HIPAA-Compliant Software for Solo and Group Therapy Practices
What HIPAA actually requires of practice software, what it does not, and how solo and group therapy practices should check a vendor before they sign.

HIPAA compliance is not a certificate a product earns; it is a set of safeguards plus a signed BAA. For a group practice, software must also separate access by role and log every action. Ona signs a BAA with every workspace, encrypts data in transit and at rest, and keeps immutable audit trails.
Quick answer:
- What HIPAA asks of software: a signed BAA, a unique login per person, role-based access, audit controls, transmission security, and encryption you either implement or justify in writing.
- What it does not ask for: any certification. No federal program certifies software as HIPAA compliant, so treat the phrase "HIPAA certified" as marketing and ask what actually stands behind it.
- What changes in a group: every extra clinician, biller and front-desk hire is another identity, another role and another line in the audit trail. That is the part software built for one person quietly skips.
What HIPAA actually asks of your software
The Security Rule is shorter and duller than the sales pitch around it. Stripped to what a vendor must give you, it is six things.
A signed BAA. Your practice is the covered entity. Any vendor that creates, receives, maintains or transmits patient data on your behalf is a business associate, and the BAA is the contract that binds them to safeguard it and to tell you when something goes wrong. No BAA, no legitimate use of the tool, however good its encryption is.
Access controls. Each person gets their own login. Shared front-desk accounts are the most common finding in a small practice, and they are fatal to the rest of the model: if four people use one identity, the audit trail means nothing.
Audit controls. The system has to record activity on records containing patient data. This is the requirement that quietly decides whether you can answer a complaint, because "we think only Dr. Lang opened that chart" is not an answer.
Integrity controls. Records must not be altered or destroyed without that being detectable. Versioning and immutable signed documents are how software delivers this.
Transmission security. Data moving across a network has to be protected against interception.
Encryption, with an asterisk. Encryption at rest and in transit is an addressable implementation specification, not a flat command. Addressable means you assess it, implement it where reasonable, and document the equivalent alternative if you do not. In 2026 there is no defensible alternative, so read any vendor's silence on encryption as an answer.
Around that sits the part no vendor can do for you: your own risk analysis, your policies, your workforce training, and the periodic review of who still has access to what.
This is general information about what buyers should check, not legal advice.
What HIPAA does not ask for
A certification. There is no federal HIPAA certification for software. No agency reviews, endorses or certifies products. When a vendor says "HIPAA certified", they mean a voluntary third-party framework such as HITRUST or SOC 2, an auditor's report, or their own self-assessment. All three are useful signals. None of them is HIPAA, and only one of them is independent.
A specific product, or a single product. Nothing in the rule says your record, your video and your billing have to live in one system. Consolidation is an operational argument, not a legal one. It is a good argument, because each extra vendor is another BAA, another copy of the record and another access list to review, but it is yours to make, not the regulator's.
Perfection. The rule scales with the practice. What a solo therapist must do and what a fifteen-clinician group must do are genuinely different, which is why this question surfaces at the second hire.
What changes when a solo practice becomes a group
For one clinician, compliance is mostly about the perimeter: the laptop, the login, the vendor list. Add people and the problem moves inside the building.
A biller needs the claim and the code but not the session note. A front-desk hire needs the calendar and the phone but not the chart. A second clinician needs their own caseload and, usually, nothing at all from their colleague's. Minimum necessary stops being a principle and becomes a configuration.
Then the questions get practical. Who removes access the day someone leaves? Can you show, for one patient on one date, who opened the record? If the answer is "we would have to ask support", you have found the gap before an auditor did.
Behavioral health carries extra weight here. The notes are more sensitive than most of medicine, and the release requests arrive from schools, courts and employers.
The questions to put to any vendor
Ask these on the demo call and take notes.
- Do you sign a BAA with every customer, on every plan, or only above a certain tier?
- Is patient data encrypted in transit and at rest, and where is it stored?
- Does every user get a unique login, and is two-step verification available to all of them?
- What roles exist out of the box, and what does each one see by default?
- Can I scope access by location or by team as we add sites?
- Show me the audit trail for one patient record. Can I export it?
- Which parts of what you just demonstrated are add-ons, and what do they cost at our headcount?
- Do you publish a third-party security report, and will you send it before we sign?
Question seven catches more buyers than the rest combined. A plan that looks compliant in the demo and then puts secure messaging, video or the audit-ready consent behind a paid tier is a budgeting problem discovered after migration.
How Ona answers them
Ona is a general ambulatory EHR; its own FAQ says "Ona scales from solo clinics to enterprise systems". Behavioral health is one of nine specialties it serves, not the boundary of the product. Here is what the platform states, feature page by feature page.
BAA with every workspace. Not a tier, not an enterprise upsell. A BAA is in place with every Ona workspace, and it is signed at onboarding.
Encryption in transit and at rest. Patient data is encrypted in both states. Messaging and video calls are end-to-end encrypted. On the ambient scribe, recordings are "encrypted in transit and at rest inside your dedicated tenant, playable only by users with chart access", and Ona states it never trains models on your audio.
Role-based access, with group-shaped controls. Access is role-based. Team channels can be scoped to a location, reporting runs per provider, and in messaging patients only ever see their own thread, with restricted conversations limited to named members. Every account, clinician, staff or patient, can turn on two-step verification with an authenticator app.
Immutable audit trails. Messages, edits and membership changes are stored with author and timestamp. Consents capture the timestamp, the signer, the exact template version, the IP address and the user agent, cannot be altered once signed, only superseded, and export as a self-contained audit PDF for an inspection. You can find any consent by patient, template, version or date range.
Consent where recording happens. The scribe records behind a per-visit banner the patient can see and pause, with consent language configurable by jurisdiction and logged with a timestamp. Telehealth is encrypted end to end, every session is access-logged, and full-video recording is not the default.
Where Ona is thin
The honest column, because you will find this out anyway.
Ona publishes no third-party security certification and no uptime SLA. If your procurement, your credentialing body or a contracting employer wants a HITRUST or SOC 2 report in the file, Ona does not have one to send. TherapyNotes, SimplePractice and Healthie all publish third-party certification: HITRUST at TherapyNotes and SimplePractice, SOC 2 Type 2 and HITRUST R2 at Healthie. That is a real difference and it belongs in your notes.
Human support is in-app chat and email from a primarily business-hours team. The AI receptionist answers patient calls around the clock; a person does not.
Telehealth is 1:1 today, so there are no purpose-built group visits or shared medical appointments. Messaging deliberately does not read message content for emergencies, so keep your own phone and coverage policy in front of that.
And for a group of three or more practitioners, omnichannel messaging is a $150 per month add-on rather than part of the seat. It is free at two practitioners or fewer.
How the main options compare
One axis only: how much of a group practice's compliance surface, meaning messaging, video, documentation, consents and the audit trail, sits inside the base subscription rather than behind an add-on. This is not a security ranking and not a quality ranking. Prices and compliance statements were read on each vendor's own site in September 2026.
| Coverage order | Platform | What the vendor publishes on compliance | Access control and audit | In the base price | Watch for | Pricing |
|---|---|---|---|---|---|---|
| 1 | Ona | HIPAA compliance, BAA with every workspace, encryption in transit and at rest, end-to-end encrypted messaging and video, dedicated tenant. No third-party certification published | Role-based access, immutable audit trails, two-step verification on every account, location-scoped channels, per-provider reporting, consents logged with timestamp, IP and user agent | Every feature on every plan: charting, ambient scribe, telehealth, consents, tasks, reports, patient portal | Omnichannel messaging is $150 per month above two practitioners; human support is business hours; telehealth is 1:1; no published certification or uptime SLA | $130 practitioner seat, $45 staff seat, monthly, 10% off annually |
| 2 | TherapyNotes | HIPAA compliance and HITRUST certification, including AI HITRUST; TLS and FIPS 140-2 compliant encryption; onsite and offsite backups | Six named user roles on minimum-necessary access, an activity log across nearly every action, two-factor authentication | Secure client and staff messaging, custom client portal, basic telehealth, unlimited storage and backups, 24/7 phone and email support | ePrescribe, premium telehealth, reminders and electronic billing are metered or per-clinician add-ons | Solo $69; Group $79 first clinician plus $50 per additional, free non-clinical staff |
| 3 | SimplePractice | HIPAA compliance, HITRUST CSF certification and PCI compliance, with a BAA published in the footer | Team members, and with them roles and permissions, are exclusive to the Plus plan | Telehealth, client portal, progress notes, paperless intake and online payments on every plan | Secure client messaging starts on Essential; AI note taking, Care Aide and ePrescribe are paid add-ons; $20 annual CPT fee per clinician | Starter $49, Essential $79, Plus $99; additional clinicians from $74 |
| 4 | Healthie | HIPAA and PCI compliance, SOC 2 Type 2 and HITRUST R2 certification, with a BAA offered | Roles and permissions plus internal team chat arrive on the Group plan | Scheduling, charting, telehealth, payments and mobile app from the entry plan | Roles, permissions and internal chat are Group-plan features; claims and e-prescribing are add-ons | Core $19.99, Essentials $49.99, Plus $129.99, Group $149.99+ with $50 per clinician; 10% off billed yearly |
| 5 | ICANotes | HIPAA compliance and ONC-ATCB certification | Per-clinician licensing, non-clinical users priced separately after the first | Notes, scheduling, messaging and billing tools by tier | Telehealth and AI scribe are per-user add-ons; the subscription requires a three-month commitment | Notes Only $55, Non-Prescribing $75, Prescribing $213 plus $99 activation |
Screening forms are an access question too
One place where access control gets concrete. Ona ships PHQ-9 with the canonical 0 to 27 scoring and all five severity bands, GAD-7 scored 0 to 21 with its standard bands, and a preconfigured suicidality flag on item 9 that fires when the question is answered above "Not at all".
Two details matter for a group. Scores are visible to clinicians only; the patient sees an ordinary questionnaire with no point values or clinical labels. And scores are not rolled up across patients, so each result stays on its own form. If tracking a score across a caseload is central to how you work, check that before you move.
What it costs
$130 per practitioner seat and $45 per staff seat per month, with every feature on every plan and 10% off the whole bill annually. Three practitioners and a front-desk hire is $435 per month, plus $150 if you want omnichannel messaging at that headcount. Practices running five or more practitioners, several locations, or volume that does not fit a tier get custom pricing built around the practice.
Add-ons: e-prescribing $45 per prescribing practitioner, EPCS $25 more and requires e-prescribing, calls with transcription and recording $25 per month, the AI receptionist from $100 per month for 400 minutes through $400 for 1,500, with $0.20 per minute beyond the tier. The Ona Clearing House runs from $69 per month for 100 claims to $1,099 for 2,500, with unlimited providers and payer enrollments on every plan and no separate account to open. Full detail sits on the pricing page.
There are no setup fees and no long-term contract. Migration from any EHR is free, usually inside one business day for the export and import, with full cutover in one to three weeks for smaller practices. The trial is 14 days with no credit card.
Frequently asked questions
Is Ona HIPAA compliant for a group practice?
Yes. Ona states it is fully HIPAA compliant, and a BAA is in place with every Ona workspace at any size. Patient data is encrypted in transit and at rest, messaging and video are end-to-end encrypted with immutable audit trails, access is role-based, recordings sit inside your dedicated tenant, and every account can turn on two-step verification with an authenticator app.
What does HIPAA actually require of software?
A signed BAA with the vendor, access controls with a unique login per person, audit controls that record what happened to a record, integrity controls, and transmission security. Encryption is an addressable specification rather than a flat rule, which means you either implement it or document a reasonable alternative in writing. In practice, every serious vendor encrypts.
Is any software HIPAA certified?
No. There is no federal HIPAA certification for software and no agency endorses or certifies products. A vendor saying certified usually means a voluntary framework such as HITRUST or SOC 2, or an internal self-assessment. Ask which one it is, who issued it, what was in scope and when it expires.
Does a BAA with my EHR vendor cover the whole practice?
No. A BAA covers that vendor only. Every other service touching patient data needs its own: the video tool, the messaging app, the transcription service, the clearinghouse, the fax line, the storage drive. Fewer vendors means fewer agreements to chase and fewer copies of the record, which is the practical argument for one system.
How does a group practice stop clinicians from seeing each other's charts?
With role-based access, and by checking what the default actually is. In Ona, access is role-based, team channels can be scoped to a location, reporting is per provider, patients only ever see their own thread, and screening scores are visible to clinicians only. Ask any vendor to show you the clinician view for a patient who is not on that clinician's caseload.
What does Ona not publish that procurement may ask for?
A third-party security certification such as HITRUST or SOC 2, and an uptime SLA. Ona publishes its HIPAA compliance, a BAA with every workspace and the technical detail behind both. If your credentialing body or an enterprise client requires a certification report, raise it on the demo call before you migrate.
Next step
Bring the eight questions above to a call and make the vendor answer them on screen, with your own workflow loaded: one patient, one consent, one note, one audit trail, one export. Book a 15-minute demo and ask for the clinician view of a chart that is not theirs, or start the 14-day free trial with full access and no credit card. More on documentation that survives a review: behavioral health on Ona.

Written by
Ona Health team