HIPAA for therapists in private practice
What a solo or small therapy practice actually needs in place: whether HIPAA applies to you, the safeguards that matter most, and the tools you'll need a BAA for.
HIPAA for therapists in private practice: at a glance
A therapist in private practice is covered by HIPAA if they, or a billing service acting for them, transmit health information electronically in a standard transaction such as an insurance claim. Covered therapists need a documented risk analysis, a BAA with every vendor that handles client information, secure email and messaging, individual accounts with MFA, and a breach plan. Psychotherapy notes kept separate from the record get extra protection.
| HIPAA applies if | You or your billing service submit claims or other standard transactions electronically |
|---|---|
| First priority | A written risk analysis |
| Vendors needing a BAA | EHR, email, telehealth, cloud storage, billing |
| Extra protection | Psychotherapy notes kept separate from the record |
| Common gap | Emailing clients from an account without a BAA |
Does HIPAA apply to your practice?
HIPAA applies to a health care provider who transmits health information electronically in connection with a standard transaction — for example, submitting insurance claims or checking eligibility electronically (45 CFR 160.103). That includes transactions a billing service submits on your behalf.
If your practice is fully private-pay and neither you nor anyone acting for you ever conducts these electronic transactions, you may not be a covered entity. That is worth confirming rather than assuming — and state privacy laws and your professional ethics code apply either way. Most therapists who accept insurance are covered.
Psychotherapy notes get extra protection
HIPAA gives special status to psychotherapy notes: notes a mental health professional records about the contents of a counseling session, kept separate from the rest of the record (45 CFR 164.501). Most uses and disclosures of them require the client’s specific authorization (164.508(a)(2)). Diagnosis, treatment plans, session times and progress summaries are not psychotherapy notes — they belong to the regular record.
The protection only works if the notes are actually separated. Check whether your EHR has a dedicated psychotherapy notes area.
What to put in place first
- A written risk analysis covering everywhere client information lives: EHR, email, telehealth, file storage, phone, laptop.
- BAAs with every vendor that stores or transmits client information — EHR, email, telehealth, cloud storage, billing.
- Email you can use with clients: a service that signs a BAA, encrypts messages, and lets clients open them easily — plus a record of client preferences.
- One account per person, with MFA, on every system holding client information.
- A short breach plan, so a misdirected email or lost device is assessed and documented, not ignored.
The pages below explain each requirement and compare tools on the criteria that matter for a small practice.
Main risks
- Emailing or messaging clients from a personal or free account that has no BAA.
- No documented risk analysis — one of the most common gaps OCR finds.
- Psychotherapy notes kept inside the general record, losing their extra protection.
- Shared logins and no multifactor authentication on the EHR or mailbox.
- A misdirected email or lost laptop treated as "no big deal" instead of assessed as a possible breach.
Requirements that matter most here
- Psychotherapy notes →§ 164.501What counts as psychotherapy notes under HIPAA, how they differ from progress notes, and the extra protection they get — for therapists choosing how to keep their notes.
- Security risk analysis →§ 164.308(a)(1)(ii)(A)Every covered entity and business associate must document an accurate and thorough assessment of risks to the ePHI it holds — and then act on it. It is one of the most commonly missing pieces of HIPAA compliance, including in small practices.
- Business associate agreements (BAAs) →§ 164.502(e)Any vendor that creates, receives, maintains or transmits PHI on your behalf is a business associate, and you need a signed BAA with it before it touches patient data. No BAA means you should not put PHI in that tool.
- Emailing patients →§ 164.522(b)HIPAA allows providers to email patients, with reasonable safeguards. Patients may also ask to receive information by email; if they prefer unencrypted email after being warned of the risk, a provider may honor that.
- Encryption of ePHI →§ 164.312(a)(2)(iv)Encryption is "addressable", not optional: you either encrypt ePHI at rest and in transit, or document why not and use an equivalent safeguard. For email and cloud tools, encrypting is almost always the reasonable choice.
- Access control and sign-in →§ 164.312(a)(1)Only the right people should reach ePHI, each under their own account, with a reliable way to confirm who is signing in. In practice: unique user accounts, strong authentication such as MFA, and automatic logoff.
- Notifying patients of a breach →§ 164.402An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless a documented four-factor assessment shows a low probability of compromise. Affected individuals must be notified without unreasonable delay and no later than 60 days after discovery.
Solutions to look at
If something happens
Frequently asked questions
Do therapists who don't take insurance need to follow HIPAA?
If you never conduct standard electronic transactions, directly or through a billing service, you may not be a HIPAA covered entity. Confirm this rather than assume it — state privacy laws and ethics codes apply regardless.
Are psychotherapy notes part of the medical record?
Not if they are kept separate. Psychotherapy notes are a therapist's notes on session content kept apart from the record; most uses and disclosures require the client's authorization.
What email can a therapist use with clients?
A service that signs a BAA and encrypts messages, set up with MFA. Compare options on the HIPAA email services page.