Clients tell you things they have not told their families. Weight, diagnoses, medications, what they eat when nobody is watching, why they gave up the last three times. You collected it in a form and it now lives on your laptop. Almost nobody starting a practice has thought about what that means.
First, the HIPAA question
People assume HIPAA covers anything health-related. It does not. HIPAA's rules apply to covered entities, and the federal definition at 45 CFR 160.103 lists three: a health plan, a health care clearinghouse, and a health care provider who transmits health information in electronic form in connection with a transaction covered by the rules. Those transactions are largely the standardized electronic exchanges that go along with insurance billing.
A private nutrition coach who takes payment directly from clients and never bills a payer often falls outside all three. That is a legal conclusion about your specific practice, though, not a rule of thumb to rely on. A business associate agreement with a clinic, a contract with an employer's health plan, or a change in how you get paid can pull you inside. Ask an attorney about your own setup and get the answer in writing.
Then set the question aside, because it matters less than people expect. Even outside HIPAA you are still bound by your state's privacy and breach notification laws, by whatever your client agreement promises, by the terms of any platform you use, and by the plain fact that a client handed you private information and trusted you with it.
What a client record should contain
A record is what you would need to pick a client back up after six months away, and what would show a third party that you practiced responsibly.
- The signed agreement and consent, with the date.
- The completed intake and any updates.
- A short note per session: date, what you discussed, what you recommended, what the client agreed to do.
- Anything you gave the client, such as a plan or handout.
- Every referral you made and why, and anything you declined to advise on because it was outside scope.
- Signed releases, and a note of anything you shared under them.
- Payment records, kept separately from health information where you can.
Write notes the same day, in neutral language, describing what happened rather than your opinion of the person. A note that reads like a diagnosis creates a scope problem that was not there before. Referrals in particular belong in writing every time.
Where it lives
The most common arrangement in a new practice is the worst one: intake forms in the email inbox, food photos in the phone's camera roll, notes in a document on a laptop the whole household uses, and a spreadsheet of contacts somewhere else.
Pick one place. A coaching platform or a single cloud folder is fine. Then do four things:
- A unique password and two-factor authentication on that account and on the email account that can reset it. Reused passwords are how most small-practice exposures happen.
- Device locks and encryption on every device that opens it, including the phone.
- One backup that is not on the same device. Losing a client's history is its own kind of failure.
- Nobody else in the account. Not a partner, not a family member, not a virtual assistant without a confidentiality agreement and their own login.
Before you put health information into any tool, read its terms. Some consumer services say plainly that they are not intended for sensitive health data, and that sentence is your problem, not theirs, once a client asks.
Consent, releases, and other people
Your intake should tell the client in plain words what you collect, where it is stored, who can see it, and when you would share it. Written before you need it, not after.
Sharing with anyone else needs a separate signed release: who it goes to, what may be shared, and when the permission ends. That includes a physician, a therapist, a trainer, a spouse, and the person who referred the client to you. Especially the person who referred the client to you, because that is where casual disclosure happens most.
Family members are not automatically entitled to anything. If a client's partner calls asking how it is going, the answer is that you cannot confirm whether someone is a client. Decide that sentence now so you are not improvising on the phone.
If a subpoena, a court order, or a lawyer's letter arrives, do not respond on your own and do not hand anything over to be helpful. Call an attorney the same day. Never delete or alter a record because a legal request showed up.
Messaging, photos, and the things that live outside the file
Most coaching now happens partly in messages. That is fine, with boundaries set in writing: which channel you use, what hours you answer, how fast you reply, and that anything medical goes to their provider instead.
The trap is that the thread becomes the record and then vanishes with a phone, an app, or a deleted account. Anything that matters gets copied into the file.
Photos are their own category. Food logs, body photos, lab results a client screenshots to you. Get explicit written permission for each purpose, keep them in the same controlled place as everything else rather than the camera roll, and never use a client's photo or story in marketing without separate written permission that says exactly where it will appear.
How long to keep it, and how to get rid of it
There is no single national retention rule for an unlicensed practice, which means you have to choose a period, write it in your policy, and follow it. Your attorney and your liability insurer are the right people to ask, because the useful answer depends on your state's limitation periods and your policy terms.
Whatever period you pick, apply it consistently, and destroy records properly at the end of it: shredding on paper, and a real deletion including backups and any copy sitting in an email attachment.
When something goes wrong
A laptop is stolen. A form goes to the wrong client. An account is breached. Work in this order:
- Stop it. Change passwords, revoke the device, pull the file back.
- Find out what was actually involved and whose information it was. Guessing is worse than not knowing.
- Write it down from the beginning, with times.
- Call your attorney and your insurer before sending anything. Breach notification duties come from state law and from your contracts, and they differ by state and by what was exposed.
- Tell the affected clients as your counsel advises, plainly, with what you are doing about it.
- Fix the cause, not just the incident.
The short version
HIPAA probably does not cover a cash-pay coaching practice, and that changes little: state law, your own agreement, and simple decency still apply. Keep one real record per client. Store it in one controlled place with a unique password, two-factor, encryption, and a backup. Get a signed release before anything goes to anyone else. Copy what matters out of message threads. Pick a retention period and follow it. And if something is exposed, contain it, document it, and call a lawyer before you call anyone else.
Questions people ask
Does HIPAA apply to nutrition coaches?
Often not. HIPAA's privacy rules apply to covered entities, defined in federal regulation as health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a covered transaction, which generally means insurance billing transactions. A private coach who does not bill insurance frequently falls outside that definition. Being outside HIPAA does not remove your duty under state privacy law, your own contracts, or your platforms' terms, and a business associate agreement can pull you in, so confirm your own status with an attorney.
Where should I store nutrition client records?
In one place you control, with a password that is not used anywhere else, two-factor authentication turned on, and a backup. Not scattered across your email inbox, phone photos, and a shared home computer account. If you use a coaching platform or cloud storage, read what its terms say about health information before you put any in it.
Can I text or message my nutrition clients?
You can, if the client agrees and you set the boundaries in writing. Say which channel you use, what hours you answer, and that anything clinical goes to their medical provider instead. Copy anything that belongs in the record into the record, because a thread on a phone is not a record and it disappears when the phone does.
Do I need written permission to talk to a client's doctor?
Yes. Get a signed release that names the person or practice, says what may be shared, and has an end date. Keep it with the file. A verbal go-ahead in a session is not enough when someone later asks why you disclosed something.
What should I do if client information is exposed?
Stop the exposure first, then find out exactly what was involved and whose information it was. Notification duties come from state breach laws and sometimes from your contracts, and they vary, so call an attorney and your insurer before you decide what to send. Write down what happened and when, from the beginning.
This article is general educational information, not medical, dietetic, or legal advice, and is not a substitute for care from a licensed physician or registered dietitian. Certifications offered on this site are private credentials, not a government license and not the Registered Dietitian (RD/RDN) credential. Nutrition practice is regulated differently in each state; confirm what you are permitted to do in your state before practicing.