Regulated SMBs

Back-office AI for clinics and agencies that can’t afford a finding.

For home-health agencies, dental and medical practices, billing services, and advisors — AI agents that draft and route, but never act on patient or money data without your signoff. Plus an audit log your surveyor can read.

Not a HIPAA-covered entity. No BAA available today.You approve before anything material happensPer-run cost cap

You face enterprise compliance with SMB headcount.

  • You face the same compliance work product as an enterprise — with SMB headcount.
  • Generic AI tools can't produce a log a regulator would accept.
  • Enterprise compliance platforms are priced for organizations 10x your size.
  • One breach can end the practice.

What a small-but-regulated team gets out of GoodHelp.

Audit-ready by default

Hash-chained action ledger plus signed evidence export — KMS-rooted signing key, JSON manifest plus body. The audit pack is one click, not a fire drill.

Approval gates on anything material

You (or your designated approver) sign off before patient-data or money-data actions execute. Enforced fail-CLOSED (SOD_REQUIRE_AUDIT_AVAILABLE=true): if the SoD audit context is unavailable the approval is blocked rather than allowed.

Right-sized pricing

Built for organizations that count seats, not budgets. Per-agent monthly fee plus LLM passthrough; per-run cost cap to keep an over-eager agent from running away with the meter.

A vendor that takes compliance seriously

Trust Center is real, not aspirational. Every control links to a claim file with file:line evidence and a re-verification cadence.

The control envelope, in numbers.

~10,000

SMBs served via sister brand Minute7

Hash-chained

Action ledger, KMS-rooted

Per-run

Cost cap (rolling-window caps not marketed)

Where regulated-SMB teams put us to work.

Vendor invoice triage

Classifies and routes invoices. Regex-based PII redaction at ledger write time keeps sensitive fields out of the audit log.

Inbound patient/client email triage

Drafts a response and routes for human approval before send. No outbound communication leaves the platform without an approver in the loop.

Monthly compliance task assembly

Surfaces overdue items to the owner (or your designated compliance approver). Every status change writes to the action ledger.

Access-log auditor

Flags unusual access patterns for human review. Designed to support — not replace — your own review cadence.

Breach-notification drafter

Drafts the template and facts; never sends without explicit approval from the designated approver per SoD policy.

What regulated-SMB buyers ask first.

Can you sign a BAA?

No. GoodHelp does not currently offer a Business Associate Agreement and is not a HIPAA-covered entity. If your use case involves Protected Health Information today, GoodHelp is not the right fit. Operational workflows that don't touch PHI (scheduling, vendor mgmt, AR collections, payroll prep) are the safer starting place.

What evidence do you provide if a regulator audits us?

Action ledger plus a signed evidence pack covering any window, any agent. The pack is a JSON manifest plus body (CSV/TSV/JSON) with an asymmetric KMS-rooted signing key.

Do you store PHI?

We design to minimize handling of regulated data. Regex-based PII redaction runs at ledger write time. PHI-adjacent workflows should be discussed with sales before deployment; we'll point you at the specific controls and confirm fit.

Pricing?

$5/agent per month plus LLM passthrough margin (15% BYOK / 30% managed). Per-run cost cap enforced. Most SMBs running 3–6 agents land in the low-three-figures monthly all-in; talk to sales before relying on this estimate. See the pricing page for current numbers.

Show us your audit checklist.

Thirty minutes with someone from our team. Bring the line items your regulator cares about; we’ll show you the corresponding control.