Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Therapists

The HIPAA compliance and security operating system for therapy practices. Behavioral health records carry consequences most specialties never face — employment, custody, safety, and whether a patient returns at all. Patient Protect runs the risk analysis, psychotherapy-note controls, policies, training, and vendor agreements across your EHR, telehealth platform, and home offices, with the evidence kept where you can produce it.

A therapy practice is a HIPAA covered entity when it or a service acting for it electronically conducts an HHS-adopted standard transaction, such as a claim or eligibility inquiry. Cash-pay status alone does not answer the question. Covered practices must complete every duty below; non-covered practices may still be governed by state mental-health privacy, professional, and contractual requirements.

HIPAA compliance is not optional for a covered therapy practice.

If your practice is a HIPAA covered entity, it is required to maintain an active, documented compliance program — and if it performs covered functions as a Business Associate, it must implement the Security Rule and every other duty attaching to that role. The responsibility does not transfer to your EHR, IT company, consultant, insurance carrier, or software provider. Those partners can support the work; your practice remains responsible for completing it.

Watching one training video is not a compliance program. Downloading a policy template is not a compliance program. Signing one BAA is not a compliance program. HIPAA requires your practice to implement, maintain, and document the complete operating system behind each of those activities.

Your practice is required to do all of the following

  1. 01Conduct and document a Security Risk Analysis

    Identify every place electronic protected health information enters, moves through, or leaves the practice. Assess the systems, devices, people, vendors, locations, workflows, threats, and vulnerabilities that could compromise that information.

    45 CFR §164.308(a)(1)(ii)(A)

  2. 02Manage the risks the analysis uncovers

    Turn identified risks into a documented remediation plan. Assign responsibility, prioritize the work, implement safeguards, and preserve evidence showing how the practice responded.

    45 CFR §164.308(a)(1)(ii)(B)

  3. 03Designate Privacy and Security Officials

    Assign and document who is responsible for developing, maintaining, and enforcing the practice's privacy and security program. In a small practice, one person may perform both roles — but the responsibilities must still be assigned and documented.

    45 CFR §164.530(a) · §164.308(a)(2)

  4. 04Maintain written policies and procedures

    Document how the practice protects patient information, controls access, handles permitted disclosures, responds to incidents, enforces workforce accountability, and maintains required privacy and security safeguards.

    45 CFR §164.316(a) · §164.530(i)

  5. 05Train the entire workforce

    Train workforce members on the privacy policies relevant to their roles and maintain an ongoing security-awareness program. Preserve records showing who was trained, what the training covered, and when it was completed.

    45 CFR §164.530(b) · §164.308(a)(5)

  6. 06Identify and govern every Business Associate

    Determine which vendors and service providers create, receive, maintain, or transmit protected health information on the practice's behalf. Execute the required Business Associate Agreement before protected information flows and maintain the agreement as part of the practice's compliance record.

    45 CFR §164.502(e) · §164.308(b) · §164.504(e)

  7. 07Implement administrative, physical, and technical safeguards

    Control who can access patient information, secure the systems and locations where it is maintained, review activity, authenticate users, protect data integrity, and safeguard electronic transmission.

    45 CFR §164.308 · §164.310 · §164.312

  8. 08Protect patient privacy rights

    Maintain the required notices, authorization processes, complaint procedures, and workflows for responding to patient requests involving access, amendments, confidential communications, restrictions, and applicable disclosure accounting.

    45 CFR §164.520 · §164.524 · §164.526 · §164.522 · §164.528

  9. 09Prepare for incidents, outages, and breaches

    Maintain security-incident procedures, data backup, disaster recovery, emergency operations, mitigation, and breach-notification processes before an event occurs.

    45 CFR §164.308(a)(6) · §164.308(a)(7) · Subpart D

  10. 10Preserve proof that the work was completed

    Retain the assessments, risk decisions, policies, training records, official designations, BAAs, acknowledgments, incident records, and other documentation needed to demonstrate what the practice actually did.

    45 CFR §164.316(b) · §164.530(j)

The Security Risk Analysis is where the work begins.

The Security Rule requires an accurate, thorough assessment of the risks and vulnerabilities affecting every form of electronic protected health information your practice creates, receives, maintains, or transmits. This is commonly called a Security Risk Analysis, or SRA.

The federal government publishes its own Security Risk Assessment Tool for small and medium-sized practices. You are not required to use that particular tool. You are required to perform and document the underlying analysis.

Patient Protect provides its own guided SRA. It walks the practice through the assessment in plain language, identifies what is missing, and carries those findings into risk management, remediation, policies, tasks, and documentation — so the assessment ends with the problem assigned and resolved, not merely named.

A five-minute readiness quiz is not an SRA. Reviewing only your EHR is not an SRA. Reusing an old checklist that no longer reflects your systems, vendors, workforce, or workflows is not an SRA.

That includes our own free tool. The Patient Protect Score is a free exposure scan and a starting point. It is not your completed Security Risk Analysis, and we will not tell you it is.

What a therapy practice’s Security Risk Analysis must cover

Behavioral health practices hold information whose exposure can affect a patient's employment, family relationships, safety, custody matters, reputation, and willingness to continue treatment. The SRA must reflect the sensitivity and the actual way therapy is delivered.

  • The EHR or practice-management system and the access available to clinicians, supervisors, billing personnel, and administrative staff
  • Telehealth platforms, clinician home offices, personal or practice-issued devices, local networks, waiting rooms, chat logs, and recordings
  • Patient portals, scheduling tools, intake forms, email, text messaging, and after-hours communication
  • The creation, separation, storage, access, and disclosure of psychotherapy notes when the practice maintains them
  • Supervision, peer consultation, case-review, and group-therapy documentation workflows
  • Billing services, payment systems, cloud storage, backup, transcription, and other vendors that handle PHI on the practice's behalf
  • The risk of inappropriate disclosure to relatives, employers, attorneys, schools, courts, or other third parties

What the behavioral health compliance program must also address

  • A written distinction between ordinary clinical records and psychotherapy notes
  • Separate controls and authorization procedures for psychotherapy notes when they are created
  • State mental-health confidentiality, minor-consent, and duty-to-warn or duty-to-protect requirements
  • 42 CFR Part 2 procedures when the organization qualifies as a Part 2 program
  • Training for clinicians and administrative staff on family requests, subpoenas, court orders, employer inquiries, and crisis disclosures

Generic healthcare policies are not enough when the practice's daily work involves uniquely sensitive records and disclosure decisions.

What HIPAA actually looks like for behavioral health & therapy practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Mental health practices operate under HIPAA as covered entities through standard electronic transactions — claims submission, eligibility verification, e-prescribing where applicable. State mental health confidentiality laws apply on top and frequently impose stricter standards than HIPAA. Programs treating substance use disorder under federal-assistance criteria are subject to 42 CFR Part 2, which has stricter consent, redisclosure, and breach-notification rules than HIPAA. State professional licensure boards (LMFT, LCSW, LPCC, psychology) layer additional record-keeping and disclosure rules.

OCR enforcement patterns

OCR's enforcement record in mental health includes cases involving disclosure of psychiatric records to family members without authorization, psychotherapy notes accessed beyond minimum-necessary, unsecured patient communication via personal-device texting and email, missing breach notification on incidents involving fewer than 500 individuals (the small-incident reporting requirement is often missed), and inadequate workforce training on the specific disclosure rules that apply to mental health records.

Standards beyond HIPAA

42 CFR Part 2 for substance use disorder programs imposes a separate compliance framework that overlaps with HIPAA but is not satisfied by HIPAA compliance alone. Section 164.524(a)(1)(i) creates a special protection for psychotherapy notes — the right-of-access exclusion only applies when notes are maintained separately from the rest of the record. State-by-state duty-to-warn laws for threats of harm to self or others create disclosure obligations that intersect with HIPAA's permissive disclosure provisions under §164.512(j). State mental health confidentiality statutes vary widely in scope.

Common compliance gaps

Audits and incidents in mental health practice routinely surface psychotherapy notes mixed into the general patient record (loses the §164.524 protection), informal patient communication via personal-device SMS and email, group therapy session records mishandled (every member of the group has independent rights), supervision and case-consultation platforms operating without BAAs, missing 42 CFR Part 2 protocols where the practice treats SUD under federal-assistance criteria, and inadequate documentation of duty-to-warn disclosures.

Compliance documentation, then state record law.

HIPAA requires six-year retention of policy documentation; state mental health record-retention laws frequently require longer periods (some states impose seven to fifteen years post-discharge or post-last-encounter). 42 CFR Part 2 has its own retention framework for SUD records. Psychotherapy notes maintained separately under §164.524(a)(1)(i) protection can be retained or destroyed under different rules than the general record — practices choosing to destroy psychotherapy notes per the clinician's discretion should document the policy explicitly. Long-term retention obligations for minors typically run until age of majority plus statute-of-limitations period.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to behavioral health & therapy practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

HIPAA training for behavioral health & therapy practices.

A 19-module HIPAA Foundations series with the workforce roles, PHI workflows, disclosure scenarios, and vendor risks that actually apply to behavioral health & therapy practices— not a generic healthcare course.

Where behavioral health & therapy practices are most exposed.

Psychotherapy notes require protections beyond standard ePHI

Under HIPAA, psychotherapy notes have heightened protections — they cannot be disclosed even with a standard patient authorization in many cases. Your compliance program needs to distinguish between clinical notes and psychotherapy notes. The penalty for mishandling them is severe.

Telehealth platforms may not be HIPAA compliant

Zoom, Doxy.me, SimplePractice — a signed BAA is the starting point, not the finish line. The COVID-era enforcement discretion for telehealth has ended, so the ordinary Security Rule expectations apply in full: encryption appropriate to your risk analysis, controlled recording storage, and a configuration the practice can evidence.

42 CFR Part 2 adds federal substance abuse protections

42 CFR Part 2 does not attach to every clinician who treats substance use disorder. It applies to federally assisted programs that hold themselves out as providing SUD diagnosis, treatment, or referral, and to the records those programs create. Run that test first. If your practice qualifies, Part 2 adds consent, redisclosure, and notice obligations on top of HIPAA — and HIPAA compliance alone does not satisfy them. If it does not qualify, say so in your documentation rather than leaving the question open.

Solo practitioners carry the same HIPAA burden as hospitals

A solo therapist handling 40 patients is a covered entity with the same 45+ HIPAA requirements as a health system. No IT department, no compliance officer, no legal team — but the same regulatory exposure and the same potential fines.

Built for behavioral health & therapy practices, not hospital systems.

Risk assessment for behavioral health

SRA wizard covers telehealth, psychotherapy notes, and substance abuse record workflows specific to therapy practices. Not a generic healthcare questionnaire.

BAA tracking for telehealth vendors

Track agreements with Zoom, SimplePractice, TherapyNotes, and every other vendor. Get expiration alerts. Know your compliance status before OCR asks.

Secure patient communication

Stop using personal email and texts for appointment reminders and session follow-ups. BAA-gated messaging keeps clinical information inside your compliance perimeter.

Workforce training modules

HIPAA training designed for therapy practice staff — including reception, billing, and clinical roles. Completion documented automatically for audit readiness.

42 CFR Part 2 overlay for substance use disorder confidentiality

Mental health practices treating SUD face a stricter confidentiality framework than HIPAA alone. The platform's policy generation handles 42 CFR Part 2's specific consent, redisclosure, and breach notification rules in addition to HIPAA — most generic compliance vendors treat them identically and miss the gap.

Psychotherapy notes handled per §164.524(a)(1)(i)

Psychotherapy notes are explicitly excluded from the right-of-access rule when maintained separately from the rest of the record. The platform supports the separate-storage architecture required, plus the access-log distinction between psychotherapy notes and the broader record — without which the practice loses both the legal protection and the audit defense.

HIPAA already requires the work. Patient Protect starts at $39 a month.

For a covered practice, HIPAA does not ask whether the organization has the budget, internal expertise, or spare time to build a compliance program. The obligation already exists. The only real question is whether you run it through spreadsheets, generic templates, disconnected training and scattered agreements — or keep the whole program in one place.

  • Guided Security Risk Analysis
  • Risk-management and remediation workflows
  • 48 customizable policies and procedures
  • HIPAA Foundations workforce training
  • Completion tracking and verifiable training certificates
  • Workforce and vendor management
  • Business Associate Agreement tracking and documentation
  • Compliance scoring and centralized audit evidence
Start your 14-day free trial

$39 per office per month · Up to 25 personnel · No long-term contract

State-specific HIPAA rules for behavioral health & therapy practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for behavioral health & therapy practices.

Do solo therapists need HIPAA compliance software?

Yes. Solo practitioners are covered entities under HIPAA with identical regulatory requirements. OCR does not reduce obligations based on practice size. A single therapist handling patient records faces the same 45+ HIPAA requirements — and the same fine schedule — as a hospital system.

How does Patient Protect handle psychotherapy notes?

Patient Protect's risk assessment and policy framework addresses the heightened protections required for psychotherapy notes under §164.508(a)(2), including separate authorization requirements, access controls, and disclosure restrictions that go beyond standard ePHI handling.

Is telehealth HIPAA compliant?

Telehealth can be HIPAA compliant — but only with the right configuration. Your platform vendor must sign a BAA, transmission must be encrypted to the standard your risk analysis supports, and you need documented policies for remote access. The COVID-era enforcement discretion has ended, so remote care carries the same Security Rule obligations as in-person care.

What does HIPAA compliance cost for a therapy practice?

Behavioral health compliance consultants typically charge $4,000–$10,000 per year. Patient Protect starts at $39/month ($468/year) with no contracts — covering risk assessments, policies, BAA management, telehealth compliance documentation, and ongoing monitoring.

Are psychotherapy notes treated differently than other mental health records under HIPAA?

Yes. Section 164.524(a)(1)(i) excludes psychotherapy notes from the patient right of access when those notes are kept separately from the rest of the record. The exclusion only applies if the practice actually maintains the notes in a separate file or system — notes mixed into the general medical record lose the protection. Patient Protect's architecture supports the separate-storage requirement explicitly.

When does 42 CFR Part 2 apply on top of HIPAA?

42 CFR Part 2 applies to federally assisted programs that hold themselves out as providing substance use disorder diagnosis, treatment, or referral. That is a narrower test than it first appears: a mental health practice that treats co-occurring SUD is not automatically a Part 2 program, and many are not. Run the qualifying-program analysis and document the conclusion either way. Where Part 2 does apply, the 2024 final rule moved its consent model closer to HIPAA — a single patient consent can now cover future uses and disclosures for treatment, payment, and health care operations — while keeping distinct redisclosure, notice, and patient-rights requirements. HIPAA compliance alone still does not satisfy Part 2.

Can therapists text or email patients?

Ordinary SMS and unencrypted email are not secure channels — but HIPAA does not prohibit them outright. The Privacy Rule permits communicating through a patient's requested channel with reasonable safeguards and a documented warning about the risks (§164.522(b)), and the Security Rule still requires the practice to assess and document that decision. For clinical content tied to a mental health condition or treatment, a secure messaging platform is the channel a practice can actually govern, restrict, and evidence.

Does a therapy practice have to complete a HIPAA Security Risk Analysis?

If the practice is a covered entity, yes — and cash-pay status alone does not answer that question. Where the practice or a service acting for it electronically conducts an adopted standard transaction, it must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a therapy practice that means the EHR, the telehealth platform, clinician home offices and personal devices, chat logs and recordings, the patient portal, intake forms, after-hours messaging, supervision and case-consultation workflows, and any separately maintained psychotherapy notes. A practice that is not covered still typically faces state mental-health privacy and professional obligations that require substantially similar work.

Which of our behavioral health vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR or practice-management vendor, telehealth platform, billing service, transcription service, cloud storage and backup, secure messaging, scheduling and intake tools, and any supervision or case-consultation platform that stores identifiable session content. The last one is the most commonly missed in behavioral health, because consultation platforms feel like professional tools rather than vendors. Other treating clinicians involved in a patient's care are not business associates — provider-to-provider treatment disclosures are a different relationship. Classify each vendor by what it actually does before signing anything.

How do group therapy records work when every member has independent HIPAA rights?

Each participant is a patient with their own rights of access and amendment, and each participant's session record can contain information about the others. That is the tension. The practical answer is documentation architecture: keep individual clinical records that address the individual patient's participation and response, rather than one narrative record describing the group. When a member requests access, the practice must be able to produce that member's record without disclosing another participant's information — which is far easier if the records were structured that way from the start than if they have to be redacted afterward. Group consent to participate is not the same as authorization to disclose one member's information to another.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a therapy practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your patients trust you with their most sensitive data.

Make sure your compliance protects them. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions