Do Doulas Need to Be HIPAA Compliant? | DoulaFlow
For doulas

Do doulas need to be HIPAA compliant?

It is one of the most common questions in doula business groups, and the usual answers are either "yes, obviously" or "no, don't worry about it." Both are wrong often enough to matter.

Short answer

Most doulas in private practice are not covered by HIPAA. HIPAA follows electronic insurance billing, not the sensitivity of the information you hold. If your clients pay you directly, it very likely does not apply to you. If you bill Medicaid or insurance, it may.

HIPAA follows the billing, not the secret

The common assumption is that HIPAA covers anyone who handles private health information. It doesn't. It covers specific organizations, called covered entities, and there are only three kinds:

That third one is where doulas either land or don't, and the deciding factor is the billing, not the birth. A doula can know a family's medical history, attend the birth, and keep detailed notes, and still be outside HIPAA entirely, because she never files an electronic claim.

There is a fourth category worth knowing: a business associate is a company that handles protected health information on behalf of a covered entity. That is the category a software vendor falls into, which is why the question of a Business Associate Agreement comes up at all.

Why most doulas are not covered

A doula in private practice, paid directly by the families she supports, is generally not a covered entity. There is no claim, no clearinghouse, and no standard transaction. Holding sensitive information does not by itself put you under HIPAA, however uncomfortable that sounds the first time you hear it.

This is the part most often gotten wrong in both directions. Some doulas assume they are covered and buy compliance they do not need. Others hear "you're not covered" and conclude that nothing applies to them, which is a different mistake, and the more expensive one.

When a doula may be in scope

Three situations change the answer. If any describes your practice, it is worth a conversation with an attorney rather than a business group.

Not covered by HIPAA does not mean no rules

This is the part that gets skipped, and it is the part that can cost you.

So the honest framing is not "HIPAA or nothing." It is that a private-practice doula is usually governed by state law, her contracts and her ethics, rather than by a federal statute written for insurers.

Where DoulaFlow stands

DoulaFlow is not HIPAA compliant, and we do not offer a Business Associate Agreement.

If you bill Medicaid or insurance for your services, or you handle a covered entity's patient information, DoulaFlow is not the right fit for that work. We would rather tell you that on this page than have you find it out three months in.

For the doulas who are not covered, which is most of them, the question that matters is whether client information is protected properly. Here is what is true today:

You can read the specifics in the privacy policy, and how the product handles client records in the help pages.

Common questions

Do doulas need to be HIPAA compliant?

Most doulas in private practice do not, because HIPAA applies to covered entities, and a doula paid directly by her clients is generally not one. HIPAA follows electronic billing for standard insurance transactions rather than the sensitivity of the information. A doula who bills Medicaid or insurance electronically, or who works inside a hospital or practice that is itself covered, may be in scope and should take advice.

What is a covered entity?

Under HIPAA a covered entity is a health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with a transaction for which the federal government has adopted a standard, such as a claim or an eligibility check.

Is DoulaFlow HIPAA compliant?

No. DoulaFlow is not HIPAA compliant and does not offer a Business Associate Agreement. If you bill Medicaid or insurance for your services, or you handle a covered entity's patient information, DoulaFlow is not the right fit for that work.

If HIPAA does not apply to me, are there no rules about client privacy?

No. State privacy and records laws still apply and some are stricter than HIPAA. Contracts with a hospital or agency can impose their own obligations, and certifying organizations set confidentiality standards of their own. Being outside HIPAA means different rules, not no rules.

Know what your practice is made of.

Practice software for doulas who intend to do this for a long time. Fourteen days free, no card.

Start free trial