Skip to content
IT tips Updated Noah Stegman

HIPAA IT Checklist for Therapists and Small Practices

A plain-English IT guide for therapists: HIPAA Security Rule basics, business associate agreements, telehealth, EHRs, email, encryption, and California law.

For a solo or small therapy practice, HIPAA-ready IT comes down to a short list: a written risk analysis, a business associate agreement (BAA) with every vendor that handles client information, a telehealth platform and electronic health record (EHR) covered by those agreements, encrypted devices, unique logins with multi-factor authentication, and a plan for email and texting. California’s Confidentiality of Medical Information Act applies on top. This guide walks through each item and ends with a checklist.

This is IT guidance, not legal advice. Confirm your obligations with a health care attorney or compliance adviser.

Does HIPAA Apply to a Solo Therapist?

HIPAA applies to covered entities, which include health care providers that transmit health information electronically in connection with standard transactions such as insurance claims and eligibility checks. A therapist who bills insurance electronically, directly or through a billing service or EHR, is covered. Practice size makes no difference.

A strictly private-pay practice that never conducts those transactions may fall outside HIPAA. It is still bound by California’s medical privacy law (covered below), and the safeguards in this guide are the sensible standard either way.

What Does the HIPAA Security Rule Require Technically?

The Security Rule covers electronic protected health information (ePHI): client information in your EHR, email, files, phone, and backups. It requires administrative, physical, and technical safeguards, and it is built to scale, so a solo practice documents simpler measures than a hospital does.

Start with the risk analysis. Every covered entity must assess the risks to the ePHI it holds and document the result. The free Security Risk Assessment Tool from ONC and the HHS Office for Civil Rights is designed for small and medium practices and walks through the questions.

Then the technical safeguards. 45 CFR 164.312 lists them:

SafeguardStatus in the ruleWhat it looks like in a small practice
Unique user identificationRequiredEvery person has their own login to the EHR, email, and computer. No shared accounts.
Emergency access procedureRequiredA documented way to reach records if you are locked out or incapacitated
Automatic logoffAddressableScreen lock after a few minutes; EHR session timeout
Encryption of stored dataAddressableFull-disk encryption on laptops, phones, and backup drives
Audit controlsRequiredThe EHR’s access log, plus sign-in logs for email
Integrity controlsAddressableUsing systems that record changes to records, and backups
Person or entity authenticationRequiredStrong passwords plus multi-factor authentication (MFA)
Transmission securityAddressableEncrypted connections for email, portals, and video

“Addressable” does not mean optional. It means you implement the measure if it is reasonable and appropriate, or document why not and what you do instead. For a laptop holding client information, it is hard to write a convincing reason not to encrypt it.

A rule change is pending. HHS proposed an update to the Security Rule, published in the Federal Register on January 6, 2025, that would make encryption and MFA mandatory with limited exceptions. As of September 2026 it remains a proposal and the current rule is in force. Practices that already encrypt and use MFA would have little to change. Our HIPAA IT compliance guide covers the full set of safeguards.

Which Vendors Need a Business Associate Agreement?

A business associate is any vendor that creates, receives, stores, or transmits client information for you. HIPAA requires a signed BAA with each one before they handle that information. How you get the BAA differs by vendor:

VendorHow the BAA works
SimplePracticeAgreed to when you sign up; all platform features are covered
TherapyNotesBuilt into the Terms of Service for customers who are covered entities
Microsoft 365Included by default through Microsoft’s Data Protection Addendum; nothing separate to sign
Google WorkspaceA super administrator must review and accept it in the Admin console under Account, Account settings, Legal and compliance. It covers only the services on Google’s included functionality list, and third-party add-ons are excluded.
Doxy.meA BAA is included for all users; the one on free accounts is meant for individual providers
ZoomZoom for Healthcare executes a BAA. Confirm with Zoom that your specific plan is covered before using it with clients.

Free consumer accounts (a personal Gmail address, personal Dropbox, iCloud) are not covered by a BAA. Do not put client information in them.

Others that commonly need a BAA: a billing service, an answering service, an online backup provider, a transcription or AI note-taking tool, and your IT provider if they can access systems containing client information.

What Does Telehealth Require Now That the COVID-Era Flexibility Has Ended?

During the public health emergency, HHS said it would not penalize providers for good-faith use of everyday video apps. That policy expired on May 11, 2023, and the 90-day transition period ended on August 9, 2023. Ordinary HIPAA rules apply to telehealth again.

In practice:

  1. Use a video platform that gives you a BAA: the telehealth built into your EHR, Doxy.me, Zoom under a healthcare BAA, or Microsoft Teams under your Microsoft 365 agreement.
  2. Stop using consumer apps such as FaceTime or a personal Zoom account for sessions.
  3. Do not record sessions unless you have a clinical reason, client consent, and a plan for storing the recording as part of the record.
  4. Run sessions from an encrypted, updated device on a network you control. At home, that means your own router with a strong Wi-Fi password and current firmware.
  5. Use a private room and headphones. Privacy of the physical space is part of the safeguard.

How Should a Practice Choose and Secure an EHR?

SimplePractice, TherapyNotes, and TheraNest (from Ensora Health) are cloud EHRs built for behavioral health. They combine notes, scheduling, billing, a client portal, secure messaging, and telehealth. Since the vendor runs the servers, your work is on the account and the devices:

  • Turn on MFA for every user. A stolen password is the most direct route into client records.
  • Give each person their own login with the role they need. A biller does not need clinical notes.
  • Know how HIPAA treats psychotherapy notes. HIPAA defines them as a mental health professional’s notes analyzing session conversations that are kept separate from the rest of the record. Use the EHR feature designed for them so that separation holds.
  • Plan for retention and exit. California requires a marriage and family therapist to retain client records for at least seven years after therapy ends, or for a minor, seven years after the client turns 18. Check the statute for your own license type. Before relying on any EHR, find out how you would export complete records if you closed the account.
  • Keep browsers and operating systems updated on every device used to sign in.

What About Email, Texting, and Secure Messaging?

HHS says the Privacy Rule allows providers to communicate with patients by email, provided reasonable safeguards are applied. It does not prohibit unencrypted email with clients, but it expects precautions such as checking the address and limiting what is disclosed, and it suggests warning clients about the risks so they can choose.

A workable policy for a small practice:

  • Use the EHR’s client portal and secure messaging for anything clinical.
  • Use a business email account covered by a BAA (Microsoft 365 or Google Workspace), never a free personal account.
  • Keep ordinary email to scheduling and logistics, and tell clients so in your intake paperwork.
  • When you must email clinical information to another provider or an insurer, use message encryption. Our email encryption guide explains the options.
  • Standard text messaging is not encrypted and is rarely covered by a BAA. Use the EHR’s messaging or reminders feature instead.

How Do You Encrypt Laptops, Phones, and Backups?

Encryption turns the contents of a device into unreadable data without the password. It also has a legal benefit: HIPAA’s breach notification rules apply to unsecured information, so a lost laptop that was properly encrypted is a very different event from one that was not.

  • Windows 11: open Settings, then Privacy & security, then Device encryption. On Pro editions, search for “Manage BitLocker” and turn it on. Save the recovery key somewhere other than the laptop.
  • Mac: open System Settings, then Privacy & Security, then FileVault, and turn it on.
  • iPhone and iPad: data is encrypted once a passcode is set. Use at least six digits.
  • Android: current devices encrypt by default once a screen lock is set.
  • Backup drives and USB sticks: encrypt them too, or avoid storing client information on them.

Add a screen lock of five minutes or less, remote wipe (Find My on Apple devices, or a mobile device management tool for a group practice), and a password manager so every account has a unique password.

Which California Rules Apply on Top of HIPAA?

The Confidentiality of Medical Information Act (CMIA) applies to California health care providers, including licensed mental health professionals, whether or not HIPAA does. Civil Code 56.101 requires providers who create, store, or dispose of medical information to do so in a way that preserves its confidentiality. It also requires electronic record systems to protect the integrity of records and to log changes and deletions, including who made them and when. A purpose-built EHR meets this far more easily than a folder of documents.

Where HIPAA and California law differ, the stricter protection applies. Ask your adviser how this affects your release and consent forms.

What Happens If There Is a Breach?

Under HIPAA, affected individuals must be notified without unreasonable delay and no later than 60 days after discovery. For HHS, breaches affecting 500 or more people are reported at the same time, and smaller breaches are reported within 60 days after the end of the calendar year. Ransomware on a computer holding client records generally needs to be assessed as a possible breach. Our guide on what to do after a data breach lists the first steps.

Shared Office Suites

If you sublet an office by the day or share a suite, treat the building’s Wi-Fi and printers as public. Use your own password-protected hotspot or a VPN for client work, do not print client documents to a shared printer, take your devices with you, and lock the screen whenever you step out.

IT Checklist for a Therapy Practice

  • A written risk analysis exists and was reviewed in the last 12 months
  • A BAA is in place with the EHR, email provider, telehealth platform, billing service, backup provider, and IT provider
  • No client information is kept in personal email, personal cloud storage, or standard text messages
  • Telehealth runs only on a platform covered by a BAA
  • MFA is on for the EHR, email, and any cloud storage
  • Every person has an individual login with an appropriate role
  • Every laptop, phone, tablet, and backup drive is encrypted, and recovery keys are stored safely
  • Screens lock automatically within five minutes
  • Devices and browsers update automatically
  • Lost devices can be wiped remotely
  • A password manager is in use, with no reused passwords
  • You know how to export full records from the EHR, and how long you must retain them
  • An emergency access plan names who can reach records if you cannot
  • Home and office Wi-Fi use strong passwords; shared building Wi-Fi is not used for client work
  • A one-page breach plan lists whom to contact and the notification deadlines

Questions to Ask Any IT Provider

  • Will you sign a business associate agreement before accessing any system?
  • How do you limit and log your own access to systems that contain client information?
  • Can you help me complete and document the risk analysis, and explain what remains my responsibility?
  • How will you verify that every device is encrypted, and show me evidence?
  • What would you do if a laptop were lost or an account were compromised?
  • How are scope and price agreed before work starts?

When You Do Not Need Much IT Help

A solo therapist with one encrypted laptop, one phone, a cloud EHR with built-in telehealth and messaging, and a business email account under a BAA can handle most of this alone using the checklist above. Outside help becomes more useful when you add clinicians, administrative staff, shared devices, an office network, or insurance audits that ask for documentation.

Common Questions

Can therapists still use FaceTime or Skype for sessions?

Not under the old COVID-era allowance. HHS ended its telehealth enforcement discretion on May 11, 2023, and the transition period closed on August 9, 2023. Video sessions now need a platform whose vendor provides a business associate agreement, along with the usual Security Rule safeguards on your devices and accounts.

Is Gmail HIPAA compliant?

A free personal Gmail account is not covered by a BAA and should not hold client information. Paid Google Workspace can be used once a super administrator accepts Google’s BAA in the Admin console, and only for the services Google lists as included. You still need MFA, sensible sharing settings, and a policy on what goes in email.

Does HIPAA require encryption?

Encryption is an addressable safeguard under the current Security Rule, which means you implement it when reasonable or document an equivalent alternative. For laptops and phones that hold or reach client records there is rarely a good alternative. A 2025 HHS proposal would make encryption mandatory, but it is not final as of September 2026.

Do I need a BAA with my IT provider?

Yes, if the provider can access systems that contain client information, such as your computer, email, or backups. That access makes the provider a business associate under HIPAA. The agreement should be signed before any work begins, and it applies to us as much as to anyone else.

How Coastal Growth Co. Can Help

We can set up and document the technical side of this list: device encryption, MFA, business email under a BAA, secure home and office networks, backups, and the IT sections of your risk analysis. We sign a BAA before touching any system that holds client information, and scope and price are agreed first. See our cloud, email, and AI service and managed IT service, or reach us through the contact page.

Need a hand with this?

I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.

Let's talk arrow_forward

Get in touch

Talk with Noah

Tell me about your business and what is getting in the way. A recurring problem, an upcoming project, or a setup you would like a second opinion on.

noah@coastalgrowthco.com

Noah Stegman · Coastal Growth Co.

Your message goes to Noah. I will reply by email. Please leave out passwords and sensitive account details.