06/18/2026
Using Central Reach, Motivity, Chorus, ReThink or Ensora etc. This is for you:
Using these does not mean you're HIPAA compliant.
I see this constantly in ABA practices, especially early-stage ones. The platform is compliant. The contract is signed and a BAA is in place. And then someone is emailing a session note, an authorization, or a parent update from their personal Gmail account.
That's a breach. Full stop.
But even if PHI never touches the inbox.. there's another problem nobody talks about.
Your staff are logging into your clinical platform with their personal email.
That matters because:
- When they leave, can you disable that access immediately?
- Where are their password reset links going? Their MFA codes?
- If their personal email gets compromised, that's now a direct path into your client data.
- You have zero control over an inbox you don't own.
HIPAA compliance isn't about the software. It's about the entire ecosystem PHI touches.
Personal emails are not compliant. Ever. Even just as a login.
Staff accessing client data on personal phones without a device policy? NOT COMPLIANT.
WhatsApp, personal texts, Messenger for parent communication? NOT COMPLIANT
The BAA you signed with your platform doesn't protect you when your RBT logs in from an account you can't audit, control, or deactivate.
Compliance lives in your policies, your training, your enforcement, and your culture, not just your tech stack.
Google Workspace and Microsoft 365 are both inexpensive. Both give you control over every account, every login, every offboard. Don't let a small cost per month, drain everything you spent years building.
This is where compliance actually starts.
Call now to connect with business.