5 min read Security

Video Platform Security Settings for Remote EMDR

A practical settings checklist for locking down Zoom, Teams, Meet, and similar platforms before running confidential remote EMDR sessions with clients.

By CloudEMDR Team
Video Platform Security Settings for Remote EMDR

CloudEMDR runs alongside whichever video platform you already use for the session itself — Zoom, Microsoft Teams, Google Meet, Skype, Doxy.me, or another. That platform is where the sensitive conversation actually happens, so its own security settings matter just as much as anything in your EMDR software. Here's a practical checklist for locking it down before a session.

Why this is worth a separate pass

Most video platforms ship with sensible defaults, but “sensible for a general business call” and “appropriate for a confidential therapy session” aren’t always the same thing. A handful of settings are worth checking deliberately rather than trusting the defaults, and it only takes a few minutes to work through them once per platform.

A practical settings checklist

Access control

  • Require a passcode or password on every session, not just a link. A link alone can be forwarded, guessed, or stumbled into.
  • Use a waiting room or lobby where you personally admit each participant, rather than letting anyone with the link join directly.
  • Generate a new meeting ID for recurring clients periodically, rather than reusing one static personal link indefinitely.
  • Lock the meeting once your client has joined, if your platform supports it, so no one else can enter after the session starts.

Recording and storage

  • Turn off automatic cloud recording as a default setting, and only record when there’s a specific, consented reason to.
  • If you do record, know exactly where the recording is stored, who else at your organization (if any) can access it, and how long it’s retained before deletion.
  • Disable participant-side recording where your platform allows it, so a client can’t inadvertently (or deliberately) save a session without your knowledge.

Default to not recording

Unless you have a specific clinical or supervisory reason to record, and clear consent for it, the simplest and safest default is to leave recording off entirely.

In-session privacy

  • Disable screen sharing for participants, so only you can share your screen unless a specific moment calls for otherwise.
  • Turn off file transfer inside the call unless you actually need it — an open channel for arbitrary files is one more thing that doesn’t need to be available by default.
  • Review who’s on your account’s contact or directory list if your platform has one, so a client’s name or presence isn’t visible to others who use the same organizational account.
  • Use a private, dedicated space for the call on your end, with headphones so your side of the conversation isn’t audible to anyone else nearby.

Account-level basics

  • Turn on two-factor authentication for your video platform account itself. It’s a common weak point that has nothing to do with the call and everything to do with someone else logging in as you.
  • Keep the platform’s app or client updated, since security fixes usually ship in routine updates rather than special announcements.
  • Review connected third-party apps or integrations periodically, and remove any you no longer use — each one is a little more surface area.

Check your specific plan and region

Exact setting names, defaults, and what's available on a free versus paid tier vary by platform and change over time. Treat this as a checklist of categories to check in your platform's own settings, not a literal menu path.

Where CloudEMDR sits in this picture

CloudEMDR is deliberately built to need as little of your client’s information as possible: a client joining a Remote Session only needs to open a link and click start — no account, no personal data collected on their end. That doesn’t replace locking down your video platform, but it does mean the EMDR layer of the session isn’t adding its own separate pile of client data to protect. If you’re building out a broader privacy or data-handling policy for your practice, our piece on GDPR compliance in digital therapy covers the wider principles worth applying regardless of your platform.

Getting the technical side dialed in generally — not just security settings but camera, audio, and connection quality — also reduces the chances of a rushed, distracted setup where a security setting gets skipped. Our teletherapy tech setup guide covers that ground, and if a heavy caseload of remote sessions is wearing on you specifically, our piece on vicarious trauma and self-care is worth a read too.

Build it into your routine, not a one-time check

The most reliable way to keep these settings in place is to fold them into a setup routine you run before sessions generally, rather than a one-off configuration you do once and forget. Platforms periodically change their defaults with updates, so a quick recheck every few months is worth the time. Pairing this with a consistent pre-session checklist for consent and logistics means the security side doesn’t get treated as separate from everything else you’re already doing to prepare.

Keep the EMDR layer simple and private

CloudEMDR never asks your client for personal information — they just click start. Try the moving dot free, or start a Pro trial for distraction-free Remote Sessions.

Wanna try out CloudEMDR?

Get started with remote therapy in just a few clicks. CloudEMDR works with any video call software and you can get started today, for free.