In a digital world where data is one click away, cybersecurity for therapists has become part of everyday practice. Perhaps your laptop has a password and you keep client records carefully. But what if you lose your phone, someone gets into your email, or sensitive data is shared by mistake? This article walks you through the simple basics and helps you protect what matters most: your clients’ trust.

GDPR in a therapy practice

Every therapist in private practice should have a simple but clear GDPR policy — a document describing how you handle clients’ personal data. You don’t have to write it from scratch: you can start from a template, such as our privacy policy template for therapy practices (in Czech).

At a minimum, it should cover:

  • what data you collect (for example name, contact details, therapy notes),
  • why you collect it (for example to provide your service),
  • how you store it and for how long,
  • who has access to it,
  • how clients can ask for their data to be erased or corrected.

It’s a legal requirement, and also an important signal of transparency towards your clients. Information about GDPR belongs in your informed consent for therapy as well.

The most common threats to client data

Even with a small practice and trustworthy clients, risks come from outside and from inside. These are the three most common threats every therapist should be ready for:

  1. Data breaches. A hacked email account or cloud storage, leaked login details or an insecure app can put sensitive data in the wrong hands. It often happens without you knowing — a weak password or one click on a malicious link is enough.
  2. Human error. We all make mistakes — sending an email to the wrong person, say, or leaving your notes open on screen during a session. Even an honest mistake can compromise confidentiality.
  3. Physical threats. A lost phone, a stolen laptop or an unlocked therapy room can all lead to a data leak if your devices aren’t properly protected. That’s why secure technology and strong passwords matter, even if your devices only travel “between home and the practice”.

Cybersecurity for therapists: 5 basic principles

  1. Strong passwords and two-factor authentication. Use a unique, strong password for every service — ideally with a password manager such as Bitwarden or 1Password. Turn on two-factor authentication (2FA) wherever you can, especially for email and the apps you work with. In Lumi, you’ll find it in the settings.
  2. Secure devices. Protect your phone and computer with a password, keep them updated and turn on disk encryption. If a device is stolen, the data stays safe.
  3. Backups. Back up important data regularly to a safe place — ideally encrypted and separate from your main device. Automatic backups save you the worry if a device breaks or goes missing.
  4. Secure apps. Choose tools designed with privacy in mind that meet European requirements such as GDPR. Don’t send sensitive information by ordinary email or over unencrypted platforms. For notes, bookings and invoicing, use a specialised tool such as Lumi. If you lose a device, Lumi lets you sign out of all devices in one step.
  5. Stay alert. Phishing emails and fake text messages are getting more convincing all the time. If something looks suspicious, don’t click — check it through another channel. A healthy dose of distrust is the foundation of digital hygiene.

Summary

Cybersecurity isn’t just a technical matter — it’s an ethical commitment to your clients. It protects their trust and your business. The good news is that you can handle most of the basics yourself; you don’t need to be an IT expert. Build good habits, use secure tools and keep checking that everything is up to date. And if you’re not sure, don’t be afraid to ask for help — looking after security is part of being a professional.