Network · Smart Referrals
The other office does not have to buy anything. They do have to sign.
Referral records leave most practices by fax or by somebody's email, because the alternative has always required the other end to adopt your software. This does not.
HIPAA mapping
Where this fits in the HIPAA rules.
4 provisions this capability contributes to, each with the specific Smart Referrals behavior behind it. The obligation stays with your practice — the mapping shows which part of the work the platform carries.
§164.506(c)(2)Disclosures for treatment
Permits a covered entity to disclose PHI to another covered entity for that entity's treatment activities without an authorization. Referral to a treating provider is the textbook case, which is why the hard part of referrals is not permission — it is the channel.
§164.502(e)(1)Business associate assurances
Where a recipient handles PHI on your behalf rather than as a treating provider, satisfactory assurances are required first. The referred-to office executes the Patient Protect agreement before it can retrieve anything, so the paperwork precedes the file rather than chasing it.
§164.312(e)(1)Transmission security
Requires technical measures guarding against unauthorized access to ePHI transmitted over a network. This is the provision fax and personal email fail, and the reason the channel matters more than the consent question most referral marketing dwells on.
§164.502(b)Minimum necessary
Does not apply to disclosures to a provider for treatment, which surprises people. It does apply to much else you might send alongside, and deciding what actually needs to travel with a referral remains your practice's judgement.
What it does
Referral records still move by fax, and everyone knows why.
It is not that practices prefer fax. It is that every secure alternative has required the office at the other end to sign up for something, and the specialist you refer to has their own systems, their own vendors and no interest in adopting yours because you asked. So the records go out the one way that works everywhere, which is the way with no audit trail and a documented history of landing on the wrong machine.
Smart Referrals removes the adoption problem from the receiving side. The office you are referring to executes the Patient Protect business associate agreement and can then retrieve the files through Secure Messaging — at no cost, on no trial, without becoming a Patient Protect customer. What they get is receipt of what you sent them, not the platform.
Your side executes no separate referral-specific business associate agreement — you still run the referral, but you do not paper a new BAA to do it. The exchange runs through the same governed channel, is recorded the same way, and the referred-to offices you build up appear as a count on your Scoreboard rather than as a folder of fax confirmations nobody has looked at since.
How it works
5 mechanisms keep Smart Referrals working.
The receiving office signs, and that is the whole onboarding.
A referred-to office executes the Patient Protect BAA before it retrieves anything. That is the entire ask — no subscription, no trial period that expires into a sales call, no software to evaluate. The agreement is the thing that makes the exchange lawful, so it is the thing the product insists on, and nothing else.
Free retrieval means retrieval, not the platform.
Worth being exact, because this is where products usually blur. A referred-to office using the free experience can receive files through Secure Messaging. It does not thereby hold Basic or Pro, it is not on a fourteen-day trial, and no clock is running against it. If that office later wants the platform it becomes a customer in the ordinary way, and the referral relationship is why they would have heard of it.
No separate BAA on your side, per referral or otherwise.
The referring practice does not execute a referral-specific business associate agreement. To be exact about what that does and does not mean: you still do the referral — decide what to send, to whom, and when. What you do not do is add a new agreement to the pile each time, which sounds like an administrative detail and is the difference between a channel a practice uses and one it means to use once the paperwork is sorted out.
The records travel through the governed channel.
Referral files move through Secure Messaging, which means they get its properties rather than a second implementation of them: encrypted in transit and at rest, gated on agreement state, and recorded with sender, recipient and time. A referral is a use of the exchange, not a parallel system with its own security story to verify.
Referral offices are a number you can see.
The offices you have connected to appear as a count on the Compliance Scoreboard alongside your workforce, vendors and policies. It is a small thing that does a specific job: referral relationships are otherwise invisible operational state, remembered by whoever set them up and forgotten when that person leaves.
Who this is for
Built for the practices that need it most.
Practices whose referral records go out by fax.
Which is most of them, and rarely by choice. If the reason is that the specialist will not adopt your software, this removes that reason without asking you to argue for it.
Practices that refer to the same handful of offices.
The value compounds where the relationships are stable — the two orthodontists, the oral surgeon, the imaging center. Signing once and exchanging repeatedly is a very different proposition from signing per referral.
Practices that have been asked how records left the building.
After an incident or during a review, the question is how PHI traveled and what record exists of it. A fax confirmation sheet is not that record.
What you get
5 outcomes you’ll feel in week one.
No adoption ask.
The receiving office signs an agreement, not a contract with us.
Free on the receiving side.
Retrieval through Secure Messaging, no trial and no clock.
No extra BAA on your side.
You run the referral; you do not paper a new agreement for it.
The governed channel, reused.
Encryption, gating and logging come from Secure Messaging.
Relationships you can count.
Referral offices appear on the Scoreboard rather than in someone's memory.
Does the office I refer to need to buy Patient Protect?
Do we need a separate BAA for referrals?
What does the receiving office actually get?
Can we refer for substance use disorder treatment records?
What about patient consent for the referral itself?
Which plan includes this?
What it does not do.
- The referred-to experience is not a disguised 14-day full-platform trial
- No expiration period is claimed, because none is verified
Continue exploring
Related features in the platform.
Network
Secure Messaging
Encrypting a message is the part everyone gets right. Knowing whether the person receiving it is covered by an agreement, and refusing to send when they are not, is a different job — and it is the one this channel does.
Learn moreDefense
Vendor & BAA Governance
A BAA is either in force or it is not, and most practices cannot say which. Six states, one list, and ePHI blocked where no agreement covers it.
Learn moreDefense
ePHI Audit
The question after an incident is never abstract. It is whether one named person opened one named record on one particular afternoon, and whether you can show it.
Learn moreSign once. Exchange for as long as the relationship lasts.
The reason referral records still move by fax is that the alternative asked too much of the other end. This asks for a signature.
