Neurofeedback Therapy Records: Intake to Release Workflow
A parent's attorney faxes your front desk a request for "the complete file, including all raw EEG data and session recordings" for a 14-year-old who completed 32 sessions at your clinic. Your practice management system holds the progress notes and the superbills. The raw session data lives in a vendor's cloud portal that only two clinicians can log into. You have 30 days.
That gap — between what your chart holds and what your equipment generates — is the entire administrative problem with neurofeedback therapy encounters. This post is about the records, retention, authorization, and vendor workflow around those visits. It is not clinical guidance and makes no treatment recommendations. It is written for the people who answer the records request, sign the vendor contract, and get the call when something goes out the door wrong.
Inventory What a Neurofeedback Therapy Encounter Actually Generates
Before you can release records, retain records, or scope a breach, you need a written inventory. Most practices that offer this service accumulate artifacts in four or five separate systems, and nobody has ever mapped them.
Build the list with the clinician who runs the equipment, not from memory. A typical encounter produces:
- The clinical note in your EHR or practice management system, including consent documentation and any assessment instruments the clinician administered.
- Software-generated session data — the amplifier or training software's per-session output: timestamps, protocol or montage identifiers, channel data, session duration, and whatever summary metrics the product produces.
- Raw signal files, if your configuration retains them. These are often large, proprietary-format files stored locally on the training workstation or synced to a vendor portal.
- Vendor-hosted reports — PDFs or dashboards generated in a manufacturer's cloud environment and sometimes emailed to clinicians.
- Billing and financial records, including self-pay ledgers, package purchase agreements, and any superbill you handed the patient for out-of-network submission.
- Correspondence — referral letters to and from prescribers, school communications, and portal messages.
Write the inventory as a table with three columns: artifact, system of record, and who has access. That single document answers most records-request questions and drives your risk analysis, your BAA list, and your retention schedule.
Is Raw EEG Data Part of the Designated Record Set?
Short answer: if your practice uses it to make care decisions or bills against it, treat it as part of the designated record set and produce it on request.
The designated record set under 45 CFR 164.501 covers medical and billing records maintained by or for a covered entity, plus any other records the entity uses in whole or in part to make decisions about individuals. Software-generated session summaries, protocol logs, and progress metrics from neurofeedback therapy sessions fall squarely inside that definition when the clinician relies on them. The location of the file does not change the analysis — data held by a vendor on your behalf is still "maintained for" you.
Raw signal files are the harder call. If your clinicians never open them and they exist only because the software writes them by default, you have a defensible argument that they are not used to make decisions. Do not improvise that determination at the counter. Decide it once, in writing, with your privacy officer and a clinician, document the reasoning, and apply it consistently to every request. Inconsistency is what turns a records dispute into a complaint. HHS's right of access guidance is the controlling reference, and OCR has pursued a long line of enforcement actions over access failures.
The 30-Day Clock and the Format Problem
You have 30 calendar days from receipt of the request, with one permitted 30-day extension if you notify the individual in writing of the reason and the new date. Your intake channel matters: if requests arrive by fax, portal message, and voicemail, all three start clocks, and only one of them is logged.
Format is where these encounters get awkward. Individuals may request an electronic copy, and you must provide it in the form and format requested if it is readily producible. A proprietary raw data file is often not readily producible in any way the requester can open. The workable practice:
- Produce the standard exportable outputs — clinical notes, session summary PDFs, billing records — as searchable PDF.
- For proprietary files, offer the native export and state plainly in your cover letter what software reads it.
- If native export is genuinely not possible, document why and offer an alternative format you can produce, then confirm the requester's agreement in writing.
Fees You Can and Cannot Charge
You may charge a reasonable, cost-based fee limited to labor for copying, supplies, and postage. You may not charge for search and retrieval time, and you may not charge a per-page fee for records you maintain electronically and produce electronically. Extracting a large data set from a vendor portal feels like billable work. It is retrieval. Absorb it.
Psychotherapy Notes Are a Narrow Exception — Do Not Stretch It
Practices delivering these services under a behavioral health license often assume the psychotherapy notes exception shields most of the file. It does not. Under 45 CFR 164.501, psychotherapy notes are the clinician's personal process notes documenting a private counseling session, kept separate from the rest of the record. Anything else is fair game.
Specifically excluded from the definition: medication prescription and monitoring, session start and stop times, modalities and frequencies of treatment furnished, results of clinical tests, and summaries of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress. Nearly everything a neurofeedback session generates — start and stop times, modality, frequency, test results, progress summaries — is on that exclusion list.
If your clinicians keep process notes, they must be in a physically or logically separate location. Notes commingled in the same encounter record lose the protection entirely. HHS's page on HIPAA and mental health information is worth circulating to clinical staff annually.
The Vendor Layer: Portals, Loaner Equipment, and Missing BAAs
Every cloud-connected component in this workflow creates or receives protected health information on your behalf. That means a business associate agreement before data flows, not after the first support ticket.
Run this list against your executed agreements:
- The amplifier or training software manufacturer, if it hosts session data, generates reports in its cloud, or provides remote support that reaches into patient data.
- Any remote-session or telehealth platform used for supervised at-home training.
- Your assessment instrument publisher, if scoring happens on their servers.
- The IT contractor who images and maintains the training workstations.
- Your billing service and any clearinghouse.
- Cloud storage where clinicians park exported files — including the personal drive account someone set up in 2023.
Two patterns show up repeatedly in these practices. First, the equipment manufacturer is treated as a device supplier rather than a business associate, so nobody ever asks for a BAA even though session data syncs to their servers nightly. Second, a clinician emails session reports to a referring prescriber using a plain consumer email account. Both are contract-and-training problems, not technology problems.
If you find gaps, close the paper first. You can generate a signature-ready Business Associate Agreement through a six-step wizard with PDF and DOCX export — a one-time purchase, no subscription — which is faster than waiting on a vendor's legal department to send a template you will have to redline anyway.
Loaner and Home-Use Equipment
If your practice loans hardware for at-home sessions, add three items to your checklist: a signed equipment agreement that addresses data on the device, a documented wipe procedure at return, and a named person responsible for performing it. Devices returned with a previous patient's session files on local storage are an impermissible disclosure waiting for a witness. NIST's SP 800-66r2 maps Security Rule requirements to practical safeguards and is a reasonable backbone for that procedure.
Authorizations for Schools, Coaches, Attorneys, and Courts
Records from these encounters get requested by parties outside healthcare more often than most clinical services. School IEP teams, athletic programs, disability insurers, and family-law attorneys all come calling.
None of them get records on a phone call. A valid authorization under 45 CFR 164.508 needs a specific description of the information, the named recipient, the purpose, an expiration date or event, the individual's signature and date, and the required statements about revocation and redisclosure. "Release all records" scrawled on a school letterhead is not an authorization.
Train the front desk on one rule: requests from anyone other than the patient, their personal representative, or a treating provider go to the privacy officer before anything leaves the building. Log the decision either way.
Minors and Split Custody
Parental access to a minor's record is governed largely by state law, and state behavioral health confidentiality statutes are frequently stricter than HIPAA. Keep a one-page summary of your state's rule at the records desk, and require a copy of the custody order on file before releasing to a non-custodial parent. If your practice operates in a federally assisted substance use disorder program, the 42 CFR Part 2 requirements — whose alignment with HIPAA reached its compliance date in February 2026 — layer additional consent and notice obligations on top of everything above.
Retention: Two Different Clocks
HIPAA requires six years of retention for compliance documentation: policies, risk analyses, BAAs, authorizations, training records, and breach determinations. That clock runs six years from creation or last effective date, whichever is later.
HIPAA does not set a medical record retention period. State law and payer contracts do, and for minors the period commonly runs from the age of majority rather than the date of service — which can mean holding pediatric session data for well over a decade. Write both clocks into a single retention schedule that names each artifact from your inventory, the applicable period, and the deletion owner. Then confirm your vendor's contract does not delete data on a shorter cycle than your schedule requires. Portal data purged at 24 months does not help you at year seven.
Cash-Pay Does Not Automatically Mean Outside HIPAA
Many practices offering these services run substantially self-pay. Some conclude they are not covered entities. Occasionally that is true — a provider that never conducts a covered electronic transaction may sit outside HIPAA entirely. But if you submit a single electronic claim, verify eligibility electronically, or transmit an electronic remittance for any patient, you are a covered entity for your whole practice.
And falling outside HIPAA does not mean falling outside regulation. The FTC's Health Breach Notification Rule reaches non-HIPAA health apps and connected devices, and state privacy statutes apply regardless. Document your covered-entity determination in writing, with the reasoning, and revisit it whenever your billing model changes.
Assign This Workflow by Name
Roles, not intentions. A workable division for a small practice:
- Front desk: date-stamps and logs every records request within one business day, routes non-patient requests to the privacy officer, verifies identity per your written procedure.
- Privacy officer: validates authorizations, decides scope against the designated record set inventory, tracks the 30-day clock on a shared log, signs the cover letter.
- Clinical lead: performs vendor-portal exports, applies the documented rule on raw signal files, confirms nothing from another patient is in the export package.
- Practice administrator: maintains the artifact inventory, the BAA register, and the retention schedule; reviews all three at least annually and after any vendor change.
Rehearse it once with a fake request before a real one arrives. The failure mode is almost never bad intent — it is a request that sat in a fax tray for three weeks while everyone assumed someone else owned it.
Start with the inventory table this week, then reconcile it against your signed agreements. If the reconciliation turns up a vendor touching session data without a contract in place, build and execute the BAA before the next sync runs — and if your broader policy set and risk analysis are equally overdue, automating the full compliance document set is a faster path than rewriting templates from scratch.