CompyMax

Is SimplyBook.me HIPAA compliant?

Only under specific conditions

Yes on the Standard plan and above, where SimplyBook.me's HIPAA feature and a signed business associate agreement are both stated to be available — but the agreement is affirmed on a marketing page rather than in the help or legal documentation, so get it in writing before the first patient books.

Applies to SimplyBook.me. Last reviewed against SimplyBook.me's own documentation. Next review February 6, 2027.

Reviewed by Dr. Rachel Foster, MD — Pediatrician and small practice owner.

What you must do

  • Subscribe to Standard or Premium. The HIPAA custom feature is 'available with Standard and Premium (former Gold and Platinum) subscriptions', and the vendor's healthcare guide states the agreement comes 'on its Standard plan and above'.
  • Ask support for the business associate agreement and keep the executed copy. No request form or process is published anywhere on the site — the affirmation that one is signed appears only in a marketing article.
  • Enable the HIPAA custom feature before taking a patient booking. It is what enforces two-factor authentication for every user, auto-logout, and the block on SimplyBook's own support staff accessing your data.
  • Expect notification templates to change: the feature masks patient and service names in email and SMS, and the service and client variables in templates stop working, precisely because those messages travel unencrypted.
  • Pair it with the Clean History feature and set a retention rhythm, rather than letting years of past appointments accumulate.

Does SimplyBook.me sign a business associate agreement?

Yes. SimplyBook.me offers one. Standard or Premium (formerly Gold and Platinum). Not published. Contact SimplyBook.me support and ask for the business associate agreement alongside enabling the HIPAA custom feature — the vendor affirms one is signed on Standard and above but documents no route.

See their documentation.

What this means in practice

SimplyBook.me's HIPAA feature is unusually concrete about what it does: it forces two-factor authentication on every user, adds an auto-logout, locks SimplyBook's own support staff out of your data, and masks patient and service names in the notification emails and texts — because those travel unencrypted. The plan gate is Standard or Premium, and the feature simply does not exist below that.

The agreement is the part to be careful with. The statement that a business associate agreement is signed on Standard and above lives in a marketing article, not in the help documentation or the legal terms, and no request process is published anywhere. Ask support for it in writing before the first patient books, and treat the enablement of the feature and the execution of the agreement as two separate boxes to tick.

Expect the feature to change how the product behaves. The service and client variables in notification templates stop working because they are masked, Zapier cannot be connected at all, and the API feature is incompatible. A practice that built its confirmation emails around the service name, or its workflow around Zapier, discovers this mid-migration.

How organizations get this wrong

The specific mistakes we see with SimplyBook.me, not generic advice.

  • Enabling the HIPAA feature and never asking for the agreement, because the feature toggle feels like the compliance step.
  • Building notification templates that merge the service name, which the masking silently blanks once the feature is on.
  • Planning a Zapier or API integration first and discovering both are unavailable with the HIPAA feature active.
  • Staying on the entry tier because the price is right, where the feature — and with it the whole compliant configuration — does not exist.

What the agreement does not cover

  • Zapier, which cannot be connected while the HIPAA feature is active, and the API custom feature, which cannot be used with it.
  • The free and entry tiers — the feature does not exist below Standard.
  • Your own obligations. SimplyBook.me states the feature does not replace the customer's own security controls.

Alternatives

Listed on merit. We take no payment for placement and use no affiliate links.

  • Acuity Scheduling

    The closest comparison: a self-serve agreement on a stated plan tier, with the product trade-offs documented

  • Zoho Bookings

    Where you would rather have the agreement template from a legal team than a support conversation

  • Calendly

    The tool many practices already have — and the one whose terms forbid patient information outright

Signing the agreement is step one. Proving it is step two.

Once you have the agreement with SimplyBook.me, someone has to know it exists, where the copy is, when it needs revisiting and who owns it. That register is what a client's security questionnaire is actually asking about, and it is the section of an evidence pack most organizations cannot produce on request.

$79/month, 14-day free trial, no credit card. The checker itself stays free and needs no account.

Sources

Every statement above comes from SimplyBook.me’s own published documentation, read on the date shown.

  1. HIPAA custom featureSimplyBook.me. Published February 16, 2026. Read August 30, 2026.
  2. How to Set Up Online Appointment Scheduling for Clinics & HealthcareSimplyBook.me. Published July 7, 2026. Read August 30, 2026.
  3. HIPAA-Compliant Scheduling for Small ClinicsSimplyBook.me. Published September 18, 2025. Read August 30, 2026.
  4. How to Schedule Clients in SimplyBook.me with HIPAASimplyBook.me. Published January 14, 2025. Read August 30, 2026.

Change history

  • First published.

This page is information, not certification and not legal advice. It reflects SimplyBook.me’s published documentation as read on August 30, 2026; vendors change their terms without notice, so confirm anything you rely on directly with the vendor. Whether your own use is compliant depends on your configuration, your executed agreement and how your staff actually work. No company can be “HIPAA certified” — no such designation exists.

Think something here is wrong or out of date? Tell us at support@hipaacompliancesoftware.org — corrections are published with a dated note in the change history above, never silently. See our editorial standards for how entries are researched and re-verified.