Are psychotherapy notes protected differently under HIPAA?
Yes. Psychotherapy notes receive heightened protections under HIPAA — they must be stored separately from the general medical record, require specific patient authorization for most disclosures, and cannot be disclosed simply because a patient authorized release of their medical records. This separation must be enforced in your record-keeping system.
Does 42 CFR Part 2 apply to my practice?
Only if the practice qualifies as a Part 2 program. The rule reaches federally assisted programs that hold themselves out as providing substance use disorder diagnosis, treatment, or referral — not every psychiatrist, counselor, or therapist whose patients have a substance use disorder. Run that test and document the answer. Where Part 2 does apply, the 2024 final rule aligned its consent model more closely with HIPAA: a single patient consent can cover future uses and disclosures for treatment, payment, and health care operations, while distinct redisclosure, notice, and patient-rights obligations remain.
What does HIPAA compliance cost for a psychiatry practice?
Patient Protect starts at $39/month with no contracts — covering risk assessments, behavioral health-specific policies, 42 CFR Part 2 compliance, staff training, and continuous monitoring. Whether you use it alongside your existing compliance partner or as a standalone solution.
Are psychiatric records subject to additional protection beyond HIPAA?
Generally no, but several layers apply on top depending on the practice configuration: 42 CFR Part 2 for federally-assisted SUD treatment; state mental health confidentiality laws that often impose stricter standards than HIPAA; Schedule II prescribing rules under DEA. The compliance program that satisfies HIPAA is necessary but not sufficient for most psychiatric practices.
Can psychiatrists discuss patients with consulting colleagues without specific consent?
Treatment-purpose communication between healthcare providers is permitted under §164.506 without specific patient authorization. Treatment-purpose includes peer consultation about a current patient. The communication should still observe minimum-necessary under §164.502(b) and follow the practice's documented disclosure policy. Consultations going beyond treatment-purpose (academic case discussions, training scenarios) typically require de-identification or specific authorization.
How do psychiatric records intersect with insurance utilization review?
Insurance utilization review falls under §164.506's payment-purpose exception — disclosure of clinical information to support coverage decisions is permitted without specific authorization. Psychotherapy notes (when properly maintained separately) are exempt from this disclosure even for utilization review unless specifically authorized. Practices should document which record categories travel with utilization review submissions and which are withheld under the psychotherapy-notes exception.
Does a psychiatry practice have to complete a HIPAA Security Risk Analysis?
Yes. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a psychiatry practice that means the EHR including how psychotherapy notes are stored and separated where they exist, e-prescribing and EPCS systems with their identity and audit controls, telehealth platforms and recordings, laboratory interfaces used for medication monitoring, supervision and consultation workflows, portals and messaging, and access held by clinicians, supervisors, trainees, and administrative staff. Sensitivity does not create a different analysis — it raises the consequence of an incomplete one.
Which of our psychiatry vendors need Business Associate Agreements?
Any organization handling PHI on the practice's behalf: the EHR, telehealth platform, e-prescribing service where it maintains data for you, billing service, claims clearinghouse, transcription, secure messaging, scheduling and intake tools, cloud storage and backup, and IT support. Pharmacies dispensing to your patients and laboratories performing medication-monitoring tests are generally treating providers rather than business associates — provider-to-provider treatment disclosures do not require a BAA. Payers conducting utilization review are not business associates either. Classify each relationship and record the conclusion.
How does EPCS for controlled-substance prescribing relate to our HIPAA obligations?
They are separate frameworks that overlap in practice. EPCS is a DEA requirement governing electronic prescribing of controlled substances: identity proofing of the prescriber, two-factor authentication at signing, access controls over who can create and transmit orders, and audit records the practice must retain. HIPAA is a separate obligation covering the confidentiality, integrity, and availability of the ePHI in those same systems. Satisfying EPCS does not satisfy the Security Rule, and a HIPAA-compliant practice is not automatically EPCS-compliant. The overlap is real and useful — the authentication and audit controls EPCS forces are ones your risk analysis would likely call for anyway — but the two have to be documented as what they are.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a psychiatry practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.