
HIPAA Compliance Guide for Acuity Scheduling Users
Acuity Scheduling, a HIPAA-compliant appointment scheduling solution, provides secure handling of Protected Health Information (PHI) through its Powerhouse plan. Here's what you need to know about making your Acuity account HIPAA compliant:
Setting Up HIPAA Compliance
- Upgrade to the Powerhouse plan
- Navigate to Customize Appearance
- Click Appointment Booking Page Options
- Sign the Business Associate Agreement (BAA)
Key Security Features
- Encrypted PHI handling
- Restricted file uploads from local devices only
- No client form responses in email notifications
- Limited calendar sync capabilities
- Disabled integrations with non-HIPAA compliant services
Your HIPAA Responsibilities
- Configure appropriate security settings
- Manage PHI in emails and text notifications
- Review third-party integrations for compliance
- Maintain proper business practices
- Implement necessary security controls
Additional Security Measures
- Email notifications exclude sensitive information
- Client form responses are protected
- Package balance checks require direct login
- Calendar syncing restricted to compliant services
- Text message opt-out available
Third-Party Integration Management
Before connecting any third-party services:
- Verify HIPAA compliance
- Establish necessary agreements
- Adjust security settings
- Review data sharing practices
- Document compliance measures
Accessing Your BAA
- Go to Customize Appearance
- Select Scheduling Page Options
- Click "View and Download Your Signed BAA"
- Download PDF if needed
Remember: HIPAA compliance requires more than just enabling features. You must actively manage your account settings and business practices to maintain compliance.
Related Articles

Understanding Squarespace Payment Reserves: A Complete Guide
