BAAs, Notes, and Client Data: An AI Compliance Checklist for California Therapists
Aug 24, 2026You are setting up a new documentation tool. The onboarding screen mentions HIPAA, there's a checkbox about a business associate agreement, and a handful of account settings you've never seen before. Signing feels like the responsible move, but a question lingers. Does checking that box actually mean client information is protected, or does it just mean you agreed to something you haven't fully read? For any BAA therapist researching this, the honest answer is that a signed agreement is only the first step, not the whole picture.
A BAA Is a Starting Point, Not the Whole Checklist
A business associate agreement exists to define what a vendor can and cannot do with protected health information when that vendor is acting as a business associate. It sets expectations around safeguards, breach notification, and what happens to information when the relationship ends. But not every software tool needs one, and not every vendor offering one means your practice is automatically covered. The real first question is whether the vendor is creating, receiving, maintaining, or transmitting client information on your behalf. If the answer is yes, the agreement matters. If the tool never touches identifiable client details, it may not apply the same way.
Before You Sign Anything, Ask These Questions
A little curiosity before signup saves a lot of cleanup later.
- Does the vendor create, receive, or store client information? If so, a BAA likely matters.
- Is the agreement available for the plan you're actually using? Some tiers include it, others don't.
- Can subcontractors access what you submit? Ask directly if it isn't stated.
- What security protects the account itself? Passwords, two factor login, and access controls all count.
- How are breaches or incidents communicated? You want to know, not guess.
- Can you export or delete your information later? This matters more than people expect.
The Agreement Does Not Tell You Everything
Signing an agreement answers a contractual question. It does not decide how much client detail you should actually type into a system, whether an output is accurate, or who on your team can see it. This is where HIPAA AI therapy questions tend to get confusing, because clinicians assume a compliant vendor means every use is automatically safe. It doesn't. The agreement protects the relationship. Your daily habits protect the client.
Follow the Information From Entry to Deletion
It helps to think of client information as something on a journey, not something that simply exists inside software.
- Before it goes in: only include what's actually necessary, and skip identifying details you don't need to enter.
- While it's being processed: know roughly where it's handled and who could access it along the way.
- After the task is done: find out if the system keeps a copy, and for how long.
- If you ever leave the platform: check whether your records export cleanly and what gets deleted for good.
Thinking in stages like this makes an abstract privacy concern feel a lot more manageable.
Progress Notes Need Their Own Rules
A finished note isn't always the only file that matters. If a session was transcribed first, ask where that transcript lives, whether it's stored longer than the note itself, and which version actually becomes your official record. Drafts and source material can quietly stick around in a system long after you've moved on to the next client.
Give Documentation a Clear Start and Finish
A simple routine keeps this from becoming guesswork.
- Before drafting: use only approved tools and decide what details are truly needed.
- During the process: limit account access and avoid unnecessary identifying information.
- Before saving: read the note fully and correct anything that overstates or misses the mark.
- After saving: follow your practice's rule for handling drafts and temporary files.
Who Can Get Into the Account Matters Too
Software settings only go so far. A shared login with an assistant, a former employee's account that was never deactivated, a supervisee using a personal profile instead of an approved one, these everyday habits shape therapist data privacy just as much as any encryption setting does. Protecting client information is part technology and part practice culture.
Put These Decisions Into Writing
A checklist in your head disappears the moment you're busy. Written policy keeps decisions consistent no matter who's covering your caseload that week. A solid policy generally covers approved tools, restricted information, who can create accounts, documentation and draft handling, a vendor review process, and what happens if something goes wrong. Building this from a blank page takes time most practices don't have, which is exactly why having templates to start from is worth considering.
California Compliance Isn't One Single Rulebook
Worth noting clearly: the Board of Behavioral Sciences does not administer HIPAA, so AI compliance California BBS questions usually involve more than one authority at once, including licensing standards, ethics codes, and applicable state and federal privacy law. Treat these as overlapping responsibilities rather than one single checklist to satisfy.
Run This Check Before Adding Any New Tool
New software always looks appealing before you dig into the details, and it's easy to sign up first and ask questions later. A quick run through these steps before you commit keeps that instinct in check.
- Identify what client information the tool will touch.
- Confirm whether a BAA applies.
- Review retention and deletion terms.
- Decide who gets account access.
- Set a documentation rule for drafts and notes.
- Record the decision in your written policy.
Turn the Checklist Into Something You Can Actually Use
A checklist tells you what to look for. A written policy makes sure those answers hold up over time. Rouse Academy's Complete Law and Ethics of AI Policy Pack gives California therapists BBS and CAMFT aligned templates covering BAAs, documentation, and compliance, while the paired 3 CE Law and Ethics course explains the reasoning behind those decisions so the policy actually makes sense in practice, not just on paper.
Find your happy spots through our erotic educational courses
- Learn how mindfulness helps with sexual anxiety
-
Address performance anxiety
-
Communication Techniques for Sexual Needs
-
Sex and Intimacy for Survivors
-
Overview of Sexual Anxiety
Receive our 2-page overview completely changing how you view sex.
Receive updates through our weekly newsletter!
We hate SPAM. We will never sell your information, for any reason.