How to Keep Client Data Safe as a Therapist in India
A practical guide to protecting client data in a therapy practice - the real risks, encryption, access control, secure storage, and what DPDP compliance requires day to day.

The everyday habits that expose client records, and the specific steps that keep a therapy practice secure.
Summary
Keeping client data safe as a therapist in India means closing four specific gaps: unencrypted storage, uncontrolled access, scattered tools, and unclear compliance with the Digital Personal Data Protection Act. Most exposure does not come from a sophisticated attack. It comes from session notes in a personal Google Drive, client details backed up through WhatsApp, or a shared laptop with no access controls. This article covers the real risks therapists in India face, what encryption and access control actually require, where records should be stored, and what DPDP compliance looks like day to day. It closes with a practical checklist a solo practitioner or small clinic can act on this week. The guidance is written for therapists, counsellors, psychologists, and psychiatrists managing client records without a dedicated IT or compliance team.
Table of Contents
- How to Keep Client Data Safe as a Therapist in India
- The Real Risks to Client Data in a Therapy Practice
- Encryption: At Rest and In Transit
- Access Control: Limiting Who Can See What
- Secure Storage and Data Residency
- Compliance Basics: What DPDP Requires Day to Day
- A Practical Checklist for Keeping Client Data Safe
Client data stays safe when it is encrypted, stored on servers under Indian jurisdiction, accessible only to the people who need it, and handled in a way that meets the Digital Personal Data Protection Act. Most therapists in India are not exposed because of a targeted attack. They are exposed because session notes live in a personal Google Drive, intake forms sit in an email inbox, or a laptop holding years of client history has no protection beyond a fingerprint lock.
The stakes are higher than they look. IBM’s 2025 Cost of a Data Breach Report puts the average healthcare data breach at $7.42 million globally, the costliest of any industry for the fourteenth year running. In India, IBM’s own research found the average cost of a data breach reached an all-time high of ₹19.5 crore in 2024, up 39 percent since 2020. Healthcare was hit hardest of any sector, accounting for nearly 22 percent of all attacks that year. None of that requires a large clinic. A solo practitioner’s laptop or a shared clinic drive is exposure enough.
This post covers what actually puts client data at risk, what encryption and access control require in practice, where records should be stored, and what compliance with India’s DPDP Act looks like day to day. It ends with a checklist you can act on this week, without a dedicated IT team.
How to Keep Client Data Safe as a Therapist in India
Keeping client data safe is not one action. It is four practices working together, each covering a different type of exposure.
- Encryption makes data unreadable to anyone without the right key, whether it is sitting on a server or moving between devices.
- Access control limits who inside a practice can open a given client’s records, down to the individual level.
- Secure storage means records live on infrastructure built for sensitive data, under a known legal jurisdiction, not scattered across personal apps and devices.
- Compliance with the DPDP Act means consent, breach response, and data-handling processes match what Indian law now requires of every practitioner who holds client information.
Missing any one of these leaves a gap. A password-protected folder without encryption is still readable if the device is lost. Encrypted storage without access control still lets anyone with a login open every record in the practice. The sections below cover each one, and what it looks like specifically for a therapy practice in India.
The Real Risks to Client Data in a Therapy Practice
Most client data exposure in a therapy practice traces back to a small set of recurring habits. Sophisticated cybercrime is rarely the cause.
Session notes and intake forms end up in a personal Google Drive or Google Docs account. These tools were not built for clinical records, and without a signed enterprise data agreement, storing therapy documentation there creates a compliance gap along with a security one.
Client details get backed up through WhatsApp. WhatsApp’s own documentation confirms that chat backups stored in Google Drive or iCloud do not carry the same end-to-end encryption as the live conversation. A backup containing a client’s name, contact details, or session context sits in plain, readable form on a third-party server.
Phishing remains one of the most exploited entry points into healthcare data. Healthcare is more vulnerable to it than any other major industry: one 2024 industry analysis put the sector’s phishing susceptibility at 41.9 percent and found that 88 percent of healthcare employees opened a phishing email that year. A single compromised inbox can expose every attachment and message tied to a practice.
Devices go unmanaged. A laptop or phone holding years of session notes, with no encryption and no separation between personal and clinical use, is a single point of failure. If it is lost, stolen, or shared with a family member, every record on it is exposed.
Insider access goes untracked. A separate breach analysis found unauthorised access to healthcare records has risen 162 percent over three years, and that 61 percent of healthcare data breaches trace back to negligent employees rather than external attackers. A front-desk assistant with full access to clinical notes, or a departing staff member whose login was never revoked, is a risk most practices never check for.
Encryption: At Rest and In Transit
Encryption converts client data into a form that is unreadable without the correct key. It has to apply in two states for it to actually protect anything.
Encryption at rest protects data while it is stored, in a database, on a device, or inside a backup. The recognised standard is AES-256, the same level of encryption used to protect financial and government systems. If a laptop is stolen or a server is compromised, the data on it stays unreadable without the encryption keys.
Encryption in transit protects data as it moves between a client’s device, a practitioner’s device, and a server. This is what secures a telehealth session or a message sent through a booking system, and the standard here is TLS 1.2 or higher.
A tool or habit that covers only one of these leaves client data exposed. A password on a laptop does nothing if the files themselves are not encrypted. A secure video call does nothing to protect the session notes typed up afterward and saved to an unencrypted drive. For a fuller breakdown of what encryption and the rest of the security standard require, see our guide on what makes mental health software secure.
Access Control: Limiting Who Can See What
Encryption protects data from outsiders. Access control protects it from the wrong insiders, and this is the layer most solo practitioners and small clinics skip entirely.
In a solo practice, access control still applies to anyone besides the practitioner: a virtual assistant, a billing contractor, or an intern reviewing intake forms. In a clinic with multiple practitioners, it becomes essential. Role-based access control means each person can see only the records their role requires. A scheduling coordinator does not need to read session notes. A therapist should have full access to their own caseload and no visibility into another practitioner’s clients, unless a referral or transfer makes it appropriate.
Two things make access control work. Permissions have to be assignable at the level of the individual client record, not just at the level of the whole account. And every access has to be logged, so if a record is opened by someone who should not have seen it, there is a trail showing when and by whom.
The habit to break is the shared login. A single password shared across a front desk, a billing assistant, and a therapist means there is no way to know who actually opened a given file, and no way to revoke one person’s access without changing it for everyone.
Secure Storage and Data Residency
Where records live matters as much as how they are protected.
Data residency determines which country’s laws apply to a client’s records and who is accountable if something goes wrong. For a therapist in India, keeping data on India-based servers is the safer default. It keeps records under Indian law, avoids the cross-border questions that come with foreign-hosted tools, and matches what a client assumes happens to their information when they share it with a practitioner in India.
This is where the everyday habits from earlier in this post catch up with a practice. A personal Google Drive account, a WhatsApp backup, or a free-tier cloud tool typically stores data on infrastructure outside India, governed by another country’s laws, with no contractual guarantee of the safeguards a clinical record needs. Backups compound the risk. A record deleted from the main folder can still exist, unencrypted, in a backup copy on a different server entirely.
Secure storage for a therapy practice means one system, built for clinical data, with encryption, access control, and India-based hosting applied consistently, not a patchwork of whatever tool was convenient when a client was first booked.
Compliance Basics: What DPDP Requires Day to Day
India’s Digital Personal Data Protection Act is now enforceable law, with the DPDP Rules notified in November 2025 and full compliance mandatory by May 13, 2027. It applies to every practitioner who collects client data, including a solo therapist working from a single room.
Day-to-day compliance comes down to a short list of standing practices. Give clients a proper consent notice before collecting any data, kept separate from the therapeutic agreement itself. Collect only what clinical care genuinely requires, not an intake form padded with questions unrelated to treatment. Store records with encryption and access controls appropriate to sensitive personal data. Give clients a way to access, correct, or delete their data. If a breach happens, respond with a documented process, including notifying affected clients without delay.
None of this replaces good security practice. It sits on top of it. Encryption and access control are what make compliance possible; the DPDP Act is what makes it mandatory. For the full breakdown of consent, data residency, and a practitioner’s six core obligations under the Act, see our guide on what DPDP means for mental health practitioners in India.
A Practical Checklist for Keeping Client Data Safe
Most of what puts client data at risk can be fixed without new software or a large budget. Use this checklist to find the gaps in a practice this week.
- Session notes: Confirm they are stored in one system built for clinical data, not split across Google Docs, WhatsApp, and email.
- Device security: Check that every laptop and phone holding client data is encrypted and password-protected, not just protected by a lock screen.
- Backups: Turn off or review any automatic backup, WhatsApp to Google Drive is the most common, that stores client information in a location without proper encryption.
- Access list: Write down everyone with access to client records, from co-practitioners to billing staff, and confirm each person’s access matches what their role actually requires.
- Departed staff: Revoke access immediately for anyone who has left the practice. A forgotten login is an open door.
- Consent notice: Confirm clients receive a clear, separate notice about data collection before intake, not just consent to begin therapy.
- Data location: Ask any tool used for scheduling, notes, or payments where client data is physically stored, and get a direct answer.
A practice that can check off all seven has closed most of the gaps that lead to exposure.
Aroha is built around this exact checklist. It hosts client records on India-based servers, encrypts them at rest and in transit, and enforces role-based access control, with consent and documentation workflows designed around what the DPDP Act requires.
Most exposure in a therapy practice starts with convenience: a familiar tool that was never built for clinical data, used because it was already open. Aroha publishes practical security and compliance guides like this one every month, written for the realities of running a practice in India.
The information in this post is provided for general awareness and is not legal advice. For guidance specific to your practice’s obligations, consult a qualified legal professional.
Related Articles

What Makes Mental Health Software Secure?
A practitioner's guide to what makes mental health software secure; encryption, HIPAA alignment, DPDP readiness, access control, and data residency. The criteria to verify before trusting any tool with client data.

How to Choose Therapy Practice Software in India
A practical framework for choosing practice management software as a therapist in India: security, DPDP compliance, data residency, clinical fit, and the questions to ask before you commit.

What to Look for in Mental Health Software Built for India
Mental health software built for India keeps client data on Indian servers, is DPDP-ready, and fits how care is practised here. What to look for, and how to tell.