Is 1Password HIPAA Compliant for Therapists?
Quick Answer
No — and 1Password takes an unusual position on why. Their official Legal Center states they are not a HIPAA 'business associate' at all, because their zero-knowledge encryption means 1Password itself can never access, decrypt, or view anything stored in your vault — so they don't issue a Business Associate Agreement on any plan, including Business. Be skeptical of other sites claiming a BAA is available 'on request' for Business plans; that directly contradicts 1Password's own official statement.
Written & fact-checked by the Therapy HIPAA Hub editorial team — see our editorial standards.
Verified October 2026 against 1Password's official Legal Center
BAA Available?
No
On Which Plan
None on any plan — 1Password states it is structurally not a HIPAA business associate
It's genuinely safe to use 1Password to store your login passwords for your HIPAA-compliant tools (EHR, email, telehealth) — that's exactly what it's designed for. What's not safe is putting client names, case notes, or any identifying detail into 1Password's notes or custom fields, since there's no BAA covering that content if your vault were ever compromised.
What to Use Instead for Client Work
Keep using 1Password for what it's good at — credentials — and keep all client information inside your actual BAA-covered EHR (SimplePractice) instead of password-manager notes fields.
Affiliate link — we may earn a commission at no extra cost to you.
The 'Zero-Knowledge' Argument, Explained
1Password's position is different from most tools on this list: they aren't saying 'upgrade to get a BAA' — they're saying a BAA isn't applicable to them at all, because their encryption architecture means even 1Password's own staff cannot read what's stored in your vault. Whether or not that argument fully satisfies every reading of HIPAA's business associate definition, the practical outcome is the same: no BAA is issued, on any plan.
A Real Conflict Worth Knowing About
Several third-party compliance and SEO sites state that 1Password Business offers a BAA 'on request.' This is not supported by 1Password's own Legal Center, which makes no plan-by-plan distinction and states plainly that no BAA is issued. Until 1Password's own site says otherwise, treat the 'Business plan BAA available' claim as unverified and don't rely on it for a client-data decision.
Trusted by 225,000+ Therapists
50% Off Your First 4 Months of SimplePractice
SimplePractice is the #1 HIPAA-compliant practice management platform for therapists. Includes a signed BAA, encrypted messaging, telehealth, and full insurance billing.
Limited-time summer offer · No credit card required for trial
Need HIPAA-compliant email only? See Hushmail for Healthcare →
FAQ — 1Password and HIPAA
Does 1Password Business include a signed BAA?
No, according to 1Password's own Legal Center — they state they are not a HIPAA business associate on any plan due to their zero-knowledge encryption model. Some third-party sites claim otherwise; 1Password's own official statement should take precedence.
Is it safe to store a client's information in a 1Password note?
No. Even though 1Password is a secure password manager, there is no Business Associate Agreement covering any content stored there. Use it only for login credentials, never for client names, notes, or other PHI.
What should I use instead to store client-related information securely?
Keep client information inside your HIPAA-compliant EHR, which is covered under its own signed BAA. 1Password is still a great tool for securing the login credentials to that EHR and your other accounts.