Intro: Four Compliance Surfaces, Two of Them Routinely Misstated
ABA software compliance requirements span four distinct regulatory surfaces, and vendor content routinely misstates two of them. Providers scoping a practice management platform need clarity before development begins, not after a denied claim or a licensing complaint. This overview covers HIPAA, certification versus licensure documentation, electronic visit verification, and coverage that varies by plan type.
Two errors appear most often. Electronic visit verification is frequently described as a federal mandate covering applied behavior analysis directly. It is not. The Cures Act requirement applies to personal care and home health services. States decide separately whether in-home ABA falls under it.
A related error treats the certifying body’s ethics code as government law, when it governs certification rather than legal practice. This article is educational and strategic, not legal, regulatory or clinical advice. Confirming these obligations with qualified counsel, the state Medicaid agency, and the state licensure board is the right starting point.
HIPAA in a Pediatric, In-Home, Multi-Device Setting
The provider is a covered entity, and a hosted platform vendor is generally a business associate requiring a signed agreement. What makes ABA distinctive is where protected health information travels once care begins.
Clients are typically minors, so a parent or guardian is usually the personal representative, with state-specific exceptions. Custody arrangements, separated households, and multiple caregivers with different access rights are common rather than rare.
A platform built through custom software development can enforce role-based access, so a technician sees only assigned clients. Each device should complete a formal enrollment step before it goes into the field.
Field devices run the data collection app built through custom mobile app development. They need encryption at rest, session timeouts, and remote wipe capability. A documented lost-device procedure matters most, since protected health information travels into family homes and back out again.
That makes device management part of the compliance architecture, not routine IT housekeeping. Information blocking and patient access provisions also apply to health care providers, shaping how record requests are handled. The proposed HIPAA Security Rule update remains pending as of mid-2026. Its status should be confirmed before architecture is fixed.
Ethics Code Documentation and State Licensure
Certification Is Not Licensure
The Behavior Analyst Certification Board’s (BACB) Ethics Code for Behavior Analysts, effective January 2022, governs certificants, not the general public. BACB Ethics Code documentation covers records, supervision, informed consent, and confidentiality, with certification consequences for violations.
Separately, most states now license behavior analysts through boards with independent documentation and retention rules. Both layers can bind the same practitioner, and a platform serving multiple states inherits both. Current requirements from each source should be verified rather than assumed from memory.
Records: Timely, Accurate, Retained
ABA record retention obligations cover creating documentation contemporaneously and storing it securely. Records should be disposed of appropriately once the retention window closes. The current stated minimum period, along with any longer state requirement, should be confirmed before architecture decisions are finalized. Retention length shapes storage, archival, and deletion design from the start.
Supervision Documentation
ABA supervision documentation should track technician oversight against whatever the current published requirements specify, recorded at the time it occurs. A running position, rather than a monthly summary, lets a shortfall surface while the period is still open. Current supervision percentages and contact frequency should be confirmed against the certifying body’s published standards, not assumed from memory
Consent, Assent, and Versioning
Informed consent from a guardian, and assent from the client where appropriate, should be captured. Both should tie to the specific plan version they relate to. This lets a practice show exactly what was agreed to and when. Managing those versions and access rights happens in the office console built through web application development.
EVV Under the 21st Century Cures Act: and Whether It Applies to You
Section 12006 of the 21st Century Cures Act requires state Medicaid programs to implement electronic visit verification. It covers personal care and home health care services. Deadlines were January 2020 and January 2023, with reduced federal matching funds for states that missed them.
EVV must capture six data elements for each visit: service type, the individual receiving care, service date, delivery location, the individual providing care, and start and end times. These elements form the baseline across every state system.
The central applicability question comes first: does a given state extend electronic visit verification to in-home ABA? The federal mandate names personal care and home health services specifically. Some states have extended EVV to Medicaid-funded ABA services. Many others have not.
This is a state-level determination that should be confirmed with the state Medicaid agency directly, not inferred from vendor marketing. Where EVV does apply, the state’s model determines the technical work involved. Open models often allow a provider’s own system to serve as the verification tool. Closed models require transmission to a designated aggregator built to that vendor’s specification. For providers operating across multiple states, this becomes a per-state determination and often a per-state integration project.
State Autism Insurance Mandates, Medicaid, and What Actually Drives Coverage
Every US state has enacted some form of autism insurance mandate, but the details vary widely. Scope of covered services, age limits, dollar or hour caps, and diagnosis requirements differ by state.
One nuance is often missed: self-funded employer plans are generally exempt from state autism insurance mandates. Two families working for similar employers in the same state can end up with materially different benefits. A platform needs to treat plan type as a real attribute rather than assuming uniform commercial coverage.
Medicaid coverage for children under 21 rests on the Early and Periodic Screening, Diagnostic and Treatment provision. It does not rest on state mandate laws. This is a separate legal basis with separate implications for documentation.
Most Medicaid-funded ABA runs through managed care organizations, each with its own authorization process and documentation rules. A provider contracted with several MCOs is effectively operating several rule sets at once. These details should be verified per state and per plan type rather than assumed nationally.
Assessment Instruments Are Licensed Intellectual Property
Standardized assessment instruments, including VB-MAPP, ABLLS-R, AFLS, Vineland, and PEAK, are copyrighted products owned by their publishers. A platform cannot reproduce their items, embed their protocols, or automate their scoring without a written license.
Rewording items to build an equivalent tool does not resolve the legal issue. It also introduces a clinical validity problem alongside the licensing one.
If assessment integration is a goal, treat it as a licensing negotiation with its own timeline and cost. Keep it separate from development. That process should begin well before the related development work starts. Where no license exists, the platform can reference assessments completed outside the system and store resulting scores as documents.
This belongs in the project budget and plan from the outset, not on a future feature list.
Incident, Restraint, and Mandated Reporting Documentation
Providers need a documented path for incidents, including injuries, concerning behaviors, and medication errors. This also covers any restrictive procedure permitted under policy and state regulation. The software’s role is documentation, routing, and reporting.
That means capturing what occurred, notifying the right clinical and administrative staff promptly, and producing records regulators require. Restraint and seclusion are governed by state regulation and, in school settings, by additional rules. The platform records and routes; it does not guide clinical practice.
Behavior analysts and technicians are generally mandated reporters for suspected abuse or neglect, with state-specific timelines. Making that reporting pathway visible and documented reduces reliance on individual memory during a stressful moment. These requirements should be verified per state with legal counsel.
Establishing this compliance scope is the first job of a discovery sprint. Covered in Why US ABA Therapy Providers Should Run a Technology Discovery Sprint Before Committing to Custom Practice Management Software.
Final Thoughts
Providers that scope software against the obligations that actually apply build platforms that produce their own evidence. That includes HIPAA in a pediatric, multi-device setting and certification versus licensure as separate documentation layers. It also includes EVV as a state rather than a federal determination, plus coverage and assessment instruments as licensed property.
Which obligations become concrete product features is mapped in ABA Therapy Software Features. This overview remains educational and strategic, not legal, regulatory or clinical advice.
Confirming these obligations with qualified counsel, the state Medicaid agency, and the licensure board remains essential before architecture is fixed. Establishing the EVV position, licensure documentation requirements, and an assessment licensing plan early keeps compliance from becoming a rebuild.
NewAgeSysIT works through this scoping with providers during discovery. Learn more about digital transformation solutions from one of the leading AI software companies in the United States.