Skip to content
Blog

Who Owns Your Client Data? What Therapists Should Ask Before Choosing Practice Software

S
Segun O·Jul 22, 2026·9 min read

Who owns the data on the platform where you keep your client's billing history, session frequency, and diagnosis codes?


Therapists in private practice often overlook a key question. They usually assess software based on features, price, and onboarding. Data ownership is hidden in terms of service that few read. For a long time, this seemed acceptable.


It no longer is. The practice management software market has consolidated rapidly over the last several years. Platforms that began as simple tools for solo users have now received major venture capital funding. They’ve been acquired and, in some cases, have changed their business models. These shifts can have real effects on the data stored on their servers. Data that includes your clients' names, contact information, diagnosis codes, session frequency, billing history, and payment records.


This guide answers key questions every therapist should ask before picking a practice management platform. It also covers the standards that keep you and your clients safe.

Why This Matters More Than It Used To

When a software company takes on venture capital funding, it accepts an obligation to generate returns for its investors. That pressure shapes product decisions in ways that are not always visible to the end user. Features get added to attract enterprise clients. Pricing tiers shift. Platforms get acquired and merged into larger health data ecosystems.


None of this is necessarily sinister. It creates a misalignment. What benefits the platform's investors often clashes with what’s best for the solo therapist. The therapist’s client data is on that platform.


The main concern is this: aggregated, de-identified health data (like session frequency, diagnosis patterns, treatment duration, and billing amounts for many clients) is very valuable commercially. It is used in insurance risk modeling, healthcare research, pharmaceutical targeting, and population health products. A platform with hundreds of thousands of clients across many practices has a huge data asset. This is true even if no single record can be identified.


HIPAA protects identifiable protected health information (PHI). It does not regulate de-identified data. After removing direct identifiers to meet HIPAA's de-identification standard, a platform's terms of service, not federal law, control how they can use the data.

That is the gap worth understanding.

What to Read in a Platform's Privacy Policy

Most therapists skip this step. The terms of service are long and dense. The onboarding makes signing feel like just a formality. But a few specific clauses tell you almost everything you need to know.

Data use beyond service delivery

Look for language describing how the platform uses your data and your clients' data. Acceptable language limits use to deliver the service you paid for. Concerning language includes phrases like "improve our products," "conduct research," and "share with trusted partners." It also mentions "aggregate and analyze usage patterns" without clear limits on commercial use.

De-identified data rights

Look for clauses describing what the platform can do with de-identified data. Some platforms can gather and sell de-identified data as a separate product. Others prohibit this entirely. The difference is in the text.

Data portability and deletion

If you leave the platform, can you export your clients' records completely? How long does the platform retain data after account closure? What is the process for requesting deletion? Platforms that make exit difficult or retain data indefinitely warrant additional scrutiny.

Third-party sharing

Look for a list of categories of third parties the platform shares data with. "Service providers" and "subprocessors" are standard and expected. "Business partners," "affiliated companies," and "analytics providers" deserve closer attention.

The BAA Is Necessary But Not Sufficient

Every therapy practice covered by HIPAA needs a signed Business Associate Agreement with any vendor that manages PHI for them. This is non-negotiable and legally required before PHI enters the platform.

The BAA matters. It shows that your vendor knows they are a business associate. They agree to handle PHI carefully, follow breach notification timelines, and explain what happens to PHI if the relationship ends.


But the BAA does not govern de-identified data. It does not restrict what a platform does with aggregated usage patterns. It does not prevent data from being used in ways that were not possible when the agreement was signed. The BAA is a required minimum, but it doesn’t limit what a platform can do with data.


When evaluating any practice management platform, a signed BAA is the starting point, not the ending point.

The Questions to Ask Any Practice Software Vendor

Before you choose a platform, ask these questions to their sales or support team. Be sure to read their answers closely.

Does your company have any revenue streams that involve client or practice data beyond the subscription fee?

This includes:

  • Research partnerships

  • Data licensing

  • Analytics products sold to third parties

  • Aggregated data sold to insurance or pharmaceutical companies

What does your privacy policy permit you to do with de-identified data?

Ask them to point you to the specific clause. If they cannot answer this clearly, that is informative.

Who has acquired your company, or who are your major investors?

VC-backed platforms bought by health insurance companies, pharmacy benefit managers, or health data aggregators pose a unique risk. It’s important to understand this risk before your client data goes into their system.

What happens to my data if you are acquired?

Acquisitions transfer data assets. If a platform gets bought after your clients' data is in it, the new owner takes that data. The original privacy policy might not carry over.

Can I export all of my data and my clients' data completely if I leave?

And what is your data retention policy after I close my account?

What Good Data Handling Looks Like

The contrast is worth describing. A privacy-first platform follows a simple rule: it only uses data collected to provide the service. It is not a secondary revenue stream. It is not an asset to be packaged and sold.

In practical terms, that looks like:

Role-Based Access Control

Data access is restricted by role so that only the people who need to see specific information can access it. An administrative user does not need to see clinical notes. A billing user does not need access to intake documents. Permissions match responsibilities.

MFA-Supported Authentication

Sign-in uses multi-factor authentication. This helps lower the risk of account takeovers, a major cause of healthcare data breaches.

Encrypted Transport and Storage

Sensitive data is encrypted in transit and at rest. Attachments and documents remain in a secure portal instead of being sent through unprotected email.

A BAA that is available before you sign up

Not something that appears after a sales call, not locked behind a legal review process. A platform that publishes its BAA template openly, before procurement, is signaling that it has nothing to hide in the agreement.

Privacy-first data handling as a stated principle.

The platform's data use is limited to what is necessary to deliver the service. That principle is stated explicitly.

Where Cohessra Stands

Cohessra is practice management software built specifically for cash-pay private practices. The business model is the subscription fee. There is no extra revenue from client data. There are no research partnerships and no analytics products based on practitioner or client records.


The security architecture is built around the principles above. Access is structured by role so sensitive workflows stay controlled. Sign-in is MFA-supported. Data handling is designed to be purposeful and limited to what is needed to deliver the service. You can review the Business Associate Agreement before purchasing. The template is available at cohessra.com/legal/baa. You can request the executed agreement before any PHI enters the platform.


Cohessra's security approach includes the following:

  • Role-based access control

  • Encrypted transport and storage

  • Controls for HIPAA readiness

  • GDPR-aligned privacy practices

  • SOC 2-oriented reviews when needed

This ensures strong data protection for our customers. Full details are at cohessra.com/security.

In a Nutshell

Your clients trust you with some of the most sensitive information they will share with anyone. The platform that stores that information should be chosen with the same care you apply to every other clinical decision.


Read the privacy policy. Ask about de-identified data rights. Understand the BAA before you sign. Know who owns your platform and what incentives they are operating under.


The subscription fee should be the business model. If not, and if the platform's investors seek a return that subscriptions can't provide, we should ask where that return is coming from.

Frequently Asked Questions

1. Does my practice management software own my client data?

It depends on the platform's terms of service. Most platforms don't claim ownership of your client's identifiable records. However, many can aggregate, de-identify, and use that data commercially without your consent. Pay close attention to the data use clause. This section explains what the platform can do with de-identified data once it’s stripped of direct identifiers. HIPAA does not cover de-identified data, so federal law does not address this issue. Instead, check the platform's privacy policy.

2. Is a Business Associate Agreement enough to protect my clients' data?

A BAA is a legal must and a good starting point. However, it only covers identifiable protected health information (PHI) as defined by HIPAA. It doesn’t limit what a platform can do with de-identified or aggregated data. This type of data is valuable and not included in the agreement. A BAA shows that the platform knows its compliance duties. It doesn’t reveal the platform's business model or whether client data fuels additional revenue beyond your subscription fee.

3. What should I do if my practice management software gets acquired?

Acquisitions pass data assets to the new owner. If your platform gets acquired, the new owner takes over the data. Depending on the acquisition terms, the original privacy policy may not stay the same. Before you choose a platform, ask, what happens to client and practice data if there’s an acquisition? The answer, or lack of one, reveals how the company views data stewardship.

4. Can I move my client data if I switch platforms?

You should be able to export your data, but not all platforms make it easy. Before you sign up for any practice management software, check if you can get a full record of all client data, billing history, and documents whenever you need. Also, look into the platform's data retention policy after you close your account. How long do they keep your data? What’s the process for requesting complete deletion? Be careful with platforms that have long retention periods or make exporting difficult.

5. How do I know if my billing software is actually HIPAA-compliant?

HIPAA compliance is about maintaining safeguards. You can check if a vendor will sign a Business Associate Agreement, use role-based access control, and encrypt data. A HIPAA-ready platform makes this information easy to find.


Cohessra

See it in action

Cohessra helps practices manage billing, client communication, and records in one place. Book a demo and we'll walk you through it.