Trust & Compliance

Last updated: July 26, 2026

Automate Admits is built for admissions and intake teams that handle sensitive health information. This page explains how we handle HIPAA and 42 CFR Part 2, the standing Business Associate Agreement we offer every customer, every subprocessor we rely on, and how we protect your data. We publish the gaps as plainly as the controls — read the subprocessor and Part 2 sections before you send us regulated records.

On this page

HIPAA & Business Associate Business Associate Agreement 42 CFR Part 2 Security program Subprocessors Data handling & retention Incident response Compliance roadmap Contact

HIPAA & Business Associate status

When you use Automate Admits to communicate with patients and leads, we act as your Business Associate under the HIPAA Rules (45 CFR Parts 160 and 164). You remain the Covered Entity (or, in some arrangements, another business associate) and control the care relationship; we provide the software and process protected health information (PHI) only to deliver the Service on your behalf.

We are software, not a healthcare provider — we do not provide medical, clinical, or treatment advice, and we are not part of your care team. But because your conversations can include PHI, we take on the safeguards, reporting, and contractual obligations that HIPAA requires of a business associate.

We describe Automate Admits as HIPAA-eligible, not HIPAA-certified. There is no such thing as HIPAA certification — no government body certifies software. What we mean is that the Service is architected and contracted so a covered entity or business associate can use it for PHI: we sign a BAA, PHI is stored and processed on infrastructure covered by our own BAAs, and we implement Security Rule safeguards. Compliance is a shared outcome; how you configure and use the Service is part of it.

Standing Business Associate Agreement (BAA)

We publish a single, standing BAA that applies to every customer — you don't need to negotiate or sign a separate agreement for your organization. By subscribing to and using Automate Admits to handle PHI, your organization accepts the standing BAA by reference; it is incorporated into our Terms of Service and takes effect the moment the Service is used with PHI.

Need a countersigned copy for your records, or want to review the full text before you sign up? Request it at privacy@automateadmits.com. Signed-in customers can also read the full BAA and policy pack under Settings → Policies & procedures.

The standing BAA commits us to, among other things:

The published BAA governs; this summary is for orientation only.

42 CFR Part 2 — substance use disorder records

Many of our customers are substance use disorder (SUD) treatment programs. Where the Service is used by a Part 2 program, we act as a Qualified Service Organization (QSO). Every account owner accepts our QSO agreement at signup, and that acceptance is recorded against the account.

What we commit to

What the platform does not do — read this

We would rather tell you plainly than let you assume. Automate Admits does not currently provide Part 2 consent management. Specifically, the platform has no patient-consent record, no consent revocation workflow, no segmentation of Part 2 records from other records, no automatic application of the redisclosure notice, and no accounting-of-disclosures log. Those controls live in your systems and your procedures, not ours.

As the covered program, you are responsible for obtaining, documenting, and honoring any patient consent required before information is entered into or sent through the platform, for applying the required notice prohibiting redisclosure to anything you send out of it, and for maintaining any accounting of disclosures Part 2 requires of you. We give you a per-organization compliance checklist inside the app that includes a periodic Part 2 consent review, but the checklist is a reminder — the review itself is manual and performed by your team.

See our 42 CFR Part 2 statement for the full detail.

Security program

PHI is encrypted in transit (TLS) and at rest, access is role-based and least-privilege, passwords are stored only as salted hashes, and two-factor authentication is available. PHI access and account changes are recorded in a per-organization activity log. Full technical detail is on our Security page.

Because the AI agent must read message content to draft replies, the Service is not end-to-end encrypted; data is encrypted in transit and at rest and access-controlled.

Subprocessors

This is the complete list of providers that receive customer data when you use the Service. Every one is engaged under contractual confidentiality and security obligations. Where we have executed a business associate agreement, we say so; where we have not, we say that too. We do not claim BAAs we do not hold.

SubprocessorPurposeData it receivesBAA
Amazon Web Services, Inc.Application hosting, database, object storage, and compute — the system of record, where PHI is stored and processedAll application and patient data (PHI), encrypted at rest and in transitYes — BAA
Paubox, Inc.Transactional & notification email to your teamTeam email addresses and notification content, which can reference a contactYes — BAA
Stedi, Inc.Insurance eligibility & benefits verification (X12 270/271 clearinghouse)Patient first name, last name, date of birth, and member ID; your provider NPI and organization name. The full 271 benefits response is returned and stored by usYes — BAA
Anthropic, PBCAI drafting and conversation summarizationThe contact record and the recent conversation transcript, including any images or media the contact sent. Not used to train modelsNo BAA
Meta Platforms, Inc.Send and receive messages on the Facebook Pages and Instagram accounts you connectMessage content and the contact's platform profile on channels you connectNo BAA
Telnyx LLCSMS and voice transport, phone numbers, call recording, and speech-to-text transcriptionPhone numbers, message bodies, and call audio in transit; transcription sends call audio to Telnyx's speech-to-text service, which is powered by OpenAI Whisper. Recordings and transcripts are stored by us on AWSNo BAA
Cloudflare, Inc.Public marketing site, static-asset delivery, DNS, and CDN/DDoS protectionPublic marketing content and application code only — no PHINo PHI
Stripe, Inc.Subscription and top-up payment processingBilling contact and card data only — no patient dataNo PHI

About the three providers without a BAA

Three subprocessors can receive information that may constitute PHI and are not covered by a business associate agreement with us. You should know exactly what that means before you decide how to use the Service.

How to reduce your exposure. Every AI-generated reply, on every channel, sends the contact record and the recent transcript to Anthropic; there is no channel that avoids that today, and there is no email channel. What you can control: leave the Facebook and Instagram channels disconnected so Meta never holds a copy of the conversation, leave call transcription off so no audio reaches Telnyx's speech-to-text service, and instruct the AI agent to collect only the minimum necessary. If your compliance posture requires a BAA with every downstream processor, talk to us at privacy@automateadmits.com before you go live. We will update this page the moment any of these agreements is executed.

We give notice before adding or replacing a subprocessor that handles PHI. To be notified, email privacy@automateadmits.com.

Data handling & retention

Incident & breach response

On discovery of a security incident or breach of unsecured PHI, we contain and investigate, and notify affected customers without unreasonable delay and no later than 60 days after discovery, in accordance with 45 CFR 164.410. Report a suspected incident to privacy@automateadmits.com.

Compliance roadmap

We are an early-stage company and we build our compliance program in the open. Current status:

We will update this page as our program matures. If your due-diligence process needs specific documentation, contact us.

Contact

Compliance, BAA, or data-handling questions — including requesting a countersigned BAA — go to privacy@automateadmits.com.

Request a BAA

Automate Admits is operated by Automate Admits, Inc. This page is provided for general information and is not legal advice. The published Terms of Service, Privacy Policy, DPA, 42 CFR Part 2 statement, and standing Business Associate Agreement govern the relationship between you and Automate Admits, and are governed by the laws of the State of Wyoming.