HIPAA obligations for doulas are not automatic — they depend on your organization, services, and relationships. Here is what to consider and when secure communication matters.
Get started for freeSchedule a demo →Not every doula has the same HIPAA obligations. HIPAA applies to covered entities and their business associates. Whether a doula qualifies depends on the organization, services provided, insurance relationships, contracts with covered entities, and the type of information handled. Regardless of formal HIPAA status, doulas handle sensitive client information — due dates, medical history, birth preferences, photos — and secure communication can be valuable for client trust, professional practice, and reducing personal-phone risk. This is not legal advice. Consult a compliance advisor for your specific situation.
HIPAA applies to covered entities — healthcare providers who transmit health information electronically for certain transactions, health plans, and healthcare clearinghouses — and to their business associates. Whether a doula practice falls into either category depends on the specifics.
A doula who works independently, does not bill insurance, and does not contract with a covered entity may not have formal HIPAA obligations. A doula practice that accepts insurance, subcontracts with a hospital or midwifery practice, or handles information on behalf of a covered entity may qualify as a business associate. The distinction matters because it determines your legal obligations, not just your preferences.
More doulas are accepting insurance than in previous years. As insurance relationships increase, so does the likelihood that HIPAA applies. This is not a hypothetical — it is a real and growing consideration for doula practices.
Consider these questions: Does your practice bill insurance directly? Do you contract with hospitals, birth centers, midwifery practices, or other covered entities? Do those contracts include business associate agreement requirements? Does your practice transmit health information electronically for standard transactions?
If the answer to any of these is yes, your practice may have HIPAA obligations that apply to client communication. A compliance advisor can evaluate your specific situation. For background on what a BAA is and why it matters, see what is a BAA?
Even when formal HIPAA obligations do not apply, doulas handle information clients consider deeply private: due dates, medical history, birth preferences, family planning details, photos, and insurance information. Communicating this over personal text messages, WhatsApp, and email creates risks that have nothing to do with regulatory compliance.
Personal-phone communication means messages leave when staff leave. There is no audit trail if a dispute arises. Backup doulas have no context for coverage. And clients increasingly expect their providers to handle sensitive information carefully, whether or not the law requires it.
A dedicated practice number, organization-owned conversations, shared visibility for backup doulas and practice owners, and a platform that signs a Business Associate Agreement. That combination gives doula practices a communication setup that works whether HIPAA applies or not — and meets the standard if it does.
Clients and partners should be able to participate without downloading an app. Sensitive information should travel through a secure channel, not regular SMS or email. And the conversation history should stay with the practice, not on one doula's personal phone.
BloomText gives doula practices a dedicated number for client communication. Clients reply over SMS — no app required. Group conversations include the client, partner, primary doula, and backup doula. Every message stays on the practice account. Sensitive conversations travel through Secure Chat, and a signed BAA is included on every plan. See HIPAA texting for doulas for the full workflow.
See pricing for current plans.