Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Psychiatry & Counseling

The HIPAA compliance and security operating system for psychiatry practices. Psychotherapy notes, controlled-substance prescribing, telehealth, and medication monitoring each carry their own rules on top of the Security Rule. Patient Protect runs the risk analysis across all of it, manages policies, training, and vendor agreements, and keeps the record you would need to produce.

Psychiatry practices that electronically bill, check eligibility, request authorization, or conduct other adopted transactions are HIPAA covered entities. Once covered, the duties below are required. Psychotherapy notes, qualifying Part 2 records, controlled-substance prescribing, and state mental-health law add obligations; they do not replace HIPAA's core program.

HIPAA compliance is not optional for a covered psychiatry practice.

If your practice is a HIPAA covered entity, it is required to maintain an active, documented compliance program — and if it performs covered functions as a Business Associate, it must implement the Security Rule and every other duty attaching to that role. The responsibility does not transfer to your EHR, IT company, consultant, insurance carrier, or software provider. Those partners can support the work; your practice remains responsible for completing it.

Watching one training video is not a compliance program. Downloading a policy template is not a compliance program. Signing one BAA is not a compliance program. HIPAA requires your practice to implement, maintain, and document the complete operating system behind each of those activities.

Your practice is required to do all of the following

  1. 01Conduct and document a Security Risk Analysis

    Identify every place electronic protected health information enters, moves through, or leaves the practice. Assess the systems, devices, people, vendors, locations, workflows, threats, and vulnerabilities that could compromise that information.

    45 CFR §164.308(a)(1)(ii)(A)

  2. 02Manage the risks the analysis uncovers

    Turn identified risks into a documented remediation plan. Assign responsibility, prioritize the work, implement safeguards, and preserve evidence showing how the practice responded.

    45 CFR §164.308(a)(1)(ii)(B)

  3. 03Designate Privacy and Security Officials

    Assign and document who is responsible for developing, maintaining, and enforcing the practice's privacy and security program. In a small practice, one person may perform both roles — but the responsibilities must still be assigned and documented.

    45 CFR §164.530(a) · §164.308(a)(2)

  4. 04Maintain written policies and procedures

    Document how the practice protects patient information, controls access, handles permitted disclosures, responds to incidents, enforces workforce accountability, and maintains required privacy and security safeguards.

    45 CFR §164.316(a) · §164.530(i)

  5. 05Train the entire workforce

    Train workforce members on the privacy policies relevant to their roles and maintain an ongoing security-awareness program. Preserve records showing who was trained, what the training covered, and when it was completed.

    45 CFR §164.530(b) · §164.308(a)(5)

  6. 06Identify and govern every Business Associate

    Determine which vendors and service providers create, receive, maintain, or transmit protected health information on the practice's behalf. Execute the required Business Associate Agreement before protected information flows and maintain the agreement as part of the practice's compliance record.

    45 CFR §164.502(e) · §164.308(b) · §164.504(e)

  7. 07Implement administrative, physical, and technical safeguards

    Control who can access patient information, secure the systems and locations where it is maintained, review activity, authenticate users, protect data integrity, and safeguard electronic transmission.

    45 CFR §164.308 · §164.310 · §164.312

  8. 08Protect patient privacy rights

    Maintain the required notices, authorization processes, complaint procedures, and workflows for responding to patient requests involving access, amendments, confidential communications, restrictions, and applicable disclosure accounting.

    45 CFR §164.520 · §164.524 · §164.526 · §164.522 · §164.528

  9. 09Prepare for incidents, outages, and breaches

    Maintain security-incident procedures, data backup, disaster recovery, emergency operations, mitigation, and breach-notification processes before an event occurs.

    45 CFR §164.308(a)(6) · §164.308(a)(7) · Subpart D

  10. 10Preserve proof that the work was completed

    Retain the assessments, risk decisions, policies, training records, official designations, BAAs, acknowledgments, incident records, and other documentation needed to demonstrate what the practice actually did.

    45 CFR §164.316(b) · §164.530(j)

The Security Risk Analysis is where the work begins.

The Security Rule requires an accurate, thorough assessment of the risks and vulnerabilities affecting every form of electronic protected health information your practice creates, receives, maintains, or transmits. This is commonly called a Security Risk Analysis, or SRA.

The federal government publishes its own Security Risk Assessment Tool for small and medium-sized practices. You are not required to use that particular tool. You are required to perform and document the underlying analysis.

Patient Protect provides its own guided SRA. It walks the practice through the assessment in plain language, identifies what is missing, and carries those findings into risk management, remediation, policies, tasks, and documentation — so the assessment ends with the problem assigned and resolved, not merely named.

A five-minute readiness quiz is not an SRA. Reviewing only your EHR is not an SRA. Reusing an old checklist that no longer reflects your systems, vendors, workforce, or workflows is not an SRA.

That includes our own free tool. The Patient Protect Score is a free exposure scan and a starting point. It is not your completed Security Risk Analysis, and we will not tell you it is.

What a psychiatry practice’s Security Risk Analysis must cover

Psychiatry combines highly sensitive records, psychotherapy-note protections, telehealth, prescribing, laboratory monitoring, supervision, and high-consequence disclosure decisions. The SRA must reflect all of those systems and workflows.

  • The EHR and the storage, separation, access, and disclosure of psychotherapy notes when they are created
  • E-prescribing and EPCS systems, prescriber identity controls, multifactor authentication, and audit trails
  • Telehealth platforms, recordings, chat, remote devices, home offices, and patient communication
  • Laboratory interfaces used for medication monitoring
  • Supervision, consultation, care coordination, and shared-record workflows
  • Billing, payment, portals, intake, scheduling, messaging, email, text, and e-fax
  • Access by clinicians, supervisors, trainees, administrative personnel, and external service providers

What the psychiatry compliance program must also address

  • A written distinction between the general clinical record and psychotherapy notes
  • Specific storage, access, and authorization controls for psychotherapy notes when maintained
  • DEA and EPCS controls when controlled substances are prescribed electronically
  • 42 CFR Part 2 requirements when the organization qualifies as a Part 2 program
  • State mental-health confidentiality and duty-to-warn or duty-to-protect rules
  • Training on family, custody, employer, insurance, court, law-enforcement, and crisis-disclosure scenarios

The sensitivity of psychiatric information does not create a separate version of HIPAA. It raises the consequence of getting the same core obligations wrong.

What HIPAA actually looks like for psychiatry & counseling practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Psychiatric practices operate under HIPAA as covered entities through standard electronic transactions — claims, eligibility, e-prescribing including controlled substances under DEA EPCS. 42 CFR Part 2 applies separately to programs treating substance use disorder under federal-assistance criteria. State mental health confidentiality laws apply on top, frequently with stricter standards than HIPAA. Section 164.524(a)(1)(i) creates a specific protection for psychotherapy notes when maintained separately from the general record. State pharmacy boards govern controlled-substance prescribing. State medical boards impose practice and supervision rules.

OCR enforcement patterns

OCR's psychiatric enforcement record includes cases of psychotherapy notes mixed with the general record (losing the §164.524 protection), controlled-substance prescribing audit trail gaps, treatment record disclosure to family members without authorization, and disclosure errors during insurance utilization review. The DEA has been active in EPCS enforcement; the combination of OCR HIPAA enforcement and DEA prescribing enforcement creates a dual-framework risk for psychiatric practices that prescribe controlled substances.

Standards beyond HIPAA

Section 164.524(a)(1)(i) psychotherapy notes protection requires separate-storage architecture. 42 CFR Part 2 for substance use disorder programs. State mental health confidentiality laws (the spectrum is wide; some states impose substantially stricter requirements than HIPAA). DEA EPCS for Schedule II prescribing (stimulants for ADHD, certain mood-stabilizing medications). State controlled-substance e-prescribing requirements. Duty-to-warn variations by state intersecting with HIPAA's permissive disclosure under §164.512(j).

Common compliance gaps

Recurring gaps in psychiatric practice compliance: psychotherapy notes architecture not properly implemented (notes mixed into the general EHR record), EPCS not fully deployed for Schedule II prescribing where required, supervisor-supervisee record sharing scenarios without documented framework, 42 CFR Part 2 not implemented where the practice treats SUD under federal-assistance criteria, state mental health confidentiality requirements not layered on top of HIPAA training, and inadequate documentation of duty-to-warn disclosures.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State psychiatric record laws govern patient record retention (some states impose seven to fifteen years post-discharge or post-last-encounter). 42 CFR Part 2 has its own retention rules separate from HIPAA. Psychotherapy notes maintained separately under §164.524(a)(1)(i) can be retained or destroyed under different rules — the practice must document the retention policy explicitly. DEA EPCS audit trail retention is separate. Long-term retention obligations for minor patients typically run until age of majority plus statute-of-limitations period.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to psychiatry & counseling practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

Where psychiatry & counseling practices are most exposed.

Psychotherapy notes have protections beyond standard ePHI

Under HIPAA, psychotherapy notes cannot be disclosed even with a standard patient authorization in many cases. They must be stored separately from the medical record and require their own specific authorization for release. Most EHR systems don't enforce this separation architecturally.

42 CFR Part 2 adds federal substance abuse protections

If you treat substance use disorders, patient records carry additional federal protections. Disclosure rules under Part 2 are stricter than standard HIPAA — requiring patient consent for most disclosures, including to other healthcare providers. Make sure your compliance program explicitly addresses Part 2.

E-prescribing controlled substances requires EPCS compliance

Electronic Prescribing of Controlled Substances (EPCS) adds identity verification, two-factor authentication, and audit trail requirements on top of standard HIPAA obligations. Make sure your compliance program explicitly addresses EPCS controls.

Telehealth sessions create long-lived sensitive records

Recorded therapy sessions, chat transcripts, and asynchronous messaging are ePHI with heightened sensitivity. Storage, access controls, and retention policies for psychiatric telehealth records require specific attention beyond standard telehealth compliance.

Built for psychiatry & counseling practices, not hospital systems.

Psychiatry-specific risk assessment

SRA wizard covers psychotherapy note handling, 42 CFR Part 2, EPCS compliance, and telehealth session security — not a generic practice questionnaire.

Policy generation for behavioral health

Auto-generated policies covering psychotherapy note protections, substance abuse record handling, and EPCS procedures — customized to your practice.

Secure messaging with BAA gating

HIPAA-compliant messaging that automatically gates content based on BAA status — critical for practices communicating about sensitive behavioral health information.

Staff training on psychiatric privacy

Training modules covering psychotherapy note protections, Part 2 requirements, EPCS compliance, and handling sensitive behavioral health records.

Schedule II e-prescribing and EPCS compliance

Psychiatric practices prescribing stimulants for ADHD or other Schedule II medications operate under DEA's electronic prescribing of controlled substances framework on top of HIPAA. The platform handles the dual-framework audit-trail and identity-proofing requirements without duplicating record-keeping.

Psychotherapy notes architecture for §164.524(a)(1)(i) protection

Psychotherapy notes maintained separately from the rest of the record qualify for the right-of-access exclusion. Most EHRs handle this through a process that's easy to misconfigure. Patient Protect's policy generation produces the documentation architecture and access-log distinction the protection requires.

HIPAA already requires the work. Patient Protect starts at $39 a month.

For a covered practice, HIPAA does not ask whether the organization has the budget, internal expertise, or spare time to build a compliance program. The obligation already exists. The only real question is whether you run it through spreadsheets, generic templates, disconnected training and scattered agreements — or keep the whole program in one place.

  • Guided Security Risk Analysis
  • Risk-management and remediation workflows
  • 48 customizable policies and procedures
  • HIPAA Foundations workforce training
  • Completion tracking and verifiable training certificates
  • Workforce and vendor management
  • Business Associate Agreement tracking and documentation
  • Compliance scoring and centralized audit evidence
Start your 14-day free trial

$39 per office per month · Up to 25personnel · No long-term contract

State-specific HIPAA rules for psychiatry & counseling practices.

HIPAA is federal. What a state adds on top of it varies more than most compliance guidance admits — some states impose their own notification deadline and regulator notice, and others exclude HIPAA covered entities from their breach statute entirely. Select your state to see which of those is true where you practice.

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk analysis structured to §164.308(a)(1)(ii)(A)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 9. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, compliance scoring, secure messaging, and standard PIPAA usage.

Recommended

Pro

$99/mo

Everything in Basic, plus the patient-facing workflows. Patient Management and Digital Forms, expanded PIPAA usage, and up to 50 personnel.

See full feature comparison →

Common questions about HIPAA compliance for psychiatry & counseling practices.

Are psychotherapy notes protected differently under HIPAA?

Yes. Psychotherapy notes receive heightened protections under HIPAA — they must be stored separately from the general medical record, require specific patient authorization for most disclosures, and cannot be disclosed simply because a patient authorized release of their medical records. This separation must be enforced in your record-keeping system.

Does 42 CFR Part 2 apply to my practice?

Only if the practice qualifies as a Part 2 program. The rule reaches federally assisted programs that hold themselves out as providing substance use disorder diagnosis, treatment, or referral — not every psychiatrist, counselor, or therapist whose patients have a substance use disorder. Run that test and document the answer. Where Part 2 does apply, the 2024 final rule aligned its consent model more closely with HIPAA: a single patient consent can cover future uses and disclosures for treatment, payment, and health care operations, while distinct redisclosure, notice, and patient-rights obligations remain.

What does HIPAA compliance cost for a psychiatry practice?

Patient Protect starts at $39/month with no contracts — covering risk assessments, behavioral health-specific policies, 42 CFR Part 2 compliance, staff training, and continuous monitoring. Whether you use it alongside your existing compliance partner or as a standalone solution.

Are psychiatric records subject to additional protection beyond HIPAA?

Generally no, but several layers apply on top depending on the practice configuration: 42 CFR Part 2 for federally-assisted SUD treatment; state mental health confidentiality laws that often impose stricter standards than HIPAA; Schedule II prescribing rules under DEA. The compliance program that satisfies HIPAA is necessary but not sufficient for most psychiatric practices.

Can psychiatrists discuss patients with consulting colleagues without specific consent?

Treatment-purpose communication between healthcare providers is permitted under §164.506 without specific patient authorization, and treatment-purpose includes peer consultation about a current patient. Minimum necessary does not apply to that consultation — §164.502(b)(2)(i) exempts disclosures to a provider for treatment — so what you share is a clinical judgement governed by your documented disclosure policy rather than by §164.502(b). Consultations that go beyond treatment-purpose, such as academic case discussion or training scenarios, typically require de-identification or specific authorization, and minimum necessary does apply once the purpose is no longer treatment.

How do psychiatric records intersect with insurance utilization review?

Insurance utilization review falls under §164.506's payment-purpose exception — disclosure of clinical information to support coverage decisions is permitted without specific authorization. Psychotherapy notes (when properly maintained separately) are exempt from this disclosure even for utilization review unless specifically authorized. Practices should document which record categories travel with utilization review submissions and which are withheld under the psychotherapy-notes exception.

Does a psychiatry practice have to complete a HIPAA Security Risk Analysis?

Yes. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a psychiatry practice that means the EHR including how psychotherapy notes are stored and separated where they exist, e-prescribing and EPCS systems with their identity and audit controls, telehealth platforms and recordings, laboratory interfaces used for medication monitoring, supervision and consultation workflows, portals and messaging, and access held by clinicians, supervisors, trainees, and administrative staff. Sensitivity does not create a different analysis — it raises the consequence of an incomplete one.

Which of our psychiatry vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR, telehealth platform, e-prescribing service where it maintains data for you, billing service, claims clearinghouse, transcription, secure messaging, scheduling and intake tools, cloud storage and backup, and IT support. Pharmacies dispensing to your patients and laboratories performing medication-monitoring tests are generally treating providers rather than business associates — provider-to-provider treatment disclosures do not require a BAA. Payers conducting utilization review are not business associates either. Classify each relationship and record the conclusion.

How does EPCS for controlled-substance prescribing relate to our HIPAA obligations?

They are separate frameworks that overlap in practice. EPCS is a DEA requirement governing electronic prescribing of controlled substances: identity proofing of the prescriber, two-factor authentication at signing, access controls over who can create and transmit orders, and audit records the practice must retain. HIPAA is a separate obligation covering the confidentiality, integrity, and availability of the ePHI in those same systems. Satisfying EPCS does not satisfy the Security Rule, and a HIPAA-compliant practice is not automatically EPCS-compliant. The overlap is real and useful — the authentication and audit controls EPCS forces are ones your risk analysis would likely call for anyway — but the two have to be documented as what they are.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a psychiatry practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Psychiatric records carry protections that most HIPAA programs miss.

See your real exposure in five minutes. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions