HIPPA vs. HIPAA

HIPPA is a common misspelling of HIPAA. It's that simple. What's more complicated? Understanding what HIPAA actually means (and doesn't mean).


What is HIPPA?

Folks ask this all the time on the internet.

And the truth is:

It's a misspelling of HIPAA.

But more importantly, what is HIPAA?

HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. (Yes, that 1996 -- 30 years ago! Wow, time flies.)

One of its main goals is to protect private medical records from being shared without consent. It also has some baseline security requirements on how that data should be transmitted/stored, and perhaps most importantly, it has requirements on what to do in the event of a data breach -- the timeline of when impacted users should be notified, for example.

When companies or services declare themselves "HIPAA compliant", it means that they meet these requirements. There is no official or recognized third party that can certify HIPAA compliance.

And when you see the "HIPAA compliant" sticker on websites, do you know what it doesn't mean?

  • HIPAA doesn't mean that your data is 100% secure and protected.
  • HIPAA doesn't mean that the service is protected from data breaches.
  • HIPAA doesn't mean that the data is end-to-end encrypted.
  • HIPAA doesn't mean that you have nothing to worry about.

These things weren't really meant to be covered by HIPAA way back in 1996. It was about handling patient data responsibly and not selling it off to other third parties without the patient's permission. So it's not necessarily HIPAA's fault.

But...

It falls on all of us to understand what HIPAA means and does not mean.

Companies want you to see the HIPAA badge and think: "Oh ok, no need to worry -- any data I toss their way is safe."

Companies want clinicians to say to their patients: "Don't worry, this new ambient listening AI scribe I want to use is HIPAA compliant."

And there's a lot more to the story than that.

And if you're doubting this, just take a look at this: There are hundreds of data breaches for HIPAA compliant companies each year.

What is HIPPA?

(Yes, this is intentionally misspelled for comedic effect...)

So anyway, what started out as a joke about the spelling of HIPAA (and HIPPA) turned into a post about much more than that.

Yes, Quill Therapy Solutions is HIPAA compliant.

And equally important, we choose to handle as little personal health information as possible -- and we choose to store none of it. And we choose to never record therapy sessions or transcribe therapy sessions. We want no place in the therapy room during sessions.

Because while we're HIPAA compliant, it's even more responsible and secure to minimize any and all potential privacy risks.

Thanks for reading this tangent!

Published on Aug. 11, 2026.

← View All Articles

Quill Therapy Solutions

What is Quill?

Quill streamlines progress notes for therapists, saving time by generating notes from a verbal or typed session summary. With privacy at its core, Quill never records client sessions, protecting the therapist-client relationship and avoiding ethical and confidentiality risks. Just record a summary, click a button, and Quill generates your notes for you.

Try Quill for free today, no credit card required. And for unlimited notes (and other types of therapy documentation), it's only $20/month. (Even less for teams.)

Try Quill and save time on notes.