Is Brightwheel HIPAA Compliant?

Brightwheel says it themselves: they do not certify HIPAA compliance. If your ABA practice uses Brightwheel for parent communication, you have a problem.

Get started for freeSchedule a demo →
No

No. Brightwheel explicitly states that it "does not certify HIPAA compliance for its platform." Brightwheel is designed for childcare centers and preschools, with compliance focused on FERPA and state licensing requirements. It does not offer a BAA. ABA therapy practices that use Brightwheel for parent communication about treatment are operating outside HIPAA.

Why?

Brightwheel explicitly disclaims HIPAA compliance

Brightwheel's own security FAQ states: "Although brightwheel meets many of the requirements of HIPAA, brightwheel does not certify HIPAA compliance for its platform." This is an explicit acknowledgment that the platform should not be used for HIPAA-regulated communication.

Source: Brightwheel Security FAQ

Brightwheel does not offer a BAA

Brightwheel's security documentation does not mention Business Associate Agreements. Without a BAA, Brightwheel cannot legally act as a business associate for healthcare providers, and any PHI transmitted through the platform is unprotected under HIPAA.

Source: Brightwheel Security FAQ

Brightwheel claims HIPAA does not apply to its data

Brightwheel states that "the U.S. Department of Health & Human Services (HHS) has stated that HIPAA regulations do not apply to the type of information stored and collected in brightwheel." This is true for daycare enrollment forms and attendance records. It is not true for ABA therapy communication about diagnoses, treatment plans, behavior data, and clinical observations, which are protected health information.

Source: Brightwheel Security FAQ

Built for childcare, not for healthcare

Brightwheel is a childcare management platform for preschools and daycares with features like attendance tracking, daily reports, billing, and parent check-in. It complies with FERPA and state childcare licensing requirements. ABA therapy is not childcare. It is a prescribed medical treatment, and the communication standards are fundamentally different.

Source: Brightwheel Security

What Brightwheel says

Brightwheel's security FAQ states: "Although brightwheel meets many of the requirements of HIPAA, brightwheel does not certify HIPAA compliance for its platform. The U.S. Department of Health & Human Services (HHS) has stated that HIPAA regulations do not apply to the type of information stored and collected in brightwheel or similar software."
Source: Brightwheel Security FAQ

HIPAA-compliant alternatives

BloomText

Purpose-built HIPAA messaging for healthcare practices including ABA. Signed BAA on every plan, read receipts that document parent notifications, and cross-organization messaging at no extra cost.

Spruce Health

HIPAA-compliant communication platform for medical practices with secure messaging, phone, fax, and telehealth.

TigerConnect

Enterprise clinical communication platform for hospitals and health systems with role-based messaging and EHR integrations.

Frequently Asked Questions

Is Brightwheel HIPAA compliant?

No. Brightwheel explicitly states that it does not certify HIPAA compliance. It is designed for childcare centers and preschools, not healthcare providers. Using Brightwheel for communication about ABA therapy, diagnoses, or treatment plans violates HIPAA.

Why does Brightwheel say HIPAA doesn't apply?

Brightwheel cites HHS guidance that HIPAA does not apply to the type of information childcare centers typically store, such as enrollment forms and attendance. This is correct for daycares. But ABA therapy is healthcare, and communication about treatment, behavior data, and clinical observations is protected health information that HIPAA does cover.

Our ABA clinic looks like a daycare. Does HIPAA still apply?

Yes. The physical setting does not determine which regulations apply. ABA therapy is a medical treatment prescribed by physicians and covered by health insurance. Regardless of whether your clinic looks like a school or daycare, communication about treatment is governed by HIPAA, not FERPA or state childcare regulations.

What should ABA practices use instead of Brightwheel?

ABA practices need HIPAA-compliant messaging with a signed BAA, audit trails for documenting parent notifications, and admin controls for managing staff access. BloomText provides all of these on every plan including the free plan. Parents reply via SMS with no app required.

Sources

Last verified June 25, 2026.

  1. BloomText pricing
  2. Brightwheel Security FAQ
  3. Brightwheel Security
  4. HHS HIPAA Security Rule

Need HIPAA-compliant messaging?

Get started for freeSchedule a demo →

Trusted by today's leading healthcare professionals

Streamlined appointment schedulingWith BloomText Broadcast SMS Messaging, I literally took the job of 20 employees and I can do it by myself in three and a half hours.Chief Administrative Officer, Radiology
Best HIPAA app on the marketBloomText has brought our clinic into the modern age, and our patients love being able to communicate with us via text or through our website.Office Administrator, Family Medicine
Excellent for acute careBloomText is the nervous system for my business. It helps us differentiate ourselves in terms of our communication and our quality of care.Clinical Director, Acute Care