Skip to content
TargetFlo — ABA therapy center operations software

Security & Compliance

HIPAA aware ABA software, built so PHI is isolated by design

A four-schema architecture keeps client data in its own governed space. Role-based access, audit trails, encryption in transit and at rest, a PHI guard on SMS, and scoped AI do the rest. BAAs available.

TargetFlo four-schema HIPAA-aware architecture isolating PHI from public, ops, and identity data in ABA therapy center software

What does HIPAA-aware mean in TargetFlo?

HIPAA aware ABA software means the controls HIPAA expects are built into the architecture rather than promised in a policy: PHI lives in an isolated database schema, access is granted by role and location, every action is audited, data is encrypted in transit and at rest, and AI features are scoped to what they need. TargetFlo provides these controls and signs a Business Associate Agreement; your center remains the covered entity. See the HIPAA notice and privacy policy for the formal statements.

Four-schema architecture

public · ops · identity · phi

Isolation is a design principle, not a checkbox. Operational features are wired to ops; only PHI-authorized workflows reach phi.

public

Reference data: payer list, CPT codes, pipeline stage definitions, course catalog

Non-PHI

ops

Operational data: stage counts, task status, fax queue metadata, training completion, dashboard KPIs

Non-PHI

identity

Users, roles, sessions, location membership, Workspace account links

Non-PHI

phi

Clients, guardians, insurance, documents, eligibility payloads, signed consents — isolated and separately governed

PHI — isolated

Dashboards read ops

KPIs, stage counts, and queue sizes are computed from operational tables. A leadership report never joins to a client row.

Integrations write where they belong

Fax payloads and eligibility responses land in phi. Workspace lifecycle touches identity. Nothing crosses without an authorized workflow.

AI is wired to one schema at a time

OCR writes to phi under human confirmation. The planned MCP assistant reads ops only and has no connection path to phi.

Controls

Eight controls, all in the product

Described as what they do — not as certifications we claim.

Four-schema architecture

public, ops, identity, and phi are separate database schemas. PHI is isolated by design, and operational features query ops — not phi.

Role-based access

Intake coordinator, clinician, front office, location manager, org admin, guardian, and external provider each see only what their role and location permit.

Audit trails

Views, edits, downloads, sends, integration actions, and AI calls are recorded with actor, timestamp, and target.

Encryption in transit and at rest

TLS for every connection; encrypted storage for databases and for documents held in Google Cloud Storage.

PHI guard on SMS

Outbound text messages are checked for identifiers before send. Guardians get appointment and portal prompts, not diagnoses over SMS.

AI scoping

OCR runs inside the PHI boundary with human confirmation; the planned MCP assistant reads only non-PHI aggregates.

Business Associate Agreements

BAAs are available for customers. We sign as your business associate and hold our own subprocessors to the same standard.

Backups and residency

We commit to encrypted, regularly tested backups and to hosting customer data in United States regions.

Access & audit

Everyone sees their job. Everything they do is recorded.

Multi-location ABA providers have coordinators, clinicians, front office, leadership, guardians, and external providers in the same system. Role- and location-based access defines what each one can reach; the audit trail records what they did with it.

  • Roles: intake coordinator, clinician, front office, location manager, org admin, guardian, external provider
  • Location scoping so one site's staff never browse another site's families
  • Guardians in the parent portal see only their own child's documents and signatures
  • Audit trail covers views, edits, downloads, sends, integration actions, and AI calls — filterable and exportable

Audit trail · sample

  • 09:12:04coordinator@…VIEW documentphi/doc/…4f2a
  • 09:12:41coordinator@…LINK fax → referralops/referral/…0c11
  • 09:14:07systemELIGIBILITY 270 sentphi/insurance/…b7e0
  • 09:14:09systemELIGIBILITY 271 storedphi/insurance/…b7e0
  • 09:20:33frontoffice@…SMS blocked · PHI guardops/broadcast/…91aa
  • 09:31:50orgadmin@…PROVISION Workspaceidentity/user/…e3d9

Encryption & documents

Encrypted moving, encrypted stored, referenced never copied

Every connection to TargetFlo uses TLS. Databases are encrypted at rest. Documents — fax pages, uploaded records, signed consents and SOPs — are stored encrypted in Google Cloud Storage and referenced from the phi schema so there is one copy, one access path, and one audit record.

  • TLS for browser, API, webhook, and integration traffic
  • Encryption at rest for databases and object storage
  • Documents in Google Cloud Storage, accessed only through TargetFlo's permission checks
  • Signed consents and POCs stored with version history in the parent portal

Browser / API / webhooks

TLS in transit

public · ops · identity · phi

Encrypted at rest

Google Cloud Storage

Encrypted documents, referenced from phi

Role check + audit on every access

Enforced in TargetFlo

Control by control

What each control means for your center

TargetFlo security controls and what each one means for an ABA therapy center
ControlWhat it means for your center
Four-schema data architectureClient and family data cannot be reached by dashboard, task, or AI features. A report on pipeline throughput never touches a name or a diagnosis.
Role- and location-based accessA coordinator in one location does not see another location's families. Guardians see only their own child's records in the portal.
Audit trail on every actionWhen a compliance officer asks who viewed a document or sent a message, the answer is one query, not a reconstruction.
TLS in transit, encryption at restReferral faxes, signed consents, and eligibility responses are encrypted whether they are moving or stored.
Documents in Google Cloud StorageFax pages and uploaded records live in encrypted object storage, referenced from the PHI schema, with access through TargetFlo only.
PHI guard on SMSBroadcast texts to families are checked for names, dates of birth, and clinical terms before they leave. Staff cannot accidentally text PHI.
AI scoped to its inputOCR sees the fax it is reading; compose assist sees the draft; the MCP assistant sees counts. No feature has general database access.
Google Workspace least privilegeTargetFlo requests account lifecycle and org unit scopes only. It does not read employee email or Drive files.
Business Associate AgreementA BAA is available for every customer handling PHI in TargetFlo. Subprocessors are covered under their own agreements.
Encrypted, tested backupsWe commit to regular encrypted backups and periodic restore tests so a bad day does not become a data-loss event.
US data residencyWe commit to hosting customer data in United States regions, with residency documented in your agreement.

PHI guard & AI scoping

Two places PHI usually leaks. Two controls that stop it.

Text messages and AI assistants are where well-meaning staff and clever tools most often move PHI somewhere it should not go.

PHI guard on SMS

Broadcast and one-to-one texts to families are checked before send for names, dates of birth, and clinical terms. Flagged messages are blocked with an explanation. Detailed communication moves to email or the parent portal, where access is authenticated.

See Communications

AI scoped to non-PHI aggregates

Gemini OCR sees the fax it reads and writes to phi under human confirmation. Compose assist sees the draft. The planned MCP assistant for Claude receives server-computed counts and rates only — never a client name, DOB, diagnosis, or insurance ID.

See the AI & MCP Assistant

Commitments

BAA, backups, and residency

Stated as commitments we make in your agreement, not certifications we imply.

Business Associate Agreement

Available for every customer. TargetFlo signs as your business associate; infrastructure and AI subprocessors are covered under their own terms.

Encrypted, tested backups

We commit to regular encrypted backups and periodic restore tests, with retention and recovery objectives documented in your agreement.

United States data residency

We commit to hosting customer data in US regions. Region choices are documented so your compliance team can reference them.

Want the detail? Read: What “HIPAA-aware” software means for ABA centers · HIPAA notice · Privacy policy

FAQ

Security & compliance FAQs

Walk through the architecture with your compliance lead

Book a demo and bring your security questionnaire. We show the four schemas, the audit trail, and the PHI guard live, and send the BAA for review.