Consent, Records, and Secure Communication When Coordinating ABA Services

A plain-language guide for case managers, school staff, and providers on what can be shared, with whom, and through which channels.
Educational note: This guide is educational and does not replace medical, legal, school, or insurance advice. Privacy laws are applied to specific facts, and organizational policies differ. Always follow your own organization's privacy policies and consult your privacy or compliance officer about specific situations. HIPAA references here are plain-language orientation drawn from official HHS guidance, not legal interpretation.
Read this first. Two different things govern information sharing in ABA coordination: what federal privacy rules generally permit, and what each organization's own policies require. They are not the same. An exchange that federal rules may permit can still require a signed release under a provider's, plan's, or agency's internal policy. When in doubt, the practical answer is almost always the same: confirm consent is documented before sharing, and use a channel your organization has approved.
Coordinating ABA services is a team activity. A case manager preparing for a care-plan meeting, a daycare director wondering how a child's morning routine is going, a pediatrician who wants to know whether services started: all of these are reasonable, care-driven requests for information. And all of them run through the same three questions: Is there consent to share this? How much should be shared? Through what channel?
If those questions have ever slowed you down, that is not a sign of an obstructive process. It is a sign that the people handling a child's information are taking it seriously. This guide explains the basics in plain language so coordination can be both careful and fast.
Why Information Sharing Has Rules
Most ABA providers, health plans, and medical providers are covered by the federal Health Insurance Portability and Accountability Act (HIPAA). In plain terms, HIPAA's Privacy Rule sets national rules for how "covered entities" (health care providers, health plans, and clearinghouses) and their business associates may use and share identifiable health information, and its Security Rule requires reasonable safeguards for that information in electronic form.
Behavior analysts also carry their own professional obligation. The Behavior Analyst Certification Board's Ethics Code for Behavior Analysts requires certificants to protect confidential information, to disclose it only under defined conditions such as informed consent, and, when authorized to share, to share only the information critical to the purpose of the communication. So when an ABA team asks, "Can you confirm we have consent on file for that?", that check helps ensure the exchange follows applicable privacy requirements and professional standards.
Schools sit in a slightly different world. Records that schools maintain about students are generally governed by FERPA, the federal education records law, rather than HIPAA, and joint HHS and Department of Education guidance explains how the two laws interact. The practical takeaway: when ABA information crosses between a health care organization and a school, expect both sides to follow their own rules, with a signed release as the common bridge. This is orientation only, not education-law guidance.
Consent and Release of Information: The Basics
A release of information (often called an ROI or an authorization) is the family's written permission for one organization to share specific information with another. It is the workhorse document of ABA coordination.
Based on HHS guidance, a valid HIPAA authorization generally includes:
- What information may be shared (described specifically, not "everything")
- Who may share it (the releasing organization)
- Who may receive it (a named person or organization, or a described category)
- Why: the purpose of the disclosure
- When it ends: an expiration date or event
- A signature from the individual or their personal representative, with the date
Two features of authorizations matter every day in coordination work:
Authorizations are specific. A release naming the health plan does not cover the school. A release covering progress summaries does not necessarily cover full session-by-session records. If the document does not describe the recipient and the information you need, a new or updated release may be needed.
Authorizations are revocable. Families may generally revoke an authorization at any time, in writing, for future disclosures. A release signed at intake a year ago may no longer be in effect. This is why careful organizations re-confirm consent status rather than assuming it.
What HIPAA generally permits without a signed authorization.
Here is where the two-layer distinction from the top of this article matters most. Under the Privacy Rule, covered entities are generally permitted to share information without a signed authorization for treatment, payment, and health care operations: for example, two treating providers coordinating care for the same child, or a provider sending documentation the health plan needs to process a claim. The Privacy Rule also applies a minimum necessary standard to most disclosures: share the amount of information needed for the purpose, and no more.
But "HIPAA may permit it" is not the end of the analysis. Many organizations, reasonably, require a documented release for exchanges beyond routine treatment and payment, or for any exchange with a non-medical party. Health plans and Medicaid programs may have their own consent documentation requirements. When a provider asks for a signed ROI before an exchange that you believe federal rules would permit, that is usually organizational policy at work, not obstruction. When an organization requires a release, completing its required authorization is usually the practical next step.
What Typically Requires a Signed Release
Every organization's policy differs, so treat this as a general orientation rather than a rulebook.
Sharing with schools and daycares. Because schools generally sit under FERPA rather than HIPAA, exchanges between an ABA provider and a school routinely run on signed releases in both directions. If ABA services are delivered on a school or daycare site, expect consent paperwork as part of setup. The day-to-day mechanics of working together on site are covered in our school and daycare coordination guide.
Sharing with community agencies and non-treating parties. Support coordinators at community organizations, housing or benefits programs, attorneys, and similar parties are typically outside the treatment-payment-operations lane, so a signed authorization is the normal expectation.
Sharing between providers who are not both treating the child. A prior provider, an evaluator the family is only considering, or a provider the family consulted once may each be treated differently under organizational policy. Confirm rather than assume.
Anything beyond the minimum needed. Even with consent in place, the professional habit is to share the summary rather than the full chart when the summary answers the question. If a care-plan meeting needs to know whether goals are progressing, a progress summary usually serves better than hundreds of pages of session data.
One sentence on two neighboring topics: consent documentation is also a standard element of a complete ABA referral packet, which we cover in our referral checklist for case managers; and when a family moves between ABA providers, the records side of that transition has its own workflow, covered in our provider-transition guide.
Families Control Their Information
It is easy, in busy coordination work, to talk about records as if they belong to the organizations exchanging them. They do not. The information is about the child, and families have important rights and choices about how it is accessed and shared, subject to applicable law.
In plain-language terms, based on HHS guidance:
- Parents generally act for their minor children. Under HIPAA, a parent is generally the child's "personal representative" and may exercise the child's privacy rights (authorizing disclosures, requesting records, revoking releases) with limited exceptions defined by law.
- Families may see and obtain copies of their child's records. HIPAA gives individuals a right of access to their health information held by covered providers and plans, and personal representatives may exercise that right for a child.
- Families decide the scope. A family may authorize sharing with the school but not a community agency, or progress summaries but not full records. Narrow consent is valid consent, and professionals should honor the boundaries as written.
- Families may change their minds. Revoking an authorization for future disclosures is the family's right, and it is not something a coordinating professional should treat as a problem to be argued with.
For coordinating professionals, this has one practical implication: when consent is unclear, the family is the first call, not a workaround.
Secure and Insecure Channels
HIPAA's Security Rule requires covered organizations to use reasonable administrative, physical, and technical safeguards for electronic health information, including protecting information transmitted over networks. It does not hand every organization the same tool list; each organization decides what it approves. What follows is general orientation; your own organization's approved channels control.
Generally more secure. Encrypted email systems, secure web portals, electronic record systems with individual logins, and secure fax with a confirmed number are the common approved channels for records exchange between organizations. Phone conversations between verified parties are a normal channel for discussion, with the usual care about who can overhear.
Handle with care. Standard unencrypted email is a gray zone. HHS guidance recognizes that providers may communicate electronically with patients when they apply reasonable safeguards (verifying the address, limiting what the message contains), and families may express preferences about how they are contacted. Between organizations, however, many privacy policies restrict what ordinary email may carry. A common, sensible pattern: logistics by email, records by secure channel.
Generally avoid for identifiable clinical content. Standard text messages, personal email accounts, consumer messaging apps, and social media are not designed for health information exchange and are commonly prohibited by organizational policy for identifiable clinical content.
Two everyday examples show how mistakes actually happen:
- A coordinator types "Mar" and autocomplete helpfully selects the wrong Maria. A progress report leaves the building addressed to a stranger. Address verification before sending is the safeguard that catches this.
- An office faxes an evaluation to a number from an old referral sheet. The number was reassigned months ago. Confirming the fax number with the receiving office, especially the first time, is the safeguard here.
Neither mistake requires a careless person. They require only a busy one, which is why channel habits matter more than good intentions.
Records-Request Etiquette Between Organizations
When you need records from another organization, a little structure makes the exchange faster for everyone.
- Define the minimum you need. "The most recent progress summary" moves faster than "all records", and it is usually what the meeting actually requires.
- Confirm consent before you ask. Check whether a release naming your organization is on file, and whether it covers the information you need. If not, help the family complete one first.
- Put the request in writing through an approved channel. A written request with the child's identifying details, what is needed, the purpose, and your secure delivery method gives the releasing organization everything it needs to act.
- Allow reasonable processing time. Records requests are typically handled by specific staff under specific procedures. Building a few business days into your planning is realistic; same-day expectations usually are not.
- Confirm receipt and store securely. Close the loop with the sender, and file what you received in your own organization's approved system, not a personal drive or inbox folder.
- Document the exchange. Note what was requested, when, under which consent, and what was received. If a question ever arises, the answer is in your notes.
Tone matters as much as the steps. The organization asking for a signed release is not stalling, and the one taking three days to respond is not ignoring you. Assume good faith, ask what is needed to move forward, and keep the family informed.
Questions Coordinating Professionals Can Ask
When you are unsure how to handle an exchange, these questions usually get you to the answer quickly:
- "Do you have a release on file naming our organization, and what does it cover?"
- "What is your preferred secure channel for receiving records?"
- "Who handles records requests on your team, and what does a complete request need to include?"
- "Is a progress summary sufficient for this purpose, or is the full record needed?"
- "Has the family placed any limits on what they want shared with us?"
- "Can you confirm the fax number or secure email address before I send?"
- And to your own organization: "What channels are approved for sending identifiable client information, and where is that policy written down?"
Secure-Communication Checklist for Coordinating Professionals
Use this quick check before any exchange of identifiable ABA information between organizations.
Before sharing: - [ ] Consent confirmed: a current, unexpired release covers this recipient and this information, or the exchange clearly falls within your organization's documented no-authorization-needed categories - [ ] Scope confirmed: you are sharing the minimum needed for the purpose, not everything on hand - [ ] Family boundaries honored: any limits the family placed on sharing are reflected in what you send
Choosing the channel: - [ ] The channel is on your organization's approved list for identifiable information - [ ] The recipient's address or number is verified (no autocomplete, no old referral sheets) - [ ] Nothing identifiable is going into a standard text, personal email, or consumer messaging app
When sending: - [ ] The message states what is enclosed, under what consent, and who to contact with questions - [ ] Attachments checked: the right child, the right documents, nothing extra - [ ] Receipt confirmation requested for records transmissions
Afterward: - [ ] The exchange is documented: what, when, to whom, under which consent - [ ] Received records are stored in your approved system - [ ] Anything that went wrong (wrong recipient, unexpected content) is reported to your privacy or compliance contact right away, per your organization's procedure
How Blooming Approaches Coordinated Communication
Blooming Behavioral Health provides ABA services in Broward, Miami-Dade, and Palm Beach counties, delivered in natural settings (home, school, daycare, and the community) rather than in a center.
Because our services live in the places where children actually spend their days, coordination with case managers, schools, and other providers is part of our routine work.
When authorized by the family, our team can:
- Communicate with case managers and coordinating professionals
- Help identify what consent documentation an exchange needs
- Confirm the secure channels we use for sending and receiving records
We follow our own written privacy procedures, and we will tell you plainly what we need on file before we can share.
Professionals can learn more on our page for professionals, reach our team at (754) 799-3780, or point a family to our start-an-intake page when a referral is taking shape. We cannot speak for another organization's policies, but we can make our side of the exchange clear, prompt, and secure.
Reviewed for operational and compliance accuracy by Carlos Marquez, Director of Services and Compliance Officer.
Federal HIPAA Guidance (HHS)
- HHS — HIPAA for Professionals (hub). https://www.hhs.gov/hipaa/for-professionals/index.html
- HHS — Summary of the HIPAA Privacy Rule. https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html
- HHS — Summary of the HIPAA Security Rule. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
- HHS — FAQ: Authorizations. https://www.hhs.gov/hipaa/for-professionals/faq/authorizations/index.html
- HHS — FAQ: Does the HIPAA Privacy Rule permit health care providers to use e-mail to discuss health issues with their patients? https://www.hhs.gov/hipaa/for-professionals/faq/570/does-hipaa-permit-health-care-providers-to-use-email-to-discuss-health-issues-with-patients/index.html
- HHS — Personal Representatives (guidance). https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/personal-representatives/index.html
- HHS — Your Rights Under HIPAA (guidance materials for individuals, including the right to access health records). https://www.hhs.gov/hipaa/for-individuals/guidance-materials-for-consumers/index.html
Federal Regulation
- eCFR — 45 CFR Part 164 (Security and Privacy), including §§ 164.502, 164.506, 164.508, 164.524. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164
Schools and Education Records
- HHS / U.S. Department of Education — Joint Guidance on the Application of FERPA and HIPAA to Student Health Records. https://www.hhs.gov/hipaa/for-professionals/special-topics/ferpa-hipaa/index.html
Professional Standards
- Behavior Analyst Certification Board — Ethics Code for Behavior Analysts (sections 2.03–2.05, confidentiality and documentation; updated August 2024). https://www.bacb.com/wp-content/uploads/2022/01/Ethics-Code-for-Behavior-Analysts-240830-a.pdf
Ready to begin?
Start intake, verify insurance, or talk to a team member. We respond within one business day.