HIPAA Compliance for Therapists, Counselors, and Mental Health Practices

If you are a therapist in private practice who transmits health information electronically to bill insurance, you are a covered entity under federal law. HIPAA for therapists is not optional, the Health Insurance Portability and Accountability Act applies directly to your practice and governs how you handle protected health information (PHI).
Mental health records require a higher standard of care because patients share their most vulnerable moments with you. A breach of that trust damages both your professional reputation and their personal well-being. HIPAA is a 1996 US federal law. Its administrative simplification rules protect the privacy and security of PHI, and these rules are enforced by the HHS Office for Civil Rights (OCR).
This guide breaks down what solo and small group behavioral health practices need to know: how to protect patient data, secure your technology, and stay on the right side of the law without getting overwhelmed by technical jargon.
Key Takeaways
- If you transmit health information electronically to bill insurance, you are a covered entity and HIPAA applies — even to a solo practice.
- Psychotherapy notes kept separate from the medical record get the strictest protection: disclosure generally requires the patient’s specific written authorization, even for treatment.
- Every vendor that touches electronic PHI must sign a business associate agreement (BAA). A missing BAA is itself a violation.
- Most breaches of unsecured PHI must be reported to affected individuals no later than 60 days after discovery.
- A documented risk analysis is the foundation. OCR has repeatedly cited a missing or incomplete risk analysis as the common thread in its HIPAA settlements.

Why HIPAA for Therapists Protects Mental Health Records Differently
The Privacy Rule governs how PHI may be used and disclosed. For mental health providers, the rules acknowledge that therapy records carry extra weight, the law treats certain types of notes differently than standard medical files, and mental health records confidentiality is a core focus.
| Record Type | Protection Level | Disclosure Requires |
|---|---|---|
| Standard PHI | Standard Privacy Rule protections | Patient authorization or a permitted use (treatment, payment, healthcare operations) |
| Psychotherapy notes, kept separate from the medical record | Strictest protection under HIPAA | Patient’s specific written authorization — even for treatment purposes |
| Psychotherapy notes, not separated from the medical record | Standard PHI protections only | Same as standard PHI; the extra safeguard is lost |
PHI is individually identifiable health information held or transmitted in any form. HHS recognizes 18 identifiers that can make health information identifiable: names, addresses, phone numbers, email addresses, and biometric identifiers among them. Removing all 18 identifiers creates a safe harbor that de-identifies the data.
The HIPAA privacy rule for mental health records states that psychotherapy notes get exceptionally strict protection. By definition, these are notes recorded by a mental health professional documenting or analyzing the contents of a conversation during a private counseling session. To qualify for this extra protection, the notes must be kept completely separate from the rest of the patient medical record.
What “kept separate” actually means: a locked file cabinet, a password-protected folder in your EHR, or an encrypted digital drive that clinical staff cannot open from the main patient record. If your notes live in the same digital folder as the billing record, the extra HIPAA protection does not apply.
When stored separately, you generally cannot disclose these notes without the patient’s specific written authorization, even to other healthcare providers for treatment purposes. This is the single most important documentation distinction for therapists to understand.
Therapists often ask when they can share mental health information without authorization. The Privacy Rule allows disclosures to prevent a serious and imminent threat to the health and safety of a person or the public. This intersects with a therapist’s duty to warn under HIPAA.
While state laws usually dictate your specific duty to warn, federal law permits you to disclose necessary information to law enforcement or family members to prevent harm. You must also provide patients with a Notice of Privacy Practices that clearly explains these boundaries.
The Modern Risk Surface for Therapy Practices
Therapy is no longer just a notepad in a quiet room. Today, you rely on software to run your business, and that digital shift introduces new risks for HIPAA compliance in private practice therapy.

What counts as ePHI in a therapy practice:
- Electronic health record (EHR) data
- Email containing patient information
- Cloud backups and file shares
- Telehealth video sessions and recordings
- Scheduling applications with patient names
- Digital intake forms
- Billing portal data
Electronic PHI (ePHI) is the electronic subset of patient data. Every tool that touches ePHI must be secured, this includes telehealth platforms, scheduling applications, and digital intake forms. If you use therapy software like a specialized EHR system, that vendor is considered a business associate.
You must know which vendors need a BAA to stay compliant. Therapist business associate agreements are legally binding contracts required before a business associate may access PHI. A BAA makes the vendor legally responsible for protecting the data and specifying permitted uses, safeguards, and breach reporting.
A missing or unsigned BAA is itself a violation of the Privacy Rule. A business associate may not create, receive, maintain, or transmit PHI without a signed contract in place. Using unsecured texting apps with clients, or failing to secure a BAA for your telehealth video platform, are common HIPAA violation examples therapists encounter.
If a vendor experiences a hack, or if you lose an unencrypted laptop containing patient files, you trigger mental health breach notification requirements. What you must do, and by when, depends on how many people the breach affects:
| Breach size | Who you must notify | Deadline |
|---|---|---|
| Any breach of unsecured PHI | Affected individuals | Without unreasonable delay, and no later than 60 days after discovery |
| 500 or more individuals | HHS and prominent media outlets in the affected area, in addition to individuals | Within the same 60-day window |
| Fewer than 500 individuals | HHS | Annually |
The stakes for data security are high. The 2024 Change Healthcare hack exposed the health data of 192.7 million people, the largest healthcare data breach in US history.
Small practices may not have millions of records, but civil penalties are still tiered by culpability. Fines range from roughly $100 to $50,000 per individual violation, with an annual cap that reaches about $1.5 million per violation category for willful neglect.
A Right-Sized HIPAA Program for a Solo or Small Group Practice
Building a compliance program for mental health providers does not have to be overwhelming. If you need the step-by-step roadmap to secure your practice, start with the basics. The Security Rule requires three safeguard categories to protect ePHI:
| Safeguard type | What it covers | Example controls |
|---|---|---|
| Administrative | Policies, people, and training | – Documented risk analysis<br>- Designated Privacy and Security Officers<br>- Regular HIPAA training for mental health staff |
| Physical | Facilities, workstations, and media | – Facility access controls<br>- Workstation security<br>- Locked storage for laptops and paper records<br>- Proper media disposal |
| Technical | The systems that store and move patient data | – Access controls with unique user IDs<br>- Audit logging<br>- Encryption of ePHI at rest and in transit |
The 5-stage process to get your practice compliant:
- Conduct a risk analysis — Document every place ePHI lives in your practice: your EHR, your phone, your email, your backup drive.
- Implement safeguards — Based on what the risk analysis found, put administrative, physical, and technical controls in place. Every gap identified gets a written control in response.
- Train staff and sign BAAs — Every person and every vendor who touches ePHI needs training and a signed agreement.
- Document everything — Policies, training records, access logs, and BAA files must be ready to produce if OCR comes asking.
- Review annually — Compliance is not a one-time project. Schedule a yearly review to catch new risks and update your documentation.
Every HIPAA settlement in 2025 traced back to one failure: no proper risk analysis. Every single one the government announced in the first 8 months of the year, 16 out of 16, cited a missing or incomplete risk analysis as the common thread.
Technical safeguards are where many practices fall short. Even if you use secure practice management software, your actual computers and networks need protection. Encryption has a real payoff here: properly encrypted data whose key was not compromised is generally not considered unsecured PHI, meaning its loss is usually not a reportable breach.
Compliance is an ongoing state you maintain and can evidence. It is a service LeadingIT delivers for clients to help you become and stay compliant. LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois practices meet HIPAA since 2010. We serve roughly 200 organizations and 2,500+ users from offices in Woodstock and Manteno.
LeadingIT operates the technical half of HIPAA, managing access controls, multi-factor authentication, encryption, tested backups, and monitoring. We sign BAAs with our practice clients as standard and help produce the documentation an auditor asks for when an investigation is triggered.
What triggers an OCR investigation: a complaint, a reported breach, or selection under the OCR audit program. The process is mostly a documentation request for your risk analysis, policies, training records, access logs, and BAAs.
See Where You Stand
Free 2-minute HIPAA Risk-Check: 8 plain-English questions, your audit-readiness level and the gaps to fix. No sign-up to see your result. free HIPAA compliance checklist
Related Guides
- What Is HIPAA? A Plain-English Guide for Business Owners
- What Is a HIPAA Business Associate Agreement (BAA)?
- How to Become HIPAA Compliant: A Step-by-Step Roadmap
- HIPAA Violations: Examples, Fines, and What Happens
Frequently Asked Questions
Do therapists have to comply with HIPAA?
Yes, if a therapist transmits health information electronically in connection with covered transactions like billing insurance, they are a covered entity. Solo practitioners and small group practices must follow the same privacy and security rules as large hospitals.
What are the HIPAA 3 rules?
The three rules that matter most for compliance are the Privacy Rule, the Security Rule, and the Breach Notification Rule. The Privacy Rule governs how PHI is used and disclosed. The Security Rule mandates technical, physical, and administrative safeguards for electronic data, while the Breach Notification Rule dictates how to report exposed data.
What is an example of a HIPAA violation as a therapist?
Common violations include texting patients PHI on unencrypted personal phones or using a telehealth video platform without a signed Business Associate Agreement. Another frequent violation is failing to conduct a formal, documented security risk analysis for the practice.
What is a red flag for a therapist?
A major red flag is a practice that relies on consumer-grade email or file-sharing tools to store patient session notes without proper encryption. Failing to train administrative staff on privacy policies or lacking a designated Privacy Officer are also significant compliance warning signs.
What are the four most common HIPAA violations?
Common enforcement findings include failing to conduct a risk analysis, lacking signed Business Associate Agreements with vendors, improper disposal of PHI, and unauthorized access to medical records. Addressing these areas can significantly reduce your risk of OCR penalties.
Secure Your Therapy Practice
Protecting your patients means protecting their data with the right technology and documentation. You can take the free Risk-Check to identify your gaps today. Learn more about LeadingIT’s HIPAA compliance services to see how we help Illinois practices meet these standards. To get started, book a call or contact us at 815-788-6041.
