COMPLIANCE · PLATFORM
Is your therapy CRM HIPAA compliant? Five questions that settle it
Most healthcare CRMs, ours included, are a configuration of a white-label platform. The question is slightly the wrong shape, and the agency that answered it with a one-word “yes” skipped the part that matters. Here is what the platform actually offers, what an agency has to do with it, and what stays with your practice regardless.
A note on what this is: a plain description of how one platform’s HIPAA offering works, written by a reseller of that platform. It is not legal advice, and TheraCRM.pro is not a covered entity. Your own counsel should review anything you act on.
The short answer
The platform TheraCRM.pro runs on, like the platforms behind most healthcare CRMs, is not “HIPAA compliant” in the way the phrase is usually meant, because no software is. Compliance is a status your practice holds by having safeguards, policies, training, and agreements in place. What the platform does offer is a paid HIPAA module that adds technical safeguards to an agency’s account and puts a Business Associate Agreement in place with the platform. A therapy practice running on a sub-account of that platform is working inside that framework only if four things are true at once, and none of them happen by default.
- The agency bought the module. It is a separate subscription on the agency’s account, $297 a month or $2,970 a year at the provider’s published price, and it is non-cancellable once purchased. Many agencies reselling the platform to healthcare have never bought it.
- HIPAA mode is switched on for your specific sub-account. Buying the module makes it available account-wide; it still has to be enabled individually per client in the sub-account’s advanced settings. An agency can hold the module and leave yours off.
- A BAA is executed with the agency, not only with the platform. The provider’s own materials describe the agency as a business associate of the practice. The platform’s BAA runs to the agency; you need your own with whoever configures and can see your account.
- The build keeps PHI inside the channels the module covers. The module covers contacts, notes, custom fields, SMS/MMS, voice recordings, email, form and survey submissions, calendars, and invoices. It does not extend to third-party integrations, and the provider does not publish coverage for social messaging channels or most AI features.
THE HONEST ONE-LINE VERSION
What the HIPAA module actually provides
Stated as the provider states it, and attributed to the provider rather than to us: covered data is encrypted with AES-256 at rest and TLS 1.2 or 1.3 in transit, multi-factor authentication is enforced for users, audit logging is granular, and the provider’s own support staff have restricted access to HIPAA-enabled accounts. The mobile app’s conversations, calendars, and contacts inherit the same controls. Activation takes 48 to 72 hours after purchase, and the BAA is signed in the platform, where it can be viewed and downloaded. Those are real safeguards. They are also the platform’s share of a responsibility that is split three ways.
What it does not do
- It does not make your practice compliant. Workforce training, access reviews when staff leave, device policy, your own risk analysis, and your Notice of Privacy Practices are yours and cannot be delegated to software.
- It does not cover what the provider has not documented. The provider publishes what its module covers and does not publish an exclusions list. Zapier, Make, webhooks, the public API, calendar sync, payment processors, and EHR connectors are not stated to be inside the BAA, so a careful build treats them as outside it and does not route PHI through them.
- It does not scope your AI features. The provider names Reviews AI as handled under HIPAA and is silent on conversation AI, voice agents, and workflow AI actions. If an agency put a general-purpose AI receptionist on your line and let it discuss symptoms, that is a decision the module did not make for them.
- It does not follow you freely on exit. A HIPAA-enabled sub-account can only be transferred to another agency that also holds the HIPAA module. Leaving for one that does not means migrating data rather than moving the account. Ask before you sign, not after.
Five questions for any agency selling you a sub-account on this platform
The answers are all verifiable, which is the point. An agency that has done the work can show you each one in a few minutes. One that has not will change the subject to how secure the platform is.
- Is the HIPAA module purchased on your agency account? It shows in the agency’s billing. Ask to see it.
- Is HIPAA mode enabled on my sub-account specifically? It is a visible setting. Ask for a screenshot dated today.
- Will you sign a BAA with my practice, and can I read it before I pay? The platform’s BAA covers the platform. Yours with the agency is separate.
- Which channels in your build carry patient information, and which are outside the BAA boundary? The answer should name channels and integrations, not say “everything is encrypted.”
- What happens to my data and my account if I leave you? The transfer restriction is real. A straight answer names it.
What we do differently, stated as steps rather than adjectives
We resell the same platform, and we are careful never to claim it is more secure in our hands than in anyone else’s. The difference we can defend is that the steps the platform leaves optional are mandatory in our build, and each one is something you can check.
- The HIPAA module is purchased on our agency account and kept current. It is not an add-on tier for you.
- HIPAA mode is enabled on your sub-account before go-live, and confirming it is a line on our onboarding checklist that cannot be skipped.
- Aday Interactive signs a BAA with your practice on every plan, before any patient information moves.
- Intake is built minimum-necessary. First-touch messages carry logistics, not clinical detail, and the voice agent is scoped to scheduling.
- Social messaging channels are left out of the inbox, and integrations are treated as outside the BAA boundary until the provider says otherwise in writing.
- The transfer restriction and the export limits are disclosed on the HIPAA page and in the terms, so you hear about them from us first.
None of this makes anyone “HIPAA certified.” No such government certification exists, for us, for the platform, or for any competitor. If a vendor uses the phrase, that is a reason to ask the five questions above more carefully, not less.
Questions we get asked about this
So is the platform HIPAA compliant or not?
No software is "HIPAA compliant" on its own; compliance is a status your practice holds. The platform offers a paid HIPAA module with technical safeguards and a Business Associate Agreement. Whether your account sits inside that framework depends on whether the agency bought the module, enabled HIPAA mode on your specific sub-account, signed its own BAA with you, and kept patient information inside the channels the module covers.
Does a BAA with my agency cover the platform too?
No. They are two agreements. The platform signs a BAA with the agency, and the agency signs one with your practice. You should be able to read both. Aday Interactive signs a BAA with every practice on every plan, and the platform BAA is available on request.
Does the mobile app carry the same protections?
The provider states that the mobile app's conversations, calendars, and contacts inherit the same controls as the web application under the HIPAA module, including multi-factor authentication and audit logging. That is the provider's statement, attributed to the provider.
How can I check whether HIPAA mode is on for my account?
It is a visible setting in the sub-account's advanced settings. Ask your agency for a dated screenshot. If they cannot produce one, or the module has never been purchased on their agency account, your account is not in a HIPAA-enabled configuration regardless of what the proposal said.
My current agency never bought the module. What now?
Ask them to buy it and enable HIPAA mode on your sub-account, and to sign a BAA with you, then verify all three. If you move instead, note that a sub-account can only be transferred to another agency that also holds the HIPAA module; otherwise the data is migrated rather than the account moved. Either way, involve your counsel about the period during which patient information was handled without those protections.
Related
Want the four checks run on your current account?
Bring whatever your current vendor sent you. A 30-minute consultation goes through module, sub-account status, BAA chain, and channel boundary, and tells you plainly where each one stands.