HIPAA-compliant therapy software must meet specific technical and administrative requirements to legally handle protected health information (PHI). In 2026, with AI tools entering clinical workflows and telehealth becoming standard, choosing the right software is more complex — and more important — than ever. This guide explains the actual HIPAA requirements (not the marketing versions), provides a 12-point evaluation checklist, and reviews how leading therapy platforms compare on security.
What does HIPAA compliance actually require for therapy software?
The BAA: most important document you'll sign
How to evaluate therapy software: 12-point security checklist
Comparing HIPAA compliance across therapy platforms
Frequently asked questions
Is Google Docs HIPAA compliant for therapy notes?
Google Workspace (paid Business/Enterprise plans) can be HIPAA compliant if Google signs a BAA with you. Free Gmail/Google Docs accounts are NOT covered. Even with a BAA, you must configure sharing, access, and retention settings correctly.
Can I use Zoom for telehealth under HIPAA?
Yes, but only with a Zoom for Healthcare plan that includes a signed BAA. Standard Zoom accounts (free, Pro, Business) do not include a BAA and should not be used for therapy sessions involving PHI.
What happens if I have a HIPAA breach?
You must notify affected individuals within 60 days, report to the HHS Office for Civil Rights, and if 500+ people are affected, notify the media. Penalties range from $100 to $50,000 per violation. Having signed BAAs with all vendors limits your liability significantly.
Does HIPAA apply to therapists in private practice?
Yes, if you transmit any health information electronically (email, EHR, billing). Essentially all therapists in the US are covered entities under HIPAA. The only exception is therapists who exclusively use paper records and don't bill insurance electronically.
Ready to streamline your CBT practice?
CBT Assistant Pro helps therapists build formulations 3× faster with AI-assisted documentation. HIPAA compliant. Free trial, no credit card.
Start Free Trial →