Medcurity Get Compliant Now

HIPAA for Therapists: Private Practice Compliance Guide

Last updated: March 2026 | 12 min read

Quick Answer

If you're a therapist who bills insurance, uses electronic health records, or transmits patient information electronically, HIPAA applies to you. You must implement privacy controls, secure patient records, document consent, protect communications, and notify patients of breaches. Solo practices are covered entities if they bill insurance. Compliance requires written policies, staff training, secure systems, and Business Associate Agreements with vendors.

Do I Need HIPAA Compliance as a Therapist?

When HIPAA Applies to Therapists

HIPAA requirements apply if your therapy practice meets any of these conditions:

• You bill insurance companies or Medicare/Medicaid
• You use electronic health records (EHRs or practice management software)
• You transmit patient information electronically (email, secure messaging, fax)
• You operate as a small business health plan
• You use any digital/electronic patient records

If you answer "yes" to any of these, HIPAA requirements apply regardless of practice size. Solo therapists are covered entities.

When HIPAA May Not Apply

HIPAA may not apply if you:

• Maintain only paper records
• Do not bill insurance (cash-only practice, though this is rare)
• Do not transmit any information electronically

Even if you think you're exempt, consult legal counsel. Most modern therapy practices trigger HIPAA requirements.

HIPAA Privacy Requirements for Therapists

Privacy Notice

You must provide every client with a written Notice of Privacy Practices (NPP) explaining:

• How you use and disclose their mental health information
• Their rights under HIPAA (access, amendment, accounting of disclosures)
• How they can file complaints
• Your contact information
• How you maintain confidentiality

Clients must sign and return the NPP acknowledgment before treatment.

Permitted Uses Without Consent

You can use/disclose PHI without explicit consent for:

• Treatment (therapy, coordination with other providers)
• Payment (billing insurance, collections)
• Healthcare operations (scheduling, staff training, compliance activities)

Disclosures Requiring Authorization

Written authorization is required for:

• Sharing information with family members or friends
• Disclosure to employers
• Insurance claims beyond basic verification
• Sharing with other therapists/providers (if not for active treatment coordination)
• Disclosure to third parties

Mandatory Disclosures (No Consent Needed)

You must disclose when:

• Court orders or legal subpoenas are issued
• Required by law for abuse/neglect reporting
• Responding to requests from HHS for HIPAA investigations

HIPAA Security Requirements for Therapists

Administrative Safeguards

You must designate a Privacy and Security Officer responsible for:

• Developing and maintaining HIPAA policies
• Staff training and compliance
• Breach response procedures
• Business Associate management

Physical Safeguards

Secure physical access to patient records:

• Locked filing cabinets for paper records
• Limited access to record storage areas
• Video surveillance or security systems (if storing records off-site)
• Office access control (locks on doors and windows)
• Proper disposal (shredding, secure deletion) of old records

Technical Safeguards

Secure electronic systems and communications:

• Password-protected EHR systems with automatic lock-out
• Encrypted email for patient communication
• Encrypted hard drives and devices
• Secure messaging systems instead of regular email for PHI
• Firewall and antivirus protection
• Access logs and audit trails
• Two-factor authentication for EHR systems
• Backup systems with encryption

Telehealth Security

If you conduct teletherapy:

• Use HIPAA-compliant platforms (not Zoom for healthcare)
• Ensure private, secure internet connection
• Inform patients of any potential privacy risks
• Ensure patient location has privacy (no listeners)
• Document that patient consented to telehealth risks

HIPAA Compliance Checklist for Therapists

Business Associate Agreements for Therapists

Who Needs a BAA?

You must have Business Associate Agreements with any vendor that handles patient health information:

• EHR/practice management software vendors
• Cloud storage providers (if storing PHI)
• Therapist supervision/consultation groups (if they access records)
• Billing and insurance services
• Office IT support companies
• Answering services or appointment scheduling services
• Email services, file storage (if used for PHI)

BAA Essential Components

Each BAA must include:

• Permitted uses and disclosures of PHI
• Safeguard requirements for PHI
• Breach notification obligations
• Subcontractor requirements (BAAs with sub-vendors)
• Right to audit and access
• Termination and return/destruction of PHI
• Liability and indemnification

Frequently Asked Questions

Can I use Zoom for therapy sessions?

Regular Zoom is not HIPAA-compliant for therapy. You need HIPAA Business Associate Agreements with Zoom (which are available) and must follow specific security requirements: private rooms, password-protected meetings, waiting rooms enabled, recording disabled unless necessary. Many therapists use HIPAA-compliant platforms like VSee, Doxy.me, or Thera-Link instead.

What if a parent calls asking about their adult child's therapy?

You cannot confirm that the person is in treatment, provide any information, or discuss their progress without written authorization from the adult client. Even confirming they are a client violates privacy. If no authorization exists, do not speak to the parent beyond scheduling appointments or payments.

If I'm served a subpoena for client records, must I comply?

Subpoenas for therapy records require special handling. Therapists typically have a statutory duty to protect client privacy that may supersede subpoenas. Consult an attorney immediately before releasing records. Many states allow therapists to file a motion to quash. Do not release records based on a subpoena alone - get legal guidance first.

What's the penalty if I breach HIPAA?

Civil penalties for HIPAA violations range from $100-$50,000 per violation, with annual maximum penalties reaching millions. Criminal penalties can result in up to $250,000 fines and 10 years imprisonment for willful violations. Additionally, HHS may prohibit therapists from billing Medicare/Medicaid, effectively ending a practice.

Protect Your Therapy Practice with HIPAA Compliance

Therapists face unique HIPAA challenges around sensitive mental health records. Medcurity helps private practices implement practical compliance systems, secure patient data, and respond to breaches. From solo practitioners to group practices, we provide guidance tailored to therapy settings.

Get Your Therapy Practice Compliant