Bilingual intake for South Florida practices

T
TheraCRM.pro

Bilingual intake for South Florida practices

UNIFIED INBOX · HOW IT IS BUILT

One thread per person: why the shared inbox beats the shared login

Most practices already share an inbox. They share it by sharing a password. The difference between that and a unified inbox is not convenience; it is whether the audit log can say who read what, and whether a patient’s texts, emails, and calls are one conversation or four.

4 min read

THE SHORT ANSWER

A unified inbox puts every channel a patient uses (SMS, email, phone, web chat) into a single thread per person, and gives each staff member their own login with role-based access. The result is a conversation the whole team can see, internal notes the patient never does, texting from the practice number rather than personal phones, and an audit log that names a person rather than “frontdesk.” Social messaging channels are deliberately not in it.

The shared login problem

Walk into most dental practices and the front-desk computer is logged into the practice email as frontdesk@, has been since it was set up, and three people use it across a day. It works. It is also the reason that when a compliance question arrives, the audit trail says the practice’s inbox was accessed 340 times last month by a chair. Under HIPAA’s access-control and audit requirements that is not a record of who saw a patient’s information. It is a record that someone did.

The fix is not a policy asking people to log out. It is one login per person, with permissions set by role, in a system where doing that is the default rather than a chore. A hygienist sees what a hygienist needs. A coordinator sees the pipeline. The owner sees everything. Every read and every send is logged against a name.

The four-conversations problem

A new patient texts the practice number on Tuesday. On Wednesday she emails to ask about insurance. On Thursday she calls and leaves a voicemail. On Friday she uses the chat widget on the website. In most practices that is four conversations in four places, and the person who answers on Friday has no idea about Tuesday. In a unified inbox it is one thread, in order, with the channel marked on each message and the language tag at the top.

  • Every message in and out, on every channel, in one scrollable history per person.
  • Internal notes in the thread, visible to staff, never sent to the patient.
  • Assign the thread to a clinician or coordinator; see who owns it and since when.
  • Reply by text from the practice number, so no staff member texts a patient from a personal phone again.
  • The pipeline card and the thread are the same record; moving one updates the other.

What is not in the inbox, and why

Instagram direct messages, Facebook Messenger, and WhatsApp are not channels in this inbox. Patients use them, and the temptation to pull them in is real. The platform we build on publishes what its HIPAA module covers, and social messaging channels are not on that list; the companies that run those channels do not generally sign business associate agreements for them. A patient conversation tends to contain exactly the information those channels are not documented to protect. So the inbox is SMS, email, voice, and web chat, the four channels that sit inside the BAA boundary, and the practice’s social profiles carry a message directing people to those.

This is a smaller inbox than some vendors offer. It is also one we can describe to a compliance officer without qualification, which is the point.

The dental version

For a dental practice the thread is where the treatment-plan conversation lives. The plan was presented in the chair; the questions come by text that evening; the financing question comes by email; the yes comes by phone. One thread means the coordinator who marks the case accepted can see the whole path to it. It also means that when the unscheduled-treatment report flags a case six weeks later, the follow-up message goes into a conversation with context rather than starting cold.

What the audit log says afterwards

Every access is by a named user. Every outbound message has a sender. Every internal note has an author. When staff leave, one account is disabled and nothing else changes. When a patient asks who at the practice has seen their messages, there is an answer. None of that is a feature a practice buys a CRM for. It is the thing the practice is glad of the one time it matters.

Questions we get asked about this

What is wrong with the front-desk login everyone uses?

The audit log records that 'frontdesk' accessed the inbox 340 times last month. Under HIPAA's access-control and audit requirements that is not a record of who saw a patient's information. One login per person, with role-based access, fixes it by default.

Which channels are in the inbox?

SMS, email, voice, and web chat, the channels that sit inside the platform's published HIPAA coverage. Instagram, Facebook Messenger, and WhatsApp are not, because that coverage is not published for them.

Can staff text patients from the practice number?

Yes, from inside the thread. No staff member needs to text a patient from a personal phone, and every outbound message has a named sender.

Can we leave notes the patient does not see?

Yes. Internal notes live in the thread, are visible to staff by role, and are never sent.

Related

Still on a shared login?

A 30-minute consultation shows what one login per person and one thread per patient look like configured for your team.