Therapy notes contain some of the most sensitive personal information that exists — mental health diagnoses, trauma histories, relationship details, substance use, legal history, suicidal ideation. The obligation to protect this data is both ethical and legal. But most therapists make software and storage decisions based on features and price, not security.
Short answer: the critical data security questions for therapy notes are: Is data encrypted at rest and in transit? Is client data used to train AI models? Who at the company can access my data? What happens to data when I cancel? A provider that can’t answer these directly is a red flag.
The Actual Risks (Ranked)
Not all security risks are equal. For therapy notes specifically:
| Risk | Likelihood | Impact |
|---|---|---|
| AI training on client data | Medium — common in AI tools | Severe — loss of control over sensitive data |
| Data breach at provider | Low-medium | Severe — reputational, legal, client harm |
| Unauthorized internal access (provider staff) | Low | Severe if it occurs |
| Account compromise (weak password, no 2FA) | Medium | High — direct access to all your notes |
| Unencrypted local storage (laptop, USB) | High — many therapists use these | High — total exposure if device lost/stolen |
| Data loss (no backup) | Medium | High — years of records lost |
The risks most therapists think about (hackers) are not the most likely ones. The risks most therapists underestimate: AI training, unencrypted local files, and what happens to data after cancellation.
Cloud vs Local: What Actually Matters
The cloud vs local debate is the wrong framing. The right question is: what are the security practices of the specific solution you’re using?
| Cloud (secure provider) | Local (encrypted, backed up) | Local (unencrypted) | |
|---|---|---|---|
| Data at rest | Encrypted (if provider does this right) | Encrypted (if you set this up) | Not encrypted — exposed if device lost |
| Data in transit | Encrypted (TLS) | Not applicable | Not applicable |
| Backup | Automatic (if provider does this) | Manual or absent | Usually absent |
| Access if device stolen | Data not on device | Protected if encrypted | Exposed |
| Provider access risk | Exists — depends on policy | None | None |
| Vendor lock-in | Risk if no export | None | None |
A Word document on an unencrypted laptop is not “more private” than a reputable cloud system — it’s less secure in almost every dimension.
The AI Training Risk: The Question Most Therapists Don’t Ask
AI-powered therapy note tools are proliferating. Most therapists evaluate them on speed and output quality. The data security question they miss:
Is client data used to train or improve the AI model?
This matters because:
- “Training data” means the content of your session notes could influence the AI’s outputs for other users
- “De-identified” data is often not truly de-identified at the detail level therapy notes contain
- Once data is used in training, it cannot be “un-trained” — there is no meaningful deletion
What to look for in the privacy policy:
Red flag language:
- "improve our services"
- "improve model performance"
- "aggregated and de-identified data may be used"
- "to develop and improve our AI"
Green flag language:
- "client data is never used for AI training"
- "model training uses only synthetic data"
- "you retain full ownership; we do not use your data
for any purpose other than providing the service"
When in doubt, ask directly in writing. A legitimate provider will give you a direct answer.
6 Questions to Ask Any Provider
Before committing to any software for therapy notes, get specific answers to these six questions:
1. Where is data stored? Which country, which cloud infrastructure (AWS, Azure, Google Cloud — and in which region). This matters for legal jurisdiction. Data stored in the EU falls under GDPR. Data stored in the US may fall under different subpoena rules.
2. Encryption at rest and in transit? “We take security seriously” is not an answer. Look for: AES-256 at rest, TLS 1.2+ in transit. If they can’t tell you the standard, they may not be encrypting.
3. Does client data train AI models? Must be a direct no. “We anonymize data before any use” is not the same as “no.”
4. Who at your company can access my client data? Ideally: nobody, by design (zero-knowledge architecture). Realistically: only specific named roles, under specific conditions, with audit logging. If the answer is “our support team can see notes to help you,” that’s a meaningful privacy tradeoff.
5. What happens to data if I cancel? Can you export everything in a readable format? Is data deleted after cancellation, and within what timeframe? Get this in writing.
6. What is your breach notification policy? How quickly will you be notified if a breach occurs? In many jurisdictions, providers are required to notify you within 72 hours. Does the provider’s policy meet your jurisdiction’s requirements?
Provider Evaluation Checklist
THERAPY NOTES PROVIDER — SECURITY EVALUATION
ENCRYPTION
□ Data encrypted at rest: □ Yes Standard: _______ □ Unknown
□ Data encrypted in transit (TLS): □ Yes □ Unknown
□ Encryption keys managed by: □ Provider □ Me □ Unknown
AI AND DATA USE
□ Client data NOT used for AI training: □ Confirmed in writing □ Unclear
□ Specific language in privacy policy: ____________________
ACCESS CONTROLS
□ Provider staff access to data: □ None by design □ Limited: ___
□ Audit logging of access: □ Yes □ Unknown
□ 2FA available for my account: □ Yes □ No
DATA LOCATION
□ Data stored in: ________________________________________
□ Legal jurisdiction: ____________________________________
□ Subprocessors disclosed: □ Yes □ No
DATA PORTABILITY AND DELETION
□ Full export available: □ Yes Format: _______ □ Unknown
□ Data deleted on cancellation: □ Yes Within: _______ □ Unknown
□ Deletion confirmed in writing: □ Yes □ No
BREACH NOTIFICATION
□ Breach notification timeline: _________________________
□ Meets local legal requirements: □ Yes □ Unknown
OVERALL
□ Would proceed with this provider
□ Would not proceed — reason: __________________________
□ Need more information: ________________________________
What Encryption Actually Means (and Doesn’t)
Encryption at rest means data is encrypted when stored on servers. If the provider’s database is breached, the attacker gets encrypted data, not readable notes. This requires AES-256 or equivalent.
Encryption in transit (TLS) means data is encrypted while traveling between your device and the server. This is now standard for any website (the padlock in your browser). It does not protect data stored on the server.
End-to-end encryption (E2EE) means only you can decrypt your data — not even the provider can read it. This is the strongest form of protection but means the provider cannot help you recover a forgotten password and AI features (which require the provider to read the text) are impossible. Very few therapy note apps offer true E2EE.
“Secure” without specifics means nothing. Every provider says they take security seriously. Ask for the specific standard.
What Happens When You Cancel
This is the question most therapists never ask until it’s too late.
What you need before canceling any service:
- Full export of all notes and client records in a readable format (PDF, CSV, or plain text — not a proprietary format you can’t open without the software)
- Confirmation that data will be deleted from provider servers after export, and within what timeframe
- Any client-facing records you’re required to retain under your professional regulations
Questions to ask before signing up (not after canceling):
□ Can I export all notes and client records at any time?
□ What format is the export?
□ Is data deleted after I cancel? Within how long?
□ Is deletion verifiable (certificate of deletion)?
If a provider locks your data in a proprietary format or makes export difficult, that is a vendor lock-in risk as well as a data control problem.
Basic Security Hygiene (Your Side)
Security is not only about the provider. Your practices matter too:
YOUR ACCOUNT
□ Strong unique password (not used anywhere else)
□ Two-factor authentication enabled
□ No sharing of login credentials with anyone
YOUR DEVICES
□ Device password / PIN enabled
□ Full-disk encryption enabled (FileVault on Mac, BitLocker on Windows)
□ Auto-lock after inactivity (max 5 minutes)
□ No therapy notes in personal email drafts or unencrypted notes apps
YOUR NETWORK
□ No therapy note access on public Wi-Fi without VPN
□ Home router with current firmware and strong password
PHYSICAL
□ Screen not visible to others in shared workspace
□ Printer output not left unattended
□ Paper notes shredded, not recycled or binned
TheraMemory’s approach: client data is never used to train AI models. Post-session dictation is processed to structure your note — the content stays yours. Data is encrypted at rest and in transit. You can export all records at any time.
See Also
- Best Apps for Therapy Notes 2026
- Progress Notes vs Process Notes
- Pre-Session Review: 2 Minutes Before Every Client
- From First Session to Treatment Plan
Try TheraMemory free for 14 days
Client data never used for AI training. Encrypted at rest and in transit. Full export available at any time. Direct answers to security questions — not marketing language.
Start free