Skip to main content

Guardrails: what Lia will and will not do

The rules Lia operates under: identity, hard limits, escalation, contact hours and opt-outs, HIPAA and authorization, pausing, and what provider offices are told.

Written by Product Team

What this article helps with: The rules Lia operates under. How Lia identifies itself, what it will never do, when it stops and hands work to a person, contact hours and opt-outs, HIPAA and authorization, what pausing really does, and what your clients' providers are told.

Who this is for: Managing partners, firm admins, and anyone who has to be comfortable with an agent messaging clients and provider offices under the firm's name.

When not to use this article: This is about limits and compliance behavior, not setup. For configuring escalation rules, FAQs, and firm context, see the Agent Settings article.


Key Terms

What do you mean when you say...

  • Escalation = Lia stopping and handing something to a named person, with the reason and what was already attempted.

  • Opt-out = a client telling Lia to stop contacting them. All outbound contact ends.

  • Pause = blocking outbound messages for one client or for the whole firm, while keeping the work in progress.

  • HIPAA authorization = the signed document that has to be on the client before Lia can request bills or records.


Overview

Lia texts your clients and emails their provider offices under your firm's name. That only works if the limits are clear, so this article states them plainly rather than reassuringly.

Two limits are enforced by the system rather than the agent's judgment: Lia can only email a provider that is in your directory, linked to the case, and has an email address on file, and nothing involving bills or records sends without a signed HIPAA authorization. The rest are operating rules Lia follows in every conversation.


How Lia identifies itself

That is set by your introduction message. The one Hona ships by default names the agent and states that it is an AI assistant. That introduction is yours to edit in Agent Settings, so if your firm rewrites it, check that it still tells clients what you want them to know. We recommend keeping the disclosure in it.

If a client asks at any later point whether they are talking to a person, Lia answers honestly and offers to connect them with someone on your team. There is no mode in which Lia pretends to be a member of staff.

The introduction names your firm and the people on the case and explains what Lia will be doing. You can also turn on a Firm Introduction, a personal text from your firm sent before Lia's first message, so the hand-off comes from a person first.


What Lia will never do

These are hard limits, not preferences.

  • No medical advice. Lia does not assess symptoms, interpret them, or recommend treatment. What a client says gets noted on the case and the client is pointed back to their provider.

  • No legal advice. Lia does not discuss case details, settlements, or strategy. Those questions go to your team.

  • No changing appointments on its own. Lia does not reschedule, cancel, or modify a real appointment unilaterally. Where scheduling is in use, Lia gathers times from the office and hands them to the client to choose.

  • No promises it cannot keep. Lia does not commit the firm to actions it cannot perform.

  • No pressure. Lia does not push in a way that could read as harassment. Follow-up has a cadence and a limit.

  • No health information in an email subject line. Ever, on any provider email.

  • No contact between 7pm and 9am in the client's own timezone, not your office's.

One more limit worth naming: Lia does not make phone calls. Lia texts clients and emails provider offices. Inbound calls are handled by Hona's AI Receptionist, which is a separate product.


When Lia escalates instead of continuing

Escalation is the pressure valve. When Lia reaches the edge of what an agent should handle, it stops and hands the conversation to a person rather than improvising.

Lia escalates when:

  • The client asks for a human.

  • The client expresses frustration or distress.

  • The client has not responded after 5 contact attempts.

  • A task cannot be completed within its deadline.

  • The client mentions pain or symptoms that are not currently being treated.

  • The client misses an appointment and cannot be reached.

Every escalation carries the reason and what was already attempted, so the person picking it up is not starting from nothing. Escalations arrive with a priority, a date, a description, and an assignee, and some carry an action button such as Upload signed authorization.

On top of these, your firm writes its own rules. In Agent Settings, each rule reads "Escalate when the client [condition]" and assigns to the case owner or to a role.

The Escalation rules page in Agent Settings showing rule cards with priority labels, rule type, and assignees

Expect more escalations at the start. Lia escalates rather than guessing, so a thin setup escalates often. Firm context and FAQs across the case type bring the rate down.


Contact hours and opt-outs

Lia contacts clients between 9am and 7pm in the client's local timezone. Outside those hours, nothing goes out.

Opt-outs are absolute. If a client texts STOP or any equivalent, all outbound contact stops immediately and does not resume. There is no re-engagement sequence and no cooling-off period after which Lia tries again.

A softer request is handled with the same seriousness. A casual "please stop texting me" gets one acknowledgement and an escalation to your team, then nothing further from Lia.

Lia also stops after 5 failed contact attempts and escalates instead of continuing to try.

Worth separating two things that sound alike. Enrollment controls whether Lia is assigned to a client and case. Texting consent controls whether Lia can actually reach them. A client can be enrolled and not textable, in which case Lia simply does not send.


HIPAA and authorization

Lia operates under HIPAA and TCPA rules, and the specifics are concrete.

  • No health information in subject lines.

  • Minimum necessary collection. Lia asks provider offices for what the case needs, not for everything they hold.

  • Everything is logged. Client threads and provider email threads sit on the case, readable by anyone working it.

  • TCPA hours, opt-outs, and the 5-attempt limit are enforced as described above.

A signed HIPAA authorization is always required before Lia requests bills or records, and it cannot be removed as a requirement. Nothing involving bills or records sends without it, and when it is in place it is attached to the request automatically. On the Provider Liaison page, the Billing and Medical records rows carry a Needs HIPAA authorization chip for exactly this reason.

Firms can add their own required documents alongside it, for example a Lien Release, under Authorization documents. There is also a "Require authorization before scheduling" option, off by default.

The Provider Liaison settings page showing collection toggles, authorization documents, and email recipient rules

When authorization is missing, Lia does not proceed quietly. The client's Treatment tab shows the Liaison as blocked with an authorization state, and an escalation arrives with an Upload signed authorization action.

One more boundary on the provider side: Lia never finds a clinic on its own and never emails an address it was not given. A provider has to be in your Provider directory, linked to the case, and have an email address on file. The system enforces both conditions.


What pausing actually does

Pausing is real. It blocks outbound messages at the execution layer, not by asking the agent nicely. A paused agent that is explicitly told to text a client cannot do it, and says so.

Work in progress is kept, not thrown away, and resumes when you unpause. Open provider requests are left in place rather than cancelled.

There are two per-client controls in the case header:

  • In Treatment pauses treatment-related messages for that one person.

  • Provider Liaison holds provider outreach for that one client while the Liaison keeps running for everyone else.

Firm-wide toggles live in Agent Settings. The Provider Liaison page has a master toggle that reads Off for the whole firm, and when it is off the page states plainly that the Liaison is paused and your settings are kept.


What providers are told

Provider offices need to know who is writing and why, and that the firm is not directing care. Every outbound provider email carries that plainly. This line is verbatim from a real outbound email:

"our office is not involved in directing treatment, and all clinical decisions remain with your practice."

The same principle runs through the rest of the provider-facing behavior. Lia asks for attendance, bills, and records. Lia does not question a treatment plan, negotiate care, or ask an office to do anything clinical.

Provider recommendations follow the same logic on the client side. Only providers your firm has marked Preferred, of the type asked for, and near the client are ever surfaced. If there are not enough nearby, Lia offers none rather than a thin list. By default suggestions go to the assigned case manager for approval before the client sees them. The client chooses.


Where to go next


Conclusion

Lia is built to stop early rather than push through. It says what it is, keeps to lawful hours, honors an opt-out permanently, will not touch bills or records without a signed authorization, and hands anything sensitive to a named person. If you want to walk through any of this before enabling a skill, chat with our support team or email [email protected].

Did this answer your question?