PD Geek

Is SimplePractice HIPAA Compliant? What Therapists Need to Know

← Back to Blog

THERAPY · Dec 25, 2025 · 4 min read

SimplePractice is HIPAA compliant, but YOUR setup might not be. Here's what therapists miss about HIPAA compliance beyond the EHR.

Is SimplePractice HIPAA Compliant?

Short answer: Yes, SimplePractice is HIPAA compliant.

Real answer: That doesn't mean YOUR practice is compliant.

What SimplePractice Does Right

SimplePractice signs a Business Associate Agreement (BAA) with every practice. They:

  1. Encrypt data at rest and in transit
  2. Maintain audit logs
  3. Have proper access controls
  4. Complete regular security assessments

When SimplePractice says they're HIPAA compliant, they mean their servers and software meet the requirements. And they do.

What SimplePractice Can't Control

Here's what keeps therapists up at night (or should):

Your laptop:

  1. Is it encrypted?
  2. Does it auto-lock after 5 minutes?
  3. Is there a password on it?
  4. What happens if it's stolen from your car?

Your home WiFi:

  1. Is it secured with WPA3?
  2. Is it separate from your kids' gaming network?
  3. Can your neighbors see your traffic?

Your login:

  1. Do you use the same password everywhere?
  2. Is MFA enabled?
  3. Who else knows your password?

Your phone:

  1. Is the SimplePractice app PIN-protected?
  2. Is the phone itself encrypted?
  3. What if you lose it at the coffee shop?

The "Shared Responsibility" Model

Think of it like renting an office:

  1. Landlord's job: Safe building, working locks, fire suppression
  2. Your job: Lock your file cabinets, shred documents, control who has keys

SimplePractice is the landlord. They built a secure building. But you're responsible for everything inside your "unit."

What Therapists Actually Need to Do

1. Enable MFA on SimplePractice (takes 2 minutes)

  1. Settings → Security → Two-Factor Authentication
  2. Use an authenticator app, not SMS

2. Encrypt your devices

  1. Mac: FileVault (System Preferences → Security)
  2. Windows: BitLocker (Settings → Update & Security)
  3. Phone: Usually on by default, verify in settings

3. Secure your network

  1. Change default router password
  2. Use WPA3 if available
  3. Consider a separate "work" network

4. Create an incident response plan

  1. What do you do if your laptop is stolen?
  2. Who do you call?
  3. How do you notify clients if needed?

5. Document everything

  1. HIPAA requires written policies
  2. Keep training records
  3. Maintain risk assessments

The 42 CFR Part 2 Wrinkle

If you treat substance abuse, you have stricter requirements than regular HIPAA:

  1. More restrictive consent requirements
  2. Limits on redisclosure
  3. Different breach notification rules

SimplePractice doesn't handle this for you. You need proper policies and potentially additional technical controls.

Bottom Line

SimplePractice: HIPAA compliant ✓

Your laptop: Probably not ✓

Your network: Definitely not ✓

Your documentation: Almost certainly not ✓

The EHR is one piece of compliance. Don't let it give you false confidence.

Not sure if your practice is actually compliant? We assess therapy practices every week. Get Free Assessment

Need Help With Your Practice’s Security?

Free assessment, no obligation, real answers.

Get Free Assessment

(469) 306-9520 • Serving Dallas-Fort Worth

PD Geek is an operating brand of Pleasant Digital, LLC. © 2026 Pleasant Digital, LLC. Contact PD Geek through the Contact page.

Dental Practices · Therapy & Counseling · Churches & Nonprofits · Blog · Privacy Policy · Terms of Service