Last updated: September 14, 2026 · plain answers to the questions a therapist should ask any software that holds a client's record
PracticeDocket runs on a major US cloud provider, in the United States. Client records are stored in a database encrypted with a key dedicated to PracticeDocket, with continuous backups that let us restore to any moment in the previous 35 days. Session audio, where a practice chooses to record, is stored encrypted and deleted automatically after the retention period (90 days by default) or the moment the practitioner purges it.
Each practice's data is isolated. A practitioner's sign-in reaches their practice and nothing else; that boundary is enforced in the data layer, not by convention.
We use a small number of vendors, each under a Business Associate Agreement where they can see protected health information. We send them as little as the job needs. By function, and in every case the least the job allows:
| What for | What they see | BAA |
|---|---|---|
| Hosting, database and text-message delivery | Encrypted storage; text bodies carry no clinical content | Yes |
| Email delivery | Appointment, form and invoice emails — no clinical content | Yes |
| Transcribing recorded sessions and voice notes | The audio, for transcription; deleted after | Yes |
| Drafting notes, summaries and insights for your review | Transcript text with names stripped; nothing is retained or used for training | Yes |
| Card payments | An invoice number and an amount — never a service or a diagnosis | Not needed: no PHI |
| Showing your sessions in your own calendar (optional) | Initials, time and location only | Not needed: no PHI |
We name each vendor, and share the signed agreements, once a mutual NDA is in place — which is the normal footing for a diligence review and the one we would ask for in your position. Write to security@practicedocket.com and we will send the list, the BAAs and anything else your review needs.
Protected health information stays inside. Appointment emails and texts say when and where, not why. Calendar events carry initials. Payment descriptions carry an invoice number. Video meeting titles say "Telehealth session". This is a rule in the code, with tests that fail if anyone breaks it.
Every read and write of a client's record is logged with who, what and when, and the log is visible to the practice on the client's page and under Activity. Logs are kept even after a record is deleted, as the law requires.
A practice can export its records and leave. A client's complete record can be produced on request. Cancelling an account does not delete the records the law says a practice must keep; we hold them for the practice, encrypted, for the retention period the practice sets, and then delete them.
We will tell the affected practice without unreasonable delay, and in every case within the time HIPAA requires, with what happened, what was involved, and what we did. Practices are covered by our Business Associate Agreement, which you sign when you create your practice.
Honest about the gaps: we do not yet hold a SOC 2 report. Annual third-party penetration testing and a formal risk analysis are on the plan for the coming year, ahead of the updated HIPAA Security Rule. This page will say when they are done.
Write to security@practicedocket.com. If you have found a vulnerability, tell us there first and we will take it seriously and thank you for it.