Mental Health Marketing Agency

HIPAA Compliance Checklist for a New Therapy Practice

September 2, 2026 8 min read
Share Article:
HIPAA Compliance Checklist for a New Therapy Practice

The safeguards, agreements, and habits that protect client information and keep your new practice compliant from day one.

HIPAA compliance for a new therapy practice comes down to a few essentials: protect client information with the right safeguards, sign a business associate agreement with every vendor that touches that information, put written policies and a risk assessment in place, and give clients the privacy notices they are owed.

It sounds like a lot, but most of it is straightforward once you know what to cover. Building these habits from day one is far easier than fixing gaps later, and it protects both your clients and your practice. Use the checklist below to get set up correctly.

HIPAA is one part of the compliance foundation we cover in our guide to how to start a private therapy practice. At Mental Health IT Solutions, we help therapists build practices, and market them, in a HIPAA-conscious way.

This checklist is general education for mental health professionals and is not legal or compliance advice. HIPAA is detailed and fact-specific, and state laws may add requirements. For your practice, confirm your obligations with a qualified healthcare attorney or HIPAA compliance professional.


What is HIPAA, and does it apply to your therapy practice?

HIPAA is the federal law that protects clients’ health information, and it applies to nearly every therapy practice that handles protected health information electronically, including billing, scheduling, or emailing clients.

Under HIPAA, you are usually a covered entity, and the client details you hold, names tied to appointments, diagnoses, session notes, and more, are protected health information, or PHI. If you bill insurance, you are almost certainly covered. Three parts of the law matter most: the Privacy Rule, which governs how PHI may be used and shared, the Security Rule, which sets safeguards for electronic PHI, and the Breach Notification Rule, which tells you what to do if PHI is exposed.

Even a cash-only practice often qualifies, and following HIPAA is wise regardless, since it is the professional standard for protecting client trust. Many states also have their own privacy laws that add requirements on top of HIPAA.


The HIPAA compliance checklist for a new therapy practice

The checklist below is organized the way HIPAA is: administrative, physical, and technical safeguards, plus vendor agreements, client privacy, telehealth, and breach response.

Administrative safeguards

  • Complete a security risk assessment to identify risks to the electronic PHI you hold. This is required and is the foundation of the Security Rule.
  • Put written HIPAA policies and procedures in place for privacy and security.
  • Designate a Privacy Officer and a Security Officer. In a solo practice, that is you.
  • Train anyone who handles PHI, including contractors, and document your own training.
  • Keep your HIPAA documentation for at least six years.
  • Have a written breach response plan before you need it.

Business associate agreements

Sign a business associate agreement, or BAA, with every vendor that stores or handles PHI on your behalf, and do it before you share any client information.

  • Get a signed BAA with your EHR, email provider, video platform, billing service, cloud storage, appointment reminder tool, and any transcription service.
  • Keep copies of every signed BAA on file.
  • Do not use a tool for PHI if the vendor will not sign a BAA. Notably, standard Google Analytics and Google Ads do not offer BAAs, so PHI must never reach them.

Physical safeguards

  • Store any paper records in locked cabinets, and keep your office and file areas secure.
  • Encrypt and set auto-lock on every device that can access PHI, including laptops and phones.
  • Position screens so they cannot be seen by others, in the office and during telehealth.
  • Shred paper records and securely wipe devices before disposal.

Technical safeguards

  • Use a HIPAA-compliant EHR, email, video platform, and intake forms, each covered by a BAA.
  • Encrypt PHI both in transit and at rest, including email that contains client information.
  • Require unique logins, strong passwords, and multifactor authentication.
  • Enable automatic logoff on systems that hold PHI.
  • Secure your network and Wi-Fi, and keep encrypted backups of your data.

Client privacy and rights

  • Provide clients your Notice of Privacy Practices and post it where they can see it.
  • Use informed consent that addresses privacy and, if relevant, telehealth.
  • Get proper authorization before disclosing PHI, and share only the minimum necessary.
  • Honor client rights to access and request corrections to their records.

Telehealth

  • Use a HIPAA-compliant video platform with a BAA. Consumer tools like personal FaceTime, or a standard Zoom account without a BAA, are not sufficient.
  • Hold sessions in a private, secure space, on a secure device and connection.
  • Obtain telehealth-specific consent from clients.

Breach response

  • Know what counts as a breach of unsecured PHI.
  • Be ready to notify affected clients, generally within 60 days, and to notify HHS as required.
  • Document any incident and your response, and use encryption to reduce breach risk.

HIPAA and your website and marketing

Your website and marketing can create HIPAA risks if they capture or share client information, so keep protected health information out of any tool that cannot sign a BAA.

Standard analytics and advertising pixels, including Google Analytics, Google Ads, and the Meta pixel, do not offer business associate agreements, so they should never receive PHI. In practice, that means keeping tracking off intake, booking-confirmation, and client portal pages, using a secure contact form, and never putting client details in unsecured email. If you run paid ads, our guide to creating a Google Ads campaign for your therapy practice walks through doing it the right way.

This is exactly where a specialized partner helps. A well-designed therapist website and SEO for therapists can attract clients while keeping your setup HIPAA-conscious, so you grow without putting client privacy at risk.

Want a website that is built HIPAA-consciously?
We design fast, conversion-focused websites for therapists, with privacy in mind from the start. Explore website design and development

Getting found and staying compliant are not at odds when your marketing is built for healthcare.

Grow your practice the right way
Our mental health SEO services help you rank on Google and in AI search while keeping your marketing HIPAA-conscious. See our mental health SEO services


How to maintain HIPAA compliance over time

HIPAA compliance is ongoing, not a one-time setup.

Keep it current with a simple routine: repeat your risk assessment at least once a year, update your policies as your tools change, retrain when needed, review your BAAs, keep software patched, and document everything. A little maintenance prevents the gaps that lead to breaches and penalties.


Frequently asked questions

Does HIPAA apply to cash-only therapists?

Often, yes. Many cash-only therapists still qualify as covered entities, and even when the rules are unclear, following HIPAA is the professional standard for protecting client information. State privacy laws may also apply.

What is a business associate agreement, and who needs one?

A BAA is a contract with any vendor that handles PHI on your behalf, such as your EHR, email, video platform, or billing service. You must have a signed BAA before sharing client information with that vendor.

Is regular email HIPAA compliant?

Not by default. Standard email is not secure enough for PHI unless it is encrypted and the provider signs a BAA. Use a HIPAA-compliant email service, or avoid putting client details in email altogether.

Is Zoom HIPAA compliant for therapy?

Only with a BAA. Zoom offers a healthcare plan that includes a BAA, which can be compliant, but a standard consumer account without a BAA is not. The same applies to other video tools.

Are Google Analytics and ad pixels HIPAA compliant?

No. Google Analytics, Google Ads, and the Meta pixel do not offer BAAs, so PHI must never reach them. Keep tracking off any page that could involve client information, such as intake and booking-confirmation pages.

Do I need a HIPAA risk assessment?

Yes. A security risk assessment is required under the Security Rule and should be repeated regularly. It identifies risks to your electronic PHI so you can address them.

What happens if I violate HIPAA?

Consequences range from corrective action plans to significant financial penalties, depending on the severity and whether the violation was willful. Beyond fines, a breach can damage client trust, which is why prevention matters most.


Protect your clients, and your practice

HIPAA compliance for a new therapy practice is very manageable when you work through it step by step: understand what applies, put the right safeguards and agreements in place, protect privacy in your marketing, and keep it current over time. Do that from the start, and you build a practice your clients can trust and that is ready to grow safely.

Want to grow your practice without compromising privacy?
Mental Health IT Solutions helps therapists build and market practices in a HIPAA-conscious way, from websites to SEO. Let us help you do it right. Contact our team for a free consultation

Found this helpful?

Share it with your network and help others heal.