Building HIPAA Compliant Software: A Therapist's Guide
Wondering what goes into building hipaa compliant software? Learn why local data ownership is the safest route for solo therapy practices.
If you have ever wondered why some therapy software gets called "HIPAA compliant" and other software does not, the honest answer is that HIPAA does not stamp products as compliant. HIPAA is a set of obligations — safeguards you put in place and contracts you sign — and software either supports those obligations or it does not.
Whether you are shopping for an EHR, weighing a custom build, or just trying to evaluate marketing claims, it helps to understand what HIPAA-compliant software actually requires. This guide breaks the requirements into the three safeguard categories HIPAA uses, explains the contracts and controls underneath them, and makes the case for why local data ownership is the safest, lowest-risk route for a solo practice. For the practical side of designing EHR software, our guide to creating EHR software is a useful companion.
The three categories of safeguards
The HIPAA Security Rule organizes protections into three groups. Good software should support all three.
Administrative safeguards
These are the policies and procedures that govern how PHI is handled. Software supports them by enabling:
- Risk analysis and ongoing risk management.
- Workforce training and sanctions for violations.
- Access management — assigning the minimum access each person needs.
- Contingency planning, including backups and disaster recovery.
- Periodic evaluation of safeguards.
A tool cannot do your risk analysis for you, but it should not make it harder. Look for features that let you document access decisions and export evidence when you need it.
Physical safeguards
Physical protections limit access to the hardware and facilities where PHI lives. For a solo therapist, that usually means:
- Controlling physical access to the device that stores records.
- Securing workstations and mobile devices with locks and encryption.
- Protecting backups and media, including how they are moved or destroyed.
Local data ownership maps onto this category cleanly: when records live on a device you physically control, you can see and limit who touches the hardware. Cloud-only storage pushes that responsibility onto a vendor's data center you will never visit.
Technical safeguards
These are the technology controls that protect electronic PHI:
- Access controls: unique user IDs, automatic logoff, and role-based permissions.
- Audit controls: hardware, software, and procedural mechanisms that record and examine activity.
- Integrity controls: protections that keep PHI from being altered or destroyed improperly.
- Transmission security: encryption of PHI when it moves across networks.
Encryption is technically "addressable" under the rule, meaning you must implement it or document an equivalent alternative. In practice, HHS treats encryption as the expected standard, and unencrypted PHI is treated as "unsecured" for breach-notification purposes.
The contracts: Business Associate Agreements
Under HIPAA, a business associate is any person or organization that performs functions involving PHI on behalf of a covered entity — in your case, the therapist. Software vendors that create, receive, maintain, or transmit your clients' PHI are business associates, and you need a signed BAA with each one before PHI flows.
A BAA should define, at minimum:
- How the vendor will safeguard PHI.
- How breaches will be reported and how quickly.
- That the vendor will not use PHI for its own purposes.
- How PHI will be returned or destroyed when the relationship ends.
If a vendor will not sign a BAA, that vendor cannot handle PHI in your practice. This single question rules out a surprising number of consumer tools. Our no-nonsense HIPAA guide for solo therapists covers the broader compliance picture.
What to require in any software you adopt
When you evaluate software, demand evidence for the following:
- A signed BAA before any PHI is processed.
- Encryption at rest and in transit.
- Unique user identification and automatic logoff.
- Audit logs that are tamper-evident and retained appropriately.
- Access controls that enforce least privilege.
- A documented risk analysis on your end, with the software as one component.
- Clear data handling: where data lives, how long it is kept, and how it is deleted.
A product that cannot clearly answer these is a risk regardless of how polished the interface looks. You can turn the list above into a structured review using our HIPAA checklist for solo practices.
Why local data ownership is the safest route
Most cloud EHRs store your clients' records in a shared environment alongside thousands of other practices. That model is convenient, but it concentrates risk: a single breach at the vendor can expose many practices at once, and you depend on the vendor's safeguards — which you cannot inspect — to protect your data.
Local data ownership flips that model. When records live on a device you control, the blast radius is one machine, not a multi-tenant cloud. You control the encryption, the access rules, the backups, and whether the device is connected at all. Fewer parties touch the data, which means fewer business associates, fewer BAA relationships to maintain, and fewer places where a breach can originate.
For a solo therapist, "fewer parties" is not a minor advantage — it is most of the compliance picture. Local ownership also tends to align with a one-time software license instead of monthly cloud rent, so you lower both risk and cost at the same time.
Building vs. buying vs. owning
You do not need to build software from scratch to benefit from HIPAA-aligned design. The realistic options are:
- Rent a cloud EHR: convenient, but ongoing cost, vendor-controlled data, and broad shared risk.
- Build custom: maximum control, but an enormous time and security burden you probably cannot staff alone.
- Own a locally stored EHR with a one-time license: you control the hardware and data, you pay once, and the safeguards map cleanly onto the categories above.
For most solo therapists, the third option hits the best balance of safety, cost, and simplicity.
Bottom line
HIPAA-compliant software is not about a badge — it is about administrative, physical, and technical safeguards, signed BAAs, encryption, access controls, audit logs, and an honest risk analysis. The fewer parties that touch your clients' data, the smaller your exposure. Local data ownership gives a solo practice the smallest, most controllable blast radius, and it usually costs less over time because you are not paying rent forever.
See how much perpetual EHR rent would cost you over a career with our software rent calculator, and if owning your software sounds right, request a demo. Demos use fake client data so you can explore the workflow freely.
References
- [1] U.S. Department of Health and Human Services. HIPAA Security Rule — Laws and Regulations. Accessed August 2026.
- [2] U.S. Department of Health and Human Services. Business Associates. Accessed August 2026.
- [3] U.S. Department of Health and Human Services. Encryption Guidance. Accessed August 2026.
- [4] American Psychological Association. Record Keeping Guidelines. Accessed August 2026.