Public Comment Draft — open through October 31, 2026

BAAI/S-1 · Version 0.9 · Public Comment Draft

AI Documentation Standard for Behavior Analysis

Standard for AI-Assisted Clinical Documentation in Applied Behavior Analysis

Published by Behavior Analysts for AI (BAAI) · July 2026

0. Status of This Document

This is a public comment draft. It carries no regulatory or credentialing authority and creates no obligation for any practitioner or organization. It is a voluntary, practitioner-developed standard intended to define what defensible AI-assisted documentation looks like in ABA until — and after — formal guidance exists.

Comment period: open through October 31, 2026. Submit comments via the BAAI Standards page. Version 1.0 will publish a disposition of all comments received and will be ratified by founding members.

BAAI is not affiliated with, or endorsed by, the Behavior Analyst Certification Board (BACB®). References to the BACB Ethics Code are nominative. This document is not legal, billing, or compliance advice; organizations remain responsible for verifying requirements with counsel, payers, and regulators.

License: CC BY 4.0. Share and adapt with attribution.

1. Scope

1.1 This standard applies to the use of artificial intelligence — including generative AI and large language models — to draft, edit, summarize, or audit clinical documentation in applied behavior analysis, including: session notes, treatment plans and goal language, assessment summaries, caregiver/parent-training notes, supervision notes, and discharge summaries.

1.2 It applies to individual practitioners (BCBA-D, BCBA, BCaBA, RBT) and to organizations that deploy AI documentation tools on their behalf.

1.3 Out of scope: behavior-detection and computer-vision systems, scheduling and revenue-cycle automation, and payer-side AI — except where their output enters the clinical record, in which case the record-touching output is in scope.

1.4 This standard supplements — never replaces — the BACB Ethics Code, HIPAA, state law, and payer contract requirements. Where any of those conflict with this standard, they control.

2. Normative and Informative References

Normative (conformance depends on them):

  • BACB Ethics Code for Behavior Analysts (2022), esp. 1.01 (truthfulness), 1.05–1.06 (competence), 2.03–2.04 (confidentiality), 2.05 (documentation protection & retention), 2.06 (accuracy in service billing & reporting), 2.11 (informed consent)
  • HIPAA Privacy & Security Rules (45 CFR Parts 160, 164), including business-associate requirements
  • Applicable CPT® coding requirements for adaptive behavior services (97151–97158) and payer documentation policies

Informative (context and alignment):

  • CASP, Practice Parameters for Artificial Intelligence Use in Applied Behavior Analysis (2025) — organizational governance
  • AIC-ABA, Ethical Guidelines for AI in ABA, v2.0 (2025) — ethics education
  • Jennings & Cox (2024), Behavior Analysis in Practice — ethics mapping
  • Cox & O'Donnell (2025) — vendor "LLM-wrapper" critique
  • HHS-OIG Medicaid ABA audit reports: Indiana (2024), Wisconsin (2024), Colorado (2026)

This standard is positioned as the documentation-specific, audit-oriented layer beneath CASP's organizational parameters and AIC-ABA's ethics guidance.

3. Terms and Definitions

AI-assisted note
Any clinical document where an AI system generated or materially edited content, regardless of how much the human changed afterward.
Source data
Contemporaneously collected session records (trial data, duration/frequency measures, ABC data, task analyses, staff observations) existing before AI drafting begins.
Human reviewer of record
The credentialed person who reviews an AI draft and signs the final note, thereby adopting its entire content as their own professional statement.
Hallucination
AI-generated content describing events, quotes, data values, or clinical circumstances not present in source data.
Attestation metadata
The recorded facts of how a note was produced: tool and model version, date/time of generation, reviewer identity, review timestamp.
BAA
A HIPAA business associate agreement executed with any vendor whose system receives PHI.

KeywordsSHALL = mandatory for conformance. SHOULD = expected; deviations must be justifiable. MAY = permitted.

4. Conformance Levels

Conformance is claimed at one of three cumulative levels. Each level includes all requirements of the levels below it.

LevelNameMeaning
L1DisclosedAI use is lawful, PHI-safe, disclosed, and covered by policy. The ethical floor.
L2VerifiedEvery AI-assisted note passes a defined human verification workflow before it enters the record.
L3Audit-ReadyThe organization can prove L1 and L2 to a third party from records alone — attestation metadata, monitoring data, and a vendor due-diligence file.

Requirements below are tagged [L1], [L2], or [L3].

5. Requirements

5.1 Data Provenance

5.1.1 [L1]AI-assisted notes SHALL be generated from source data collected during or immediately after the session. AI SHALL NOT be used to create a note where no source data exists.

5.1.2 [L2]Quantitative statements in the final note (counts, percentages, durations, trial results) SHALL match source data exactly. Rounding conventions SHOULD be defined in policy.

5.1.3 [L2]The organization SHALL retain source data and be able to link any AI-assisted note to the source data that produced it, for the full record-retention period.

5.1.4 [L1]Practitioners SHALL NOT enter fabricated placeholder data to induce an AI tool to produce a note.

5.2 Human Review and Clinical Responsibility

5.2.1 [L1]Every AI-assisted note SHALL be reviewed by a qualified human before it is signed or submitted. Auto-submission of unreviewed AI output SHALL NOT occur under any configuration.

5.2.2 [L1]The human reviewer of record adopts the entire content of the signed note. "The AI wrote it" SHALL NOT be treated as mitigating within the organization's accountability structure.

5.2.3 [L2]Review SHALL be substantive, not perfunctory: the reviewer verifies events described against their own knowledge of the session and the source data, per a written verification procedure (see 5.10.2).

5.2.4 [L2]The reviewer SHALL hold the credential appropriate to the document type under payer and BACB supervision rules (e.g., RBT session notes reviewed per supervision structure; treatment plans by the responsible BCBA).

5.2.5 [L1]AI SHALL NOT be the final author of clinical judgment: recommendations, medical-necessity justifications, risk statements, and goal modifications SHALL originate from, or be explicitly confirmed by, the responsible clinician.

5.3 Accuracy and Hallucination Controls

5.3.1 [L1]The following SHALL NOT appear in a final note unless independently verified true by the reviewer: client quotes; descriptions of specific behavioral episodes; caregiver statements; environmental events. If the AI inserted them and the reviewer cannot verify them, they SHALL be deleted.

5.3.2 [L2]Organizations SHALL maintain a written list of prohibited generative content (minimum: invented quotes, unobserved events, embellished progress language, template text presented as observation) and train users on it.

5.3.3 [L2]Progress and regression statements SHALL be traceable to graphed or tabulated data. Optimistic summary language without data support SHOULD be treated as an accuracy defect, not a style choice.

5.3.4 [L3]Accuracy defects found in review or monitoring SHALL be logged by category (see 5.10) to enable tool-level and user-level trend analysis.

5.4 PHI and Platform Controls

5.4.1 [L1]PHI SHALL NOT be entered into any AI system not covered by an executed BAA. Consumer chat tools (free or consumer-subscription tiers of general chatbots) SHALL NOT receive PHI under any circumstances.

5.4.2 [L1]"HIPAA-ready," "HIPAA-friendly," or similar marketing language SHALL NOT be accepted as evidence of compliance. The executed BAA is the evidence.

5.4.3 [L2]Organizations SHALL determine and document whether the vendor uses customer data for model training, and SHALL disable or contractually exclude training on client PHI.

5.4.4 [L2]De-identification used to work outside a BAA SHALL meet the HIPAA Safe Harbor or expert-determination standard — removing the client's name alone is not de-identification.

5.4.5 [L1]Access to AI documentation tools SHALL sit inside the organization's normal access-control, password, and device policies.

5.5 Disclosure and Consent

5.5.1 [L1]The organization SHALL maintain a written policy stating which AI documentation tools are approved, for which document types, and by which roles. Undisclosed personal use of unapproved AI tools on client records SHALL be prohibited.

5.5.2 [L1]Clients/caregivers SHALL be informed, in plain language during intake or upon adoption, that AI tools assist with documentation, consistent with informed-consent obligations (Code 2.11). Organizations SHOULD offer an opt-out path or document why one is not offered.

5.5.3 [L2]Where a payer, state Medicaid program, or contract requires disclosure of AI-generated documentation, the organization SHALL comply and SHALL keep evidence of compliance.

5.5.4 [L2]Marketing or payer-facing claims about AI use SHALL match actual practice (Code 1.01).

5.6 Attestation and Audit Trail

5.6.1 [L2]For every AI-assisted note, the record SHALL capture: (a) the tool used, (b) model/version where the vendor exposes it, (c) generation timestamp, (d) reviewer identity, (e) review/signature timestamp.

5.6.2 [L3]Organizations SHOULD retain the AI draft alongside the signed final (or a diff, or the vendor's edit log) so the scope of human editing is demonstrable. Where the platform cannot do this, the gap SHALL be documented in the vendor file (5.8) and compensating review controls noted.

5.6.3 [L2]Signatures and timestamps SHALL comply with payer signature requirements; AI tools SHALL NOT apply, simulate, or pre-populate a clinician's signature.

5.6.4 [L3]Attestation metadata SHALL be producible within the organization's standard audit-response timeline (SHOULD: ≤ 10 business days).

5.7 Billing Alignment

5.7.1 [L1]The final note SHALL independently support the CPT code, units, service time, location, participants, and rendering provider billed. AI-generated content SHALL NOT be relied on to "fill" documentation requirements that the session facts do not support.

5.7.2 [L1]AI SHALL NOT generate or infer session start/stop times, service duration, or units. These SHALL come from source records only.

5.7.3 [L2]Medical-necessity language SHALL reflect the clinician's actual determination. Boilerplate necessity paragraphs generated by AI SHOULD be flagged by review as a defect when not individualized.

5.7.4 [L2]Where one clinician's notes feed another's billing (e.g., RBT notes under BCBA-billed codes), the verification workflow SHALL cover the dependency.

5.8 Vendor Due Diligence

Before deployment — and at least annually — the organization SHALL maintain a vendor file containing:

5.8.1 [L1]The executed BAA.

5.8.2 [L3]A vendor-provided description of architecture sufficient to answer: is this a proprietary model, a fine-tuned model, or a wrapper over a general-purpose LLM? Which third parties receive data?

5.8.3 [L3]Data-flow documentation (where PHI travels, where it rests, retention, deletion) and available security review or certification (e.g., SOC 2).

5.8.4 [L3]The vendor's stated accuracy/validation evidence — and a dated note that no peer-reviewed accuracy study exists where that is the case, so the organization's own monitoring (5.10) is the operative control.

5.8.5 [L2]Configuration records: which safety features (review gates, audit modules) are enabled, and who may change them.

5.9 Training and Competence

5.9.1 [L1]No practitioner SHALL use an approved AI documentation tool on client records before completing organization-defined training covering: the tool's failure modes (including hallucination), the verification procedure, PHI rules, and this standard's prohibited practices.

5.9.2 [L2]Training SHALL be documented (person, date, content version) and refreshed when tools or policies materially change.

5.9.3 [L2]Supervisors SHALL incorporate AI-documentation quality into supervision of RBTs and trainees, consistent with Code competence obligations (1.05–1.06).

5.10 Quality Monitoring

5.10.1 [L3]The organization SHALL audit a defined sample of AI-assisted notes on a defined schedule (SHOULD: monthly at adoption; at minimum quarterly thereafter) against this standard.

5.10.2 [L2]A written verification procedure SHALL define what reviewers check before signing (minimum: data-match per 5.1.2, hallucination screen per 5.3.1, billing alignment per 5.7.1).

5.10.3 [L3]Findings SHALL be logged against an error taxonomy (SHOULD, at minimum: data mismatch · fabricated content · unsupported clinical claim · billing misalignment · PHI handling · missing attestation), with corrective action tracked to closure.

5.10.4 [L3]Monitoring results SHALL feed vendor reassessment (5.8) and training (5.9). A tool whose defect rate does not respond to corrective action SHOULD be suspended.

6. Audit-Evidence Matrix (Informative)

What an auditor asks → what a conforming organization produces:

Auditor requestArtifactClause
"Who wrote this note?"Signed note + attestation metadata (tool, model, reviewer, timestamps)5.6.1
"Does the note support the claim?"Note ↔ source-data linkage; time/units from source records5.1.3, 5.7.1–5.7.2
"How do you know the AI didn't make things up?"Verification procedure + review logs + error-taxonomy monitoring data5.10.2–5.10.3
"Where does client data go?"Executed BAA + data-flow documentation + training-use exclusion5.4.1, 5.4.3, 5.8.3
"Did families know?"Intake disclosure/consent language + policy5.5.1–5.5.2
"Who was allowed to use this tool?"Approved-tool policy + training records5.5.1, 5.9.2

7. Prohibited Practices (Bright Lines)

Regardless of conformance level, the following are inconsistent with this standard:

  1. Submitting an AI-generated note no human reviewed.
  2. Entering PHI into a consumer AI tool without a BAA.
  3. Signing a note containing events, quotes, or data the signer cannot verify.
  4. Using AI to generate session times, durations, or units.
  5. Creating a note by AI for a session with no source data — or that did not occur.
  6. Fabricating placeholder data to trigger note generation.
  7. Representing AI-drafted documentation as fully human-authored where a payer or regulator requires disclosure.
  8. Letting an AI tool apply or simulate a clinician's signature.

8. Implementation Guidance for Small Practices (Informative)

A solo BCBA or small agency can reach L1 in roughly a week: adopt a one-page approved-tool policy, execute the vendor BAA, add an AI-disclosure paragraph to intake consent, complete tool training, and stop all PHI use in consumer chatbots. L2 is a workflow change: write the verification procedure, verify data-match before signing, and capture tool/reviewer/timestamps (most platforms already log these). L3 adds sampling audits and a vendor file — achievable without new software using a spreadsheet and the free BAAI checklist, which operationalizes this standard item by item.

9. Revision Roadmap

  • v0.9 (this draft) — public comment through October 31, 2026
  • v1.0 (2027) — disposition of all comments received; payer-specific annex; vendor self-attestation template; alignment review against any BACB or CASP updates; first stable release, ratified by founding members, with conformance self-declaration language for organizations

Annex A — BACB Ethics Code Cross-Reference (Informative)

Code provisionWhere this standard operationalizes it
1.01 Being truthful5.3 (accuracy), 5.5.4 (claims match practice), §7
1.05–1.06 Competence5.9 (training and supervision)
2.03–2.04 Confidentiality5.4 (PHI and platform controls)
2.05 Documentation protection & retention5.1.3, 5.6 (provenance, attestation, retention)
2.06 Accuracy in billing & reporting5.7 (billing alignment), 5.10 (monitoring)
2.11 Informed consent5.5.2 (client/caregiver disclosure)

Annex B — Selected References (Informative)

  1. HHS-OIG, Medicaid ABA audit reports: Indiana ($56M improper, 2024); Wisconsin ($18.5M improper, 2024); Colorado ($77.8M improper, 2026) — documentation deficiencies found in essentially all sampled claims.
  2. CASP, Practice Parameters for Artificial Intelligence Use in Applied Behavior Analysis (2025).
  3. AIC-ABA, Ethical Guidelines for AI in ABA v2.0 (Dec 2025).
  4. Jennings & Cox (2024), "Starting the conversation around the ethical use of AI in ABA," Behavior Analysis in Practice.
  5. Cox & O'Donnell (2025), on "LLM-wrapper" vendor claims and due diligence.
  6. BACB, Ethics Code for Behavior Analysts (2022); BACB newsletter note on AI (July 2024).
Submit Comments

© 2026 Behavior Analysts for AI · CC BY 4.0 · Public comment draft

Cite as: BAAI/S-1 v0.9 (2026)

The Cumulative Record

A monthly, evidence-first digest of AI developments that matter to behavior analysts. No hype. Unsubscribe anytime.

Educational content only — not legal, billing, or clinical advice.