Most coaches first meet HIPAA the uncomfortable way: a client asks “is this secure?”, a partner clinic requests proof of compliance, or a corporate contract lands with a data-protection clause. This guide covers what HIPAA actually requires of a coaching practice, when it applies to you, and how to audit every tool you use, in plain language.
This guide is educational and is not legal advice. HIPAA applicability depends on your specific situation; consult a qualified professional for your practice.
Does HIPAA Apply to Coaches?
It depends on what you handle, not what your title is. HIPAA (the Health Insurance Portability and Accountability Act) governs protected health information, or PHI: information about a person’s health, care, or payment for care that is tied to their identity.
You work with covered entities. If you take referrals from clinics, partner with healthcare providers, or deliver coaching inside a medical or insurance context, you are likely a “business associate” and must sign Business Associate Agreements (BAAs) and protect PHI accordingly.
You handle health information at scale. Health and wellness coaches collect intake forms about medications, conditions, sleep, and mental health. Depending on how your services are structured and billed, this can create HIPAA obligations directly.
Your clients and partners expect it. Even where HIPAA does not legally bind an independent coach, enterprise buyers, wellness programs, and increasingly individual clients treat compliance as table stakes. Meeting the standard is a business advantage regardless of legal necessity.
If health information enters your practice, build to the HIPAA standard. It is cheaper than retrofitting and it wins trust.
What Counts as PHI in a Coaching Practice
PHI is broader than medical records. In a typical coaching business it shows up as:
- Intake form answers about conditions, medications, sleep, stress, or goals like “manage my diabetes”
- Booking notes (“post-surgery recovery support”, “struggling with stress eating”)
- Session notes you keep about a client’s health journey
- Messages and emails where clients mention symptoms or treatment
- Video sessions where health is discussed
- Payment records tied to health services
A name on a calendar is not PHI. A name plus a reason for the visit usually is. That is why the audit below covers every tool where client information flows, not just your notes app.
The Four Requirements Every Tool Must Meet
HIPAA does not certify software. It sets requirements that any tool touching PHI must meet:
- A signed BAA. The vendor must sign a Business Associate Agreement accepting legal responsibility for protecting PHI. A secure tool without a BAA still fails. This is the single fastest check you can run on any product.
- Encryption. Client data must be encrypted in transit and at rest.
- Access controls. The tool must limit who can see client information, with authentication and role-based access.
- Breach support. The vendor must be able to support breach notification obligations if something goes wrong.
Audit Your Stack: Tool by Tool
Walk through every place client information lives. For each tool, ask one question first: will the vendor sign a BAA on my plan?
Scheduling. Booking forms collect names plus reasons for visits. Calendly does not offer a BAA on standard plans (our full breakdown). Acuity offers one only on higher-tier plans with a separate enablement process (details).
Video. Live sessions transmit PHI even when nothing is recorded. Zoom signs BAAs only on eligible paid plans, on request, with feature restrictions (our full breakdown).
Forms and intake. This is often the highest-risk tool in a coaching stack because intake forms ask health questions directly. Free consumer form tools generally offer no BAA (is Google Forms compliant?).
Email and messaging. Client emails about health are PHI. Standard consumer email offers no BAA. Either use a compliant email service or, better, move client communication into a platform with encrypted, compliant messaging built in.
CRM and notes. Wherever you store client records and session notes needs the same four requirements as everything else.
Payments. Payment processors handling health-service transactions should be part of your audit too.
If that list looks like five separate vendor negotiations, that is exactly why all-in-one platforms exist for this niche. Vibly covers scheduling, video sessions, secure messaging, intake forms, payments, and client records with HIPAA compliance and a BAA for every client on every plan, from $20/month (see plans). Security documentation lives in the Vibly Trust Center.
Common Myths
“HIPAA doesn’t apply to coaches, only doctors.” HIPAA applies based on data and relationships, not job titles. Coaches working with covered entities or handling PHI can absolutely have obligations, and market expectations apply to everyone.
“My tools are secure, so I’m compliant.” Security is one of four requirements. Without a signed BAA, a secure tool still leaves you exposed.
“I don’t record sessions, so video doesn’t count.” Live transmission of PHI is still covered. The session itself needs a compliant tool, recorded or not.
“A HIPAA-compliant tool makes me compliant.” Tools are necessary but not sufficient. Your own practices matter: what you put in notification emails, who can access your accounts, how you handle client data day to day.
Download Your Free HIPAA Compliance Checklist
Want to audit your practice in minutes? Download our free HIPAA Compliance Checklist for Coaches. It walks through every tool category above with the exact questions to ask each vendor.
Frequently Asked Questions
Do health coaches need to be HIPAA compliant?
It depends on their situation. Coaches who work with healthcare providers, insurers, or employers as business associates generally do. Independent coaches may not be legally bound, but handling health information to the HIPAA standard is best practice and increasingly expected by clients and partners.
What is a BAA and why does it matter?
A Business Associate Agreement is a contract in which a vendor accepts legal responsibility for protecting the health information you store in their product. It is the fastest way to test whether a tool can be used compliantly: no BAA, no PHI.
What tools in a coaching business need to be HIPAA compliant?
Any tool that touches client health information: scheduling, video sessions, intake forms, email and messaging, session notes, CRM, and payment processing for health services.
Is client information in a coaching practice really PHI?
Often, yes. Intake answers about conditions and medications, booking notes that mention health reasons, and session discussions about physical or mental health are all health information tied to an identity.
What happens if a coach ignores HIPAA?
For coaches with legal obligations, violations carry financial penalties and mandatory breach notifications. For everyone, a data incident involving client health information is a serious trust and reputation problem, and losing enterprise or clinical partnerships over compliance gaps is common.
