Skip to content
TargetFlo — ABA therapy center operations software
Compliance

What "HIPAA-Aware" Software Means for ABA Centers

HIPAA-aware ABA software is defined by controls, not certificates: role-based access, audit trails, encryption, four-schema PHI isolation, SMS guards, and BAAs.

TargetFlo Team 6 min read
What "HIPAA-Aware" Software Means for ABA Centers — TargetFlo blog

Every vendor selling into healthcare says the word HIPAA. Fewer can tell you what their software actually does about it. "HIPAA compliant" on a landing page is a marketing phrase; there is no government certification behind it, and compliance is ultimately the responsibility of the ABA center as a covered entity.

That is why TargetFlo uses the term HIPAA-aware. It signals that the software was designed with specific, inspectable controls for protected health information — and it invites you to ask what those controls are. This article lists them.

What does "HIPAA-aware software" mean?

HIPAA-aware software is software whose architecture and features are built around the requirements of the HIPAA Privacy and Security Rules — minimum necessary access, audit controls, encryption, integrity, and business associate obligations — without claiming a certification that does not exist. In practice it means the vendor can point to concrete mechanisms: who can see what, how access is logged, how data is encrypted, where PHI is isolated, and which features are deliberately kept away from PHI. The rest of this article walks through those mechanisms as TargetFlo implements them.

Control 1: Role-based access

The Privacy Rule's minimum-necessary standard says people should see only the PHI they need for their job. In an ABA center, that means an intake coordinator sees referral and insurance details, a technician sees their assigned clients, a BCBA sees the clinical records for their caseload, and a front-office employee sees demographics and schedules but not diagnostic reports.

Role-based access control (RBAC) makes that policy enforceable rather than aspirational. TargetFlo assigns roles at the organization and location level, so a multi-location center can scope a staff member to one site. The Workforce directory is where roles are managed, and the Parent Portal applies the same principle to guardians, who see exactly one client record — their own.

Control 2: Audit trails

The Security Rule requires mechanisms that record and examine activity in systems containing PHI. Practically, that means every view, edit, upload, signature, and export of a client record is logged with the user, timestamp, and action.

Audit logs do two things. They deter inappropriate access, because staff know it is recorded. And they make investigations possible — if a family asks who viewed their child's record, or a breach is suspected, the center can answer from the log rather than guess. In TargetFlo, audit data lives in its own schema so that it cannot be edited through the application that generates it.

Control 3: Encryption in transit and at rest

Encryption is the control most vendors mention and the easiest to verify. Data moving between the browser and the server should be encrypted with TLS; data stored in databases and document storage should be encrypted at rest with managed keys.

TargetFlo stores documents — faxes, insurance cards, diagnostic reports, signed Plans of Care — in encrypted cloud storage and encrypts database storage at rest. Encryption does not replace access control, but it means a lost backup or misconfigured storage bucket is not automatically a reportable breach.

Control 4: PHI isolation through a four-schema architecture

This is the control that most distinguishes deliberate design from a retrofitted database. TargetFlo separates data into four schemas by sensitivity and purpose:

SchemaContainsWhy isolated
ClinicalClient records, diagnoses, documents, insurance identifiersHighest sensitivity; narrowest access
OperationalTasks, pipeline stage counts, courses, fax queue statusNeeded broadly; must not leak PHI
Identity and accessUsers, roles, organizations, locations, sessionsGoverns who can reach the other schemas
AuditImmutable activity logsMust be tamper-evident and separately controlled

Isolation means permissions can be granted per schema rather than per table, that reporting can query operational data without joining to clinical data, and that features which should never touch PHI — like AI-assisted operational queries — can be architecturally prevented from doing so. The Security and Compliance page describes the architecture in more depth, and our Platform overview explains how multi-tenant and multi-location isolation sit on top of it.

Control 5: PHI guard on SMS

Text messaging is convenient and inherently insecure. Carriers do not sign BAAs, and messages sit unencrypted on devices. The correct pattern is to use SMS for logistics only — "a document is ready in your portal," "your appointment is confirmed" — and never for clinical content.

TargetFlo's Communications module enforces this with a PHI guard on outbound SMS broadcasts, screening messages for content that looks like protected health information before they send. The guard is a control, not a guarantee, and it is paired with staff training on what belongs in a text. Our post on HIPAA-Safe SMS Communication for ABA Centers covers the policy side.

Control 6: AI limited to non-PHI aggregates

AI features are where many healthcare vendors get ahead of their controls. TargetFlo draws a firm line. AI-assisted OCR and extraction on inbound faxes operate on documents the center already holds, inside the platform. The planned MCP server for Claude — on the roadmap, not live — will answer operational questions such as "how many referrals entered the Insurance stage this month?" using aggregates from the operational schema only. Client names, dates of birth, diagnoses, and insurance identifiers are not in scope, by architecture rather than by policy alone.

The four-schema design is what makes that promise credible. When PHI lives in a schema the AI integration has no access to, "the assistant never sees PHI" is a property of the system rather than a hope. Read more in MCP and Claude: An AI Operations Assistant Without PHI Risk.

Control 7: Business Associate Agreements

A vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate and must sign a BAA. So must that vendor's own subcontractors that touch PHI — cloud hosting, document storage, fax providers.

Ask any vendor two questions: will you sign a BAA with us, and which of your sub-processors handle our PHI under BAAs of their own? A vendor who hesitates on either has not thought the chain through. TargetFlo is designed to operate under a BAA with each customer, and its PHI-touching integrations are selected with that requirement in mind.

Controls, not certifications

Notice what is absent from this list: a badge. There is no HHS seal for software, and third-party attestations, while useful, describe a point in time rather than a permanent state. What an ABA center can actually evaluate is the set of controls above, applied consistently, and documented well enough to survive an audit.

When you evaluate HIPAA-aware ABA software, ask for the controls. Ask who can see a diagnosis, where the log of that access lives, how documents are encrypted, whether PHI is isolated from operational data, what stops a text message from carrying clinical content, what the AI can and cannot reach, and who signs the BAA. A vendor that answers each question specifically is HIPAA-aware. A vendor that answers with a logo is not.

  • HIPAA aware ABA software
  • ABA therapy center software
  • PHI isolation
  • ABA operations platform

See it in TargetFlo

Move intake out of the fax inbox

Book a 30-minute demo and we’ll map your referral flow to the 9-stage pipeline, connect your fax provider, and show eligibility checks at intake.

Book a Demo

FAQ

Frequently asked questions

Related articles

All articles

See TargetFlo on your own referral flow

Book a 30-minute demo. We map your current intake process to the 9-stage pipeline and show how fax, eligibility, tasks, and the parent portal fit together.