Session notes, intake forms, assessment records — everything you document about your clients is sensitive personal data. In private practice, you’re the one responsible for keeping it secure. There’s no IT department, no compliance officer, no institution to absorb a breach.

This guide covers the real risks, what regulations actually require, and what practical steps protect you and your clients.

Why data security isn’t just a technical problem

Most data incidents in private practice don’t involve hackers. They involve:

  • A laptop left in a car that gets broken into
  • Notes stored in a personal Gmail account that a family member can access
  • A practice management tool with weak password protection
  • Client files in a shared folder that a cleaner or contractor can see
  • An old phone with unencrypted client notes that gets sold or lost

The threat model for a solo therapist is ordinary human error and physical theft — not sophisticated cyberattacks. That shapes what you actually need to do.

What data you’re responsible for

Everything that could identify a client and relate to their health or treatment is sensitive:

  • Names, contact details, emergency contacts
  • Session notes — including brief post-session summaries
  • Intake forms and consent documents
  • Assessment results or psychological testing records
  • Invoices and payment records (which implicitly confirm a therapeutic relationship)
  • Scheduling data (appointment records prove someone is a client)
  • Any communications: email, text, messaging app threads

This includes data you think of as “just admin.” An invoice with a client’s name sent to the wrong email address is a data breach.

What regulations apply to you

Your obligations depend on where you practice and where your clients are located.

In the United States: HIPAA (Health Insurance Portability and Accountability Act) applies to covered entities and their business associates. Whether HIPAA applies directly to you depends on whether you transmit health information electronically for billing purposes. Many private practitioners do — which means the Privacy Rule and Security Rule apply. Even if HIPAA doesn’t technically apply, most state licensing boards have their own confidentiality and record-keeping requirements.

In the European Union and UK: GDPR (General Data Protection Regulation) or UK GDPR applies if you process personal data of people in those jurisdictions. Therapy notes are “special category” data under GDPR, which means stricter processing requirements, explicit consent, and data minimization obligations.

In other jurisdictions: Most countries with developed health professions frameworks have equivalent requirements. Professional body codes of ethics typically require confidentiality protections that mirror legal requirements.

The practical minimum regardless of jurisdiction: don’t store client data in places that aren’t reasonably secure, have documented processes for handling it, and know what you’d do if something went wrong.

The risks of common storage choices

Personal cloud storage (Google Drive, Dropbox, iCloud)

Convenient but problematic. These services are not designed for clinical data:

  • Standard accounts aren’t covered by BAAs (Business Associate Agreements) required under HIPAA
  • Data may be scanned or analyzed by the provider for advertising purposes
  • Access controls are often weak — family members, shared devices, or account compromise can expose everything
  • No audit trail of who accessed what

Google Workspace for Healthcare and similar enterprise tiers offer BAAs and stronger controls, but require correct configuration.

Email and messaging

Unencrypted email is not appropriate for transmitting clinical information. Standard email (Gmail, Outlook, etc.) passes through multiple servers and can be intercepted. Secure messaging platforms (with end-to-end encryption) are better for client communication, but aren’t a substitute for a record-keeping system.

Paper records

Paper is immune to many digital threats but has its own risks: fire, flood, theft, and the simple problem that paper can’t be backed up. If paper records are your primary system, they need to be in a locked cabinet in a secure location, with clear protocols for destruction when no longer needed.

Dedicated practice management software

Purpose-built tools for therapists handle the structural security requirements by design: encrypted storage, access controls, and — for HIPAA-covered practitioners — BAAs. The tradeoff is cost and vendor dependency, but the security architecture is already built in.

Practical security measures that actually matter

Encryption

All devices that store client data should have full-disk encryption enabled. On modern Macs, this is FileVault. On Windows, BitLocker. On iPhone, encryption is on by default when you use a passcode. On Android, check settings.

Encryption means that if your laptop is stolen and powered off, the data is unreadable without your password. It doesn’t protect against someone accessing a running, unlocked device.

Strong passwords and two-factor authentication

A strong, unique password for every service that holds client data. A password manager (1Password, Bitwarden) makes this practical. Two-factor authentication — especially hardware keys or authenticator apps rather than SMS — on everything critical.

If your notes system is protected only by a password you can remember, it isn’t well protected.

Physical security

Lock your screen when you step away from your computer. In shared spaces, position screens so they can’t be read by passersby. Physical client files should be locked — filing cabinets with key locks are inexpensive.

For home offices: consider who else has access to the space and whether client notes are visible or accessible to them.

Device management

Know which devices have client data on them. If you stop using a device, wipe it properly before disposing of it. Enable remote wipe capabilities on mobile devices so you can erase them if lost or stolen.

Keep operating systems and apps updated — security patches close vulnerabilities that would otherwise be exploited.

Secure client communication

Have a clear policy on how clients can contact you and how you’ll communicate with them. If you use email with clients, use encrypted email or a secure messaging platform. Avoid exchanging clinical information over standard SMS.

What to do if something goes wrong

A data breach response plan doesn’t need to be elaborate, but you should have one:

  1. Contain: Stop further exposure. Change compromised passwords, revoke access, secure the device.
  2. Assess: What data was affected? How many clients? What type of information?
  3. Notify: Depending on jurisdiction and severity, you may have legal obligations to notify affected clients and/or regulatory bodies within specific timeframes (HIPAA: 60 days; GDPR: 72 hours to supervisory authority).
  4. Document: Keep a record of what happened, what you did, and when.
  5. Review: What failed? What changes will prevent recurrence?

Consulting with a solicitor or attorney familiar with health data law before an incident — not after — is worthwhile if your practice is growing.

Common mistakes in private practice

Using the same password for everything. A single compromised credential can expose your entire client database.

Backing up to the same location as the primary. If your laptop is stolen and the only backup is a drive sitting next to it, you’ve lost everything twice.

Never checking privacy settings on tools you use. Default settings often favor convenience over privacy. A scheduling tool that sends appointment reminders with clinical context to a client’s work email — because that’s the default — is a breach waiting to happen.

Assuming “I’m too small to be targeted.” Most breaches of small practices are opportunistic, not targeted. The risk isn’t that someone specifically wants your files — it’s that your device is valuable and happens to have sensitive data on it.

Keeping data longer than necessary. Most jurisdictions have minimum retention requirements for clinical records, but also principles of data minimization. Old records that you no longer need should be properly destroyed — shredded if paper, securely wiped if digital.

Keeping records after ending the therapeutic relationship

Clinical records typically need to be retained for a minimum period after the last session — often 7 years for adults, longer for minors (often until the client reaches a specified age plus some years). Check your jurisdiction’s specific requirements and your professional body’s guidance.

During this retention period, the same security requirements apply. A filing cabinet in a spare room with old client files needs to be just as secure as active records.

Building a sustainable system

Security doesn’t need to be perfect, but it needs to be consistent. A few decisions made at the start of your practice — where notes live, how devices are secured, how client communication happens — create the architecture for everything that follows.

The most important thing is intentionality: know where your client data is, who could access it, and what you’d do if something went wrong. Most practitioners who have breaches weren’t negligent — they simply hadn’t thought it through.

Try TheraMemory free for 14 days

TheraMemory stores client records, session notes, and intake information with encryption and professional-grade data protection — so you're not solving the security question yourself.

One secure place for everything, built for private practice therapists.

Try TheraMemory

Read also