover an error, lacks AAC access, or must disclose private information to obtain help.

Test Eleni's control against hard cases

Eleni tests keyboard-only intake, screen-reader consent, 200% zoom, color independence, captioned training, plain-language error, timeout recovery, interpreter route, AAC upload, low bandwidth, alternate channel, and support escalation. Every case retains product and version, configuration, data, user, starting state, expected safeguard, observed result, defect, owner, retest, and disposition. Test passage applies only to the named configuration and conditions.

Run Eleni's independent acceptance test

Eleni gives a reviewer the task matrix, user and technology coverage, raw observations, defects, workarounds, fixes, and retests. The reviewer repeats one client, caregiver, and workforce task. A critical task with no usable route or a hidden coaching dependency fails.

Maintain the role-based accessibility test matrix

Eleni assigns a review cadence and change triggers for requirement, product, version, configuration, workflow, integration, vendor, subprocessor, data use, law, contract, incident, staffing, access, and ownership changes. This software accessibility and communication access page remains draft until every named external review finishes.

Use organizational guidance within its public scope

Eleni uses the CASP Organizational Guidelines public overview only for high-level business, clinical-operations, and risk-management context. CASP sells the detailed guidelines. The role-based accessibility test matrix is this article's editorial operating model; CASP has not approved the specific workflow or technology.

Map vendor and cloud roles from actual functions

Current HHS Business Associates guidance classifies roles by functions and data relationships, including subcontractors and exceptions. HHS cloud guidance explains that a cloud provider handling ePHI for a regulated customer can be a business associate even when it holds encrypted data without the key. Eleni records the actual role and agreement chain for the deployed system.

Keep the current Security Rule boundary visible

HHS risk-analysis guidance covers all ePHI a regulated entity creates, receives, maintains, or transmits. The current Security Rule page still identifies the January 2025 cybersecurity update as proposed as of August 19, 2026, so current eCFR text governs. The HHS guidance index provides current risk, remote-use, mobile-device, and ransomware resources. Eleni labels proposals and readiness ideas separately from operative requirements.

Apply current administrative, technical, and documentation safeguards

Current 45 CFR 164.308 supplies administrative-safeguard duties, 45 CFR 164.312 supplies technical-safeguard duties, and 45 CFR 164.316 supplies policy, procedure, documentation, and specified six-year retention rules. Eleni evaluates each applicable standard and implementation specification without claiming HIPAA requires one product, architecture, or control label.

Separate medical records, devices, and documentation retention

HHS states in its medical-record retention FAQ that HIPAA sets no general medical-record retention period. State and other sources often control those records, while HIPAA retains specified rule documentation. HHS's personal mobile-device page also explains that many personal-device health-data activities fall outside HIPAA's covered-entity and business-associate scope. Eleni maps entity, data, device, and record status instead of applying one rule everywhere.

Review consumer-health and AI promises separately

The FTC Health Breach Notification Rule guidance requires its own entity and qualifying PHR analysis. FTC staff also tells AI companies to uphold privacy and confidentiality commitments, including promises about model training and undisclosed uses. Eleni treats that post as enforcement-oriented staff guidance and checks other law, contracts, and settings independently.

Use voluntary frameworks as organizing aids

The NIST Cybersecurity Framework 2.0 organizes outcomes across Govern, Identify, Protect, Detect, Respond, and Recover. The NIST AI RMF page says AI RMF 1.0 is voluntary and being revised. NIST SP 800-34 Rev. 1 is final federal information-system contingency guidance that private practices may adapt. The OIG General Compliance Program Guidance is voluntary and nonbinding. Eleni uses them to organize accessibility-control ownership and recovery; none creates a legal safe harbor.

Test accessibility and communication in the real workflow

Eleni checks the DOJ Title III overview and web-accessibility guidance within their scopes. The ASHA AAC Practice Portal says AAC users should always have access to their communication tools. Testing covers real tasks, alternative channels, privacy, support, and the person's ability to ask questions, correct information, assent, dissent, and report a problem.

Related resources

Sources