The hidden HIPAA cost of giving behavior techs email — and how one practice cut it

A mid-sized ABA practice · high part-time headcount · communication-heavy, email-light

This is the story of a mid-sized ABA practice that went looking for an easy win and found a line item it had simply stopped questioning: a paid email mailbox for every behavior technician on the roster. We've kept them anonymous, but the math — and the compliance trap underneath it — will be familiar to anyone who has scaled a practice past a couple dozen front-line staff.

First, the obvious question: why do behavior techs have email at all?

Nobody ever decided BTs needed email. It accreted. You spin up the practice on Microsoft 365 or Google Workspace because the owner and BCBAs need it, the wizard asks how many users, and "everyone gets an account" is the path of least resistance. Onboarding paperwork goes to an inbox. The occasional all-staff announcement goes to an inbox. So every new hire gets a mailbox, and it becomes invisible furniture.

But look at what a behavior tech's day actually involves. They're in homes and clinics, on their feet, running sessions. Their real communication is fast and mobile: "running late," "client cancelled," a quick question to the supervising BCBA, a heads-up to a parent. That happens by text and phone — not by composing an email. For most BTs, the company mailbox is a place announcements go to die.

Frequently asked questions

Isn't free email like Gmail fine for my behavior techs?

Not for anything client-related. Personal/free accounts (gmail.com, outlook.com) don't come with a Business Associate Agreement, and the provider won't sign one. The moment a tech's email includes a client's name with anything about their care, that's PHI — and a free account holding PHI is a HIPAA violation. Compliant email means a paid business plan with a signed BAA.

What exactly makes staff email a HIPAA problem?

Any system that handles PHI on your behalf has to be covered by a BAA, with encryption, access controls, audit logging, and retention. A scheduling note like "running late to a session," a parent reply, or a question about a kiddo's program all count as PHI. So every PHI-capable mailbox has to be on a paid, BAA-covered, properly-configured plan — not the free tier.

It's just a client's name, not medical details — is that really PHI?

Yes — and it's the part most practices miss. For a behavioral-health provider, the name is the disclosure: it reveals that a specific, named person is your client, and that treatment relationship is itself individually identifiable health information. You don't have to say a word about their care for it to count. So an unencrypted notification like "New message from [client name]" — sitting in a subject line, an email preview, a lock screen, or a mail-server log — is already a PHI exposure, not just an accidental one. The compliant pattern is the generic "You have a new secure message — log in to your portal to view," with no name and no content. In Wilma that conversation lives on the secure portal behind login, so the name and the message never sit in an exposed email.

If email needs a BAA, why are phone calls and faxes fine?

Because of HIPAA's "conduit exception." A carrier that only carries a message in transit — a phone company carrying a call, a fax going down a phone line — is treated as a mere conduit: it moves the information without storing it or routinely looking at it, so it doesn't need a BAA. Email is different because providers store your messages on their servers — that's maintaining PHI, not just transporting it — which is why a free mailbox can't hold it without a signed BAA. The line is transient transport vs. storage: the moment a service keeps the PHI (cloud/e-fax, recorded calls and voicemail, email), it needs a BAA. That's also why secure messaging on the client record — not personal email — is the clean fit. (General compliance posture, not legal advice.)

How much does HIPAA-compliant email actually cost?

Compliant tiers start around $6–7/user/month (Microsoft 365 Business Basic, Google Workspace Business Starter) and run $12–22 for higher tiers. For a 60-tech roster that's roughly $4,300–$9,000/year just for mailboxes most techs barely open — before the hidden costs of provisioning, securing, auditing, and offboarding a high-turnover roster.

Isn't bringing messages into Wilma just surveillance of my staff?

No — it's the same principle as a session note. Communication about a client belongs on that client's record so the practice has continuity of care and a clean audit trail. It's not about monitoring people's private lives; it's being able to answer "what did we tell this family?" — which is exactly what you can't do when it's buried in one tech's personal inbox.

What happens to all that access when a tech quits?

With email, every departure is a mailbox to find and revoke, plus a personal Gmail you never controlled and can't close. That gap is enforced: in December 2024, regulators fined one practice ~$1.19M partly for not cutting off a former worker's access and not reviewing activity logs. In Wilma, access ends inside the platform in one step — no orphaned inboxes, no "did we remember to revoke that?" after a high-churn year.

Do my techs lose anything by not having email?

In practice, no — because email wasn't how they communicated. Their day runs on fast, mobile messaging and phone: schedule changes, parent updates, quick BCBA questions. Wilma covers those with secure messaging, a business line, and SMS, all tied to the client record. Announcements and documents move into the platform and existing systems.

Is Wilma's communication actually HIPAA-ready?

Yes. Communication in Wilma lives inside the same HIPAA-grade platform already trusted with your clients' clinical and billing records — access-controlled, audited, and covered by the BAA Wilma signs as standard with every customer. That's the point: it's PHI-ready by default, not scattered across personal inboxes that aren't.