Security you can rely on

Keep your account and electronic patient health information (PHI) safe.

30-day trial. No credit card required. Access all features.
Katie Malinski, SimplePractice Story on Security

Katie M. from Austin, TX

The SimplePractice Security and Privacy Program

Our Security and Privacy Program incorporates all aspects of the platform: people, process, and technology. It is based on HIPAA, HITRUST, NIST-CSF, PCI, ISO 27001/2, and CCPA frameworks. It includes security and privacy controls across 19 different domains, including but not limited to access control, data encryption and privacy, vulnerability management, vendor management, network protection, endpoint protection, risk management, and disaster recovery.

Security and Privacy Program

HIPAA-compliant and HITRUST certified

Keep sensitive data safe with an EHR that satisfies both HITRUST and HIPAA security requirements. There are no specific HIPAA certifications an organization can obtain. However, the gold standard to confirm compliance is HITRUST certification. After review by a third-party assessor, SimplePractice received a HITRUST Certification Report by the HITRUST Alliance.

Bank-level security

SimplePractice takes the security of your account information seriously. Multiple layers of encryption are used to protect your data while it is stored or transmitted electronically. PCI-level controls are implemented to ensure that the information you process is equivalent or better than some financial institutions.

Secure servers, monitored 24/7

Physical security is an important component to protect your data. Our platform servers are housed in a facility protected by proximity readers, biometric scanners, and security guards 24/7, 365 days a year.

Constantly tested to be

We hack our own site—running thousands of tests, scanning our ports, and protecting against cross-site scripting. In addition, we partner with external security firms to assess our platforms’ with an unbiased neutral approach.


“The features I love: easy scheduling for patients, secure messaging, automatic invoice generation, note storage, and Telehealth. No other physical therapy compatible platform offers this much while being able to handle insurance.”

— Katie M. from Everett, WA

SimplePractice Testimonial, Katie McGee, PT, DPT from Everett, WA


“SimplePractice has been the best decision for my private practice as a Dietitian. It's extremely user-friendly and budget-friendly. It seems too good to be true, and I would highly recommend it to anyone.”

— Marisa M. from Rolling Hills Estates, CA

SimplePractice Testimonial, Kira Medina-Tiencken, Marisa Martorana from Rolling Hills Estates, CA


“From booking appointments through my website, hosting video appointments with clients, and billing and collecting payments, SimplePractice takes care of my private practice every step of the way.”

— Jamie M. from Los Angeles, CA

SimplePractice Testimonial, Jamie Mok, RD from Los Angeles, CA

Group Practice

“If you are thinking about a group practice, I would say get your electronic records system in place and comfortable with it. SimplePractice has been great for operating our practice.”

— Dr. Lisa H. from Tacoma, WA

Lisa Hardebeck, SimplePractice Story from Tacoma, WA

Online Appointment Requests

“If people can't book you without talking to you, you're not open for business. And SimplePractice helps with that. You can make an appointment and never have left your couch.”

— Donna O. from Washington D.C.

Donna Oriowo, SimplePractice Story from Washington D.C.



Frequently asked questions

Here are some commonly asked questions, or read all FAQs.

Is SimplePractice HIPAA-compliant?

SimplePractice is HIPAA compliant and HITRUST certified. The HITRUST framework is the gold standard of security certifications in the healthcare industry. You can learn more about all the ways we keep customer and client data safe.

Do you have a Business Associate Agreement?

Yes. By signing up for a free, 30-day trial, you agree to our Business Associate Agreement.

Is SimplePractice compliant with HIPAA’s security and privacy policies?

Yes, we take your data security seriously. Our security page contains everything about what we do to ensure the safety and integrity of your data.

Read all FAQs

Be the best version of your (business) self

Be the best version of your (business) self

Explore our other features

Manage and grow your private practice, all in one place.

Free 30-day trial. No contracts. Change anytime. Tax deductible.

Start My Free Trial
List Checkmark No credit card needed
List Checkmark Access all features
List Checkmark HIPAA-compliant