To use synthetic and de-identified data in ABA software testing, record each data set's origin, generation method, owner, intended tests, identifiers, residual reidentification risk, restrictions, access, reuse, retention, and deletion. Prefer purpose-built fictional cases when they can exercise the requirement. When real-source data is needed, use a documented lawful pathway and the practice's recognized de-identification method rather than assuming that removed names or a synthetic label solve the risk.

Define Nolan's test-data provenance and approval register

Nolan separates fictional data created without real client information, synthetic data derived through a process that may use real inputs, and data de-identified under a documented method. These categories have different provenance and risk. A realistic narrative copied from a record can still contain sensitive details even after names are replaced.

Build a decision-ready record

The test-data provenance and approval register records data-set ID, owner, origin, source systems, real-person relationship, creation or transformation method, HIPAA status and method when relevant, expert documentation or Safe Harbor evidence, residual risk, other-law and contract restrictions, purpose, fields, realism gaps, access, environment, reuse, linkage prohibition, refresh, retention, deletion, approval, and validation. Structured fields support routing, comparison, alerts, expiry, and validation. Narrative preserves workflow context, person and family experience, clinical and operational impact, uncertainty, disagreements, source limits, failed tests, and why the accountable owner approved, restricted, repaired, deferred, or rejected the item.

Run the operating workflow

Nolan begins with the exact test cases and generates the smallest fictional data set that can exercise them. If real-source information is proposed, privacy and data owners review purpose, method, anticipated recipients, combinations, and restrictions. Testers receive only approved fields. Results document which edge cases the data cannot represent, and expired sets are removed from every environment.

Keep authority and technical capability separate

HHS recognizes Expert Determination and Safe Harbor as HIPAA de-identification methods. Safe Harbor requires the specified removals plus no actual knowledge that remaining information can identify the person. Proper de-identification retains a very small, nonzero risk, and other law or contracts can still apply. The word synthetic is not a HIPAA status.

Protect care, communication, and required records

Nolan maps any effect on client safety, health information, clinical work, communication and AAC, access, records, authorizations, claims, payroll, and family contact. Technical work proceeds beside emergency and incident duties. A qualified clinician decides whether care can proceed after a material technology failure; other accountable owners decide within their domains.

Keep failures and unknowns in view

Nolan records every failed or skipped test, unknown asset or flow, workaround, vendor case, dependency, owner, due date, escalation, retest, and expiry. Conditional approval states the exact scope, safeguard, restriction, evidence, and stop condition. Open work stays in the locked denominator.

Work through a fictional practice example

Nolan locks 20 fictional test data sets. Fourteen have provenance, purpose, method, residual-risk decision, access, restrictions, reuse, and deletion evidence. One copied narrative retains a rare event, one synthetic set has unknown training inputs, one Safe Harbor file lacks the knowledge check, one set combines with a lookup table, and two have no owner. Four repair; two are destroyed. This synthetic scenario tests workflow and denominator logic. It establishes no clinical, privacy, security, legal, accessibility, payer, employment, contract, or product conclusion for a real practice or person.

Measure the locked cohort

Nolan's initial readiness is 14 of 20, or 70%. Report all 20 test data sets due, the review date, unresolved reasons, and age of open work. Data sets, records, fields, flows, users, systems, events, tests, findings, and remediation attempts retain separate denominators.

Test the hard failure modes

Nolan tests fictional edge case, rare event, date field, geographic field, free text, image, audio, linked table, model-generated case, vendor test, export, reuse, expiry, and deletion. Each case preserves the system and version, starting state, data, user or process, expected control, observed result, evidence, defect, owner, retest, and disposition. Passage applies only to the named configuration and conditions.

Address the main operating risk

Test teams can expose real people by copying convenient production records, replacing only direct names, combining data sets, or retaining realistic narratives and exports indefinitely.

Require independent acceptance

Nolan gives an independent reviewer the locked scope, source map, configuration, raw evidence, tests, failures, approvals, monitoring, remediation, and closure proof. The reviewer reproduces one ordinary case and one failure. A changed cohort, missing record, hidden manual repair, or result dependent on an undocumented step fails acceptance.

Anchor the workflow in current healthcare duties

Nolan uses the CASP public organizational overview only for high-level business, clinical-operations, and risk context. HHS risk-analysis guidance covers all ePHI a regulated entity creates, receives, maintains, or transmits. The current Security Rule page still labels the January 2025 cybersecurity update proposed, so operative requirements and future readiness ideas stay separate.

Distinguish binding duties from voluntary frameworks

Current 45 CFR 164.308 supplies administrative-safeguard duties and 45 CFR 164.312 supplies technical-safeguard duties. The HHS Healthcare Cybersecurity Performance Goals are voluntary healthcare priorities, and NIST CSF 2.0 is a voluntary outcome framework. Nolan cites the exact source for each control rather than converting guidance into a general legal requirement.

Apply the page-specific sources within their scope

Nolan's additional sources are U.S. Department of Health and Human Services, Guidance Regarding Methods for De-identification of PHI, National Institute of Standards and Technology, Privacy Framework Version 1.0, National Institute of Standards and Technology, Privacy Framework Version 1.1 Project, National Institute of Standards and Technology, SP 800-218 Secure Software Development Framework Version 1.1, National Institute of Standards and Technology, SP 800-53 Rev. 5 Security and Privacy Controls. They support the page's data, software, privacy, vendor, record, or technical boundaries. NIST federal-system guidance can inform a private practice, while current HHS regulations and applicable law, contracts, professional duties, and deployed facts control their own domains.

Preserve the test data's provenance

Nolan records whether a dataset was invented without real inputs, generated from aggregate patterns, transformed from identifiable records, or de-identified under an approved method. Those categories do not become interchangeable because a file is labeled synthetic. The record identifies the source population, transformation or generation process, prohibited joins, residual re-identification concern, approved uses, recipients, environment, retention, and deletion evidence. A privacy or legal conclusion about HIPAA de-identification comes from the authorized method and facts, not from the software team. Before reuse for a new test or model, the owner rechecks whether the purpose, data combination, vendor, output, and access population remain within the approval. Rare combinations, free text, dates, images, and small cohorts receive explicit review because they can carry identifying information even when ordinary identifiers are absent.

Maintain the control after release

Nolan assigns a review cadence and triggers for systems, data, versions, configurations, users, vendors, subprocessors, workflows, integrations, incidents, law, contracts, and ownership. Urgent response proceeds immediately. This page remains draft until the named technology, privacy, security, clinical, accessibility, records, and legal reviewers complete their work.

Related resources

Sources