Leadership · 8 min read · August 2026 · Last verified: August 2026

Is Simply.Coach HIPAA and SOC2 Compliant?
A Coach's Guide to Data Security in Practice-Management Software

Executive Briefing

Simply.Coach claims SOC2, HIPAA, and GDPR compliance, all three at once. That's more than any other platform in this comparison publicly claims. But the full SOC2 report stays behind an NDA.

Only Leap and Surge business tiers get access. So "ask for the report" is a real procurement step, not just a rubber stamp.

Bottom Line: A compliance badge is a starting point for questions, never an answer. Ask for the signed BAA. Ask for the SOC2 report.

Don't take a security page at face value.

Key Metric: CoachAccountable states directly that it is not HIPAA compliant. That's true even though its hosting environment sits in a SOC2-certified data center (coachaccountable.com, 2026).

🔍
Editorial Review: YMYL Content

This article covers data security and compliance claims. Those carry real financial and privacy implications for coaching practices. Aevum Transform has an affiliate relationship with Simply Coach.

Every claim here is sourced to each vendor's published pages. No guesswork. All sources are current as of August 2026.

See our affiliate disclosure and editorial standards.

A brass padlock resting on a stack of client folders beside a glowing laptop screen, symbolizing data security in coaching software

This article is informational, not a substitute for your own legal or compliance review. If you have hard compliance requirements, get current documentation from the vendor directly. Do that before you sign up.

Simply.Coach's Compliance Claims at a Glance

Simply.Coach claims SOC2, HIPAA, and GDPR compliance. No other platform here claims all three. That makes it the strongest option on paper for coaches with real compliance needs.

But "claims" is doing real work in that sentence. Simply.Coach's full SOC2 report isn't published anywhere. It's gated behind an NDA, on the Leap and Surge tiers only.

That's not a red flag on its own. It's a genuine procurement step. You have to ask for the report, not just trust the badge.

CoachAccountable takes the opposite stance. Its hosting environment is SOC2-certified and described as HIPAA-compliant. The company states plainly that CoachAccountable itself is not HIPAA compliant.

Paperbell and Quenza sit in between, each with different gaps. The rest of this article walks through what each claim actually means. It also covers what to verify before you trust any of them with client data.

Want the full field of coaching platforms, not just these four? See our full 9-platform comparison.

Weighing cost first? Our Simply.Coach pricing breakdown covers that separately.

What SOC2, HIPAA, and GDPR Actually Mean for a Coaching Practice

These three terms get thrown around constantly on vendor security pages. Most coaches never learn what they actually require. Here's the plain version.

SOC2

SOC2 is an independent audit report, not a fixed checklist. It measures a company's controls against five categories: security, availability, processing integrity, confidentiality, and privacy.

A vendor doesn't need all five to call itself SOC2 compliant. Most reports cover only a subset, usually security at minimum.

That's why the report matters more than the badge. It tells you which categories got audited.

HIPAA

HIPAA is a US federal law protecting health information. It isn't a certification a company can simply buy. Not even close.

A vendor can't unilaterally declare itself "HIPAA compliant" in any legally binding way.

What actually matters is a signed Business Associate Agreement, or BAA. It's a contract between the vendor and each customer handling health data.

The BAA is the legal instrument. The marketing claim is not. Full stop.

If HIPAA matters to your practice, ask one specific question: will you sign a BAA. Don't settle for "yes, we're HIPAA compliant" as a full answer.

GDPR

GDPR is the EU and UK's data protection law. It governs how a company processes personal data belonging to EU and UK residents.

It grants real rights, including data portability and the right to erasure. If you coach clients based in Europe, GDPR coverage isn't optional. It's a legal requirement for whoever processes their data.

Why This Matters for Health Coaches and Corporate Buyers

Two groups of coaches need real answers here, not marketing copy. Nothing fancy required.

Health and wellness coaches often collect sensitive data: weight, medications, diagnoses, mental health history. That's protected health information territory.

You might not be a covered entity under HIPAA yourself. Storing that data without real safeguards is still a genuine risk.

A breach involving health information is expensive to clean up. It also damages client trust in a way generic data loss doesn't. Both costs are real.

Picture a weight-management coach using intake forms that ask about medications and lab results. That's health data by any reasonable definition.

Say the platform storing those forms can't name its encryption standard. That coach is carrying risk they never agreed to.

Clients rarely ask about data security up front. They assume someone already checked.

Corporate L&D buyers and HR teams face a different pressure. Before procurement approves any platform, security review asks for a SOC2 report. It won't settle for a webpage claim.

An enterprise buyer evaluating Simply.Coach will hit that NDA requirement directly, and that's normal. Large vendors gate SOC2 reports behind NDAs constantly. The report itself details internal controls a company doesn't want fully public.

Getting the report isn't instant, either. A lower-tier practice has to upgrade first, then request the NDA.

Then it waits on legal review from both sides.

That's a real timeline, often weeks, not a same-day download. Build it into your schedule if a security review is coming.

Same lesson, every time. A compliance badge is a starting point for questions, never an answer.

Ask for the document. Ask who signs it. Ask exactly what's covered, and get the answer in writing.

Quick Look

See Simply.Coach's security page and BAA request process for yourself.

14-day free trial. No credit card required. Cancel anytime.

Explore Simply Coach →

Simply.Coach's Compliance Stack, in Detail

Simply.Coach published its SOC2, GDPR, and HIPAA compliance through a press release. Certification dates back to around November 2022. Here's what sits underneath that announcement.

Infrastructure runs on AWS, in dedicated clusters inside a Virtual Private Cloud with dedicated firewalls. Database access is restricted to the production application server, reached only through a secure tunnel. That's a meaningfully tighter setup than a shared, openly reachable database.

Encryption is named specifically, not left vague. Data access uses SHA-256 with RSA. Network traffic runs over TLS, and storage volumes are encrypted at rest.

Access controls follow role-based permissions through IAM. Passwords are hashed with salts, and accounts lock automatically after five failed login attempts. Password reset links expire after six hours, closing a common attack window.

Backups run near real-time, replicated across multiple availability zones. Content delivery runs through CloudFront, Amazon's CDN layer. None of this is vague marketing language.

It's the kind of specific, checkable detail a security page should actually have.

What's missing matters just as much. Simply.Coach doesn't publish audit dates or penetration-test results. The full SOC2 report still needs an NDA and a Leap or Surge account.

Here's how all four platforms compare on paper.

Coaching Software Compliance Claims Compared (August 2026)
Platform SOC2 Claim HIPAA / BAA GDPR Claim Hosting / Infra Transparency Notes
Simply.Coach Yes, report gated under NDA Yes, signs BAA on request Yes, covers EU/UK AWS VPC, named encryption, IAM roles Full SOC2 report needs Leap/Surge tier plus signed NDA
CoachAccountable Hosting provider (Deft) is SOC2-certified No, states itself not HIPAA compliant Not addressed in published materials Deft Chicago data center, DMZ database, hardware WAF Says outright it's the wrong tool if you need HIPAA
Paperbell Not published Not published Not published Not disclosed on public pages No certifications found as of August 2026, ask directly
Quenza Not prominently advertised Yes, claims HIPAA, will sign BAA Yes, plus CCPA claims AES-256 encryption, PIN/password security Says "Privacy by Design," SOC2 report not surfaced publicly
Sources: simply.coach/security, simply.coach/press-release/compliance-certification, coachaccountable.com/security, quenza.com, paperbell.com (August 2026).

Read that table carefully before you read too much into any single row. CoachAccountable's SOC2-certified hosting is real. But it's a hosting-provider credential, not a CoachAccountable credential.

Paperbell's blank row isn't proof of anything either way. It just means nothing is published. Ask before you assume.

Red Flags to Check on Any Coaching Software's Security Page

Most security pages exist to reassure, not inform. That's their job. A few patterns should make you slow down.

Marketing language with no specifics is the biggest one. "Bank-level encryption" means nothing without a named standard. Ask which encryption, AES-256 or something else, and where exactly it applies.

No mention of BAA availability is another. A platform can claim HIPAA compliance and never mention a Business Associate Agreement. That claim is doing more marketing than legal work.

Missing infrastructure details matter too. A real security page names its hosting provider, its encryption approach, and its access controls. A vague "trust us" page with none of that is telling you something by omission.

No named hosting provider is a related flag. Coaches rarely check this, but it's easy to verify. It tells you a lot about how seriously a vendor treats its own infrastructure.

No incident-response information rounds out the list. Every serious platform should say, somewhere, what happens after a breach. Silence on that question isn't neutral.

It's a gap.

One more pattern worth catching: GDPR claims with no mention of where data actually lives. Coverage depends partly on data location and transfer safeguards, not just a policy statement.

A security page that won't name a region or provider is telling you something. That omission is the answer. Ask directly instead of guessing.

Coaching Software Compliance Checklist

Turn the red flags above into a working checklist. Run it against Simply.Coach, or any platform you're weighing. Do it before you commit client data.

Check off what you've actually verified, not what you assume is probably true.

Coaching Software Compliance Checklist

Eight things worth confirming before you trust a platform with client data.

0 of 8 checked
You're asking the right questions. Most coaching software marketing pages won't survive this checklist unedited.

Where this leaves you is simple. Trust the platform that answers every item in writing. Be skeptical of the one that only answers in adjectives.

Simply.Coach clears most of this list, with the SOC2-under-NDA caveat noted throughout. CoachAccountable clears its hosting rows but fails the HIPAA row by its own admission. Paperbell and Quenza each clear some rows and leave others blank.

None of that is a verdict on their software quality, only on what's documented today.

Frequently Asked Questions

Is Simply.Coach HIPAA compliant?

Simply.Coach says yes. It will sign a Business Associate Agreement on request. That claim goes back to a compliance announcement around November 2022.

The BAA is what actually matters legally, not the marketing claim. Ask for the signed agreement before you assume PHI-level protections apply to your account.

What does it mean that CoachAccountable is SOC2-hosted but not HIPAA compliant?

CoachAccountable hosts its data with Deft, in a SOC2-certified Chicago data center. The company describes it as a HIPAA-compliant hosting environment. But CoachAccountable itself states plainly that the product is not HIPAA compliant.

In the company's own words, many HIPAA requirements conflict with its frictionless workflow. Simple as that.

Hosting-environment compliance and vendor compliance are different things. A coach who needs a BAA should look elsewhere.

Do I need a signed BAA or is a vendor's compliance claim enough?

A marketing claim of "HIPAA compliant" carries no legal weight by itself. Real compliance requires a signed BAA between the vendor and each customer.

A platform that won't commit to a BAA in writing is a red flag. Treat any compliance claim on its site as aspirational, not contractual.

Ready to review Simply.Coach's security page for yourself?

Aevum Transform connects coaches with Simply Coach's practice management platform. Nothing more. We are not affiliated with CoachAccountable, Paperbell, or Quenza.

Affiliate disclosure: This page contains affiliate links to Simply Coach. We may earn a commission if you buy through them, at no cost to you.

See our full disclosure policy.

Try Simply Coach + Bonuses →
Related Articles
Performance Resources