Running a Practice

Client Records and Privacy for Nutrition Coaches

Does HIPAA apply to you? Probably not, and that changes less than you think. What to keep, where to keep it, who is allowed to see it, and what to do when something goes wrong.

Clients tell you things they have not told their families. Weight, diagnoses, medications, what they eat when nobody is watching, why they gave up the last three times. You collected it in a form and it now lives on your laptop. Almost nobody starting a practice has thought about what that means.

First, the HIPAA question

People assume HIPAA covers anything health-related. It does not. HIPAA's rules apply to covered entities, and the federal definition at 45 CFR 160.103 lists three: a health plan, a health care clearinghouse, and a health care provider who transmits health information in electronic form in connection with a transaction covered by the rules. Those transactions are largely the standardized electronic exchanges that go along with insurance billing.

A private nutrition coach who takes payment directly from clients and never bills a payer often falls outside all three. That is a legal conclusion about your specific practice, though, not a rule of thumb to rely on. A business associate agreement with a clinic, a contract with an employer's health plan, or a change in how you get paid can pull you inside. Ask an attorney about your own setup and get the answer in writing.

Then set the question aside, because it matters less than people expect. Even outside HIPAA you are still bound by your state's privacy and breach notification laws, by whatever your client agreement promises, by the terms of any platform you use, and by the plain fact that a client handed you private information and trusted you with it.

The working standard: handle client health information as if someone will one day ask you to justify every place a copy of it ended up. That standard is easy to meet if you set it up at the start and miserable to retrofit.

What a client record should contain

A record is what you would need to pick a client back up after six months away, and what would show a third party that you practiced responsibly.

Write notes the same day, in neutral language, describing what happened rather than your opinion of the person. A note that reads like a diagnosis creates a scope problem that was not there before. Referrals in particular belong in writing every time.

Where it lives

The most common arrangement in a new practice is the worst one: intake forms in the email inbox, food photos in the phone's camera roll, notes in a document on a laptop the whole household uses, and a spreadsheet of contacts somewhere else.

Pick one place. A coaching platform or a single cloud folder is fine. Then do four things:

Before you put health information into any tool, read its terms. Some consumer services say plainly that they are not intended for sensitive health data, and that sentence is your problem, not theirs, once a client asks.

Consent, releases, and other people

Your intake should tell the client in plain words what you collect, where it is stored, who can see it, and when you would share it. Written before you need it, not after.

Sharing with anyone else needs a separate signed release: who it goes to, what may be shared, and when the permission ends. That includes a physician, a therapist, a trainer, a spouse, and the person who referred the client to you. Especially the person who referred the client to you, because that is where casual disclosure happens most.

Family members are not automatically entitled to anything. If a client's partner calls asking how it is going, the answer is that you cannot confirm whether someone is a client. Decide that sentence now so you are not improvising on the phone.

If a subpoena, a court order, or a lawyer's letter arrives, do not respond on your own and do not hand anything over to be helpful. Call an attorney the same day. Never delete or alter a record because a legal request showed up.

Messaging, photos, and the things that live outside the file

Most coaching now happens partly in messages. That is fine, with boundaries set in writing: which channel you use, what hours you answer, how fast you reply, and that anything medical goes to their provider instead.

The trap is that the thread becomes the record and then vanishes with a phone, an app, or a deleted account. Anything that matters gets copied into the file.

Photos are their own category. Food logs, body photos, lab results a client screenshots to you. Get explicit written permission for each purpose, keep them in the same controlled place as everything else rather than the camera roll, and never use a client's photo or story in marketing without separate written permission that says exactly where it will appear.

How long to keep it, and how to get rid of it

There is no single national retention rule for an unlicensed practice, which means you have to choose a period, write it in your policy, and follow it. Your attorney and your liability insurer are the right people to ask, because the useful answer depends on your state's limitation periods and your policy terms.

Whatever period you pick, apply it consistently, and destroy records properly at the end of it: shredding on paper, and a real deletion including backups and any copy sitting in an email attachment.

When something goes wrong

A laptop is stolen. A form goes to the wrong client. An account is breached. Work in this order:

  1. Stop it. Change passwords, revoke the device, pull the file back.
  2. Find out what was actually involved and whose information it was. Guessing is worse than not knowing.
  3. Write it down from the beginning, with times.
  4. Call your attorney and your insurer before sending anything. Breach notification duties come from state law and from your contracts, and they differ by state and by what was exposed.
  5. Tell the affected clients as your counsel advises, plainly, with what you are doing about it.
  6. Fix the cause, not just the incident.
None of this is legal advice. Whether HIPAA applies to you, what your state's privacy and breach laws require, and how long to keep records are questions for an attorney licensed in your state.

The short version

HIPAA probably does not cover a cash-pay coaching practice, and that changes little: state law, your own agreement, and simple decency still apply. Keep one real record per client. Store it in one controlled place with a unique password, two-factor, encryption, and a backup. Get a signed release before anything goes to anyone else. Copy what matters out of message threads. Pick a retention period and follow it. And if something is exposed, contain it, document it, and call a lawyer before you call anyone else.

Questions people ask

Does HIPAA apply to nutrition coaches?

Often not. HIPAA's privacy rules apply to covered entities, defined in federal regulation as health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a covered transaction, which generally means insurance billing transactions. A private coach who does not bill insurance frequently falls outside that definition. Being outside HIPAA does not remove your duty under state privacy law, your own contracts, or your platforms' terms, and a business associate agreement can pull you in, so confirm your own status with an attorney.

Where should I store nutrition client records?

In one place you control, with a password that is not used anywhere else, two-factor authentication turned on, and a backup. Not scattered across your email inbox, phone photos, and a shared home computer account. If you use a coaching platform or cloud storage, read what its terms say about health information before you put any in it.

Can I text or message my nutrition clients?

You can, if the client agrees and you set the boundaries in writing. Say which channel you use, what hours you answer, and that anything clinical goes to their medical provider instead. Copy anything that belongs in the record into the record, because a thread on a phone is not a record and it disappears when the phone does.

Do I need written permission to talk to a client's doctor?

Yes. Get a signed release that names the person or practice, says what may be shared, and has an end date. Keep it with the file. A verbal go-ahead in a session is not enough when someone later asks why you disclosed something.

What should I do if client information is exposed?

Stop the exposure first, then find out exactly what was involved and whose information it was. Notification duties come from state breach laws and sometimes from your contracts, and they vary, so call an attorney and your insurer before you decide what to send. Write down what happened and when, from the beginning.

This article is general educational information, not medical, dietetic, or legal advice, and is not a substitute for care from a licensed physician or registered dietitian. Certifications offered on this site are private credentials, not a government license and not the Registered Dietitian (RD/RDN) credential. Nutrition practice is regulated differently in each state; confirm what you are permitted to do in your state before practicing.

See what the programs cover before you enroll

Curriculum, scope, and how the self-paced format works. Read it first, then decide.

View the programs Admissions

Keep reading