Do solo therapists need HIPAA compliance software?
Yes. Solo practitioners are covered entities under HIPAA with identical regulatory requirements. OCR does not reduce obligations based on practice size. A single therapist handling patient records faces the same 45+ HIPAA requirements — and the same fine schedule — as a hospital system.
How does Patient Protect handle psychotherapy notes?
Patient Protect's risk assessment and policy framework addresses the heightened protections required for psychotherapy notes under §164.508(a)(2), including separate authorization requirements, access controls, and disclosure restrictions that go beyond standard ePHI handling.
Is telehealth HIPAA compliant?
Telehealth can be HIPAA compliant — but only with the right configuration. Your platform vendor must sign a BAA, transmission must be encrypted to the standard your risk analysis supports, and you need documented policies for remote access. The COVID-era enforcement discretion has ended, so remote care carries the same Security Rule obligations as in-person care.
What does HIPAA compliance cost for a therapy practice?
Behavioral health compliance consultants typically charge $4,000–$10,000 per year. Patient Protect starts at $39/month ($468/year) with no contracts — covering risk assessments, policies, BAA management, telehealth compliance documentation, and ongoing monitoring.
Are psychotherapy notes treated differently than other mental health records under HIPAA?
Yes. Section 164.524(a)(1)(i) excludes psychotherapy notes from the patient right of access when those notes are kept separately from the rest of the record. The exclusion only applies if the practice actually maintains the notes in a separate file or system — notes mixed into the general medical record lose the protection. Patient Protect's architecture supports the separate-storage requirement explicitly.
When does 42 CFR Part 2 apply on top of HIPAA?
42 CFR Part 2 applies to federally assisted programs that hold themselves out as providing substance use disorder diagnosis, treatment, or referral. That is a narrower test than it first appears: a mental health practice that treats co-occurring SUD is not automatically a Part 2 program, and many are not. Run the qualifying-program analysis and document the conclusion either way. Where Part 2 does apply, the 2024 final rule moved its consent model closer to HIPAA — a single patient consent can now cover future uses and disclosures for treatment, payment, and health care operations — while keeping distinct redisclosure, notice, and patient-rights requirements. HIPAA compliance alone still does not satisfy Part 2.
Can therapists text or email patients?
Ordinary SMS and unencrypted email are not secure channels — but HIPAA does not prohibit them outright. The Privacy Rule permits communicating through a patient's requested channel with reasonable safeguards and a documented warning about the risks (§164.522(b)), and the Security Rule still requires the practice to assess and document that decision. For clinical content tied to a mental health condition or treatment, a secure messaging platform is the channel a practice can actually govern, restrict, and evidence.
Does a therapy practice have to complete a HIPAA Security Risk Analysis?
If the practice is a covered entity, yes — and cash-pay status alone does not answer that question. Where the practice or a service acting for it electronically conducts an adopted standard transaction, it must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For a therapy practice that means the EHR, the telehealth platform, clinician home offices and personal devices, chat logs and recordings, the patient portal, intake forms, after-hours messaging, supervision and case-consultation workflows, and any separately maintained psychotherapy notes. A practice that is not covered still typically faces state mental-health privacy and professional obligations that require substantially similar work.
Which of our behavioral health vendors need Business Associate Agreements?
Any organization handling PHI on the practice's behalf: the EHR or practice-management vendor, telehealth platform, billing service, transcription service, cloud storage and backup, secure messaging, scheduling and intake tools, and any supervision or case-consultation platform that stores identifiable session content. The last one is the most commonly missed in behavioral health, because consultation platforms feel like professional tools rather than vendors. Other treating clinicians involved in a patient's care are not business associates — provider-to-provider treatment disclosures are a different relationship. Classify each vendor by what it actually does before signing anything.
How do group therapy records work when every member has independent HIPAA rights?
Each participant is a patient with their own rights of access and amendment, and each participant's session record can contain information about the others. That is the tension. The practical answer is documentation architecture: keep individual clinical records that address the individual patient's participation and response, rather than one narrative record describing the group. When a member requests access, the practice must be able to produce that member's record without disclosing another participant's information — which is far easier if the records were structured that way from the start than if they have to be redacted afterward. Group consent to participate is not the same as authorization to disclose one member's information to another.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for a therapy practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.