Is SimplePractice HIPAA Compliant? What Therapists Need to Know
THERAPY · Dec 25, 2025 · 4 min read
SimplePractice is HIPAA compliant, but YOUR setup might not be. Here's what therapists miss about HIPAA compliance beyond the EHR.
Is SimplePractice HIPAA Compliant?
Short answer: Yes, SimplePractice is HIPAA compliant.
Real answer: That doesn't mean YOUR practice is compliant.
What SimplePractice Does Right
SimplePractice signs a Business Associate Agreement (BAA) with every practice. They:
- Encrypt data at rest and in transit
- Maintain audit logs
- Have proper access controls
- Complete regular security assessments
When SimplePractice says they're HIPAA compliant, they mean their servers and software meet the requirements. And they do.
What SimplePractice Can't Control
Here's what keeps therapists up at night (or should):
Your laptop:
- Is it encrypted?
- Does it auto-lock after 5 minutes?
- Is there a password on it?
- What happens if it's stolen from your car?
Your home WiFi:
- Is it secured with WPA3?
- Is it separate from your kids' gaming network?
- Can your neighbors see your traffic?
Your login:
- Do you use the same password everywhere?
- Is MFA enabled?
- Who else knows your password?
Your phone:
- Is the SimplePractice app PIN-protected?
- Is the phone itself encrypted?
- What if you lose it at the coffee shop?
The "Shared Responsibility" Model
Think of it like renting an office:
- Landlord's job: Safe building, working locks, fire suppression
- Your job: Lock your file cabinets, shred documents, control who has keys
SimplePractice is the landlord. They built a secure building. But you're responsible for everything inside your "unit."
What Therapists Actually Need to Do
1. Enable MFA on SimplePractice (takes 2 minutes)
- Settings → Security → Two-Factor Authentication
- Use an authenticator app, not SMS
2. Encrypt your devices
- Mac: FileVault (System Preferences → Security)
- Windows: BitLocker (Settings → Update & Security)
- Phone: Usually on by default, verify in settings
3. Secure your network
- Change default router password
- Use WPA3 if available
- Consider a separate "work" network
4. Create an incident response plan
- What do you do if your laptop is stolen?
- Who do you call?
- How do you notify clients if needed?
5. Document everything
- HIPAA requires written policies
- Keep training records
- Maintain risk assessments
The 42 CFR Part 2 Wrinkle
If you treat substance abuse, you have stricter requirements than regular HIPAA:
- More restrictive consent requirements
- Limits on redisclosure
- Different breach notification rules
SimplePractice doesn't handle this for you. You need proper policies and potentially additional technical controls.
Bottom Line
SimplePractice: HIPAA compliant ✓
Your laptop: Probably not ✓
Your network: Definitely not ✓
Your documentation: Almost certainly not ✓
The EHR is one piece of compliance. Don't let it give you false confidence.
Not sure if your practice is actually compliant? We assess therapy practices every week. Get Free Assessment
Need Help With Your Practice’s Security?
Free assessment, no obligation, real answers.
(469) 306-9520 • Serving Dallas-Fort Worth