Paper session notes or Google Drive: why don't you follow the law and what alternative you have

"I write everything down in a notebook." "I have an Google Drive with each patient's folders." "I use an Excel spreadsheet."
If any of these phrases ring a bell, this article is for you. Because many psychologists believe that writing on paper or a basic digital file is "simple" or "safer" than using clinical software. Reality is exactly the opposite: paper and generic tools expose you to more legal risks, not less.
The law does not distinguish between a notebook, an Google Drive or specialized software. The obligation to protect your patients’ data is the same. What changes is your real ability to fulfill it.
The law is clear: the responsibility is yours, whatever you use
Law 26.529 — medical records
Art. 12 defines the medical records as the "compulsory chronological, foliated and complete document" that must record all actions performed on the patient. This definition applies irrespective of the support: paper, digital, notebook, Google Drive or specialized software.
Art. 18 states that the medical records is inviolable and that you, as a professional, are his depositary. You must "instrute the means and resources necessary to prevent access to the information contained therein by unauthorized persons."
The minimum retention period is 10 years since the last registered action (Art. 18).
Law 25.326 — Protection of Personal Data
Art. 9 obliges you to take the technical and organizational measures necessary to ensure the security and confidentiality of the data, avoiding their adulteration, loss, consultation or unauthorized processing.
Art. 9.2 prohibits recording personal data in files that do not meet technical conditions of integrity and security.
Important
These obligations apply whether you use a notebook or using state-of-the-art software. The difference is that with a notebook, fulfilling them is almost impossible.
The paper problem
It does not comply with "chronological, foliated and complete" (Art. 12)
In theory, a notebook can be chronological and foliated (if you put numbers on the pages). But in practice:
- What if you need to add information to a past session? You can't insert pages
- What if you're wrong?
- What if you fill out the notebook? You have to start another one and now the medical records is split into two notebooks
It does not comply with inviolability (Art. 18)
The law requires you to avoid unauthorized access. A notebook on a desk, a drawer with no key or a bag:
- It can be read by anyone who has physical access (cleaning staff, family members, another patient in the waiting room)
- It can be stolen without you noticing until much later.
- It has no record of who read it and when
- No password, encryption or access control
It does not comply with the conservation of 10 years (Art. 18)
Keeping a paper notebook for 10 years implies:
- Don't get wet, don't get damaged by moisture, don't burn
- Don't throw it away by mistake thinking I was old.
- Don't let the ink deteriorate over time
- Don't move and get lost in a box
- That you can find the information of a specific patient among hundreds of pages
How many notebooks 10 years ago do you keep in perfect condition? Probably none.
Not complying with delivery in 48 hours (Art. 14)
If a patient asks you for a copy of their medical records, you have 48 hours to deliver it, "authenticated by competent authority." With a notebook, that means:
- Photocopy the relevant pages (which may be distributed in several notebooks)
- Authenticate each photocopy
- Make sure the copy is complete
With software, it's a click and a PDF.
No backup
If it is lost, destroyed or stolen, there is no way to retrieve the information. and you are violating the legal obligation to keep the medical records for 10 years.
Note
A fire, a flood, a robbery. Any of these events irrecoverably destroy years of clinical records on paper. And the law does not accept "lost" as an excuse not to comply with the obligation of preservation.
The Google Drive problem (and similar)
"But I'm digital, I use Google Drive / Dropbox / OneDrive." Better than paper, but it has serious problems.
Not designed for health data
Google Drive is a generic storage tool. It does not have:
- medical records structure (chronological, foliated)
- Patient access control
- Audit log (who opened which file and when)
- Specific encryption for sensitive health data
- Compliance with Law 25.326
Google can access your files
According to Google's terms of service, the company can access the content stored in its services to operate and improve its products, comply with legal obligations and enforce its terms. This is incompatible with the duty of confidentiality of Art. 10 of the 25.326 Law.
Security depends 100% on you
| Risk | Did it ever happen to you? |
|---|---|
| By mistake share a folder with "anyone who has the link" | Probably. |
| Do not have two-step verification | Very common |
| Leave the session open on a shared computer | Come in. |
| Someone guesses your password. | If it's "123456," yes. |
| A family member or colleague with access to your Google account | Common |
No medical records structure
A Google Docs file with session notes is not a medical records in the terms of Art. 12 of the 26.529 Law. For it to be, you would need:
- That is chronological and leafy (consisting page numbers)
- Make it unalterable (someone can edit a Google Doc without leaving any visible trace)
- That informed consents are integrated (Art. 16)
- Recording of all proceedings
Google Docs does not guarantee the inalterability required by Art. 13 of the 26.529 Law for computerized medical records, as anyone with access can modify the document without permanent trace.
The "version history" is not an audit record
Google Docs has version history, but:
- Only shows changes, not accesses (you don't know who read the file)
- It is not an immutable record — the owner can delete the entire document
- It's not designed as legal evidence
- It does not comply with "non-rescribeable storage means" required by Art. 13
Direct comparison
| Legal requirement | Paper | Google Drive | Safe clinical software |
|---|---|---|---|
| Chronological and foliated (Art. 12, Law 26.529) | Hard to keep | It has no structure | Automatic |
| Inviolable (Art. 18) | No access control | Depends on your configuration | Encryption + access control |
| Conservation 10 years (Art. 18) | Very vulnerable (fire, water, theft) | Depends on your Google account | Automatic encrypted backups |
| Delivery within 48 hours (Art. 14) | Manual photocopies | Export Loose Files | Export PDF in one click |
| Unchangeability (Art. 13) | Visible but not controlled crossovers | Anyone can edit | Unchangeable records |
| Perdurability (Art. 13) | Ink is erased, paper deteriorates | Depends on Google | Professional infrastructure |
| Recoverability (Art. 13) | Impossible if lost | Google Trash (30 days) | Backups with prolonged retention |
| Integrity and safety (Art. 9, Law 25.326) | Nula | Basic | Designed for health data |
| Duty of confidentiality (Art. 10, Law 25.326) | Anyone can read the notebook | Google can access | E2E encryption: neither the provider reads |
| Access Log | No such thing | Partial | Complete |
| Integrated consent (Art. 16) | Attached loose paper | Separate file | Linked to the file |
"But it was always done that way."
That something has always been done in a way does not mean that it is legal or safe. The 26.529 Law is 2009 and the 25.326 Law is of the year 2000. Both establish clear obligations on the safety, integrity and inviolability of clinical records.
The fact that many professionals continue to use generic paper or tools does not mean that they are complying with the law. It means that they have not yet been audited.
The day a patient asks for your medical records
Can you give him a complete, chronological and authenticated copy in 48 hours? If the answer is "I would have to look in several notebooks" or "I'm not sure it's all," you have a legal problem.
The day a patient claims you
If a patient initiates a malpractice complaint or an ethical complaint, your medical records is your main defense. What if:
- The notebook was lost or deteriorated
- Google Drive files were edited after the fact
- You can't prove that you registered everything at the time.
An incomplete or unproven medical records is worse than having no medical records, because it suggests that there was modification or destruction.
"But software can also fail"
True. No system is perfect. But safe clinical software has layers of protection that paper and generic tools simply do not offer:
| Protection | Paper | Google Drive | Clinical software |
|---|---|---|---|
| Data encryption | No | In transit (HTTPS) | In transit + at rest + E2E |
| Automatic backup | No | Partial (if Google does not close your account) | Yes, daily, in separate location |
| Access Control | No | Basic (Google password) | Granular, per patient |
| Access audit | No | No | Yeah, full. |
| Immutability of records | No | No | Yes |
| Disaster recovery | Impossible | Partial | Designed for that. |
What should a psychologist who still uses paper do?
Step 1: Don't destroy what you have
Your paper records are legally valid, don't throw them away or destroy them.
Step 2: Migrate progressively
You don’t need to digitize 10 years of notebooks overnight. Start with:
- Active patients first
- Key data: reason for consultation, diagnosis, treatment plan
- Session notes from now on
Step 3: Use software designed for psychology
Not any software works. You need one that meets the requirements of Art. 13 (Law 26.529) and Art. 9 (Law 25.326). Check out our guide on how to choose safe clinical software.
Step 4: Keep old notebooks
Keep them in a safe place (keyed, protected from moisture and fire) during the legal period of 10 years since the last entry.
What should a psychologist using Google Drive do?
Step 1: Evaluate your current settings
- Do you have two-step verification enabled?
- Are there shared folders with "anyone who has the link"?
- Does anyone else have access to your Google account?
- Do you have backup outside of Google?
Step 2: Understand the limitations
Google Drive may serve as temporary storage or as additional backup, but not as a main system of medical records. It does not meet the requirements of inalterability, audit or structure of the 26.529 Act.
Step 3: Migrate to clinical software
Export your relevant files and start using a system designed for clinical practice.
How Brauni meets where paper and Google Drive cannot
| Requirement | How Brauni Meets It |
|---|---|
| Chronological and leafy (Art. 12) | Each note is recorded with date and automatic number. |
| Inviolable (Art. 18) | End-to-end encryption. Neither Brauni computer can read your data |
| Conservation (Art. 18) | Daily automatic backups, encrypted, in separate location |
| Delivery within 48 hours (Art. 14) | Export PDF complete in one click |
| Unchangeability (Art. 13) | Unchangeable record of each seat. Changes are displayed |
| Perdurability (Art. 13) | Cloud infrastructure with redundancy |
| Recoverability (Art. 13) | Quick restoration from backups |
| Security (Art. 9, Law 25.326) | Encryption, 2FA, access control, complete audit |
| Confidentiality (Art. 10, Law 25.326) | Encrypted data that cannot be read by the provider |
| Data not training AI | Your clinical information is never used to train models |
| Integrated consent (Art. 16) | Linked to patient file |
The detail of how Brauni meets each requirement is in digital medical records.
Free Brauni test for 30 days, no card
Automatic session notes, digital medical records and more.
Start for freeSummary
| Paper | Google Drive | Safe clinical software | |
|---|---|---|---|
| Legal liability | Same | Same | Same |
| Actual capacity to meet | Very low | Medium-low | High |
| Risk of loss | Very high | Medium | Low |
| Unauthorized access risk | Stop | Medium | Low |
| Cost of non-compliance | Administrative, civil and criminal sanctions | Idem | Idem, but the real risk is much lower |
| Conclusion | Not meeting most legal requirements | Partially but with significant gaps | Designed to meet |
Related articles

Privacy and Security
Choosing Safe Clinical Software: 10 Questions to Ask Your Provider
Security Checklist to evaluate any clinical management software for psychologists. Encryption, data residence, supplier access, certifications and 10 key questions.

Privacy and Security
What is Patient Privacy Monitoring and why any health app should have it
Encrypting clinical data is not enough. We explain what Patient Privacy Monitoring is (UEBA applied to health), why HIPAA demands it, and how Brauni detects suspicious access to medical records in real time.

Privacy and Security
WhatsApp with patients: limits, risks and good practices
How to use WhatsApp with patients without breaking the frame or confidentiality: clear boundaries, crisis protocol and good practices for psychologists.