Compliance Risk

Zapier and Make aren’t HIPAA compliant. For ABA intake, that’s a problem.

DIY automation tools are how a lot of practices duct-tape their front office together. The trouble is that intake data is PHI — and both Zapier and Make say, in their own words, that they don’t support it.

Zapier

“The use of regulated healthcare and medical data including Protected Health Information (PHI) under HIPAA isn’t supported on Zapier. Zapier also can’t sign business associate agreements (BAAs)… for handling PHI.”

— Zapier, official HIPAA statement

Make (Integromat)

Make does not offer a Business Associate Agreement for standard accounts and is not positioned as HIPAA compliant. Its execution logs retain the data each scenario processes, and its SOC 2 / ISO 27001 certifications are not the BAA HIPAA requires.

— Per Make’s published terms & community guidance

Vendor positions as of publication — always confirm current terms directly with each vendor.

Why running intake through them is dangerous

No BAA means you own the violation

HIPAA requires a signed Business Associate Agreement with any vendor that handles PHI on your behalf. Neither Zapier nor Make offers one for standard accounts. Sending PHI through a vendor with no BAA is a violation in itself — not just if data leaks. When PHI is processed by an uncontracted vendor, the covered entity owns 100% of it.

Your data passes through — and lingers on — their servers

These tools work by receiving your data, processing it, and passing it on. Make's execution logs, for example, retain the data each scenario processes for a period of time. Every step is a copy of PHI on infrastructure no BAA covers.

Security certifications are not the legal instrument HIPAA needs

Make holds SOC 2 and ISO 27001; those attest to security practices but are not a BAA. HIPAA specifically requires the agreement. Good security without a BAA still leaves you non-compliant for PHI.

Sub-processors multiply the exposure

Zapier connects thousands of apps and relies on sub-processors that themselves don't support HIPAA — a big reason Zapier states it can't become HIPAA compliant. Each connection is another uncovered handoff of PHI.

It becomes invisible shadow IT

A well-meaning coordinator wiring up "when a form comes in, send it to our spreadsheet and Slack" can route diagnoses and insurance IDs through three un-covered systems in an afternoon — with no one realizing PHI just left the building.

The penalties are not theoretical.

HIPAA civil penalties are enforced by the HHS Office for Civil Rights, tiered by culpability, and adjusted for inflation each year. State attorneys general can bring their own actions, and a breach triggers mandatory notification of patients, HHS, and — for larger breaches — the media.

Culpability tierPer violationAnnual cap*
No knowledge~$140 – $71,000~$2.1M
Reasonable cause~$1,400 – $71,000~$2.1M
Willful neglect — corrected~$14,000 – $71,000~$2.1M
Willful neglect — not corrected~$71,000+~$2.1M

*Figures are approximate and adjusted annually for inflation by HHS; the per-violation maximum and annual cap converge at the top tier. Criminal violations (knowingly obtaining or disclosing PHI) carry fines up to $250,000 and up to 10 years imprisonment. This is general information, not legal advice — consult qualified counsel and the current HHS penalty schedule.

The risks the front office actually carries.

Intake looks like admin. It isn’t. It’s where compliance, revenue, and clinical readiness are won or lost — long before a claim is ever filed. These are the risks that live in the front office.

Compliance

Handling PHI without a Business Associate Agreement

The front office touches protected health information (PHI) from the very first message — names, dates of birth, diagnoses, insurance IDs. HIPAA requires a signed Business Associate Agreement (BAA) with every vendor that creates, receives, stores, or transmits that data on your behalf. Consumer automation tools, generic form builders, shared inboxes, spreadsheets, and chat apps typically do not sign one.

The cost

Routing PHI through a vendor with no BAA is itself a HIPAA violation — before any breach occurs. When PHI is processed by an uncontracted vendor, the covered entity (your practice) owns the violation.

How Carelu reduces it

Carelu is HIPAA compliant and SOC 2 Type II, and signs a BAA with every provider. PHI stays inside a compliant system instead of flowing through tools that were never covered.

Revenue

Claim denials from bad or missing intake data

Most claim denials trace back to the front office: a mistyped member ID, a name that doesn't match the plan, an unverified plan, or missing demographics captured in a hurry. The error is invisible at intake and only surfaces weeks later when the claim bounces.

The cost

Denied and reworked claims, delayed cash, write-offs, and hours of staff time re-chasing families for information that should have been captured correctly the first time.

How Carelu reduces it

Carelu captures insurance details accurately and conversationally at first contact and verifies benefits up front — so the record billing works from is right the first time.

Revenue

Prior authorization gaps and lapses

ABA almost always requires prior authorization — separately for assessment and treatment, in fixed increments (often 6 months). Services delivered before an auth is in place, after one lapses, or outside the authorized units frequently can't be billed.

The cost

Unbillable, often unrecoverable services — real care delivered for free — plus scramble and denials when a reauthorization slips through the cracks.

How Carelu reduces it

Carelu captures the documentation each payer needs for authorization up front and keeps a complete, verified record, so nothing needed for the PA package is missing when it matters.

Clinical

Assessment and documentation errors

Payers demand specific diagnostic instruments, recency windows (e.g., assessments within a set number of months), and a Plan of Care with measurable, baseline-anchored goals. A missing tool, a stale evaluation, or an incomplete POC is a common reason assessments and treatment requests are denied.

The cost

Denied assessment or treatment authorizations, delayed starts, and families lost during the wait — after the clinical work has already been done.

How Carelu reduces it

Carelu gathers the diagnosis report, tools used, and required documents at intake, flagging gaps before they reach the payer instead of after.

Revenue

Starting families whose eligibility was never verified

When benefits aren't confirmed up front, a family can begin services who turns out to be ineligible, out of network, or already at their benefit limit.

The cost

Uncompensated care, awkward mid-treatment conversations about coverage, and revenue that can't be recovered.

How Carelu reduces it

Carelu verifies insurance and benefits at first contact, so your team spends assessment slots on families who can actually start care.

Compliance

Medical-necessity and coverage mismatches

Coverage rules vary by payer and plan — ASD-only indications, age ceilings, hour caps, concurrent-therapy restrictions, and state-mandate exemptions. A front office that treats every plan the same will promise care a plan doesn't cover.

The cost

Denials, compliance exposure, and families set up to expect services their plan won't pay for.

How Carelu reduces it

Carelu is built around payer-aware intake, capturing the plan and details that determine coverage — and Carelu's payer guides keep the rules straight, payer by payer.

Compliance

Missing consents and records-release authorizations

Consent to treat, HIPAA acknowledgment, and release-of-information forms are easy to skip in a rushed intake — but they gate everything downstream, from requesting a diagnosis report to billing.

The cost

Stalled intakes, inability to obtain required records, and compliance gaps that surface in an audit.

How Carelu reduces it

Carelu collects the required consents and releases conversationally, with automatic follow-up on anything missing.

Compliance

PHI sprawl and breach exposure

When intake runs on spreadsheets, personal email, shared inboxes, chat apps, and un-vetted SaaS, PHI ends up scattered across systems no one has secured or covered with a BAA. Every copy is another place a breach can happen — and automation logs can retain that data for weeks.

The cost

A breach triggers HIPAA breach-notification duties (patients, HHS, sometimes the media), investigation, and penalties — and each stray system multiplies the risk.

How Carelu reduces it

Carelu unifies intake in one compliant system of record, so PHI stops living in a dozen places it was never meant to.

Compliance

Audit and recoupment risk

Payers and Medicaid audit documentation — supervision logs, timed-code start/stop times, real-time notes, and record-retention rules. Sloppy or back-dated documentation invites clawbacks long after the money was paid.

The cost

Recoupment of already-collected revenue, corrective action plans, and in serious cases exclusion from programs.

How Carelu reduces it

Carelu produces a clean, timestamped intake record from first contact — the foundation an auditable file is built on.

Revenue

Slow or after-hours response

Before any compliance or billing risk even applies, the family has to be answered. Our research found 48% of family conversations start outside business hours — and the provider who responds first usually wins the placement.

The cost

Families lost to a competitor before intake ever begins — the largest and most invisible leak in the funnel.

How Carelu reduces it

Carelu answers every family in seconds, on every channel, around the clock — so the compliance and revenue safeguards above actually get the chance to matter.

The compliant alternative

Carelu does the intake work itself — inside a system built for PHI.

Carelu is HIPAA compliant and SOC 2 Type II, and signs a BAA with every provider. Instead of stringing PHI across form builders, spreadsheets, and un-covered automation tools, Carelu answers families, verifies insurance, and collects documents in one compliant place — then syncs the finished record into the system you already run. No PHI passing through tools that were never meant to hold it.

Sources & further reading

General information, not legal advice. Vendor terms and penalty amounts change; verify current vendor policies and the HHS penalty schedule, and consult qualified counsel for your situation.

Get PHI off the duct tape.

See how Carelu runs a compliant intake end to end — and retires the spreadsheet-and-Zap stack behind your front office.

Get a Demo