HIPAA-compliant therapy software must meet specific technical and administrative requirements to legally handle protected health information (PHI). In 2026, with AI tools entering clinical workflows and telehealth becoming standard, choosing the right software is more complex — and more important — than ever. This guide explains the actual HIPAA requirements (not the marketing versions), provides a 12-point evaluation checklist, and reviews how leading therapy platforms compare on security.
What does HIPAA compliance actually require for therapy software?
HIPAA's Security Rule specifies three categories of safeguards that any software handling PHI must implement:
Technical safeguards:
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Unique user IDs and authentication
- Automatic session timeouts
- Audit logs of all access to PHI
- Emergency access procedures
Administrative safeguards:
- Business Associate Agreement (BAA) signed by the vendor
- Workforce training on data handling
- Incident response and breach notification procedures
- Regular risk assessments
Physical safeguards:
- Data center security (SOC 2 Type II certification is the standard)
- Workstation security policies
- Device and media controls
The most common mistake therapists make: assuming a vendor is HIPAA compliant because they say so on their website. If they won't sign a BAA, they are not HIPAA compliant for your purposes — regardless of their encryption or security claims.
The BAA: most important document you'll sign
A Business Associate Agreement (BAA) is a legal contract between you (the covered entity) and the software vendor (the business associate). It specifies:
- How the vendor will protect PHI
- What they can and cannot do with your data
- Their obligation to report breaches
- Your right to audit their practices
- Return or destruction of PHI upon contract termination
Without a signed BAA, you are personally liable for any data breach involving that vendor — even if the breach was entirely their fault. HIPAA violations carry penalties of $100-$50,000 per violation, up to $1.5 million per year per violation category.
CBT Assistant Pro does not currently sign a BAA with subscribers. If your practice needs one before it can put PHI into a tool, ask us where that stands rather than assuming it is covered — this section is here to tell you what to demand of any vendor, including us.
How to evaluate therapy software: 12-point security checklist
Before purchasing any therapy software, verify:
- BAA available? Ask to see it before signing up. Read it.
- Encryption at rest? AES-256 is the standard. Anything less is a red flag.
- Encryption in transit? TLS 1.2 minimum. TLS 1.3 preferred.
- SOC 2 certified? The infrastructure hosting your data should be SOC 2 Type II certified.
- Data residency? Where are the servers physically located? Can you choose?
- Audit logs? Can you see who accessed what data and when?
- Access controls? Role-based permissions, not just one admin password.
- 2FA/MFA? Multi-factor authentication should be available (ideally mandatory).
- Data export? Can you export all your data in a standard format?
- Breach notification? What is their SLA for notifying you of a breach?
- AI data handling? If AI features exist, is your data excluded from model training?
- Uptime SLA? What availability do they guarantee?
Where CBT Assistant Pro stands against those twelve, stated plainly rather than as a row of ticks: no signed BAA; encryption in transit; encryption at rest only for private notes and credentials, not for session notes, transcripts or intake answers; hosted on DigitalOcean in New York (their SOC 2 report, not ours); audit logs, role-based access and full data export all present; and no AI training on client data.
Comparing HIPAA compliance across therapy platforms
Here's how the major platforms compare (as of 2026):
| Feature | CBT Assistant Pro | SimplePractice | TherapyNotes | Jane App |
|---|---|---|---|---|
| BAA | ❌ not offered | ✅ | ✅ | ✅ |
| Encryption at rest | Partial — private notes only | AES-256 | AES-256 | AES-256 |
| AI features | ✅ (formulations, transcription) | Limited | ❌ | ❌ |
| AI data excluded from training | ✅ | N/A | N/A | N/A |
| Audit logs | ✅ Full | ✅ Basic | ✅ Basic | ✅ Basic |
| SOC 2 infrastructure | ✅ (DigitalOcean’s report) | ✅ | ✅ | ✅ |
| 2FA | ✅ | ✅ | ✅ | ✅ |
| Data export | ✅ Full | ✅ | ✅ | ✅ |
Read that table honestly: CBT Assistant Pro leads on AI-powered clinical features (formulation, transcription, hypothesis generation) and on the no-training guarantee, and trails the established platforms on the contractual and encryption rows. If a signed BAA is a hard requirement for your practice today, those platforms meet it and this one does not.
Frequently asked questions
Is Google Docs HIPAA compliant for therapy notes?
Google Workspace (paid Business/Enterprise plans) can be HIPAA compliant if Google signs a BAA with you. Free Gmail/Google Docs accounts are NOT covered. Even with a BAA, you must configure sharing, access, and retention settings correctly.
Can I use Zoom for telehealth under HIPAA?
Yes, but only with a Zoom for Healthcare plan that includes a signed BAA. Standard Zoom accounts (free, Pro, Business) do not include a BAA and should not be used for therapy sessions involving PHI.
What happens if I have a HIPAA breach?
You must notify affected individuals within 60 days, report to the HHS Office for Civil Rights, and if 500+ people are affected, notify the media. Penalties range from $100 to $50,000 per violation. Having signed BAAs with all vendors limits your liability significantly.
Does HIPAA apply to therapists in private practice?
Yes, if you transmit any health information electronically (email, EHR, billing). Essentially all therapists in the US are covered entities under HIPAA. The only exception is therapists who exclusively use paper records and don't bill insurance electronically.
Ready to speed up your CBT documentation?
CBT Assistant Pro helps therapists build formulations 3× faster with AI-assisted documentation. HIPAA compliant. Free trial, no credit card.
Start Free Trial →