Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Therapists

The HIPAA compliance and security operating system for therapy practices. Behavioral health records carry consequences most specialties never face — employment, custody, safety, and whether a patient returns at all. Patient Protect runs the risk analysis, psychotherapy-note controls, policies, training, and vendor agreements across your EHR, telehealth platform, and home offices, with the evidence kept where you can produce it.

What HIPAA actually looks like for behavioral health & therapy practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Mental health practices operate under HIPAA as covered entities through standard electronic transactions — claims submission, eligibility verification, e-prescribing where applicable. State mental health confidentiality laws apply on top and frequently impose stricter standards than HIPAA. Programs treating substance use disorder under federal-assistance criteria are subject to 42 CFR Part 2, which has stricter consent, redisclosure, and breach-notification rules than HIPAA. State professional licensure boards (LMFT, LCSW, LPCC, psychology) layer additional record-keeping and disclosure rules.

OCR enforcement patterns

OCR's enforcement record in mental health includes cases involving disclosure of psychiatric records to family members without authorization, psychotherapy notes accessed beyond minimum-necessary, unsecured patient communication via personal-device texting and email, missing breach notification on incidents involving fewer than 500 individuals (the small-incident reporting requirement is often missed), and inadequate workforce training on the specific disclosure rules that apply to mental health records.

Standards beyond HIPAA

42 CFR Part 2 for substance use disorder programs imposes a separate compliance framework that overlaps with HIPAA but is not satisfied by HIPAA compliance alone. Section 164.524(a)(1)(i) creates a special protection for psychotherapy notes — the right-of-access exclusion only applies when notes are maintained separately from the rest of the record. State-by-state duty-to-warn laws for threats of harm to self or others create disclosure obligations that intersect with HIPAA's permissive disclosure provisions under §164.512(j). State mental health confidentiality statutes vary widely in scope.

Common compliance gaps

Audits and incidents in mental health practice routinely surface psychotherapy notes mixed into the general patient record (loses the §164.524 protection), informal patient communication via personal-device SMS and email, group therapy session records mishandled (every member of the group has independent rights), supervision and case-consultation platforms operating without BAAs, missing 42 CFR Part 2 protocols where the practice treats SUD under federal-assistance criteria, and inadequate documentation of duty-to-warn disclosures.

Compliance documentation, then state record law.

HIPAA requires six-year retention of policy documentation; state mental health record-retention laws frequently require longer periods (some states impose seven to fifteen years post-discharge or post-last-encounter). 42 CFR Part 2 has its own retention framework for SUD records. Psychotherapy notes maintained separately under §164.524(a)(1)(i) protection can be retained or destroyed under different rules than the general record — practices choosing to destroy psychotherapy notes per the clinician's discretion should document the policy explicitly. Long-term retention obligations for minors typically run until age of majority plus statute-of-limitations period.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to behavioral health & therapy practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

HIPAA training for behavioral health & therapy practices.

A 19-module HIPAA Foundations series with the workforce roles, PHI workflows, disclosure scenarios, and vendor risks that actually apply to behavioral health & therapy practices— not a generic healthcare course.

Where behavioral health & therapy practices are most exposed.

Psychotherapy notes require protections beyond standard ePHI

Under HIPAA, psychotherapy notes have heightened protections — they cannot be disclosed even with a standard patient authorization in many cases. Your compliance program needs to distinguish between clinical notes and psychotherapy notes. The penalty for mishandling them is severe.

Telehealth platforms may not be HIPAA compliant

Zoom, Doxy.me, SimplePractice — a signed BAA is the starting point, not the finish line. The COVID-era enforcement discretion for telehealth has ended, so the ordinary Security Rule expectations apply in full: encryption appropriate to your risk analysis, controlled recording storage, and a configuration the practice can evidence.

42 CFR Part 2 adds federal substance abuse protections

42 CFR Part 2 does not attach to every clinician who treats substance use disorder. It applies to federally assisted programs that hold themselves out as providing SUD diagnosis, treatment, or referral, and to the records those programs create. Run that test first. If your practice qualifies, Part 2 adds consent, redisclosure, and notice obligations on top of HIPAA — and HIPAA compliance alone does not satisfy them. If it does not qualify, say so in your documentation rather than leaving the question open.

Solo practitioners carry the same HIPAA burden as hospitals

A solo therapist handling 40 patients is a covered entity with the same 45+ HIPAA requirements as a health system. No IT department, no compliance officer, no legal team — but the same regulatory exposure and the same potential fines.

Built for behavioral health & therapy practices, not hospital systems.

Risk assessment for behavioral health

SRA wizard covers telehealth, psychotherapy notes, and substance abuse record workflows specific to therapy practices. Not a generic healthcare questionnaire.

BAA tracking for telehealth vendors

Track agreements with Zoom, SimplePractice, TherapyNotes, and every other vendor. Get expiration alerts. Know your compliance status before OCR asks.

Secure patient communication

Stop using personal email and texts for appointment reminders and session follow-ups. BAA-gated messaging keeps clinical information inside your compliance perimeter.

Workforce training modules

HIPAA training designed for therapy practice staff — including reception, billing, and clinical roles. Completion documented automatically for audit readiness.

42 CFR Part 2 overlay for substance use disorder confidentiality

Mental health practices treating SUD face a stricter confidentiality framework than HIPAA alone. The platform's policy generation handles 42 CFR Part 2's specific consent, redisclosure, and breach notification rules in addition to HIPAA — most generic compliance vendors treat them identically and miss the gap.

Psychotherapy notes handled per §164.524(a)(1)(i)

Psychotherapy notes are explicitly excluded from the right-of-access rule when maintained separately from the rest of the record. The platform supports the separate-storage architecture required, plus the access-log distinction between psychotherapy notes and the broader record — without which the practice loses both the legal protection and the audit defense.

State-specific HIPAA rules for behavioral health & therapy practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

District of Columbia compliance requirements for behavioral health & therapy practices

In addition to federal HIPAA requirements, behavioral health & therapy practices operating in District of Columbia must comply with the following state-specific obligations.

Breach notification deadline

In the most expedient time possible and without unreasonable delay, subject to the needs of law enforcement and any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.

The statute does not fix a numeric outer bound. Unreasonable delay is itself a violation and may result in state enforcement action, so treat the operative timeframe as the shortest window your incident circumstances reasonably support.

Attorney General notification

Required for all breaches

Your practice must notify the state AG in addition to affected patients and HHS.

District of Columbia-specific laws & requirements

DC uses the New-York pattern: HIPAA covers individual notice, but AG notice is independent

For HIPAA-regulated entities operating in DC, satisfying HIPAA breach-notification obligations to individuals is deemed to satisfy the § 28-3852 individual-notice requirement under subsection (g). But the separate DC Attorney General notification obligation under § 28-3852(b-1) is triggered independently once a breach affects 50 or more DC residents, and HIPAA compliance does not substitute for that AG notice. Practices notifying HHS under HIPAA still owe a separate written AG notice to DC.

Source: D.C. Code § 28-3852(a)

Verified against primary state authority as of August 2026. General reference — consult legal counsel for your specific obligations.

Primary sources: code.dccouncil.gov · oag.dc.gov

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for behavioral health & therapy practices.

Do solo therapists need HIPAA compliance software?

Yes. Solo practitioners are covered entities under HIPAA with identical regulatory requirements. OCR does not reduce obligations based on practice size. A single therapist handling patient records faces the same 45+ HIPAA requirements — and the same fine schedule — as a hospital system.

How does Patient Protect handle psychotherapy notes?

Patient Protect's risk assessment and policy framework addresses the heightened protections required for psychotherapy notes under §164.508(a)(2), including separate authorization requirements, access controls, and disclosure restrictions that go beyond standard ePHI handling.

Is telehealth HIPAA compliant?

Telehealth can be HIPAA compliant — but only with the right configuration. Your platform vendor must sign a BAA, transmission must be encrypted to the standard your risk analysis supports, and you need documented policies for remote access. The COVID-era enforcement discretion has ended, so remote care carries the same Security Rule obligations as in-person care.

What does HIPAA compliance cost for a therapy practice?

Behavioral health compliance consultants typically charge $4,000–$10,000 per year. Patient Protect starts at $39/month ($468/year) with no contracts — covering risk assessments, policies, BAA management, telehealth compliance documentation, and ongoing monitoring.

Are psychotherapy notes treated differently than other mental health records under HIPAA?

Yes. Section 164.524(a)(1)(i) excludes psychotherapy notes from the patient right of access when those notes are kept separately from the rest of the record. The exclusion only applies if the practice actually maintains the notes in a separate file or system — notes mixed into the general medical record lose the protection. Patient Protect's architecture supports the separate-storage requirement explicitly.

When does 42 CFR Part 2 apply on top of HIPAA?

42 CFR Part 2 applies to federally assisted programs that hold themselves out as providing substance use disorder diagnosis, treatment, or referral. That is a narrower test than it first appears: a mental health practice that treats co-occurring SUD is not automatically a Part 2 program, and many are not. Run the qualifying-program analysis and document the conclusion either way. Where Part 2 does apply, the 2024 final rule moved its consent model closer to HIPAA — a single patient consent can now cover future uses and disclosures for treatment, payment, and health care operations — while keeping distinct redisclosure, notice, and patient-rights requirements. HIPAA compliance alone still does not satisfy Part 2.

Can therapists text or email patients?

Ordinary SMS and unencrypted email are not secure channels — but HIPAA does not prohibit them outright. The Privacy Rule permits communicating through a patient's requested channel with reasonable safeguards and a documented warning about the risks (§164.522(b)), and the Security Rule still requires the practice to assess and document that decision. For clinical content tied to a mental health condition or treatment, a secure messaging platform is the channel a practice can actually govern, restrict, and evidence.

Does a therapy practice have to complete a HIPAA Security Risk Analysis?

If the practice is a covered entity, yes — and cash-pay status alone does not answer that question. Where the practice or a service acting for it electronically conducts an adopted standard transaction, it must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a therapy practice that means the EHR, the telehealth platform, clinician home offices and personal devices, chat logs and recordings, the patient portal, intake forms, after-hours messaging, supervision and case-consultation workflows, and any separately maintained psychotherapy notes. A practice that is not covered still typically faces state mental-health privacy and professional obligations that require substantially similar work.

Which of our behavioral health vendors need Business Associate Agreements?

Any organization handling PHI on the practice's behalf: the EHR or practice-management vendor, telehealth platform, billing service, transcription service, cloud storage and backup, secure messaging, scheduling and intake tools, and any supervision or case-consultation platform that stores identifiable session content. The last one is the most commonly missed in behavioral health, because consultation platforms feel like professional tools rather than vendors. Other treating clinicians involved in a patient's care are not business associates — provider-to-provider treatment disclosures are a different relationship. Classify each vendor by what it actually does before signing anything.

How do group therapy records work when every member has independent HIPAA rights?

Each participant is a patient with their own rights of access and amendment, and each participant's session record can contain information about the others. That is the tension. The practical answer is documentation architecture: keep individual clinical records that address the individual patient's participation and response, rather than one narrative record describing the group. When a member requests access, the practice must be able to produce that member's record without disclosing another participant's information — which is far easier if the records were structured that way from the start than if they have to be redacted afterward. Group consent to participate is not the same as authorization to disclose one member's information to another.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for a therapy practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your patients trust you with their most sensitive data.

Make sure your compliance protects them. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions