DIY automation tools are how a lot of practices duct-tape their front office together. The trouble is that intake data is PHI — and both Zapier and Make say, in their own words, that they don’t support it.
“The use of regulated healthcare and medical data including Protected Health Information (PHI) under HIPAA isn’t supported on Zapier. Zapier also can’t sign business associate agreements (BAAs)… for handling PHI.”
— Zapier, official HIPAA statement
Make does not offer a Business Associate Agreement for standard accounts and is not positioned as HIPAA compliant. Its execution logs retain the data each scenario processes, and its SOC 2 / ISO 27001 certifications are not the BAA HIPAA requires.
— Per Make’s published terms & community guidance
Vendor positions as of publication — always confirm current terms directly with each vendor.
HIPAA requires a signed Business Associate Agreement with any vendor that handles PHI on your behalf. Neither Zapier nor Make offers one for standard accounts. Sending PHI through a vendor with no BAA is a violation in itself — not just if data leaks. When PHI is processed by an uncontracted vendor, the covered entity owns 100% of it.
These tools work by receiving your data, processing it, and passing it on. Make's execution logs, for example, retain the data each scenario processes for a period of time. Every step is a copy of PHI on infrastructure no BAA covers.
Make holds SOC 2 and ISO 27001; those attest to security practices but are not a BAA. HIPAA specifically requires the agreement. Good security without a BAA still leaves you non-compliant for PHI.
Zapier connects thousands of apps and relies on sub-processors that themselves don't support HIPAA — a big reason Zapier states it can't become HIPAA compliant. Each connection is another uncovered handoff of PHI.
A well-meaning coordinator wiring up "when a form comes in, send it to our spreadsheet and Slack" can route diagnoses and insurance IDs through three un-covered systems in an afternoon — with no one realizing PHI just left the building.
HIPAA civil penalties are enforced by the HHS Office for Civil Rights, tiered by culpability, and adjusted for inflation each year. State attorneys general can bring their own actions, and a breach triggers mandatory notification of patients, HHS, and — for larger breaches — the media.
*Figures are approximate and adjusted annually for inflation by HHS; the per-violation maximum and annual cap converge at the top tier. Criminal violations (knowingly obtaining or disclosing PHI) carry fines up to $250,000 and up to 10 years imprisonment. This is general information, not legal advice — consult qualified counsel and the current HHS penalty schedule.
Intake looks like admin. It isn’t. It’s where compliance, revenue, and clinical readiness are won or lost — long before a claim is ever filed. These are the risks that live in the front office.
The front office touches protected health information (PHI) from the very first message — names, dates of birth, diagnoses, insurance IDs. HIPAA requires a signed Business Associate Agreement (BAA) with every vendor that creates, receives, stores, or transmits that data on your behalf. Consumer automation tools, generic form builders, shared inboxes, spreadsheets, and chat apps typically do not sign one.
Routing PHI through a vendor with no BAA is itself a HIPAA violation — before any breach occurs. When PHI is processed by an uncontracted vendor, the covered entity (your practice) owns the violation.
Carelu is HIPAA compliant and SOC 2 Type II, and signs a BAA with every provider. PHI stays inside a compliant system instead of flowing through tools that were never covered.
Most claim denials trace back to the front office: a mistyped member ID, a name that doesn't match the plan, an unverified plan, or missing demographics captured in a hurry. The error is invisible at intake and only surfaces weeks later when the claim bounces.
Denied and reworked claims, delayed cash, write-offs, and hours of staff time re-chasing families for information that should have been captured correctly the first time.
Carelu captures insurance details accurately and conversationally at first contact and verifies benefits up front — so the record billing works from is right the first time.
ABA almost always requires prior authorization — separately for assessment and treatment, in fixed increments (often 6 months). Services delivered before an auth is in place, after one lapses, or outside the authorized units frequently can't be billed.
Unbillable, often unrecoverable services — real care delivered for free — plus scramble and denials when a reauthorization slips through the cracks.
Carelu captures the documentation each payer needs for authorization up front and keeps a complete, verified record, so nothing needed for the PA package is missing when it matters.
Payers demand specific diagnostic instruments, recency windows (e.g., assessments within a set number of months), and a Plan of Care with measurable, baseline-anchored goals. A missing tool, a stale evaluation, or an incomplete POC is a common reason assessments and treatment requests are denied.
Denied assessment or treatment authorizations, delayed starts, and families lost during the wait — after the clinical work has already been done.
Carelu gathers the diagnosis report, tools used, and required documents at intake, flagging gaps before they reach the payer instead of after.
When benefits aren't confirmed up front, a family can begin services who turns out to be ineligible, out of network, or already at their benefit limit.
Uncompensated care, awkward mid-treatment conversations about coverage, and revenue that can't be recovered.
Carelu verifies insurance and benefits at first contact, so your team spends assessment slots on families who can actually start care.
Coverage rules vary by payer and plan — ASD-only indications, age ceilings, hour caps, concurrent-therapy restrictions, and state-mandate exemptions. A front office that treats every plan the same will promise care a plan doesn't cover.
Denials, compliance exposure, and families set up to expect services their plan won't pay for.
Carelu is built around payer-aware intake, capturing the plan and details that determine coverage — and Carelu's payer guides keep the rules straight, payer by payer.
Consent to treat, HIPAA acknowledgment, and release-of-information forms are easy to skip in a rushed intake — but they gate everything downstream, from requesting a diagnosis report to billing.
Stalled intakes, inability to obtain required records, and compliance gaps that surface in an audit.
Carelu collects the required consents and releases conversationally, with automatic follow-up on anything missing.
When intake runs on spreadsheets, personal email, shared inboxes, chat apps, and un-vetted SaaS, PHI ends up scattered across systems no one has secured or covered with a BAA. Every copy is another place a breach can happen — and automation logs can retain that data for weeks.
A breach triggers HIPAA breach-notification duties (patients, HHS, sometimes the media), investigation, and penalties — and each stray system multiplies the risk.
Carelu unifies intake in one compliant system of record, so PHI stops living in a dozen places it was never meant to.
Payers and Medicaid audit documentation — supervision logs, timed-code start/stop times, real-time notes, and record-retention rules. Sloppy or back-dated documentation invites clawbacks long after the money was paid.
Recoupment of already-collected revenue, corrective action plans, and in serious cases exclusion from programs.
Carelu produces a clean, timestamped intake record from first contact — the foundation an auditable file is built on.
Before any compliance or billing risk even applies, the family has to be answered. Our research found 48% of family conversations start outside business hours — and the provider who responds first usually wins the placement.
Families lost to a competitor before intake ever begins — the largest and most invisible leak in the funnel.
Carelu answers every family in seconds, on every channel, around the clock — so the compliance and revenue safeguards above actually get the chance to matter.
Carelu does the intake work itself — inside a system built for PHI.
Carelu is HIPAA compliant and SOC 2 Type II, and signs a BAA with every provider. Instead of stringing PHI across form builders, spreadsheets, and un-covered automation tools, Carelu answers families, verifies insurance, and collects documents in one compliant place — then syncs the finished record into the system you already run. No PHI passing through tools that were never meant to hold it.
General information, not legal advice. Vendor terms and penalty amounts change; verify current vendor policies and the HHS penalty schedule, and consult qualified counsel for your situation.
Get PHI off the duct tape.
See how Carelu runs a compliant intake end to end — and retires the spreadsheet-and-Zap stack behind your front office.
Get a Demo