Simple News Ticker Using HTML and CSS
Make 2026 Your Best Year Yet! Get 62% Off For Life!
Make 2026 Your Best Year Yet! Get 62% Off For Life!
Make 2026 Your Best Year Yet! Get 62% Off For Life!
Make 2026 Your Best Year Yet! Get 62% Off For Life!

HIPAA & Data Compliance

PowerZone is designed to support therapists and coaches in building and scaling their business, including features that can be configured to support HIPAA compliance.

HIPAA-Enabled Accounts

HIPAA compliance is not automatically enabled on all accounts.

To use PowerZone in a HIPAA-compliant way:

You must ensure your account has HIPAA mode activated

A Business Associate Agreement (BAA) must be in place Read and sign the document here to be the HIPAA Complaint

You must follow proper handling of Protected Health Information (PHI)

If you are unsure whether your account is HIPAA-enabled, please contact support immediately.

Our Role

PowerZone operates as a Business Associate using secure infrastructure provided by HighLevel.

We have a signed BAA with our platform provider to ensure:

Secure handling of data

Appropriate safeguards

Compliance-ready infrastructure

Your Responsibility (VERY IMPORTANT)

Users are responsible for:

Ensuring HIPAA settings are enabled

Using the platform in a compliant manner

Managing how PHI is collected, stored, and shared

Ensuring email/SMS communications meet HIPAA requirements

Important Limitations

Not all communication channels are automatically HIPAA-compliant - including email, SMS, and certain automation workflows.

While PowerZone provides the infrastructure and tools to support HIPAA-compliant operations, compliance depends on how those tools are configured and used.

Email & SMS Communications

Standard email and SMS are not inherently secure or encrypted in a way that guarantees HIPAA compliance.

To use these channels compliantly, you must:

Obtain proper client consent where required

Avoid transmitting sensitive Protected Health Information (PHI) unless safeguards are in place

Ensure your workflows align with HIPAA privacy and security standards

Automation & Workflows

Automations (including follow-ups, reminders, and pipelines) must be configured carefully.

Improper setup may result in:

Unintentional sharing of PHI

Data being sent through non-secure channels

Breaches of client confidentiality

Account Configuration Matters

HIPAA compliance is only supported when:

HIPAA mode is properly enabled

Required agreements (such as a BAA) are in place

Security settings are correctly configured

If these are not set up correctly, your account should not be used to store or transmit PHI.

What PowerZone Does NOT Do

PowerZone does not:

Monitor or control how you use PHI

Automatically prevent non-compliant communication

Guarantee compliance based on platform access alone

Your Responsibility as the User

You are fully responsible for:

How client data is collected, stored, and shared

Ensuring your communication methods are compliant

Training your team (if applicable) on proper data handling

Following all applicable HIPAA regulations

The Reality (plain English)

PowerZone gives you the engine.

But if you drive it off-road with client data… that’s on you.

Business Associate Agreements

If you require a BAA for your practice, Read and sign the document here to be the HIPAA Complaint

HIPAA Safe Usage Checklist

Use this checklist to ensure you are operating your PowerZone account in a HIPAA-compliant way when handling client data.

1. Activate HIPAA Mode

If you don’t see this, contact support before using any PHI

2. Be Mindful of What You Store

  • Only store Protected Health Information (PHI) when HIPAA mode is active

  • Avoid uploading unnecessary sensitive data

  • Keep records minimal and relevant

3. Use Communication Channels Carefully

  • Do not send sensitive PHI via standard email or SMS without safeguards

  • Obtain client consent where required

  • When in doubt, keep messages general (no detailed personal health info)

4. Check Your Automations

  • Review all workflows, reminders, and follow-ups

  • Ensure no sensitive data is being sent automatically

  • Avoid including PHI in:

    • email sequences

    • SMS reminders

    • pipeline notifications

5. Control Account Access

  • Only give access to authorized team members

  • Remove access immediately if someone leaves your team

  • Use strong passwords and secure logins

6. Train Yourself (and Your Team)

  • Understand what qualifies as PHI

  • Follow basic HIPAA privacy and security rules

  • Ensure anyone using your account knows what not to do

7. Keep Your Systems Clean

  • Regularly review stored data

  • Delete anything unnecessary

  • Keep your account organized and secure

8. Know Your Responsibility

PowerZone provides the tools to support HIPAA compliance.

But compliance depends on:

  • how you configure your account

  • how you communicate with clients

  • how you handle and store data

You are responsible for ensuring your usage meets HIPAA requirements.

Simple Rule to Follow

If you wouldn’t feel comfortable sending it in a public email…

Don’t send it without proper safeguards.

*Not sure if you’re set up correctly? Contact us and we’ll verify your account is configured safely.