HIPAA Notice & BAA
HIPAA-aware ABA software, with a BAA before any PHI enters
What “HIPAA-aware” means in TargetFlo, the controls behind it, how to get a Business Associate Agreement, and exactly which responsibilities are yours and which are ours.
schema: identity
non-PHIusers, roles, sessions
schema: org
non-PHIlocations, settings, staff
schema: ops
non-PHIpipeline stages, tasks, courses, KPIs
schema: phi
PHIclients, guardians, insurance, documents
Access path
What does “HIPAA-aware” mean for TargetFlo?
HIPAA-aware means TargetFlo is designed so an ABA therapy center can use it inside a compliant HIPAA program: protected health information is isolated in its own schema, every role sees only what it needs, access is audited, data is encrypted, SMS has a PHI guard, and AI features never operate on identifiable PHI. TargetFlo signs a Business Associate Agreement with every customer before PHI is entered. Read the full control set on the Security & Compliance page and the background in What “HIPAA-Aware” Software Means for ABA Centers.
Controls summary
The safeguards behind the phrase
Administrative, technical, and architectural controls that apply to every plan — Starter through Enterprise.
Role-based access control
Intake, clinical, front office, HR, portal guardian, and external provider roles see only the records and fields their job requires — scoped by location.
Audit trails
Record access, edits, document views, signatures, and admin changes are logged with user, timestamp, and location for review and incident response.
Encryption in transit and at rest
TLS for every connection; documents stored encrypted on Google Cloud Storage; database volumes encrypted at rest.
PHI isolation — 4-schema architecture
Identity, organization, operations, and PHI live in separate schemas. Dashboards, tasks, and training read operational data without touching the PHI schema.
PHI guard on SMS
Outbound SMS broadcasts are screened so client names, diagnoses, and insurance identifiers cannot leave through a text message.
AI limited to non-PHI aggregates
OCR and compose assist act on the document in front of the user. The planned MCP assistant answers from counts and rates only — never names, DOB, diagnosis, or member IDs.
Consents with versioning
Consent and SOP templates are versioned and e-signed, so you can show which guardian agreed to which version and when.
Breach notification commitment
Security incidents involving PHI are investigated and reported to the customer within the window defined in the BAA — never later than HIPAA requires.
Business Associate Agreement
BAA availability and how to request one
A BAA is included with Enterprise and available on request for Starter and Growth. No PHI enters TargetFlo until it is signed.
- 01
Request
Ask for a BAA from the contact page or during your demo. Enterprise plans include it by default.
- 02
Review
We send our standard BAA covering permitted uses, safeguards, subcontractors, breach notification, and return or destruction of PHI.
- 03
Sign
Both parties execute the BAA alongside the order form. Your counsel is welcome to redline; we turn edits around quickly.
- 04
Go live
PHI enters TargetFlo only after the BAA is in force. Onboarding then connects your fax provider and configures roles.
Request a BAA
Email hello@targetflo.com with the subject “BAA request,” or use the contact form.
Breach notification
Our commitment if something goes wrong
If TargetFlo discovers a security incident involving your protected health information, we will investigate immediately, contain it, and notify you without unreasonable delay — within the window specified in your BAA and never later than HIPAA permits for business associates.
Notification includes what happened, the categories of PHI and individuals involved to the extent known, the steps we have taken, and what we recommend you do so you can meet your own obligations to individuals, HHS, and, where applicable, the media. We keep audit logs and incident records available to support your investigation.
Policy details for website visitors are in the Privacy Policy; contractual terms are in the Terms of Service and your BAA.
FAQ
HIPAA and BAA FAQs
Walk through the security model with us
Bring your compliance lead to the demo. We show role scoping, audit trails, the PHI schema boundary, and the SMS guard on a live organization.