Bilingual intake for South Florida practices

T
TheraCRM.pro

Bilingual intake for South Florida practices

HIPAA & BUSINESS ASSOCIATE AGREEMENT

Compliance is shared — unevenly. Here’s exactly how.

TheraCRM.pro is built on third-party HIPAA-enabled infrastructure, and Aday Interactive, Inc. signs a Business Associate Agreement with your practice. The platform provides technical safeguards, we configure them, and your practice maintains its own policies, training, and workforce controls. No vendor can make a practice compliant on its own — and no one, including us, is “HIPAA certified,” because no such government certification exists.

This page exists to answer the question a competitor answers with one word. We think the more useful answer is a longer one, including the parts we cannot yet confirm.

What HIPAA compliance actually is

And, just as importantly, what it is not

HIPAA compliance is

  • A federal law — the Health Insurance Portability and Accountability Act of 1996 — that governs how protected health information is handled.
  • A set of technical, physical, and administrative safeguards a covered entity and its business associates are required to maintain.
  • Demonstrated through documented policies, executed Business Associate Agreements, access controls, audit logs, and workforce training.
  • An ongoing practice your organization holds and maintains — not a product feature and not a one-time purchase.

HIPAA compliance is not

  • A certification, seal, or badge any vendor can be awarded. No such government certification exists, for anyone.
  • Something a CRM, an EHR, or any piece of software can “be” on its own, independent of how it is configured and used.
  • Transferable to us. No vendor — including us — can make your practice compliant. Compliance is your practice’s status to hold.
  • A guarantee. “HIPAA guaranteed,” “HIPAA secure,” and “100% HIPAA compliant” are not meaningful claims, and we do not make them.

The shared-responsibility model

Three parties, three distinct jobs

No single party in this chain can carry HIPAA compliance alone. Each holds a specific, non-overlapping part of it.

The platform

HighLevel (GoHighLevel)

Provides the HIPAA-enabled infrastructure — encryption, authentication, audit logging, and the underlying BAA that makes any of this possible.

Us

Aday Interactive, Inc.

Purchases and enables the HIPAA module, configures access and messaging correctly for your practice, and signs a BAA directly with you.

Your practice

The covered entity

Holds your own HIPAA policies, trains your workforce, determines minimum-necessary access, and remains accountable for your patients’ information.

Where the agreements sit

The BAA chain

A Business Associate Agreement (BAA) is a contract required whenever protected health information passes to a party outside the covered entity. Ours runs four links deep.

Your practice

Covered Entity

↓ BAA

Aday Interactive, Inc.

Business Associate

↓ BAA

HighLevel (GoHighLevel)

Subcontractor Business Associate

↓ BAA

Subprocessors

Messaging, telephony, email, AI, hosting

Where your practice is a covered entity, Aday Interactive is a business associate. The platform provider is a subcontractor business associate to us, and it maintains its own BAAs with the subprocessors it uses for messaging, telephony, email, AI, and hosting. The provider’s own documentation names both the provider and the agency as business associates — this is not our characterization of the relationship, it is theirs.

What the platform provides

The HIPAA module, as the provider documents it

These facts come from the provider’s own published documentation, not from us. We state them because a specific answer is more useful to you than a vague one.

Account-wide, already in place

The module is purchased once for our agency account and applies to every client sub-account. It is not an add-on you are billed for, and not something that gets enabled only if you ask.

Non-cancellable once enabled

The platform provider’s own terms describe the module as non-cancellable and non-refundable. It is a permanent commitment on our side, not a switch we flip experimentally.

Encryption

AES-256 at rest. TLS 1.2/1.3 with 2048-bit keys in transit.

Enforced multi-factor authentication

MFA is required, not optional, on HIPAA-enabled accounts.

Granular audit logging

Access to covered data is logged, and support access is restricted.

The BAA itself

The provider’s BAA with our agency is signed in-app, and is viewable, signable, and downloadable.

Per-sub-account enablement

HIPAA mode is switched on individually for each client’s sub-account in Advanced Settings — an onboarding step we never skip.

Activation window

48–72 hours from purchase to full activation. We build this into your go-live timeline.

What Aday Interactive is responsible for

The obligations we take on

01

Keeping HIPAA mode active and enabled

We maintain the paid HIPAA subscription and confirm HIPAA mode is switched on for your specific sub-account before any patient data moves through it — never assumed, always checked.

02

A signed BAA with your practice

Executed before go-live, on every plan. Never an upsell, never optional.

03

Minimum-necessary access, by role

Front-desk staff see what they need to schedule. Clinicians see clinical detail. We configure the boundary rather than leaving every user an administrator.

04

What automated messages contain

Outbound SMS and email carry scheduling and logistics only — never diagnosis or treatment detail. What a patient volunteers inbound is their choice; it lands encrypted and audited.

05

Prompt breach notification to you

Florida’s Information Protection Act (FIPA) runs on a tighter clock than HIPAA’s 60 days. As your business associate, we notify you quickly enough that your own obligations stay achievable.

06

Training your team on what we built

On the system as configured — what may go over which channel, and what must not. Your own HIPAA policies and workforce training remain yours to hold.

What your practice remains responsible for

Nothing we do replaces this

A signed BAA and a correctly configured system are necessary. They are not sufficient. The following stays yours to hold, regardless of what any vendor — including us — provides.

  • Your own HIPAA policies and procedures, and the workforce training that puts them into practice.
  • Determining and documenting minimum-necessary access for your own staff, beyond the roles we configure in the system.
  • Chapter 491 supervision and scope-of-practice rules — who on your team, including registered interns, may access an intake or clinical record.
  • Your own patient consent, Notice of Privacy Practices, and authorization forms.
  • Deciding what patients should and should not send you over SMS or email, and telling them so.
  • Executing your own BAAs with any other vendor you connect to your practice, including your EHR.
  • Your own breach-notification obligations under HIPAA and Florida’s FIPA on the applicable clock.
  • 42 CFR Part 2, if your practice provides substance use disorder treatment. It is materially stricter than HIPAA and changes how we configure your account — tell us if it applies to you.

What is covered

Data objects covered under the provider’s HIPAA module

Per the provider’s own documentation. Mobile-app conversations, calendars, and contacts inherit the same controls. Reviews AI is the one AI feature the provider documents as handled HIPAA-compliantly — see the next section for what remains unclear beyond that.

Contacts & notes Custom fields SMS / MMS Voice recordings Email bodies & attachments Form & survey submissions Calendars Invoices
SCOPED DELIBERATELY

What we keep outside the boundary

The provider publishes what its HIPAA module covers. It does not publish an exclusions list. Rather than assume the gaps are fine, we treat anything undocumented as outside the boundary and build the system so PHI does not go there — which is why several capabilities you may have seen elsewhere are deliberately not part of this product. Each decision below is already in force, not pending.

Media-library file URLs

The provider’s documentation names form and survey submissions as covered, but is silent on whether files in the media library are ever served from public, unauthenticated links.

What we do about it

We have removed general file upload from the site. We will not reinstate it without written confirmation from the provider.

Which AI features are in HIPAA scope

Only Reviews AI is documented as handled HIPAA-compliantly. Conversation AI, the Voice Agent, AI Employee, and workflow AI actions are unmapped in the provider’s published material. The provider has newly disclosed three AI subprocessors — Retell AI, Synthflow, and Botpress — with no published BAA status for any of them, and no visibility into the model providers behind them.

What we do about it

We name these vendors rather than staying vague about them. Our own voice agents are scoped to scheduling and logistics only, never clinical questions.

Social and DM channels

The provider’s chat-widget documentation mentions Facebook, Instagram, and WhatsApp — but that is a capability page describing what the widget can do, not a statement that those channels sit inside the BAA boundary.

What we do about it

We do not offer social or DM channels for practices running a HIPAA-enabled configuration. This is the conservative reading, and we’re keeping it that way until something overturns it in writing.

Third-party integrations

Zapier, Make, webhooks, the public API, calendar sync, Stripe, and EHR connectors. The provider’s own platform materials place privacy-law compliance and consent on the customer, but nowhere state that these integrations sit inside the BAA.

What we do about it

We treat every integration as outside the BAA boundary until the provider confirms otherwise in writing, and we do not route PHI through one on that assumption.

Data portability and exit

What happens if you leave

Portability is limited

A HIPAA-enabled sub-account can only be transferred to another agency that also holds the provider’s HIPAA module. If you ever move to a partner who does not have it, your data has to be migrated rather than transferred as an account. We say this plainly because it is a real constraint, not a footnote.

Export has no published guarantee

The provider does not publish an export format, a data-retention period, or a deletion SLA for protected health information. What we can commit to is a good-faith export of your contact records, form submissions, and pipeline history on request — not a guarantee the provider itself has not made.

What happens to your data if Aday Interactive stops operating

This is the question a serious vendor assessment asks, and most vendors will not answer it. Here is the real position, taken from the provider’s published terms rather than from our own reassurance.

  • The BAA is tied to an active, paid subscription. The provider’s terms state that on non-payment the BAA is “immediately and automatically terminated and considered null and void without further notice.” If we stopped paying, that chain would break at once. This is precisely why we treat the module as a budgeted, permanent commitment rather than a line item.
  • You are not trapped if we go quiet. The provider’s terms provide a route that does not depend on us: a sub-account may be transferred without the agency’s approval where the customer has requested it through the in-app process, the agency has not responded for at least 30 days, and the agency’s account has been cancelled, force-cancelled for non-payment and not reactivated within 30 days, or terminated for breach. Start with the in-app transfer request — that is what puts the clock running.
  • There is a 90-day window after termination. The provider retains account data for 90 days after cancellation, during which reactivation may restore access. After that they may delete it permanently at their discretion. Ninety days is the outside edge of how long you have to act — not a reason to wait.
  • Our own obligation survives us. Under HIPAA, a business associate must return or securely destroy protected health information when the agreement ends, or document why that is infeasible and keep protecting it. That duty does not disappear because a company winds down, and it is written into the BAA you sign with us.

Ask any vendor holding your patient data these four questions. If they cannot answer them from published terms, that is the answer.

Who to contact

Questions about your BAA or this page

(305) 209-8453

For BAA copies, sub-account HIPAA status, and compliance questions

Aday Interactive, Inc.

338 Minorca Avenue, Suite 202, Coral Gables, FL 33134

We are not attorneys, and none of this is legal advice. Consult qualified healthcare counsel regarding your practice’s specific obligations, including under HIPAA, Florida’s FIPA, Chapter 491, and, if applicable, 42 CFR Part 2.