Bilingual intake for South Florida practices

T
TheraCRM.pro

Bilingual intake for South Florida practices

HIPAA & BUSINESS ASSOCIATE AGREEMENT

Compliance is shared, unevenly. Here’s exactly how.

For a practice that is a covered entity, the HIPAA-enabled configuration and BAA is a $100 a month add-on on a Practice or Group seat, and Aday Interactive, Inc. signs a Business Associate Agreement with your practice before first login. The platform provides technical safeguards, we configure them, and your practice maintains its own policies, training, and workforce controls. No vendor can make a practice compliant on its own, and no one, including us, is “HIPAA certified,” because no such government certification exists.

This page exists to answer the question a competitor answers with one word. We think the more useful answer is a longer one, including the parts we cannot yet confirm.

The HIPAA add-on

HIPAA is a named add-on, priced as the real cost it is

Practice and Group

$100 a month

For a practice that is a covered entity, the HIPAA-enabled configuration and BAA add-on is $100 a month on a Practice or Group seat: Practice with HIPAA is $749, Group with HIPAA is $1,249. Aday Interactive, Inc. sets up the configuration for minimum-necessary access, scopes the voice agent to scheduling so no health details reach it, and signs a Business Associate Agreement before first login. It runs on a dedicated HIPAA-configured account that holds only practices with the add-on.

  • Practice and Group only. Solo is for businesses that are not covered entities.
  • Guided setup ($500 one time) is required with the add-on.
  • The AI voice agent is scoped to scheduling and logistics and handles no health details, because the voice subprocessors have no published BAA status (see below).
  • The first HIPAA seat carries a 3-month minimum, the one exception to no contract, because the module cannot be switched off once it is on.

A qualifier, not legal advice

Do you need the HIPAA add-on?

If your practice bills insurance electronically, including through your EHR or a billing service, you are almost certainly a covered entity under HIPAA and will need it. If you take no insurance and send no claims, you may not be. One covered service makes the whole practice covered. We will not decide your status for you; ask your compliance counsel. Either way, health details are handled with care on every seat.

See it on the pricing page →

What HIPAA compliance actually is

And, just as importantly, what it is not

HIPAA compliance is

  • A federal law, the Health Insurance Portability and Accountability Act of 1996, that governs how protected health information is handled.
  • A set of technical, physical, and administrative safeguards a covered entity and its business associates are required to maintain.
  • Demonstrated through documented policies, executed Business Associate Agreements, access controls, audit logs, and workforce training.
  • An ongoing practice your organization holds and maintains, not a product feature and not a one-time purchase.

HIPAA compliance is not

  • A certification, seal, or badge any vendor can be awarded. No such government certification exists, for anyone.
  • Something a CRM, an EHR, or any piece of software can “be” on its own, independent of how it is configured and used.
  • Transferable to us. No vendor, including us, can make your practice compliant. Compliance is your practice’s status to hold.
  • A guarantee. “HIPAA guaranteed,” “HIPAA secure,” and “100% HIPAA compliant” are not meaningful claims, and we do not make them.

The shared-responsibility model

Three parties, three distinct jobs

No single party in this chain can carry HIPAA compliance alone. Each holds a specific, non-overlapping part of it.

The platform

HighLevel (GoHighLevel)

Provides the HIPAA-enabled infrastructure, encryption, authentication, audit logging, and the underlying BAA that makes any of this possible.

Us

Aday Interactive, Inc.

Purchases and enables the HIPAA module, configures access and messaging correctly for your practice, and signs a BAA directly with you.

Your practice

The covered entity, where you are one

Holds your own HIPAA policies, trains your workforce, determines minimum-necessary access, and remains accountable for your patients’ information.

Where the agreements sit

The BAA chain

A Business Associate Agreement (BAA) is a contract required whenever protected health information passes to a party outside the covered entity. Ours runs four links deep.

Your practice

Covered entity, where applicable

↓ BAA

Aday Interactive, Inc.

Business Associate

↓ BAA

HighLevel (GoHighLevel)

Subcontractor Business Associate

↓ BAA

Subprocessors

Messaging, telephony, email, AI, hosting

Where your practice is a covered entity, Aday Interactive is a business associate. The platform provider is a subcontractor business associate to us, and it maintains its own BAAs with the subprocessors it uses for messaging, telephony, email, AI, and hosting. The provider’s own documentation names both the provider and the agency as business associates. This is not our characterization of the relationship, it is theirs.

What the platform provides

The HIPAA module, as the provider documents it

These facts come from the provider’s own published documentation, not from us. We state them because a specific answer is more useful to you than a vague one.

Account-wide, in place before your first record

The module is purchased once for our agency account, before the first practice that needs it goes live, and applies to every client sub-account from then on. On this site it is billed as the HIPAA add-on, $100 a month on a Practice or Group seat; it is not something that gets enabled only if you remember to ask.

Non-cancellable once enabled

The platform provider’s own terms describe the module as non-cancellable and non-refundable. It is a permanent commitment on our side, not a switch we flip experimentally.

Encryption

AES-256 at rest. TLS 1.2/1.3 with 2048-bit keys in transit.

Enforced multi-factor authentication

MFA is required, not optional, on HIPAA-enabled accounts.

Granular audit logging

Access to covered data is logged, and support access is restricted.

The BAA itself

The provider’s BAA with our agency is signed in-app, and is viewable, signable, and downloadable.

Per-sub-account enablement

HIPAA mode is switched on individually for each client’s sub-account in Advanced Settings, an onboarding step we never skip.

Activation window

48 to 72 hours from purchase to full activation. We build this into your go-live timeline.

What Aday Interactive is responsible for

The obligations we take on

01

Keeping HIPAA mode active and enabled

We purchase and maintain the paid HIPAA subscription and confirm HIPAA mode is switched on for your specific sub-account before any patient data moves through it, never assumed, always checked.

02

A signed BAA with your practice

Executed before first login for every practice on the HIPAA add-on, on Practice and Group. Not optional with the add-on, and not available on Solo.

03

Minimum-necessary access, by role

Front-desk staff see what they need to schedule. Clinicians see clinical detail. We configure the boundary rather than leaving every user an administrator.

04

What automated messages contain

Outbound SMS and email carry scheduling and logistics only, never diagnosis or treatment detail. What a patient volunteers inbound is their choice; it lands encrypted and audited.

05

Prompt breach notification to you

Florida’s Information Protection Act (FIPA) runs on a tighter clock than HIPAA’s 60 days. As your business associate, we notify you quickly enough that your own obligations stay achievable.

06

Training your team on what we built

On the system as configured, what may go over which channel, and what must not. Your own HIPAA policies and workforce training remain yours to hold.

What your practice remains responsible for

Nothing we do replaces this

A signed BAA and a correctly configured system are necessary. They are not sufficient. The following stays yours to hold, regardless of what any vendor, including us, provides.

  • Your own HIPAA policies and procedures, and the workforce training that puts them into practice.
  • Determining and documenting minimum-necessary access for your own staff, beyond the roles we configure in the system.
  • Chapter 491 supervision and scope-of-practice rules, who on your team, including registered interns, may access an intake or clinical record.
  • Your own patient consent, Notice of Privacy Practices, and authorization forms.
  • Deciding what patients should and should not send you over SMS or email, and telling them so.
  • Executing your own BAAs with any other vendor you connect to your practice, including your EHR.
  • Your own breach-notification obligations under HIPAA and Florida’s FIPA on the applicable clock.
  • 42 CFR Part 2, if your practice provides substance use disorder treatment. It is materially stricter than HIPAA and changes how we configure your account, tell us if it applies to you.

What is covered

Data objects covered under the provider’s HIPAA module

Per the provider’s own documentation. Mobile-app conversations, calendars, and contacts inherit the same controls. Reviews AI is the one AI feature the provider documents as handled HIPAA-compliantly. See the next section for what remains unclear beyond that.

Contacts & notes Custom fields SMS / MMS Voice recordings Email bodies & attachments Form & survey submissions Calendars Invoices
SCOPED DELIBERATELY

What we keep outside the boundary

The provider publishes what its HIPAA module covers. It does not publish an exclusions list. Rather than assume the gaps are fine, we treat anything undocumented as outside the boundary and build the system so PHI does not go there, which is why several capabilities you may have seen elsewhere are deliberately not part of this product. Each decision below is already in force, not pending.

Media-library file URLs

The provider’s documentation names form and survey submissions as covered, but is silent on whether files in the media library are ever served from public, unauthenticated links.

What we do about it

We have removed general file upload from the site. We will not reinstate it without written confirmation from the provider.

Which AI features are in HIPAA scope

Only Reviews AI is documented as handled HIPAA-compliantly. Conversation AI, the Voice Agent, AI Employee, and workflow AI actions are unmapped in the provider’s published material. The provider has newly disclosed three AI subprocessors, Retell AI, Synthflow, and Botpress, with no published BAA status for any of them, and no visibility into the model providers behind them.

What we do about it

We name these vendors rather than staying vague about them. Our own voice agents are scoped to scheduling and logistics only, never clinical questions.

Social and DM channels

The provider’s chat-widget documentation mentions Facebook, Instagram, and WhatsApp, but that is a capability page describing what the widget can do, not a statement that those channels sit inside the BAA boundary.

What we do about it

We do not offer social or DM channels for practices running a HIPAA-enabled configuration. This is the conservative reading, and we’re keeping it that way until something overturns it in writing.

Third-party integrations

Zapier, Make, webhooks, the public API, calendar sync, Stripe, and EHR connectors. The provider’s own platform materials place privacy-law compliance and consent on the customer, but nowhere state that these integrations sit inside the BAA.

What we do about it

We treat every integration as outside the BAA boundary until the provider confirms otherwise in writing, and we do not route PHI through one on that assumption.

Data portability and exit

What happens if you leave

Portability is limited

A HIPAA-enabled sub-account can only be transferred to another agency that also holds the provider’s HIPAA module. If you ever move to a partner who does not have it, your data has to be migrated rather than transferred as an account. We say this plainly because it is a real constraint, not a footnote.

Export has no published guarantee

The provider does not publish an export format, a data-retention period, or a deletion SLA for protected health information. What we can commit to is a good-faith export of your contact records, form submissions, and pipeline history on request, not a guarantee the provider itself has not made.

What happens to your data if Aday Interactive stops operating

This is the question a serious vendor assessment asks, and most vendors will not answer it. Here is the real position, taken from the provider’s published terms rather than from our own reassurance.

  • The BAA is tied to an active, paid subscription. The provider’s terms state that on non-payment the BAA is “immediately and automatically terminated and considered null and void without further notice.” If we stopped paying, that chain would break at once. This is precisely why we treat the module as a budgeted, permanent commitment rather than a line item.
  • You are not trapped if we go quiet. The provider’s terms provide a route that does not depend on us: a sub-account may be transferred without the agency’s approval where the customer has requested it through the in-app process, the agency has not responded for at least 30 days, and the agency’s account has been cancelled, force-cancelled for non-payment and not reactivated within 30 days, or terminated for breach. Start with the in-app transfer request. That is what puts the clock running.
  • There is a 90-day window after termination. The provider retains account data for 90 days after cancellation, during which reactivation may restore access. After that they may delete it permanently at their discretion. Ninety days is the outside edge of how long you have to act, not a reason to wait.
  • Our own obligation survives us. Under HIPAA, a business associate must return or securely destroy protected health information when the agreement ends, or document why that is infeasible and keep protecting it. That duty does not disappear because a company winds down, and it is written into the BAA you sign with us.

Ask any vendor holding your patient data these four questions. If they cannot answer them from published terms, that is the answer.

Who to contact

Questions about your BAA or this page

(305) 209-8453

For BAA copies, sub-account HIPAA status, and compliance questions

Aday Interactive, Inc.

338 Minorca Avenue, Suite 202, Coral Gables, FL 33134

We are not attorneys, and none of this is legal advice. Consult qualified healthcare counsel regarding your practice’s specific obligations, including under HIPAA, Florida’s FIPA, Chapter 491, and, if applicable, 42 CFR Part 2.