Trust & Compliance
Automate Admits is built for admissions and intake teams that handle sensitive health information. This page explains how we handle HIPAA and 42 CFR Part 2, the standing Business Associate Agreement we offer every customer, every subprocessor we rely on, and how we protect your data. We publish the gaps as plainly as the controls — read the subprocessor and Part 2 sections before you send us regulated records.
On this page
HIPAA & Business Associate Business Associate Agreement 42 CFR Part 2 Security program Subprocessors Data handling & retention Incident response Compliance roadmap ContactHIPAA & Business Associate status
When you use Automate Admits to communicate with patients and leads, we act as your Business Associate under the HIPAA Rules (45 CFR Parts 160 and 164). You remain the Covered Entity (or, in some arrangements, another business associate) and control the care relationship; we provide the software and process protected health information (PHI) only to deliver the Service on your behalf.
We are software, not a healthcare provider — we do not provide medical, clinical, or treatment advice, and we are not part of your care team. But because your conversations can include PHI, we take on the safeguards, reporting, and contractual obligations that HIPAA requires of a business associate.
We describe Automate Admits as HIPAA-eligible, not HIPAA-certified. There is no such thing as HIPAA certification — no government body certifies software. What we mean is that the Service is architected and contracted so a covered entity or business associate can use it for PHI: we sign a BAA, PHI is stored and processed on infrastructure covered by our own BAAs, and we implement Security Rule safeguards. Compliance is a shared outcome; how you configure and use the Service is part of it.
Standing Business Associate Agreement (BAA)
We publish a single, standing BAA that applies to every customer — you don't need to negotiate or sign a separate agreement for your organization. By subscribing to and using Automate Admits to handle PHI, your organization accepts the standing BAA by reference; it is incorporated into our Terms of Service and takes effect the moment the Service is used with PHI.
Need a countersigned copy for your records, or want to review the full text before you sign up? Request it at privacy@automateadmits.com. Signed-in customers can also read the full BAA and policy pack under Settings → Policies & procedures.
The standing BAA commits us to, among other things:
- Using and disclosing PHI only to provide the Service, as permitted by the BAA, or as required by law;
- Limiting use and disclosure to the minimum necessary;
- Implementing administrative, physical, and technical safeguards and complying with the HIPAA Security Rule;
- Binding every subcontractor that handles PHI to written confidentiality and security obligations, and executing a business associate agreement with each one that will sign one — the current status of every subprocessor is published below;
- Reporting security incidents and breaches, and notifying you of a breach of unsecured PHI within 60 days of discovery;
- Making PHI available for access, amendment, and accounting of disclosures as required;
- Making our practices available to HHS for compliance review;
- Returning or destroying PHI on termination where feasible.
The published BAA governs; this summary is for orientation only.
42 CFR Part 2 — substance use disorder records
Many of our customers are substance use disorder (SUD) treatment programs. Where the Service is used by a Part 2 program, we act as a Qualified Service Organization (QSO). Every account owner accepts our QSO agreement at signup, and that acceptance is recorded against the account.
What we commit to
- We hold records received from a Part 2 program in confidence and use them only to provide the contracted Service — never for marketing, resale, model training, or any other purpose.
- We are fully bound by 42 CFR Part 2 with respect to those records, and we will resist in judicial proceedings any effort to obtain them other than as Part 2 permits.
- We disclose those records only to the subprocessors listed below, each of which is engaged under written confidentiality and security obligations.
- We apply the same technical safeguards to Part 2 records as to all other PHI.
What the platform does not do — read this
We would rather tell you plainly than let you assume. Automate Admits does not currently provide Part 2 consent management. Specifically, the platform has no patient-consent record, no consent revocation workflow, no segmentation of Part 2 records from other records, no automatic application of the redisclosure notice, and no accounting-of-disclosures log. Those controls live in your systems and your procedures, not ours.
As the covered program, you are responsible for obtaining, documenting, and honoring any patient consent required before information is entered into or sent through the platform, for applying the required notice prohibiting redisclosure to anything you send out of it, and for maintaining any accounting of disclosures Part 2 requires of you. We give you a per-organization compliance checklist inside the app that includes a periodic Part 2 consent review, but the checklist is a reminder — the review itself is manual and performed by your team.
See our 42 CFR Part 2 statement for the full detail.
Security program
PHI is encrypted in transit (TLS) and at rest, access is role-based and least-privilege, passwords are stored only as salted hashes, and two-factor authentication is available. PHI access and account changes are recorded in a per-organization activity log. Full technical detail is on our Security page.
Because the AI agent must read message content to draft replies, the Service is not end-to-end encrypted; data is encrypted in transit and at rest and access-controlled.
Subprocessors
This is the complete list of providers that receive customer data when you use the Service. Every one is engaged under contractual confidentiality and security obligations. Where we have executed a business associate agreement, we say so; where we have not, we say that too. We do not claim BAAs we do not hold.
| Subprocessor | Purpose | Data it receives | BAA |
|---|---|---|---|
| Amazon Web Services, Inc. | Application hosting, database, object storage, and compute — the system of record, where PHI is stored and processed | All application and patient data (PHI), encrypted at rest and in transit | Yes — BAA |
| Paubox, Inc. | Transactional & notification email to your team | Team email addresses and notification content, which can reference a contact | Yes — BAA |
| Stedi, Inc. | Insurance eligibility & benefits verification (X12 270/271 clearinghouse) | Patient first name, last name, date of birth, and member ID; your provider NPI and organization name. The full 271 benefits response is returned and stored by us | Yes — BAA |
| Anthropic, PBC | AI drafting and conversation summarization | The contact record and the recent conversation transcript, including any images or media the contact sent. Not used to train models | No BAA |
| Meta Platforms, Inc. | Send and receive messages on the Facebook Pages and Instagram accounts you connect | Message content and the contact's platform profile on channels you connect | No BAA |
| Telnyx LLC | SMS and voice transport, phone numbers, call recording, and speech-to-text transcription | Phone numbers, message bodies, and call audio in transit; transcription sends call audio to Telnyx's speech-to-text service, which is powered by OpenAI Whisper. Recordings and transcripts are stored by us on AWS | No BAA |
| Cloudflare, Inc. | Public marketing site, static-asset delivery, DNS, and CDN/DDoS protection | Public marketing content and application code only — no PHI | No PHI |
| Stripe, Inc. | Subscription and top-up payment processing | Billing contact and card data only — no patient data | No PHI |
About the three providers without a BAA
Three subprocessors can receive information that may constitute PHI and are not covered by a business associate agreement with us. You should know exactly what that means before you decide how to use the Service.
- Anthropic powers the AI agent. To draft a reply it must read the conversation, so the contact record and recent message history are sent to Anthropic's API on every turn. Anthropic does not train on this data, but we do not hold a BAA with them.
- Meta operates Facebook Messenger and Instagram. If you connect those channels, the conversation happens on Meta's platform by definition, and Meta's own terms — not ours — govern that copy of it. Meta does not offer a BAA for these APIs.
- Telnyx carries SMS and voice. Carriers generally handle message and call traffic as transport rather than under a BAA. If you enable call transcription, call audio is additionally sent to Telnyx's speech-to-text service (OpenAI Whisper) for processing.
How to reduce your exposure. Every AI-generated reply, on every channel, sends the contact record and the recent transcript to Anthropic; there is no channel that avoids that today, and there is no email channel. What you can control: leave the Facebook and Instagram channels disconnected so Meta never holds a copy of the conversation, leave call transcription off so no audio reaches Telnyx's speech-to-text service, and instruct the AI agent to collect only the minimum necessary. If your compliance posture requires a BAA with every downstream processor, talk to us at privacy@automateadmits.com before you go live. We will update this page the moment any of these agreements is executed.
We give notice before adding or replacing a subprocessor that handles PHI. To be notified, email privacy@automateadmits.com.
Data handling & retention
- Each organization's data is logically isolated in our multi-tenant database and scoped to that organization on every request. We run an automated tenant-isolation audit against the codebase as part of our release process.
- Contacts, conversations, messages, call recordings, and transcripts are retained until they are deleted. There is no automatic expiry on this data — it is kept for the life of the account. You can delete a contact or a conversation at any time from the app, and we delete or return your data on request within a reasonable period after termination.
- The security activity log is retained for six years (the HIPAA 45 CFR 164.316(b)(2) documentation horizon) and then purged automatically. Failed-login records and rate-limit counters are purged on a much shorter cycle.
- Individual data-deletion requests are honored across the platform; see our Privacy Policy.
- Payment card data is handled solely by our PCI-compliant payment processor and is never stored on our servers.
- Copies of message content that reach Meta, Telnyx, or Anthropic are governed by those providers' own retention practices, not ours. Deleting a conversation in Automate Admits does not delete Meta's copy of a Messenger or Instagram thread.
Incident & breach response
On discovery of a security incident or breach of unsecured PHI, we contain and investigate, and notify affected customers without unreasonable delay and no later than 60 days after discovery, in accordance with 45 CFR 164.410. Report a suspected incident to privacy@automateadmits.com.
Compliance roadmap
We are an early-stage company and we build our compliance program in the open. Current status:
- Standing BAA and Security Rule safeguards — live today.
- Subprocessor BAAs — executed with Amazon Web Services, Paubox, and Stedi. Telnyx has indicated a BAA may be available in future and we are pursuing it; Meta and Anthropic do not offer one for the interfaces we use. Status is published in the table above and updated when it changes.
- Part 2 consent management — not built. We act as a QSO and we have a manual consent-review checklist item, but in-product consent capture, revocation, segmentation, and disclosure accounting are on the roadmap, not shipped.
- SOC 2 Type I — on our roadmap; we are formalizing the controls and documentation needed to pursue a report. This is a stated goal, not a current certification.
- Independent penetration test — not yet performed.
We will update this page as our program matures. If your due-diligence process needs specific documentation, contact us.
Contact
Compliance, BAA, or data-handling questions — including requesting a countersigned BAA — go to privacy@automateadmits.com.
Automate Admits is operated by Automate Admits, Inc. This page is provided for general information and is not legal advice. The published Terms of Service, Privacy Policy, DPA, 42 CFR Part 2 statement, and standing Business Associate Agreement govern the relationship between you and Automate Admits, and are governed by the laws of the State of Wyoming.