AI is transforming how therapists document sessions. It can structure notes, summarize client history, and cut documentation time significantly. But using the wrong AI tool with client data is a HIPAA violation — even if the tool is excellent and your intentions are good.

Bottom line: an AI tool is HIPAA-compliant for therapy notes if and only if it signs a Business Associate Agreement (BAA) with your practice and implements the required technical safeguards. Standard consumer AI tools like ChatGPT do not meet this bar. This article tells you exactly what to look for and what to avoid.


What HIPAA Actually Requires (Not What You Think)

HIPAA does not prohibit using AI for therapy notes. It prohibits using any technology that handles Protected Health Information (PHI) without proper safeguards. The requirements that apply to AI documentation tools fall under the HIPAA Security Rule:

Technical Safeguards

  • Encryption: PHI must be encrypted in transit (when data moves between your device and the server) and at rest (when data is stored)
  • Access controls: Unique user authentication, automatic logoff, role-based permissions
  • Audit logs: The system must log who accessed what data and when
  • Transmission security: Secure communication channels (TLS 1.2 minimum)

Administrative Safeguards

  • Business Associate Agreement: A signed legal contract between you and the vendor
  • Data use policies: Clear documentation of how the vendor uses your data
  • No model training on PHI: The vendor must not use your client data to train AI models without explicit authorization

What This Means in Practice

RequirementWhat to Ask the Vendor
BAA”Do you sign a Business Associate Agreement for individual practices?”
Encryption”Is data encrypted at rest and in transit? What standard?”
No training on my data”Does my client data train your AI models?”
Data location”Where are servers located? EU or US data residency?”
Breach notification”What is your breach notification process and timeline?”
Data deletion”Can I permanently delete all client data? How?”

The BAA: The Non-Negotiable Requirement

A Business Associate Agreement (BAA) is the foundational legal requirement. Without it, using any tool that touches PHI is a HIPAA violation — regardless of how secure the tool is.

Who needs a BAA with you:

  • Any AI tool that processes session notes containing client identifiers
  • Cloud storage services where you store client files
  • EHR or practice management software
  • Transcription services that hear your sessions
  • Email providers if you send client information

Who does NOT need a BAA:

  • Your malpractice insurance carrier
  • Professional associations
  • Clearing houses for billing (they have their own HIPAA obligations)
  • Tools you use only for de-identified data

Common BAA Status of AI Tools (as of 2026)

ToolBAA Available?Notes
ChatGPT (Free/Plus/Team)NoNot for individual practitioners
ChatGPT EnterpriseEnterprise contract onlyRequires separate agreement, not standard
Google Workspace (Business/Enterprise)YesGoogle signs BAAs for eligible accounts
Microsoft 365 (Business Premium+)YesCovered under Microsoft HIPAA BAA
Dedicated clinical AI toolsTypically yesVerify per vendor

Always verify current BAA status directly with the vendor — this table reflects 2026 status and may change.


What “HIPAA-Compliant AI” Actually Means for Therapy Notes

When a vendor says their tool is “HIPAA-compliant,” that phrase alone means very little — HIPAA compliance is not certified by any government agency. What it should mean in practice:

  1. The vendor will sign a BAA with individual practitioners (not just enterprise clients)
  2. Data is not used for model training without explicit, granular opt-in consent
  3. Encryption meets or exceeds AES-256 at rest and TLS 1.2+ in transit
  4. Audit trails exist and you can request access logs
  5. Data residency is in a jurisdiction you’re comfortable with
  6. Breach notification is committed to within 60 days (HIPAA requires 60 days from discovery)
  7. Data deletion is possible and confirmed permanent

A vendor who cannot answer these questions in writing is not a compliant partner.


How to Evaluate Any AI Therapy Note Tool: Checklist

Before entering any client information into an AI tool, verify these 10 items:

HIPAA COMPLIANCE CHECKLIST — AI DOCUMENTATION TOOLS

□ 1. Vendor will sign a BAA with my practice
□ 2. Data encrypted in transit (TLS 1.2+)
□ 3. Data encrypted at rest (AES-256 or equivalent)
□ 4. My data is NOT used to train AI models
□ 5. Unique login required (not shared accounts)
□ 6. Audit logs available — I can see who accessed data
□ 7. Permanent data deletion available and confirmed
□ 8. Breach notification commitment in writing
□ 9. Vendor has published HIPAA/security documentation
□ 10. I have a signed BAA in my files before using the tool

If any item is unchecked, do not use the tool for PHI until you have a satisfactory answer.


What Therapists Are Actually Using in 2026

The AI therapy documentation landscape has matured significantly. The tools that have gained traction among private practice therapists fall into three categories:

Category 1: Session Note Structuring

These tools take your dictated or typed notes and structure them into a chosen format (BIRP, SOAP, DAP). They don’t record sessions.

What to verify: That your typed notes are encrypted and not retained after processing; BAA availability.

Category 2: Audio Transcription + Note Generation

These tools listen to (or receive a recording of) your session and generate notes. Higher accuracy but significantly higher privacy stakes — audio of therapy sessions is among the most sensitive PHI that exists.

Critical questions: Is the audio processed on-device or on remote servers? How long is audio retained? Is the transcript stored? Who can access it?

Important: Many therapists who use audio-based AI do so only for their own dictated summaries after the session — not live session recording. This substantially reduces the privacy risk.

Category 3: Full Clinical Documentation Platforms

Platforms built specifically for therapists that integrate note-taking, client history, and AI structuring in a HIPAA-compliant environment with a BAA included.

TheraMemory falls in this category: session notes are structured using AI from your typed or dictated input (not live session audio), client data is encrypted and isolated per account, and client data is never used for model training. US practitioners: TheraMemory does not currently offer a Business Associate Agreement — verify your jurisdiction’s requirements before using any tool with client PHI.


What Therapists Most Commonly Get Wrong

Mistake 1: Assuming “secure” means “HIPAA-compliant”

A tool can use excellent encryption and still not be HIPAA-compliant — because no BAA exists. Security and compliance are related but not the same.

Mistake 2: Using ChatGPT for “de-identified” notes

Many therapists believe removing the client’s name makes notes safe for any tool. HIPAA’s de-identification standard is stricter than most people realize: it requires removing 18 specific identifiers, including dates of service, geographic details smaller than state level, and any “unique identifying number or code.” Session notes with dates and general location already carry risk.

Mistake 3: Assuming employer tools are covered

If you work for a group practice, their BAAs may cover tools they provide — but not tools you use independently. Your personal ChatGPT subscription is not covered by your employer’s enterprise agreement.

Mistake 4: Using a compliant tool, incorrectly

Even with a BAA-covered tool, entering more PHI than necessary creates risk. Principle of minimum necessary: use only the client information needed for the task.


Practical Workflow: AI Notes Without HIPAA Risk

Here is a compliant workflow used by therapists who use AI for documentation:

  1. During session: take brief handwritten or typed bullet notes (no full sentences needed)
  2. Immediately after: dictate a 2-minute verbal summary into a HIPAA-compliant tool (not into your phone’s voice assistant)
  3. AI structures the note: into your chosen format
  4. You review and edit: correct any inaccuracies, add clinical judgment
  5. Store in compliant system: your EHR or clinical documentation platform

What makes this compliant: no live session audio captured, minimal PHI entered, BAA-covered tool used, therapist reviews all AI output before finalization.


See Also

Try TheraMemory free for 14 days

AI that structures your post-session dictation into BIRP, SOAP, or DAP. No live session recording. Your client data is never used for model training.

Start free