Skip to content
TargetFlo — ABA therapy center operations software

HIPAA Notice & BAA

HIPAA-aware ABA software, with a BAA before any PHI enters

What “HIPAA-aware” means in TargetFlo, the controls behind it, how to get a Business Associate Agreement, and exactly which responsibilities are yours and which are ours.

What does “HIPAA-aware” mean for TargetFlo?

HIPAA-aware means TargetFlo is designed so an ABA therapy center can use it inside a compliant HIPAA program: protected health information is isolated in its own schema, every role sees only what it needs, access is audited, data is encrypted, SMS has a PHI guard, and AI features never operate on identifiable PHI. TargetFlo signs a Business Associate Agreement with every customer before PHI is entered. Read the full control set on the Security & Compliance page and the background in What “HIPAA-Aware” Software Means for ABA Centers.

Controls summary

The safeguards behind the phrase

Administrative, technical, and architectural controls that apply to every plan — Starter through Enterprise.

Role-based access control

Intake, clinical, front office, HR, portal guardian, and external provider roles see only the records and fields their job requires — scoped by location.

Audit trails

Record access, edits, document views, signatures, and admin changes are logged with user, timestamp, and location for review and incident response.

Encryption in transit and at rest

TLS for every connection; documents stored encrypted on Google Cloud Storage; database volumes encrypted at rest.

PHI isolation — 4-schema architecture

Identity, organization, operations, and PHI live in separate schemas. Dashboards, tasks, and training read operational data without touching the PHI schema.

PHI guard on SMS

Outbound SMS broadcasts are screened so client names, diagnoses, and insurance identifiers cannot leave through a text message.

AI limited to non-PHI aggregates

OCR and compose assist act on the document in front of the user. The planned MCP assistant answers from counts and rates only — never names, DOB, diagnosis, or member IDs.

Consents with versioning

Consent and SOP templates are versioned and e-signed, so you can show which guardian agreed to which version and when.

Breach notification commitment

Security incidents involving PHI are investigated and reported to the customer within the window defined in the BAA — never later than HIPAA requires.

Business Associate Agreement

BAA availability and how to request one

A BAA is included with Enterprise and available on request for Starter and Growth. No PHI enters TargetFlo until it is signed.

  1. 01

    Request

    Ask for a BAA from the contact page or during your demo. Enterprise plans include it by default.

  2. 02

    Review

    We send our standard BAA covering permitted uses, safeguards, subcontractors, breach notification, and return or destruction of PHI.

  3. 03

    Sign

    Both parties execute the BAA alongside the order form. Your counsel is welcome to redline; we turn edits around quickly.

  4. 04

    Go live

    PHI enters TargetFlo only after the BAA is in force. Onboarding then connects your fax provider and configures roles.

Request a BAA

Email hello@targetflo.com with the subject “BAA request,” or use the contact form.

Contact us

Shared responsibility

What you own and what TargetFlo owns

HIPAA compliance is shared. TargetFlo secures the platform; your organization governs who uses it, what goes in, and how your workforce is trained.

HIPAA shared responsibility model between the customer and TargetFlo
ResponsibilityCustomer (covered entity)TargetFlo (business associate)
Executing a BAA before PHI enters the systemCustomer requests; TargetFlo provides and signsProvide BAA, sign, and maintain subcontractor BAAs
Infrastructure, hosting, and network securityTargetFlo
Encryption in transit and at restTargetFlo
Application security, patching, and vulnerability managementTargetFlo
Audit logging capabilityReview logs; respond to findingsCapture and retain logs; make them available
Role and location assignment for staffCustomerProvide role model and admin tools
Deactivating departed staffCustomer (Workspace offboarding helps)Provide offboarding workflow and Google Workspace suspend
Password, MFA, and device policies for staffCustomerEnforce configured authentication settings
Deciding what to send by SMS or emailCustomerEnforce PHI guard on SMS; provide templates
Obtaining patient and guardian consentsCustomerProvide versioned consent templates and e-signature
Third-party integrations you connect (fax, Workspace, eligibility)Customer selects and contractsSecure the integration; subcontractor BAA where PHI flows
Workforce HIPAA trainingCustomer (courses module available)Provide course builder, MCQ tests, certificates
Breach investigation and notificationNotify individuals, HHS, and media as requiredDetect, investigate, and notify customer per BAA
Data return or destruction at terminationRequest exportExport on request; destroy per BAA

Breach notification

Our commitment if something goes wrong

If TargetFlo discovers a security incident involving your protected health information, we will investigate immediately, contain it, and notify you without unreasonable delay — within the window specified in your BAA and never later than HIPAA permits for business associates.

Notification includes what happened, the categories of PHI and individuals involved to the extent known, the steps we have taken, and what we recommend you do so you can meet your own obligations to individuals, HHS, and, where applicable, the media. We keep audit logs and incident records available to support your investigation.

Policy details for website visitors are in the Privacy Policy; contractual terms are in the Terms of Service and your BAA.

FAQ

HIPAA and BAA FAQs

Walk through the security model with us

Bring your compliance lead to the demo. We show role scoping, audit trails, the PHI schema boundary, and the SMS guard on a live organization.