Do doulas need to be HIPAA compliant?
It is one of the most common questions in doula business groups, and the usual answers are either "yes, obviously" or "no, don't worry about it." Both are wrong often enough to matter.
Most doulas in private practice are not covered by HIPAA. HIPAA follows electronic insurance billing, not the sensitivity of the information you hold. If your clients pay you directly, it very likely does not apply to you. If you bill Medicaid or insurance, it may.
HIPAA follows the billing, not the secret
The common assumption is that HIPAA covers anyone who handles private health information. It doesn't. It covers specific organizations, called covered entities, and there are only three kinds:
- Health plans.
- Health care clearinghouses, which are the companies that reformat billing data between providers and insurers.
- Health care providers who transmit health information electronically in connection with a standard transaction, such as submitting a claim or checking eligibility.
That third one is where doulas either land or don't, and the deciding factor is the billing, not the birth. A doula can know a family's medical history, attend the birth, and keep detailed notes, and still be outside HIPAA entirely, because she never files an electronic claim.
There is a fourth category worth knowing: a business associate is a company that handles protected health information on behalf of a covered entity. That is the category a software vendor falls into, which is why the question of a Business Associate Agreement comes up at all.
Why most doulas are not covered
A doula in private practice, paid directly by the families she supports, is generally not a covered entity. There is no claim, no clearinghouse, and no standard transaction. Holding sensitive information does not by itself put you under HIPAA, however uncomfortable that sounds the first time you hear it.
This is the part most often gotten wrong in both directions. Some doulas assume they are covered and buy compliance they do not need. Others hear "you're not covered" and conclude that nothing applies to them, which is a different mistake, and the more expensive one.
When a doula may be in scope
Three situations change the answer. If any describes your practice, it is worth a conversation with an attorney rather than a business group.
- You bill Medicaid or insurance for your services. A growing number of states now reimburse doula care through Medicaid. If you are enrolled and submitting claims electronically, you may be a covered health care provider.
- You work inside an organization that is covered. If you are employed by or contracted to a hospital, birth center or medical practice and you handle their patients' information, you may be part of their workforce or their business associate.
- You have signed a Business Associate Agreement. If a covered entity has you sign a BAA, you have taken on obligations directly, whatever your practice looks like otherwise.
Not covered by HIPAA does not mean no rules
This is the part that gets skipped, and it is the part that can cost you.
- State law still applies. Many states have their own privacy and medical records statutes, and some are stricter than HIPAA. They do not care whether you file claims.
- Contracts can impose obligations. Hospital privileges, agency agreements and some client contracts carry confidentiality terms of their own.
- Your certifying organization has standards. Confidentiality is part of most doula codes of ethics regardless of what federal law says.
So the honest framing is not "HIPAA or nothing." It is that a private-practice doula is usually governed by state law, her contracts and her ethics, rather than by a federal statute written for insurers.
Where DoulaFlow stands
DoulaFlow is not HIPAA compliant, and we do not offer a Business Associate Agreement.
If you bill Medicaid or insurance for your services, or you handle a covered entity's patient information, DoulaFlow is not the right fit for that work. We would rather tell you that on this page than have you find it out three months in.
For the doulas who are not covered, which is most of them, the question that matters is whether client information is protected properly. Here is what is true today:
- Practice data is encrypted in transit and at rest.
- Each practice's data is isolated from every other practice's, enforced by the database on every request rather than by a filter in the application that someone could forget to apply.
- We do not sell your data or your clients' data, to anyone.
- You can ask for a copy of everything and take it with you, and you can ask us to delete it.
You can read the specifics in the privacy policy, and how the product handles client records in the help pages.
This is not legal advice. We are not lawyers, and whether HIPAA applies to your practice depends on facts we cannot see from here. If you are unsure, and particularly if you bill Medicaid or work inside a hospital, ask an attorney or your certifying organization. It is a short conversation and it settles the question properly.