Compliance

HIPAA-compliant parent communication for ABA clinics

Nearly every clinic arrives at this question the same way: the tool was picked years ago by someone solving a real problem quickly, the clinic looked like a preschool, and nobody asked whether parent messaging was a compliance surface.

This page collects what each of the common tools says about itself, in its own words, and what a replacement actually has to do.

The short version.

The school and consumer apps clinics tend to inherit do not offer a business associate agreement, and most of them say so on their own compliance pages. That closes the question at procurement, before anyone reaches a feature comparison.

What that leaves is not a shortlist but an absence: many clinics are running nothing, because the obvious tools are unavailable to them and the clinical systems they already pay for were never built for a conversation with a parent.

Why this is PHI, and not a technicality.

It is worth being precise about, because the intuition that a note about a child's day is not really medical information is the thing that lets this run for years unexamined.

ABA is a prescribed medical treatment.

It is recommended by a physician for a diagnosed condition and paid for by health plans. That is what makes a clinic delivering it a covered entity, and it is the fact that everything else follows from. The resemblance to an early-childhood setting is incidental.

Almost everything you tell a parent is clinical.

Behaviour frequency, antecedents, how a transition went, a protocol change, a note about a hard afternoon. Combined with the child’s name it is protected health information. The threshold is far lower than people assume, and photographs clear it on their own.

The obligation is on you, not on the vendor.

A vendor cannot expose you to a penalty; only your own use of it can. That is uncomfortable but it is also the reason this is worth an hour of your time rather than a vendor’s. The tool that was chosen by an office manager in 2021 is your exposure now.

What each vendor says about itself.

Quoted from the vendor's own documentation, with the date we last read it there. Follow any row for the full quote and the reasoning.

The requirements a replacement has to meet.

The first is a legal precondition. The rest are what separate a tool that survives contact with a clinic day from one that is quietly abandoned by March.

A signed BAA, before any data

Executed before a single child’s name is loaded, not promised during onboarding.

Conversations owned by the practice

A departure removes access and leaves the history behind.

Per-family scoping, enforced

A parent reaches their own child and nothing else, in any view.

Attribution on every entry

So the handoff and the audit trail are the same record, not two.

Exportable history

You can produce the record of what a family was told, on demand.

No adoption burden on parents

A tool families will not open is a tool staff will route around.

Built around the session, not the room.

In Cliqit, staff tap a child, tap what happened, and pick the detail from a list. Every entry carries the child, the technician and the time. Parents only ever reach their own child, and the practice keeps the record when someone leaves.

The same entries do two jobs without being written twice: they keep the shift handoff current during the day, and they assemble the end-of-day summary at pick-up. It runs alongside your practice management system and never touches a claim.

Questions clinics ask about this.

What makes ABA parent communication protected health information?

ABA is a prescribed treatment for a diagnosed condition, billed to health plans, which makes the clinic delivering it a covered entity. Communication about sessions, behaviour, goals and progress is health information about an identified child, so it is PHI. A photograph of a child at your clinic is PHI on its own, because the location implies the diagnosis.

Is a HIPAA-compliant app enough on its own?

No. Compliance is a property of how you use a tool, not a badge the tool carries. You need the BAA executed, access limited to staff who need it, a real retention position, and staff who understand that the clinic channel is the only channel. A compliant tool used alongside a WhatsApp group has not fixed anything.

Do we have to replace our practice management system?

No, and you should not try to. CentralReach, Rethink, Motivity and Theralytics all state that they are HIPAA compliant and act as business associates, and they are not the problem here. The gap is the day-to-day parent and team communication that sits outside those systems and has quietly ended up in classroom apps and personal phones.

Our clinics each chose a different tool. What do we do first?

Inventory before procurement. Find out which tools hold a child’s identity plus anything clinical, including photos and free-text notes, because the answer is usually wider than leadership expects and the number is what carries the internal argument. Then standardise on one platform that will sign a BAA, which solves the consistency problem at the same time.

Does encryption make a tool compliant?

Encryption is necessary and nowhere near sufficient. HIPAA also requires a business associate agreement with the operator, administrative control over access, audit trails, disclosure accounting and breach procedures. WhatsApp is the clearest illustration: excellent encryption, and an explicit disclaimer that its business services are not represented as meeting the needs of healthcare entities.

How do we handle parents who insist on texting a technician directly?

Give them something faster than texting rather than a policy telling them not to. Families reach for a personal number because it works, and staff hand it out because refusing feels unhelpful. If the clinic channel is slower or requires a parent to remember a password, the private threads come back regardless of what the handbook says.

The rest of this cluster

Sources

Every claim about another product on this page is a quote from that product’s own documentation, linked below with the date we last read it there. Vendors revise these pages. If you find one of these out of date, tell us and we will correct it.

  1. [1] brightwheelbrightwheel Security FAQs · checked August 26, 2026
  2. [2] brightwheelbrightwheel Security FAQs · checked August 26, 2026
  3. [3] ClassDojoPrivacy and Security · checked August 26, 2026
  4. [4] BloomzBloomz Security Pledge · checked August 26, 2026
  5. [5] BloomzBloomz Security Pledge · checked August 26, 2026
  6. [6] WhatsAppWhatsApp Business Terms of Service · checked August 26, 2026

Show us what you are using now.

Fifteen minutes. If what you have works for your caseload, we will tell you to keep it.