TRUST CENTER
Security at SimplPractice
Last updated 16 August 2026
Current data boundary
SimplPractice's initial release is a business-configuration platform. Patient, clinical, insurance, payment-card, credential and other protected healthcare data are prohibited.
Platform controls
- Unique authenticated users and role-based authorization.
- Tenant-scoped database rows protected by row-level security.
- Atomic client provisioning from approved templates.
- Append-only operational audit records with safe metadata.
- Secrets stored only in provider environment settings.
HIPAA status
SimplPractice does not claim HIPAA compliance. That status requires eligible infrastructure, signed business associate agreements, designated environments, implemented policies and verified operating controls before protected health information is introduced.
Reporting
Security contacts and incident-response procedures will be published before external customer access.