hipaa.systems
Scenario · Healthcare practice

HIPAA for therapists in private practice

What a solo or small therapy practice actually needs in place: whether HIPAA applies to you, the safeguards that matter most, and the tools you'll need a BAA for.

Requirements 7Solution types 1Checked 2026-10-05

HIPAA for therapists in private practice: at a glance

A therapist in private practice is covered by HIPAA if they, or a billing service acting for them, transmit health information electronically in a standard transaction such as an insurance claim. Covered therapists need a documented risk analysis, a BAA with every vendor that handles client information, secure email and messaging, individual accounts with MFA, and a breach plan. Psychotherapy notes kept separate from the record get extra protection.

HIPAA applies ifYou or your billing service submit claims or other standard transactions electronically
First priorityA written risk analysis
Vendors needing a BAAEHR, email, telehealth, cloud storage, billing
Extra protectionPsychotherapy notes kept separate from the record
Common gapEmailing clients from an account without a BAA

Does HIPAA apply to your practice?

HIPAA applies to a health care provider who transmits health information electronically in connection with a standard transaction — for example, submitting insurance claims or checking eligibility electronically (45 CFR 160.103). That includes transactions a billing service submits on your behalf.

If your practice is fully private-pay and neither you nor anyone acting for you ever conducts these electronic transactions, you may not be a covered entity. That is worth confirming rather than assuming — and state privacy laws and your professional ethics code apply either way. Most therapists who accept insurance are covered.

Psychotherapy notes get extra protection

HIPAA gives special status to psychotherapy notes: notes a mental health professional records about the contents of a counseling session, kept separate from the rest of the record (45 CFR 164.501). Most uses and disclosures of them require the client’s specific authorization (164.508(a)(2)). Diagnosis, treatment plans, session times and progress summaries are not psychotherapy notes — they belong to the regular record.

The protection only works if the notes are actually separated. Check whether your EHR has a dedicated psychotherapy notes area.

What to put in place first

  1. A written risk analysis covering everywhere client information lives: EHR, email, telehealth, file storage, phone, laptop.
  2. BAAs with every vendor that stores or transmits client information — EHR, email, telehealth, cloud storage, billing.
  3. Email you can use with clients: a service that signs a BAA, encrypts messages, and lets clients open them easily — plus a record of client preferences.
  4. One account per person, with MFA, on every system holding client information.
  5. A short breach plan, so a misdirected email or lost device is assessed and documented, not ignored.

The pages below explain each requirement and compare tools on the criteria that matter for a small practice.

Main risks

  1. Emailing or messaging clients from a personal or free account that has no BAA.
  2. No documented risk analysis — one of the most common gaps OCR finds.
  3. Psychotherapy notes kept inside the general record, losing their extra protection.
  4. Shared logins and no multifactor authentication on the EHR or mailbox.
  5. A misdirected email or lost laptop treated as "no big deal" instead of assessed as a possible breach.

Requirements that matter most here

Solutions to look at

If something happens

Frequently asked questions

Do therapists who don't take insurance need to follow HIPAA?

If you never conduct standard electronic transactions, directly or through a billing service, you may not be a HIPAA covered entity. Confirm this rather than assume it — state privacy laws and ethics codes apply regardless.

Are psychotherapy notes part of the medical record?

Not if they are kept separate. Psychotherapy notes are a therapist's notes on session content kept apart from the record; most uses and disclosures require the client's authorization.

What email can a therapist use with clients?

A service that signs a BAA and encrypts messages, set up with MFA. Compare options on the HIPAA email services page.