← BCBA Fieldwork & Supervision Hours: The Complete 2026 Guide

Guide

BIP & FBA Documentation: What Funders Require in the Paperwork

A Functional Behavior Assessment (FBA) and a Behavior Intervention Plan (BIP) are the two documents that justify ABA services to every funder — Medicaid managed care organizations, commercial payers, and TRICARE. Getting the clinical work right is your domain as a BCBA. Getting the paperwork right is a separate discipline, and it is the paperwork that gets scrutinized at prior authorization, re-authorization, and audit.

This article covers the documentation lens only: what funders expect these documents to contain, what identifiers and signatures are required, and what review cadence you need to track. It does not address how to conduct an assessment clinically or how to select or implement interventions.


Why the FBA and BIP Are the Center of the Authorization File

Before a funder approves ABA services, their clinical reviewer asks: Does this paperwork justify the hours and codes being requested? The FBA and BIP carry the most weight in that decision — together they form the evidence chain from identified problem behavior, through assessment data, to planned services.

The CMS Documentation Matters Fact Sheet for Behavioral Health Practitioners states that behavioral health records must reflect medical necessity, justify the treatment and clinical rationale, and be complete, concise, and accurate. For ABA, the FBA and BIP together must tell a coherent, data-supported story.

A 2023 OIG audit of Indiana Medicaid ABA services found $56.5 million in improper payments, with notes lacking sufficient detail to support billed CPT codes as a leading deficiency. Weak FBA-to-BIP documentation chains were a consistent upstream driver.


Required Components of a Funder-Ready FBA Report

Payers reviewing an FBA report for authorization are looking for a structured document, not a narrative summary. The following elements appear consistently across state Medicaid ABA policies and commercial payer clinical guidelines.

Identifying Information and Document Header

Every page of the FBA report should include the client’s full legal name, date of birth, Medicaid or insurance member ID, and the assessment date range. This is a technical requirement — missing or inconsistent identifiers cause administrative rejections independent of clinical quality.

Diagnosis on File

The report must reference the ASD diagnosis (DSM-5-TR criteria), the diagnosing provider’s name and credentials, and the date of diagnosis. Sunshine Health’s required ABA documentation checklist specifies that a Comprehensive Diagnostic Evaluation signed by a qualifying licensed practitioner must accompany the initial authorization request. Funders will not authorize ABA services without a confirmed ASD diagnosis in the file.

Behavioral Definition in Measurable Terms

Each target behavior must be defined operationally — meaning any two observers using the definition would measure the behavior consistently. Definitions that use vague language (“aggressive behavior,” “noncompliance”) without specifying the exact observable actions are a common deficiency flagged in payer audits.

Data-Collection Methodology and Baseline Measurements

The report must document how data was gathered — interview formats, observation protocols (ABC recording, interval recording, scatterplot), indirect assessment tools used — and present quantified baseline data: frequency per session, rate per hour, or percentage of intervals. Qualitative summaries do not meet payer standards. This baseline is also what prior authorization requests cite as the starting point against which progress will be measured at re-authorization.

Identified Behavior Function

The FBA report must state the identified function of each target behavior supported by the collected data. This is the direct link between the FBA and every BIP intervention — payer reviewers check this link explicitly. Without a documented function tied to data, the BIP’s intervention rationale has no foundation.

BCBA Signature, Credentials, and Date

The FBA report must be signed and dated by the supervising BCBA with full credentials listed. The Medicaid ABA documentation guidance for 2025 notes that several states now require e-signatures on evaluation reports — paper wet signatures may not be sufficient depending on your state.


Required Components of a Funder-Ready BIP

The BIP is the authorization document — it specifies the services you are requesting, the measurable goals those services are working toward, and the implementation structure that will govern delivery. Funders use it to decide what CPT codes to authorize, at what hours, and for what period.

The BIP must trace every intervention component back to the FBA data and function identification. Payers conducting prior authorization reviews verify this link explicitly — a BIP that lists strategies without referencing the FBA function will fail clinical review at most managed care organizations.

Operationally Defined Target Behaviors and Measurable Goals

The same behaviors defined in the FBA must appear in the BIP with identical operational definitions. Inconsistencies — even minor wording changes — signal to auditors that the documents were created in isolation. Goals must be SMART: specific, measurable, achievable, relevant, and time-bound. Re-authorization decisions are made based on data showing whether those goals were reached; vague goals cannot support a re-authorization submission.

CPT Code Rationale

The BIP should make clear which interventions map to which billed CPT codes. If you are requesting hours under CPT 97155 (protocol modification), the BIP must show the protocol modification need tied to FBA findings; if requesting CPT 97156 (family adaptive behavior treatment guidance), the caregiver training component must be documented. The BIP is where the rationale for requesting each code is established, before session notes are required to support it.

Caregiver Training and Crisis Protocol

Most Medicaid ABA policies require the BIP to document a caregiver training component. Virginia and Arkansas require treatment plans to show parent training and coordination with other providers. The BIP must also include a client-specific crisis and safety protocol — its absence is a frequent audit deficiency. The BACB’s Ethics Code for Behavior Analysts requires that behavior analysts ensure RBTs are trained to competency on the plan; many Medicaid MCOs now request evidence of that training in the authorization packet.

Signature Block: BCBA, Caregiver, and Physician

A fully executed BIP requires:

  • BCBA signature, credentials, license number, and date — confirming the plan was developed by a qualified professional
  • Caregiver or legal guardian signature and date — confirming informed consent to the plan and its components
  • Referring or ordering physician signature — required by many Medicaid programs and commercial payers; Sunshine Health’s documentation list requires a signed physician referral for initial authorization

Missing any of these signatures creates an incomplete document that will not support authorization.


Medical Necessity, Review Cadence, and Re-Authorization Documentation

Medical necessity for ABA is not established by diagnosis alone. The chain — FBA function → BIP intervention → measurable goal — is the medical-necessity argument in documentation form. If any link is missing or unsupported by data, the authorization is vulnerable regardless of the underlying clinical quality.

Authorization periods are time-limited. Most state Medicaid programs authorize ABA in six-month windows with a required re-authorization before the period closes. South Dakota Medicaid specifies prior authorizations for six months with a required re-authorization to continue. New York’s LBA policy requires treatment plan updates at least every six months. Florida Medicaid requires validated assessment tool re-administration every 12 months for comprehensive reassessments.

At each re-authorization, funders expect: a progress summary with quantified data (not narrative only — Aetna’s ABA clinical policy specifies measurable progress thresholds for continued authorization); updated operational definitions if target behaviors have changed; a revised BIP if interventions have been modified; an updated physician referral if the original has expired; and current BCBA, caregiver, and physician signatures on all updated documents.

Build a 30-day re-authorization preparation window into your scheduling system. Authorization lapses are one of the leading causes of ABA billing denials, and denied claims from a lapsed authorization period are rarely recoverable.

For session-level documentation during the authorization period, see RBT documentation and session data and ABA parent training CPT 97156 for the note requirements that tie back to the BIP. For how this documentation architecture intersects with your credentialing and supervision record, see BCBA fieldwork hours tracking.


Version Control and Record Retention

Version Control

Every BIP update must be dated, signed, and stored as a distinct document — not an overwrite of the previous version. Auditors frequently request the full version history of a BIP when reviewing a billing period. If you cannot produce the version in effect during a specific period, you cannot prove billed services were delivered under an authorized plan. Use a version numbering convention (v1.0, v1.1, v2.0) in the document header, note the modification date and reason, and retain every prior version.

Record Retention

Three overlapping requirements govern retention of FBA reports, BIPs, and associated documentation:

  • BACB Ethics Code Section 2.05 — retain records for a minimum of seven years from the date of last service, and as otherwise required by applicable laws
  • Medicaid — generally requires seven years from the date of service for Medicaid-funded ABA records
  • HIPAA — the HHS HIPAA FAQ on record retention clarifies that HIPAA sets no minimum for clinical records; state law governs, and HIPAA compliance documentation itself must be kept for six years

The practical baseline: keep all FBA reports, BIP versions, data summaries, authorization correspondence, and signature pages for at least seven years from the date of last service. For minor clients, most states extend retention to age 18 plus additional years — verify with your state licensing board. Records must be stored securely and destroyed in a manner that protects PHI.


Common Documentation Deficiencies That Trigger Denials or Audits

Based on ABA Medicaid audit findings — including the OIG Indiana review that identified $56.5 million in improper payments — and commercial payer clinical review patterns, these deficiencies most frequently cause denials or recoupment demands:

FBA: behaviors defined vaguely instead of operationally; baseline data presented as narrative rather than quantified measurements; function identification stated without supporting data; assessment date range missing or inconsistent with service start.

BIP: interventions listed without tracing back to FBA function; goals without measurable criteria; missing caregiver training component when the payer requires it; absent or generic safety/crisis protocol; outdated BIP version in file with no authorized revision.

Signatures and identifiers: missing BCBA signature or credentials; missing caregiver/guardian signature; expired or absent physician referral; inconsistent client identifiers across FBA, BIP, and session notes.

Timing: BIP dated before the FBA it is supposed to derive from; no documented BIP review at the six-month re-authorization point; progress summary submitted without data graphs or quantified metrics.


Keeping the File Audit-Ready

An audit-ready client file holds the FBA report, all BIP versions with modification history, signed authorization documents, progress summaries, and re-authorization packets in one organized location — with a clear index showing what is present and when each document was signed. When a payer requests records on a 10-day turnaround, you need to produce the complete file without searching across disconnected storage.

Pre-built document templates that include every required field, signature block, and version-control header eliminate the risk of structural omissions. The BIP & FBA Documentation Kit provides that template architecture structured around the payer requirements covered here — so the form itself prompts compliance.

For the broader supervisory and compliance infrastructure these documents sit within, the BCBA fieldwork supervision guide is the hub resource.

Disclaimer: Folio publishes general information about the operational and administrative side of running a private practice. It is not legal, medical, clinical, tax, or compliance advice, and it does not create a professional relationship. Rules vary by state, payer, and profession and change over time. Verify requirements with the primary sources cited, your licensing board, and your own qualified advisors before acting.