HIPAA for Therapists: Private Practice Compliance Guide
Quick Answer
If you're a therapist who bills insurance, uses electronic health records, or transmits patient information electronically, HIPAA applies to you. You must implement privacy controls, secure patient records, document consent, protect communications, and notify patients of breaches. Solo practices are covered entities if they bill insurance. Compliance requires written policies, staff training, secure systems, and Business Associate Agreements with vendors.
Do I Need HIPAA Compliance as a Therapist?
When HIPAA Applies to Therapists
HIPAA requirements apply if your therapy practice meets any of these conditions:
If you answer "yes" to any of these, HIPAA requirements apply regardless of practice size. Solo therapists are covered entities.
When HIPAA May Not Apply
HIPAA may not apply if you:
Even if you think you're exempt, consult legal counsel. Most modern therapy practices trigger HIPAA requirements.
HIPAA Privacy Requirements for Therapists
Privacy Notice
You must provide every client with a written Notice of Privacy Practices (NPP) explaining:
Clients must sign and return the NPP acknowledgment before treatment.
Permitted Uses Without Consent
You can use/disclose PHI without explicit consent for:
Disclosures Requiring Authorization
Written authorization is required for:
Mandatory Disclosures (No Consent Needed)
You must disclose when:
HIPAA Security Requirements for Therapists
Administrative Safeguards
You must designate a Privacy and Security Officer responsible for:
Physical Safeguards
Secure physical access to patient records:
Technical Safeguards
Secure electronic systems and communications:
Telehealth Security
If you conduct teletherapy:
HIPAA Compliance Checklist for Therapists
Business Associate Agreements for Therapists
Who Needs a BAA?
You must have Business Associate Agreements with any vendor that handles patient health information:
BAA Essential Components
Each BAA must include:
Frequently Asked Questions
Can I use Zoom for therapy sessions?
Regular Zoom is not HIPAA-compliant for therapy. You need HIPAA Business Associate Agreements with Zoom (which are available) and must follow specific security requirements: private rooms, password-protected meetings, waiting rooms enabled, recording disabled unless necessary. Many therapists use HIPAA-compliant platforms like VSee, Doxy.me, or Thera-Link instead.
What if a parent calls asking about their adult child's therapy?
You cannot confirm that the person is in treatment, provide any information, or discuss their progress without written authorization from the adult client. Even confirming they are a client violates privacy. If no authorization exists, do not speak to the parent beyond scheduling appointments or payments.
If I'm served a subpoena for client records, must I comply?
Subpoenas for therapy records require special handling. Therapists typically have a statutory duty to protect client privacy that may supersede subpoenas. Consult an attorney immediately before releasing records. Many states allow therapists to file a motion to quash. Do not release records based on a subpoena alone - get legal guidance first.
What's the penalty if I breach HIPAA?
Civil penalties for HIPAA violations range from $100-$50,000 per violation, with annual maximum penalties reaching millions. Criminal penalties can result in up to $250,000 fines and 10 years imprisonment for willful violations. Additionally, HHS may prohibit therapists from billing Medicare/Medicaid, effectively ending a practice.
Protect Your Therapy Practice with HIPAA Compliance
Therapists face unique HIPAA challenges around sensitive mental health records. Medcurity helps private practices implement practical compliance systems, secure patient data, and respond to breaches. From solo practitioners to group practices, we provide guidance tailored to therapy settings.
Get Your Therapy Practice Compliant