Section 2.3: Confidentiality, HIPAA, and Client Record Keeping
Key Takeaways
- Protected Health Information (PHI) encompasses any individually identifiable health information created, received, or stored in physical or electronic formats.
- The HIPAA Minimum Necessary Rule mandates that technicians access and disclose only the minimum amount of PHI required to accomplish direct clinical duties.
- Written Releases of Information (ROI) signed by legal guardians are required before sharing client data with outside entities, including schools, medical providers, or relatives.
- Session notes must follow objective documentation standards (e.g., SOAP format), omitting emotional bias, subjective opinions, or unverified claims.
Section 2.3: Confidentiality, HIPAA, and Client Record Keeping
Exam Core: Federal health privacy law under the Health Insurance Portability and Accountability Act (HIPAA) governs how ABAT technicians handle client data. Technicians must safeguard Protected Health Information (PHI) across all physical, verbal, and electronic mediums. Maintaining absolute confidentiality requires strict adherence to the Minimum Necessary Rule, secure data transmission protocols, and objective clinical record-keeping.
Fundamental Provisions of HIPAA Privacy and Security Rules
HIPAA legislation establishes statutory rules to protect patient health data while maintaining high-quality healthcare delivery:
- Privacy Rule: Regulates the use and disclosure of Protected Health Information (PHI) held by covered entities (healthcare providers, agencies, billing clearinghouses). It grants clients and legal guardians the right to inspect records and request corrections.
- Security Rule: Establishes national standards for protecting electronic PHI (ePHI). It mandates administrative, physical, and technical safeguards (e.g., encryption, password protection, auto-lockout timers) to ensure data confidentiality, integrity, and availability.
- Breach Notification Rule: Requires agencies to report unauthorized acquisition, access, use, or disclosure of unencrypted PHI to affected clients, the U.S. Department of Health and Human Services (HHS), and potentially media outlets within strict statutory timeframes.
Defining Protected Health Information (PHI) & The Minimum Necessary Rule
What Constitutes PHI?
PHI includes any information—whether oral, written, or electronic—that relates to the past, present, or future physical or mental health of an individual, the provision of healthcare, or payment for healthcare, and contains any of the 18 HIPAA identifiers:
- Client full name, initials, or family member names
- Geographic data smaller than a state (street address, city, ZIP code)
- All elements of dates directly related to an individual (birth date, admission date, service date)
- Contact details (phone numbers, email addresses, social media handles)
- Identification numbers (Social Security Number, insurance ID, medical record number)
- Full-face photographs, video recordings, or voice recordings
The Minimum Necessary Rule
Under HIPAA, ABAT technicians must limit their access, request, and disclosure of PHI to the absolute minimum necessary to perform direct job duties. For instance, when discussing a client's case during peer supervision, technicians should use client ID numbers or pseudonyms rather than full names, avoiding any extraneous personal details.
Data Security Standards in ABA Practice
Technicians regularly handle physical data sheets, electronic tablets, and mobile communication tools. Strict safeguards must be enforced in both home and community settings:
Physical and Digital Security Checklist
- Physical Binder Security: Paper data sheets, session notes, and program binders must be locked in a secure bag or trunk during transit. Binders must never be left unattended in visible areas of a vehicle or home.
- Device Encryption & Access Control: Agency-issued tablets or laptops containing electronic data collection software (e.g., CentralReach, Catalyst) must feature 256-bit encryption, strong multi-factor authentication (MFA), and automatic screen locks after 2 minutes of inactivity.
- Public Discussion Restrictions: Technicians must never discuss client names, diagnoses, or behavioral incidents in public spaces (elevators, school hallways, coffee shops, social gatherings).
- Prohibition of Personal Devices: Taking photos, videos, or audio recordings of clients on personal smartphones is strictly prohibited under QABA ethical rules and HIPAA regulations.
Releases of Information (ROI) and Disclosure Exceptions
An ABAT must never release client records, session data, or progress updates to third parties—including school teachers, speech therapists, extended family members, or researchers—without a signed, active Release of Information (ROI) form on file.
Legal Exceptions to Confidentiality
Confidentiality is a primary duty, but it is not absolute. An ABAT is legally permitted or required to breach confidentiality only under the following statutory exceptions:
- Mandated Reporting of Abuse: Suspicion of child abuse, neglect, or vulnerable adult maltreatment (reported directly to protective agencies).
- Imminent Risk of Harm: Severe, clear, and imminent threat of self-harm or violent harm to identified third parties (Tarasoff duty to warn).
- Judicial Court Orders: Formal legal subpoenas or court orders issued by a judge commanding record production.
Session Documentation & Objective Writing Standards
Clinical documentation serves as a legal medical record and billing justification. Notes must be completed within 24 hours of session completion using objective, measurable clinical language.
The SOAP Note Structure in ABA
- Subjective (S): Relevant caregiver reports or environmental context observed (e.g., "Caregiver reported client slept 5 hours overnight.").
- Objective (O): Measurable, observable behavioral data collected during session (e.g., "Client engaged in 4 instances of physical aggression [hitting] across 3.5 hours. DTT accuracy for receptive identification was 85% across 20 trials.").
- Assessment (A): Objective evaluation of progress toward behavioral targets based on session data (e.g., "Receptive identification mastered criterion; aggression decreased by 50% compared to baseline.").
- Plan (P): Planned focus for upcoming sessions as designated by the supervisor (e.g., "Continue prompt fading on receptive goals; maintain baseline data collection on task compliance.").
Clinical Scenario: Accidental PHI Breach in Mobile Settings
Scenario: An ABAT finishes a home session and drives to a local cafe. While working on session documentation, the technician leaves an unencrypted agency tablet logged into the data portal on the table while ordering food. A customer takes a photo of the tablet screen showing the client's full name, diagnosis, and behavior log, subsequently posting it online.
Analysis & HIPAA Consequences: This incident represents a severe HIPAA Security Breach resulting from gross negligence. The technician failed to secure ePHI and violated access control rules. The agency must launch a formal breach investigation, notify HHS and the client's family within 60 days, and implement corrective actions. The technician faces disciplinary review, potential employment termination, and QABA ethical sanctions.
Record Retention and Disposal Rules Table
| Record Category | Retention Requirement | Approved Disposal Method |
|---|---|---|
| Pediatric Client Records (Minors) | Retained for 7 years past age of majority (typically 25-28 years of age) | Cross-cut shredding (DIN 66399 Level P-4) or certified incineration |
| Adult Client Records | Retained for a minimum of 7 to 10 years from last date of service | Industrial shredding or secure digital purge with destruction certificate |
| Raw Physical Data Sheets | Uploaded to electronic EHR and stored securely per agency policy | Locked HIPAA shredding bin; never discarded in standard trash |
| Electronic PHI (ePHI) | Encrypted backups stored in HIPAA-compliant cloud storage (SOC-2 certified) | Cryptographic erasure (NIST SP 800-88 sanitization) |
An ABAT technician is compiling session notes. Which of the following entries demonstrates objective, measurable clinical documentation suitable for a medical record?
An ABAT technician receives a phone call from a client's grand-parent asking for an update on the child's progress in ABA therapy. The technician checks the chart and finds no signed Release of Information (ROI) for the grand-parent. What must the technician do?
Under the HIPAA Minimum Necessary Rule, how should an ABAT technician handle client information when consulting with a peer during a group supervision session?