A solo counselor signs up for an AI note-taking tool on a Tuesday, records nine sessions with it that week, and never asks the vendor for a contract. That single decision creates an unauthorized disclosure of protected health information for every one of those clients, and it is the most common therapy practice HIPAA failure we see in behavioral health — not hackers, not stolen laptops, but a clinician buying software with a credit card.

This is a build checklist for the person responsible for compliance inside a therapy practice: the owner, the practice manager, the designated privacy officer. It covers what you must have on paper, who does what, and the two deadlines that matter in early 2026.

Does HIPAA apply to a private therapy practice?

Yes, if your practice transmits any health information electronically in connection with a covered transaction — submitting claims, checking eligibility, receiving electronic remittance, or sending an electronic referral authorization. That makes you a covered entity, regardless of size or license type. A cash-pay therapy practice that never bills insurance and never files an electronic claim may fall outside HIPAA, but the moment you generate a superbill through a clearinghouse or run an eligibility check, you are in. State confidentiality laws and licensing board rules apply either way, and most are stricter than HIPAA.

Psychotherapy Notes Are Narrower Than Most Clinicians Think

The single most misunderstood provision in therapy practice HIPAA work is 45 CFR 164.501. Psychotherapy notes are notes recorded by a mental health professional that document or analyze the contents of a private counseling session, and that are kept separate from the rest of the individual's record. Both halves of that definition are load-bearing.

Excluded from the definition, by rule: medication prescription and monitoring, session start and stop times, modalities and frequencies of treatment, results of clinical tests, and summaries of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress to date. If your clinicians write all of that into the same note field, you do not have psychotherapy notes. You have a designated record set, and the client has a right of access to it.

What this means for your documentation policy

Decide as a practice whether you maintain psychotherapy notes at all. Either answer is defensible; ambiguity is not. If you do maintain them, your policy must state where they live, who can see them, and that they are stored separately from the chart your billing and records staff work from.

Psychotherapy notes generally require a signed authorization for disclosure — including for treatment, payment, and operations. A single authorization form may not combine psychotherapy notes with other disclosures. Train front desk and billing staff that a records request signed by an attorney does not automatically reach these notes. HHS maintains a plain-language summary of HIPAA and mental health information that you should read alongside your state statute.

The 30-Day Clock That Starts When a Client Asks for Their Chart

You have 30 calendar days from the request to provide access, with one 30-day extension available if you give the client written notice of the reason and the new date. The clock starts on the request, not on the day you locate the file. It does not pause because the treating clinician is on vacation.

Fees must be limited to a reasonable, cost-based amount — labor for copying, supplies, postage, and preparing an explanation if the client requested one. You may not charge for search and retrieval, and you may not condition access on payment of an outstanding balance. The OCR right of access guidance is the operative reference; keep a printed copy in your records procedure binder.

The two denial paths, and the paperwork each requires

Psychotherapy notes are an unreviewable exclusion — the client has no right of access to them, and your written denial says so.

Separately, a licensed health care professional may deny access on a reviewable ground: a determination, made in the exercise of professional judgment, that access is reasonably likely to endanger the life or physical safety of the individual or another person. That denial must be in writing, must be limited to the specific portion of the record at issue, and must tell the client how to request review by another licensed professional your practice designates. Name that reviewer in advance. Scrambling to find one after a denial is how a 30-day window becomes a complaint.

Your Vendor List Is Where Therapy Practice HIPAA Breaks First

Sit down and write out every outside service that touches client information. For a typical small behavioral health practice that list runs longer than owners expect:

  • Practice management and EHR platform
  • Telehealth video platform
  • Billing service or biller working as a contractor
  • Clearinghouse
  • Appointment reminder and secure messaging tools
  • AI scribe or session summarization tool
  • Transcription service
  • Cloud storage and email host
  • Answering service
  • Shredding and document destruction vendor
  • IT support with remote access to workstations
  • Outside clinical supervisor or case consultant who is not part of your workforce

Every one of those needs a signed business associate agreement before it touches PHI. A few things on the list are not business associates — your landlord, your malpractice carrier, a courier who only transports sealed envelopes — but write down the reasoning for each exclusion. When OCR asks, "we assumed" is not an answer.

Practices routinely discover mid-audit that the AI scribe, the fax-to-email service, and the biller's personal cloud folder have no agreement in place. If you are filling gaps, you can generate a signature-ready business associate agreement through a six-step wizard with PDF and DOCX export — one-time purchase, no subscription — which is faster than routing a template through a lawyer for the fifth low-risk vendor in a row.

The clause therapy practices should read twice

Check what your telehealth and EHR contracts say about using de-identified data for product development or model training. Check whether the vendor may retain records after termination and for how long. Check the breach notification timeline the vendor commits to — if it says "promptly," replace it with a number of days, because your own 60-day clock to notify clients runs regardless of when your vendor gets around to telling you.

Marketing Pixels, Intake Forms, and the FTC Problem

HIPAA is not your only exposure. The Federal Trade Commission has pursued mental health platforms for sharing consumer health information with advertising networks after promising confidentiality, and the FTC's authority reaches practices and apps whether or not HIPAA applies. Its health privacy guidance for businesses is short and worth twenty minutes.

Concretely: audit your website. If an advertising or analytics pixel sits on your appointment request page, your intake form, or a page titled with a specific condition, remove it or document a legal basis you can actually defend. Tracking code on an authenticated client portal is a disclosure, full stop. Tracking code on a public page about your practice's trauma specialty, combined with a submitted contact form, is close enough to one that you should not be litigating the difference.

The February 16, 2026 Date If You Touch Substance Use Records

The 2024 final rule aligning 42 CFR Part 2 with HIPAA carries a compliance date of February 16, 2026. Two questions to answer now.

First, is your practice a Part 2 program? Part 2 covers federally assisted programs that hold themselves out as providing substance use disorder diagnosis, treatment, or referral for treatment. "Federally assisted" is broad — Medicare or Medicaid participation, DEA registration, and certain tax statuses all count. A general therapy practice with a clinician who advertises SUD counseling should evaluate this seriously rather than assume it does not apply.

Second, does your practice receive Part 2 records from anywhere — a partial hospitalization program, a methadone clinic, a referring treatment center? If so, the rule brings notice and redisclosure obligations, and your Notice of Privacy Practices needs updating on the same timeline. Put the NPP revision on your calendar for January, not February.

The Risk Analysis OCR Asks For First

In nearly every OCR investigation of a small provider, the first document request includes the security risk analysis. Not a checklist, not a vendor's marketing certificate — an assessment that identifies where electronic PHI lives, the threats to it, your existing controls, and the residual risk you accepted or remediated. Required by 45 CFR 164.308(a)(1)(ii)(A). No exemption for practices under ten people.

NIST's SP 800-66 Revision 2 is the free implementation guide written specifically for the HIPAA Security Rule. Use it as your outline. Pair the risk analysis with a written risk management plan showing what you fixed, when, and who owned it.

Also note that HHS published a proposed rule in January 2025 to strengthen the Security Rule. It is not final as of today, but the direction is clear: asset inventories, network maps, annual risk analysis updates, and multi-factor authentication. If you are building controls now, build toward that. Automating the risk analysis and policy document set is a reasonable move for a practice without dedicated compliance staff — and no vendor, including any of them, issues a government-recognized HIPAA certification. HHS does not certify or endorse compliance products.

Breach Math for a Six-Clinician Practice

A therapist's phone with the practice app installed goes missing at a conference. Whether that is a reportable breach depends on encryption, device management, and what you can prove.

If PHI was encrypted per HHS specifications and the key was not compromised, you have no breach — safe harbor. If it was not, you run a four-factor risk assessment and document the outcome. Reportable breaches require individual notice within 60 days of discovery. Incidents affecting 500 or more individuals go to HHS within 60 days and to prominent media in the affected state. Smaller incidents go on your internal log and get submitted to HHS within 60 days after the end of the calendar year — meaning any small breach discovered in 2025 is due by March 1, 2026.

Browse the OCR breach portal and filter to behavioral health providers. The pattern is unremarkable: email compromise, ransomware at a billing vendor, misdirected records. Nothing exotic.

A 90-Day Sequence for a Small Practice

  1. Days 1–15: Name your privacy officer and security officer in writing. Build the vendor inventory. Pull every existing BAA into one folder.
  2. Days 16–45: Close BAA gaps. Complete or refresh the security risk analysis. Enable MFA on email, EHR, and cloud storage.
  3. Days 46–70: Rewrite your records request procedure with the 30-day clock, fee schedule, and denial letters as templates. Settle the psychotherapy notes question.
  4. Days 71–90: Update the Notice of Privacy Practices for Part 2 if applicable. Run workforce training and keep the attendance record. Audit the website for tracking code.

Therapy practice HIPAA compliance is not a state you reach; it is a set of documents you keep current and a set of behaviors you can evidence. The practices that survive an investigation are the ones whose folders are boring.

If your gap is agreements rather than analysis, start there — build and export your business associate agreements this week, get them signed, and file them with the vendor inventory that tells you which ones are still missing.