The risks of using mental health apps with patients don't announce themselves. A client downloads something between sessions, taps "agree" on a lengthy terms of service, and starts sharing their fears and thought patterns with an app that has no clinical oversight, no meaningful privacy protections, and no awareness of the therapeutic work you're doing together. Clients are turning to these tools whether you're involved or not.
Consumer mental health apps operate in a regulatory space that most therapists haven't needed to think about until a client brings one into their care. The core tension isn't that apps are inherently problematic; it's that the absence of clinical context creates real exposure for your clients and, by extension, your practice.
Most aren't. HIPAA applies to covered entities: healthcare providers, insurers, and their business associates. A mood tracker or AI chatbot sold directly to consumers sits outside that scope entirely, which means it can legally collect, share, or sell sensitive user data with very few constraints. There's no comprehensive federal privacy law filling this gap. A client who assumes their journaling app is held to the same standards as your practice is working from a false premise.
Mental health apps collect unusually sensitive data: mood states, rumination patterns, named anxieties, relationship conflicts. That information has value to advertisers, and the sharing mechanisms are embedded in code, not marketing copy.
The FTC's record makes this concrete. In 2024, BetterHelp was fined $7.8 million after sharing users' mental health data with third parties for advertising despite explicit confidentiality assurances. Investigations into widely used apps have found similar practices buried in difficult-to-read privacy policies across the category.
Through standard technical infrastructure. Analytics SDKs, third-party tracking libraries, and device identifiers are routinely embedded in app code. When a client opens a mental health app, those components can capture session behavior and mood inputs and route them to advertising networks as part of normal operations. Consent happens when the client taps "agree," and a survey spanning the U.S., U.K., EU, and Canada found that one in three people rarely or never read privacy policies when using digital services.
When a client engages with an app that doesn't know their treatment plan or your clinical approach, they're receiving a kind of shadow guidance that may directly interfere with session work. Apps that position themselves as mental health support carry implicit authority with clients. If what the app suggests conflicts with what you're working on together, you may not know until the session reveals an unexpected shift.
There's also a subtler risk: apps that function as perceived substitutes for professional care can erode client motivation to do the harder work that only happens in session.
Consider a client working through trauma-informed care where you have deliberately paced exposure work. Between sessions, they consult a wellness AI that recommends an exposure technique or reframe that's clinically contraindicated for where they are in treatment. The client tries it. The following session is harder than it needs to be, and you're working backward without knowing why.
This is a real gap. Unless there's a mechanism for visibility into what a client engaged with between sessions, you're working with incomplete information at every appointment.
The evaluation doesn't need to be complicated, but it needs to be intentional. Four questions matter most:
Does the app have genuine HIPAA compliance, including a Business Associate Agreement that your practice can sign? "Privacy-first design" isn't the same as HIPAA compliance.
Is the data practice transparent? What the app collects, who it shares with, and whether third-party SDKs are embedded should be clear, not buried.
Is it grounded in established therapeutic frameworks like CBT, DBT, ACT, or IFS? Or is it offering generic wellness content that could pull against your treatment approach?
Does it give you visibility and control? A HIPAA-compliant mental health app that provides no clinician oversight gives you compliance without clinical value. A clinician-guided app for therapy should let you assign activities, set topic guardrails, and see what your clients are actually engaging with between sessions.
Therapy Ally™ was built specifically for the clinical gap that generic consumer apps create. It's purpose-built for therapy practices.
Therapists using Therapy Ally select the Ally that aligns with their therapeutic approach, set guardrails on topics, assign homework that extends session work through the week, and review structured summaries before each appointment. The between-session mental health support your clients are already seeking gets replaced with something therapeutically aligned and visible to your practice.
The Clinician Console gives your practice the structure and oversight to ensure that what clients access between sessions reinforces the work happening in session, rather than working against it. Therapy Ally is HIPAA compliant, giving your practice a foundation of trust to build on. Learn more at clinician.therapyally.ai.