In the United States, HIPAA sets the baseline for how protected health information must be handled, and it applies squarely to the assessment data that psychologists and other mental health clinicians collect. Choosing software that supports HIPAA compliance is therefore not optional for covered entities. This guide explains, in plain terms, what HIPAA requires of assessment software, what a business associate agreement is, and what clinicians should verify before adopting a platform. It is general information, not legal advice.
What HIPAA covers
HIPAA, the Health Insurance Portability and Accountability Act, establishes standards for protecting health information. Two components matter most for software: the Privacy Rule, which governs how protected health information may be used and disclosed, and the Security Rule, which sets technical, physical and administrative safeguards for electronic protected health information. Assessment results, diagnoses and notes all fall within scope.
Protected health information (PHI)
PHI is individually identifiable health information, including a patient's name, contact details, diagnoses and assessment scores when linked to an identifiable person. In psychology, almost everything a platform stores is PHI. That means the software must protect it end to end, not merely at the point of storage. For an overview of what these platforms handle, see psychological assessment software in the USA.
The Security Rule safeguards
Technical safeguards
These include encryption of data in transit and at rest, unique user identification, automatic logoff and audit controls that record who accessed what and when. A HIPAA-conscious platform should be able to demonstrate each of these.
Administrative safeguards
These cover policies and procedures: workforce training, risk assessments, access management and an incident-response plan. Software supports these, but the covered entity remains responsible for its own policies.
Physical safeguards
These address the physical environment of servers and devices, including data-center security and controls on workstation access.
Encryption and access controls
Encryption is central. Data should be encrypted while moving across networks and while stored, so that intercepted or stolen data is unreadable. Access controls ensure that only authorized users see PHI, each with an individual login rather than a shared account. Role-based access limits staff to the records they need. These same principles underpin good practice everywhere; our guide on choosing assessment software covers them in a vendor-neutral way.
The business associate agreement (BAA)
When a covered entity uses a vendor that handles PHI on its behalf, HIPAA generally requires a business associate agreement. The BAA is a contract in which the vendor commits to safeguarding PHI in line with HIPAA and to reporting breaches. If a software vendor will store or process your patients' PHI and cannot provide a BAA, that is a significant red flag. Always confirm BAA availability before entrusting patient data to any platform.
Breach notification
HIPAA includes breach-notification requirements: if unsecured PHI is compromised, affected individuals and authorities must be notified within defined timeframes. Good software reduces breach risk through encryption and audit logging, and a responsible vendor will have a clear process for reporting incidents to you promptly.
What clinicians should verify
- Does the vendor sign a business associate agreement?
- Is PHI encrypted in transit and at rest?
- Are there unique logins, role-based access and audit logs?
- How and where is data stored, and how is it backed up?
- What is the vendor's breach-notification process?
- Can you export your data if you leave the platform?
Digitizing your workflow also reduces the loose paper that is hard to secure; see paper versus digital assessments and reducing clinical paperwork.
Compliance is shared, not automatic
No vendor can make you HIPAA compliant on its own. Compliance is a shared responsibility: the platform provides safeguards and a BAA, while your practice maintains its own policies, training and access discipline. A platform can be described as supporting HIPAA compliance, but your workflow decisions determine whether that compliance holds in practice.
Key takeaways
- Assessment scores, notes and diagnoses are PHI and fall within HIPAA scope.
- The Security Rule requires technical, administrative and physical safeguards.
- Encryption, unique logins, role-based access and audit logs are essential.
- Always obtain a business associate agreement before a vendor handles PHI.
- This is general information, not legal advice; compliance is a shared responsibility.
Frequently Asked Questions
See LetPsyc in your own practice
Digital psychological assessments, automatic scoring, and clinician-grade PDF reports — built for clinicians across Pakistan and beyond. Start your free trial today.
Start Free Trial