Is AI Note-Taking HIPAA / GDPR / DPDP Compliant for Therapists? (2026)
Written by Kshitij Domadia, Founder, MyKaya
Published July 23, 2026
"Is this tool HIPAA compliant?" is the first question most therapists ask before adopting an AI documentation tool. It is the right question. But it often stops there — and "yes we're HIPAA compliant" from a vendor tells you less than you might think.
This guide explains what HIPAA, GDPR, and India's DPDP Act each actually require for AI-assisted therapy documentation, what questions to ask vendors, and what you are responsible for regardless of what the tool claims.
This is an educational overview, not legal or compliance advice. Requirements vary by setting, jurisdiction, and practice structure. Consult your licensing board, malpractice carrier, or a healthcare compliance professional for your specific situation.
HIPAA (United States)
HIPAA applies to any US-based healthcare provider that transmits or processes Protected Health Information (PHI). If your therapy sessions produce clinical notes — and they do — HIPAA applies to how you use AI tools to generate or store them.
What HIPAA requires for AI documentation tools
1. A signed Business Associate Agreement (BAA)
If an AI tool processes session audio or generates clinical notes, it is a "Business Associate" under HIPAA. Before using the tool, you must have a signed BAA in place. This is not optional. Using an AI scribe without a BAA is a HIPAA violation regardless of how the vendor markets itself.
The BAA means the vendor is legally committing to: protecting PHI, reporting breaches, and deleting data when the relationship ends.
2. Encryption in transit and at rest
Session audio and generated notes must be encrypted when transmitted over a network (TLS 1.3 is the current standard) and when stored (AES-256 is typical). Ask the vendor for their encryption standards explicitly.
3. Zero data retention / no training on your data
One of the most important questions to ask: does the vendor use your client session audio or transcripts to train their AI models? This is a separate issue from storage. Data that is encrypted and stored can still be fed into model training pipelines. The vendor's privacy policy and data processing terms — not just their marketing — will tell you this.
4. Audit trails
HIPAA requires the ability to track who accessed PHI and when. The tool should provide access logs.
5. Access controls
Multi-factor authentication, role-based access (for clinic settings), and the ability to revoke access if a device is compromised or a staff member leaves.
GDPR (United Kingdom and European Union)
Under GDPR, mental health session data is "Special Category" data under Article 9 — the highest tier of protection. The rules are stricter than for ordinary personal data.
Key requirements for AI therapy tools under GDPR:
- Lawful basis for processing: Special Category data requires either explicit consent from the client or another specific lawful basis (such as health treatment purposes). Consent must be freely given, specific, informed, and unambiguous.
- Data Processing Agreement: The AI vendor acts as a data processor. You must have a Data Processing Agreement (DPA) in place — the GDPR equivalent of a BAA.
- Data residency: Data transfers outside the EEA (European Economic Area) are restricted. If the vendor's servers are in the US, they must ensure adequate protection through mechanisms like Standard Contractual Clauses (SCCs).
- Data Protection Impact Assessment (DPIA): Processing Special Category data with AI at scale typically requires a DPIA. This is a formal assessment of the privacy risks and how they are mitigated.
- Right to erasure: Clients can request their data be deleted. The vendor must be able to comply.
DPDP Act (India)
India's Digital Personal Data Protection Act 2023, with rules notified in November 2025, establishes a comprehensive framework that directly applies to mental health practice.
Key requirements:
- Health data is sensitive. Mental health session data requires explicit, informed consent before collection and processing.
- Data minimization. Collect only what is strictly necessary for the purpose (note generation).
- Breach notification. Providers must notify the Data Protection Board and affected individuals promptly in the event of a breach.
- Withdrawal of consent. Clients must be able to withdraw consent easily, and their data must be deleted upon withdrawal.
- Data Fiduciary obligations. If your practice qualifies as a Significant Data Fiduciary (typically larger organizations), you must appoint a Data Protection Officer (DPO).
The compliance checklist
Before using any AI documentation tool, verify:
| Check | What to confirm |
|---|---|
| BAA / DPA in place | Do not use the tool without a signed agreement |
| Encryption standards | TLS in transit, AES-256 at rest — confirm in writing |
| No training on your data | Check the privacy policy, not just the marketing |
| Data residency | Where are servers located? Does this comply with your jurisdiction? |
| Audit logs | Can you access records of who viewed PHI? |
| Client consent process | Have you updated your informed consent forms? |
| Breach notification | What is the vendor's timeline and process? |
What compliance means in practice
A vendor saying "we are HIPAA compliant" means they have taken steps to meet HIPAA requirements. It does not automatically make your practice compliant. You remain the covered entity — responsible for consent, data handling, staff training, and your own documentation practices.
The practical sequence:
- Verify the vendor has certifications relevant to your jurisdiction (SOC 2 Type II is the standard third-party audit)
- Sign the BAA or DPA before using the tool
- Update your client informed consent forms to disclose AI tool use
- Establish a review workflow so you read every AI-generated note before signing
- Confirm with your malpractice carrier that AI documentation tool use is covered
MyKaya is built on healthcare-grade infrastructure — encrypted with per-practice data isolation. See our security documentation or start a free trial.
