Compliance

HIPAA-Compliant Therapy Software: How to Choose the Right Tool (2026)

9 min read·Updated April 25, 2026

HIPAA-compliant therapy software must meet specific technical and administrative requirements to legally handle protected health information (PHI). In 2026, with AI tools entering clinical workflows and telehealth becoming standard, choosing the right software is more complex — and more important — than ever. This guide explains the actual HIPAA requirements (not the marketing versions), provides a 12-point evaluation checklist, and reviews how leading therapy platforms compare on security.

What does HIPAA compliance actually require for therapy software?

HIPAA's Security Rule specifies three categories of safeguards that any software handling PHI must implement: **Technical safeguards:** - Encryption at rest (AES-256) and in transit (TLS 1.2+) - Unique user IDs and authentication - Automatic session timeouts - Audit logs of all access to PHI - Emergency access procedures **Administrative safeguards:** - Business Associate Agreement (BAA) signed by the vendor - Workforce training on data handling - Incident response and breach notification procedures - Regular risk assessments **Physical safeguards:** - Data center security (SOC 2 Type II certification is the standard) - Workstation security policies - Device and media controls The most common mistake therapists make: assuming a vendor is HIPAA compliant because they say so on their website. **If they won't sign a BAA, they are not HIPAA compliant for your purposes** — regardless of their encryption or security claims.

The BAA: most important document you'll sign

A Business Associate Agreement (BAA) is a legal contract between you (the covered entity) and the software vendor (the business associate). It specifies: - How the vendor will protect PHI - What they can and cannot do with your data - Their obligation to report breaches - Your right to audit their practices - Return or destruction of PHI upon contract termination Without a signed BAA, you are personally liable for any data breach involving that vendor — even if the breach was entirely their fault. HIPAA violations carry penalties of $100-$50,000 per violation, up to $1.5 million per year per violation category. CBT Assistant Pro signs a BAA with every subscriber. The agreement covers all data processing, including AI-powered features like hypothesis generation and voice transcription.

How to evaluate therapy software: 12-point security checklist

**Before purchasing any therapy software, verify:** 1. **BAA available?** Ask to see it before signing up. Read it. 2. **Encryption at rest?** AES-256 is the standard. Anything less is a red flag. 3. **Encryption in transit?** TLS 1.2 minimum. TLS 1.3 preferred. 4. **SOC 2 certified?** The infrastructure hosting your data should be SOC 2 Type II certified. 5. **Data residency?** Where are the servers physically located? Can you choose? 6. **Audit logs?** Can you see who accessed what data and when? 7. **Access controls?** Role-based permissions, not just one admin password. 8. **2FA/MFA?** Multi-factor authentication should be available (ideally mandatory). 9. **Data export?** Can you export all your data in a standard format? 10. **Breach notification?** What is their SLA for notifying you of a breach? 11. **AI data handling?** If AI features exist, is your data excluded from model training? 12. **Uptime SLA?** What availability do they guarantee? CBT Assistant Pro scores ✅ on all 12 points: signed BAA, AES-256 encryption, TLS 1.3, AWS US-East-1 with SOC 2, full audit logs, role-based access, data export, zero AI training on client data.

Comparing HIPAA compliance across therapy platforms

Here's how the major platforms compare (as of 2026): | Feature | CBT Assistant Pro | SimplePractice | TherapyNotes | Jane App | |---|---|---|---|---| | BAA | ✅ | ✅ | ✅ | ✅ | | Encryption at rest | AES-256 | AES-256 | AES-256 | AES-256 | | AI features | ✅ (formulations, transcription) | Limited | ❌ | ❌ | | AI data excluded from training | ✅ | N/A | N/A | N/A | | Audit logs | ✅ Full | ✅ Basic | ✅ Basic | ✅ Basic | | SOC 2 infrastructure | ✅ (AWS) | ✅ | ✅ | ✅ | | 2FA | ✅ | ✅ | ✅ | ✅ | | Data export | ✅ Full | ✅ | ✅ | ✅ | The key differentiator: CBT Assistant Pro is the only platform combining AI-powered clinical features (formulation, transcription, hypothesis generation) with full HIPAA compliance and a no-training guarantee on client data.

Frequently asked questions

Is Google Docs HIPAA compliant for therapy notes?

Google Workspace (paid Business/Enterprise plans) can be HIPAA compliant if Google signs a BAA with you. Free Gmail/Google Docs accounts are NOT covered. Even with a BAA, you must configure sharing, access, and retention settings correctly.

Can I use Zoom for telehealth under HIPAA?

Yes, but only with a Zoom for Healthcare plan that includes a signed BAA. Standard Zoom accounts (free, Pro, Business) do not include a BAA and should not be used for therapy sessions involving PHI.

What happens if I have a HIPAA breach?

You must notify affected individuals within 60 days, report to the HHS Office for Civil Rights, and if 500+ people are affected, notify the media. Penalties range from $100 to $50,000 per violation. Having signed BAAs with all vendors limits your liability significantly.

Does HIPAA apply to therapists in private practice?

Yes, if you transmit any health information electronically (email, EHR, billing). Essentially all therapists in the US are covered entities under HIPAA. The only exception is therapists who exclusively use paper records and don't bill insurance electronically.

Ready to streamline your CBT practice?

CBT Assistant Pro helps therapists build formulations 3× faster with AI-assisted documentation. HIPAA compliant. Free trial, no credit card.

Start Free Trial

Related guides