Therapy notes contain some of the most sensitive personal information that exists — mental health diagnoses, trauma histories, relationship details, substance use, legal history, suicidal ideation. The obligation to protect this data is both ethical and legal. But most therapists make software and storage decisions based on features and price, not security.

Short answer: the critical data security questions for therapy notes are: Is data encrypted at rest and in transit? Is client data used to train AI models? Who at the company can access my data? What happens to data when I cancel? A provider that can’t answer these directly is a red flag.


The Actual Risks (Ranked)

Not all security risks are equal. For therapy notes specifically:

RiskLikelihoodImpact
AI training on client dataMedium — common in AI toolsSevere — loss of control over sensitive data
Data breach at providerLow-mediumSevere — reputational, legal, client harm
Unauthorized internal access (provider staff)LowSevere if it occurs
Account compromise (weak password, no 2FA)MediumHigh — direct access to all your notes
Unencrypted local storage (laptop, USB)High — many therapists use theseHigh — total exposure if device lost/stolen
Data loss (no backup)MediumHigh — years of records lost

The risks most therapists think about (hackers) are not the most likely ones. The risks most therapists underestimate: AI training, unencrypted local files, and what happens to data after cancellation.


Cloud vs Local: What Actually Matters

The cloud vs local debate is the wrong framing. The right question is: what are the security practices of the specific solution you’re using?

Cloud (secure provider)Local (encrypted, backed up)Local (unencrypted)
Data at restEncrypted (if provider does this right)Encrypted (if you set this up)Not encrypted — exposed if device lost
Data in transitEncrypted (TLS)Not applicableNot applicable
BackupAutomatic (if provider does this)Manual or absentUsually absent
Access if device stolenData not on deviceProtected if encryptedExposed
Provider access riskExists — depends on policyNoneNone
Vendor lock-inRisk if no exportNoneNone

A Word document on an unencrypted laptop is not “more private” than a reputable cloud system — it’s less secure in almost every dimension.


The AI Training Risk: The Question Most Therapists Don’t Ask

AI-powered therapy note tools are proliferating. Most therapists evaluate them on speed and output quality. The data security question they miss:

Is client data used to train or improve the AI model?

This matters because:

  • “Training data” means the content of your session notes could influence the AI’s outputs for other users
  • “De-identified” data is often not truly de-identified at the detail level therapy notes contain
  • Once data is used in training, it cannot be “un-trained” — there is no meaningful deletion

What to look for in the privacy policy:

Red flag language:
- "improve our services"
- "improve model performance"
- "aggregated and de-identified data may be used"
- "to develop and improve our AI"

Green flag language:
- "client data is never used for AI training"
- "model training uses only synthetic data"
- "you retain full ownership; we do not use your data 
   for any purpose other than providing the service"

When in doubt, ask directly in writing. A legitimate provider will give you a direct answer.


6 Questions to Ask Any Provider

Before committing to any software for therapy notes, get specific answers to these six questions:

1. Where is data stored? Which country, which cloud infrastructure (AWS, Azure, Google Cloud — and in which region). This matters for legal jurisdiction. Data stored in the EU falls under GDPR. Data stored in the US may fall under different subpoena rules.

2. Encryption at rest and in transit? “We take security seriously” is not an answer. Look for: AES-256 at rest, TLS 1.2+ in transit. If they can’t tell you the standard, they may not be encrypting.

3. Does client data train AI models? Must be a direct no. “We anonymize data before any use” is not the same as “no.”

4. Who at your company can access my client data? Ideally: nobody, by design (zero-knowledge architecture). Realistically: only specific named roles, under specific conditions, with audit logging. If the answer is “our support team can see notes to help you,” that’s a meaningful privacy tradeoff.

5. What happens to data if I cancel? Can you export everything in a readable format? Is data deleted after cancellation, and within what timeframe? Get this in writing.

6. What is your breach notification policy? How quickly will you be notified if a breach occurs? In many jurisdictions, providers are required to notify you within 72 hours. Does the provider’s policy meet your jurisdiction’s requirements?


Provider Evaluation Checklist

THERAPY NOTES PROVIDER — SECURITY EVALUATION

ENCRYPTION
□ Data encrypted at rest: □ Yes  Standard: _______  □ Unknown
□ Data encrypted in transit (TLS): □ Yes  □ Unknown
□ Encryption keys managed by: □ Provider  □ Me  □ Unknown

AI AND DATA USE
□ Client data NOT used for AI training: □ Confirmed in writing  □ Unclear
□ Specific language in privacy policy: ____________________

ACCESS CONTROLS
□ Provider staff access to data: □ None by design  □ Limited: ___
□ Audit logging of access: □ Yes  □ Unknown
□ 2FA available for my account: □ Yes  □ No

DATA LOCATION
□ Data stored in: ________________________________________
□ Legal jurisdiction: ____________________________________
□ Subprocessors disclosed: □ Yes  □ No

DATA PORTABILITY AND DELETION
□ Full export available: □ Yes  Format: _______  □ Unknown
□ Data deleted on cancellation: □ Yes  Within: _______  □ Unknown
□ Deletion confirmed in writing: □ Yes  □ No

BREACH NOTIFICATION
□ Breach notification timeline: _________________________
□ Meets local legal requirements: □ Yes  □ Unknown

OVERALL
□ Would proceed with this provider
□ Would not proceed — reason: __________________________
□ Need more information: ________________________________

What Encryption Actually Means (and Doesn’t)

Encryption at rest means data is encrypted when stored on servers. If the provider’s database is breached, the attacker gets encrypted data, not readable notes. This requires AES-256 or equivalent.

Encryption in transit (TLS) means data is encrypted while traveling between your device and the server. This is now standard for any website (the padlock in your browser). It does not protect data stored on the server.

End-to-end encryption (E2EE) means only you can decrypt your data — not even the provider can read it. This is the strongest form of protection but means the provider cannot help you recover a forgotten password and AI features (which require the provider to read the text) are impossible. Very few therapy note apps offer true E2EE.

“Secure” without specifics means nothing. Every provider says they take security seriously. Ask for the specific standard.


What Happens When You Cancel

This is the question most therapists never ask until it’s too late.

What you need before canceling any service:

  • Full export of all notes and client records in a readable format (PDF, CSV, or plain text — not a proprietary format you can’t open without the software)
  • Confirmation that data will be deleted from provider servers after export, and within what timeframe
  • Any client-facing records you’re required to retain under your professional regulations

Questions to ask before signing up (not after canceling):

□ Can I export all notes and client records at any time?
□ What format is the export?
□ Is data deleted after I cancel? Within how long?
□ Is deletion verifiable (certificate of deletion)?

If a provider locks your data in a proprietary format or makes export difficult, that is a vendor lock-in risk as well as a data control problem.


Basic Security Hygiene (Your Side)

Security is not only about the provider. Your practices matter too:

YOUR ACCOUNT
□ Strong unique password (not used anywhere else)
□ Two-factor authentication enabled
□ No sharing of login credentials with anyone

YOUR DEVICES
□ Device password / PIN enabled
□ Full-disk encryption enabled (FileVault on Mac, BitLocker on Windows)
□ Auto-lock after inactivity (max 5 minutes)
□ No therapy notes in personal email drafts or unencrypted notes apps

YOUR NETWORK
□ No therapy note access on public Wi-Fi without VPN
□ Home router with current firmware and strong password

PHYSICAL
□ Screen not visible to others in shared workspace
□ Printer output not left unattended
□ Paper notes shredded, not recycled or binned

TheraMemory’s approach: client data is never used to train AI models. Post-session dictation is processed to structure your note — the content stays yours. Data is encrypted at rest and in transit. You can export all records at any time.


See Also

Try TheraMemory free for 14 days

Client data never used for AI training. Encrypted at rest and in transit. Full export available at any time. Direct answers to security questions — not marketing language.

Start free