Telehealth Counseling: A Practice Operations Playbook
Tomorrow — February 16, 2026 — is the compliance date for HHS's final rule aligning 42 CFR Part 2 with HIPAA. If your practice provides telehealth counseling and any part of your program holds itself out as offering substance use disorder diagnosis, treatment, or referral, your consent forms, notice of privacy practices, breach procedures, and accounting-of-disclosures workflow all changed. This guide is for the administrator who has to make that real: who updates which form, which vendor needs a new agreement, and what your front desk says when a patient in a different state books a video session.
Nothing here is clinical guidance. It is the operational and privacy layer underneath the session.
Two Deadlines Sitting on Your Desk This Week
The first is Part 2. The second is older and quieter: the pandemic-era enforcement discretion that let providers use non-public-facing consumer video apps for telehealth expired in August 2023. There is no grace period left. Every platform that touches a counseling session is evaluated under ordinary HIPAA rules — Privacy, Security, and Breach Notification.
Practices that never revisited their 2020 setup are the ones getting caught. The clinician is still using a personal video account. The scheduling link still lives in a free calendar tool. Nobody ever signed a business associate agreement because in 2020 nobody had to.
Start with a scope determination and write it down. Is your practice a Part 2 program, in whole or in part? Is any clinician federally assisted within the meaning of the rule? A one-page memo signed by your privacy officer, dated and filed, is what you will hand an auditor. "We assumed we weren't covered" is not a document.
Your Telehealth Counseling Vendor Stack Is Longer Than You Think
Ask your IT contact to list every system that handles a counseling session. Then ask the clinicians. The lists will not match.
A typical behavioral health practice running telehealth counseling touches: the video platform, the EHR, the scheduling and reminder tool, the SMS gateway that sends appointment texts, the e-signature service that collects consent, the payment processor, the clearinghouse, the transcription or ambient documentation tool, the cloud backup, the answering service, and the release-of-information portal. That is eleven relationships. Each one either needs a business associate agreement or a written determination explaining why it does not.
The three vendors administrators forget
- The appointment reminder tool. "You have a session Thursday at 3 with Dr. Reyes at Northside Behavioral Health" is PHI in transit, and the vendor stores the message log.
- The interpreter service. Live interpreters hear the entire session. Contract language for language-access vendors frequently predates any HIPAA review.
- The waiting-room or intake chatbot. If it collects symptom or scheduling data before a clinician sees it, it is handling PHI.
Web trackers deserve their own line item. If your booking page for telehealth counseling loads third-party analytics or advertising pixels, that page is disclosing information about people seeking behavioral health care. OCR's tracking-technology guidance and the FTC's enforcement history in this area both point the same direction: get the pixels off pages that identify a service line, or get a signed agreement and a documented legal basis. Behavioral health pages are the highest-sensitivity version of this problem.
When you find gaps — and you will find four or five — you need executed agreements, not a to-do list. If your vendor cannot produce their own paper, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX for countersignature. It is a one-time purchase, which matters when you are closing out a dozen small vendors in a single afternoon rather than budgeting for another subscription.
Consent, Location, and Identity: The Script Your Front Desk Uses
Build a five-item opening sequence and make it a required field in the encounter template. Front desk or clinician, whoever your workflow assigns — but somebody does it every session, and the system records that it happened.
- Verify identity. Two identifiers, spoken. Not the name on the video tile.
- Capture the patient's physical location. City and state at minimum. This drives licensure, payer eligibility, place-of-service coding, and emergency response. Record it every time, not once at intake.
- Confirm who else is present. On both ends. A clinician's family member in an adjacent room is a privacy issue you own.
- Confirm the modality actually used. Video, audio-only, or a video attempt that dropped to phone. This single field prevents most telehealth billing corrections.
- Confirm telehealth consent is current. Many states require a documented consent specific to telehealth, separate from general treatment consent, and some require it annually.
Licensure sits outside HIPAA but lands on your desk anyway. Maintain a grid of clinician license by state, with expiration dates and compact privileges, and check it against the patient-location field before the session is confirmed. A session delivered into a state where the clinician is not authorized creates a billing reversal, a licensure exposure, and an awkward records question all at once.
How Practices Document Code Selection for Telehealth Counseling
Your billing lead should not be deciding codes in the moment. They should be applying a written crosswalk built from current payer policy, and documenting which policy version they applied.
What belongs in the crosswalk
Structure it by payer, then by the operational facts your intake sequence captured:
- Patient's physical location at the time of service, which determines place-of-service selection
- Modality actually delivered — synchronous audio-video versus audio-only — which determines modifier selection under most payer policies
- Clinician license type and whether the payer recognizes it for the service
- Whether the payer requires a specific telehealth modifier, a specific place-of-service, or both
- Documentation elements the payer requires in the note to support the encounter
The clinician documents what happened. The coder maps documentation to codes using the crosswalk. Nobody guesses. When a payer updates policy, the crosswalk gets a new version number and a date, and the old version stays in the file — because that is what supports claims already submitted.
For Medicare, verify current authority directly against CMS's telehealth coverage page before each quarter closes. Telehealth authority for behavioral health has been treated differently from other service categories, and general telehealth flexibilities have moved on short legislative timelines. Print the page with the date you checked it and attach it to your crosswalk version. That is your defense if policy shifted mid-cycle.
Do Patients Have a Right to Their Psychotherapy Notes?
No — and this is the question your records clerk gets wrong most often. Under the HIPAA right of access at 45 CFR 164.524, psychotherapy notes are excluded from the designated record set a patient may inspect and copy. But "psychotherapy notes" has a narrow regulatory meaning: notes recorded by a mental health professional documenting or analyzing the contents of a counseling session, kept separate from the rest of the record.
If the analysis lives in the same progress note as the medication list, diagnosis, treatment plan, session start and stop times, modalities, and functional status, it is not a psychotherapy note. It is part of the record, and it goes out. Separation is a filing practice, not a label.
Everything else follows the standard clock: 30 days from the request, with one 30-day extension available if you notify the patient in writing with a reason. Your fee is limited to a reasonable, cost-based amount. OCR's right of access guidance is the reference to keep printed at the front desk.
Three operational consequences for telehealth counseling practices:
- Audit your chart structure now. If clinicians are writing process analysis into the shared note, the exclusion is unavailable to you.
- Session recordings and full transcripts, if you keep them, are generally part of the record. Decide deliberately whether to keep them.
- Part 2 records carry additional restrictions on redisclosure and on use in legal proceedings. Your release-of-information staff need a decision tree, not judgment calls.
Clinician Home Offices Are Now Part of Your Risk Analysis
A counselor working from a spare bedroom is a workforce location you are responsible for. Your Security Rule risk analysis has to name it.
Minimum standards worth putting in policy, then verifying rather than trusting:
- Practice-managed device with full-disk encryption, automatic screen lock, and current patching
- Headset required for every session — no speakers
- Door that closes; a documented plan for households where it does not
- No local storage of PHI; work only inside sanctioned systems
- Router with a changed default password and current firmware
- An attestation signed annually, with a photo of the workspace if your culture supports it
HHS's telehealth resources for providers cover the practical setup side. If your risk analysis is still a 2021 spreadsheet that predates remote clinicians, rebuild it — automated risk analysis and policy generation will get you a defensible document faster than another round of committee meetings, and remote workforce locations belong in it explicitly.
Recording, Transcription, and AI Note Tools
Ambient documentation tools are in behavioral health now, and they change your exposure profile in three ways.
Consent. Recording law is state law, and several states require all-party consent. In telehealth counseling, the patient and clinician may sit in different states. Your policy should default to explicit documented consent from the patient, captured before recording starts, every session.
Vendor terms. Read the model-training clause. If the vendor reserves any right to use session content to improve its product, that is a use of PHI, and it needs to be either removed or squarely permitted in your BAA. Ask where audio is stored, for how long, and whether deletion is verifiable.
Retention. Decide whether raw audio is retained at all. If it is, it is discoverable and it is likely part of the designated record set. Many practices conclude that a transcript-and-delete policy with a short, enforced deletion window is the right operational answer. Whatever you choose, write it, apply it uniformly, and confirm the vendor honors it.
A 30-Day Cleanup Sequence
Week 1 — Inventory. Practice administrator pulls every vendor touching telehealth counseling from accounts payable, IT, and clinician interviews. One row per vendor: what PHI it touches, whether a BAA exists, and the execution date.
Week 2 — Paper. Privacy officer closes every missing agreement and reviews existing ones for breach-notification timelines, subcontractor flow-down, and return-or-destroy terms at termination.
Week 3 — Forms and scripts. Update telehealth consent, notice of privacy practices, and Part 2 consent language against the new compliance date. Retrain front desk on the five-item opening sequence. Version and date the coding crosswalk.
Week 4 — Verify. Pull ten recent telehealth encounters. Does each one document patient location, modality, and current consent? Does the claim match the crosswalk? Are psychotherapy notes actually filed separately? Log the findings and the corrections. That log is your evidence of an active program.
Start With the Agreements You Cannot Produce
Every telehealth counseling problem that becomes an enforcement problem starts the same way: a vendor was handling sensitive information and nobody could produce the paperwork. Run the inventory this week, and where a signature is missing, build the business associate agreement and send it out before your next staff meeting. It is the cheapest and fastest item on the list, and it is the first thing anyone will ask you for.