regulation and compliance
What does HIPAA actually require of me as an independent doula who is not a covered entity?
Most solo doulas are not covered entities, but hospital agreements, Medicaid billing, and client privacy expectations still shape how you store notes and photos. Here is where each line falls.
If you are a solo doula who takes private pay from families and does not bill any insurer electronically, HIPAA almost certainly does not apply to you directly. The rule reaches "covered entities," which are health plans, health care clearinghouses, and health care providers who transmit certain transactions in electronic form. A doula who invoices a family by Venmo, a bank transfer, or a card link is not doing any of those things.
That is the honest legal answer, and it is also incomplete. Three other things pull privacy obligations onto your desk anyway: a hospital or agency contract that makes you a business associate or binds you by its own terms, Medicaid billing that turns you into a provider with a records trail, and state privacy and consent law that never cared whether you were a covered entity in the first place.
So the useful question is not "does HIPAA apply to me." It is "which of my four or five working relationships carry privacy terms, and what do those terms require me to do with photos, notes, texts, and my calendar." Here is where each line falls.
Covered entity, business associate, and where a solo doula usually sits
HIPAA defines three positions. A covered entity is the hospital, the OB practice, the birth center, the midwifery group, the health plan. A business associate is a person or company that creates, receives, maintains, or transmits protected health information on behalf of a covered entity, under a written business associate agreement. Everyone else is outside the rule.
The independent doula paid directly by the family is normally in that third bucket. You are not treating the client as a licensed provider billing a plan, you are not a subcontractor performing a function for the hospital, and you receive the information from the client herself rather than on behalf of an institution.
One nuance worth holding onto: information a client gives you voluntarily, as your client, is not protected health information in the HIPAA sense. It is confidential because of your contract and your ethics, not because of the federal rule. The practical result is the same. The legal route matters when someone sends you a demand letter or a subpoena, because the defenses differ.
The signal that you have crossed the line
You have almost certainly become a business associate if you sign a document titled Business Associate Agreement, or if a contract says you will access the facility's electronic health record, chart in it, or receive patient lists from the facility. If someone hands you an EHR login, read the paperwork twice. A login is the clearest tell there is.
Keep reading: How does Medicaid doula reimbursement work in the states that now cover it, step by step?
When a hospital or agency contract pulls you into HIPAA terms
Volunteer doula programs, hospital-based birth companion programs, and community birth worker contracts frequently include privacy language whether or not the federal rule technically binds you. Facilities do this because it is easier to apply one standard to everyone who walks the unit than to run a legal analysis per person.
What that language typically asks of you:
- No photography or video in clinical space without facility permission, separate from the client's permission
- No discussion of any patient, including the one you are supporting, outside the care team
- Completion of the facility's own privacy training module, often annually
- Immediate reporting of any suspected disclosure to a named contact
- Return or destruction of any facility documents at the end of the engagement
Read the indemnification clause alongside the privacy clause. Some agency agreements make you responsible for the cost of a breach investigation triggered by your conduct. That is a real financial exposure for a sole proprietor, and it is worth asking your liability carrier whether your policy has any privacy or cyber endorsement before you sign.
Medicaid doula billing and the records it brings with it
Once you enroll as a Medicaid provider and submit claims, the calculus changes. Submitting standard electronic claims transactions is exactly the activity that makes a provider a covered entity. If you bill through a clearinghouse, a billing service, or a managed care portal that runs the standard transaction, you should assume you are in.
Practically that means a short list of things becomes mandatory rather than merely good practice:
- A written Notice of Privacy Practices you give clients and can produce on request
- Documented safeguards: device passwords, encryption, locked storage for paper
- Minimum necessary discipline, so a plan gets the visit dates and codes it needs and not your full narrative
- A business associate agreement with your billing service or documentation vendor
- A breach response process, because notification duties attach to unsecured records
Doulas often discover this the awkward way, when a managed care plan requests visit documentation and the only record is a text thread. Build the records habit at enrollment, not after the first audit letter.
Keep reading: How many clients can I take per month before my on call weeks start to overlap badly?
Client photos, social posts, and written release language
Birth photos are where most doulas actually get into trouble, and the exposure is contractual and reputational long before it is regulatory. A face, a hospital wristband, a room number on a whiteboard, a due date in a caption: any of these can identify a family to people who know them.
Consent for care is not consent for publication. Keep them on separate pages so a client can decline one without feeling she is declining the other. A workable release states, in plain language, what may be shown, where, for how long, and how to revoke.
| Element | Weak version | Version that holds up |
|---|---|---|
| Scope | "Permission to use photos" | Names the platforms: your website, Instagram, a printed portfolio |
| Identifiability | Silent | Separate initials for faces, for the newborn, and for the client's name or handle |
| Duration | "Ongoing" | A term, with automatic expiration unless renewed |
| Revocation | Silent | Written request removes future use within a stated number of days, with printed material excepted |
| Timing | Signed in labor | Signed at a prenatal, reconfirmed after the postpartum visit |
The reconfirmation step is the one to actually adopt. A client who said yes at 34 weeks may feel very differently about her birth photos six weeks later, and asking again costs you nothing.
Storing birth notes, texts, and shared calendars safely
Most doula records live in three places: a phone, a personal cloud drive, and a notebook in the car. Each has a distinct failure mode. The phone gets handed to a toddler. The drive gets shared with a folder link that never expires. The notebook gets left in the passenger seat.
A defensible baseline for a solo practice:
- Full disk encryption and a passcode on every device that touches client information, including the tablet you only use for contracts.
- Two factor authentication on the email account, because email is where contracts, invoices, and birth stories all end up.
- No client names in file names or calendar event titles that sync to a car display or a shared family calendar. Initials plus a due date window are enough.
- One system of record for notes, not four. Duplicated notes are the ones you forget to delete.
- Client texts summarized into that system after each contact, so your phone is a channel and not an archive.
Shared calendars deserve their own thought. If you and your backup can see each other's on call windows, decide deliberately what she sees: that you are covered from March 2 to March 16 is operationally necessary, the client's full name and clinical history is not.
See how DoulaDay handles this for birth and postpartum doula work
State privacy and consent laws that apply regardless
Two categories catch doulas who correctly concluded HIPAA does not reach them.
First, recording law. States are split between one party and all party consent for recording conversations. In an all party state, recording a phone conversation with a client, or a conversation with a nurse in the room, without everyone's agreement can be a criminal matter, not just a rude one. Know which rule your state follows before you use a voice memo to take notes.
Second, general consumer data and breach notification statutes. Many states require notice to affected residents when unencrypted personal information is exposed, and those statutes apply to businesses broadly, not only to health care. Encryption is what usually keeps a lost laptop from becoming a notification event.
Mandatory reporting sits alongside all of this. If your state names you a mandated reporter, or your agency contract does, confidentiality yields to that duty. Say so in your client agreement so no one is surprised by it later.
A simple records retention and deletion practice
Keeping everything forever feels safe and is the opposite of safe. Every file you still hold is a file you can be asked to produce or can lose. Set a schedule, write it into your client agreement, and follow it.
A practice that works for most solo doulas:
- Signed contracts and payment records: keep for the length of your state's contract limitations period, then longer if your accountant says so for tax reasons.
- Visit notes: keep for a defined term after the last visit, then delete.
- Photos without a current release: delete at the release expiration date, including the copies in your camera roll and your backup drive.
- Text threads: summarize, then clear at the end of the postpartum period.
- Inquiries that never became clients: delete within a season.
Put a recurring reminder on the first business day of each quarter, spend twenty minutes, and log what you deleted. That log is the evidence that you have a practice, which is most of what anyone reviewing you actually wants to see.
Where this leaves your week
Compliance for an independent doula is mostly a storage and calendar problem wearing a legal costume. The obligations are real but bounded: know which contracts bind you, keep signed releases current, keep client detail out of the places it does not need to be, and delete on a schedule.
That is easier when contracts, deposits, and on call windows live in one place instead of scattered across a phone, an email inbox, and a shared family calendar. DoulaDay keeps signed agreements, payment status, and your on call and backup windows together per due date window, so your calendar can show your backup the coverage without showing her the client's file. Set your retention reminders this quarter, and let the system hold the rest.