Telehealth Mental Health: HIPAA & 42 CFR Part 2 Guide
Master compliance for mental health telehealth including HIPAA, 42 CFR Part 2 substance abuse rules, psychotherapy notes, crisis protocols, and secure platforms
Understanding Mental Health Telehealth Compliance
Two Regulatory Frameworks Apply
Mental health telehealth must comply with two different regulatory frameworks:
Standard HIPAA applies to all healthcare including mental health: Privacy Rule (use/disclose PHI), Security Rule (encrypt, access controls), Breach Notification (60-day notification). Applies to all patient mental health information.
If patient is in substance abuse treatment: separate federal law applies. 42 CFR Part 2 is STRICTER than HIPAA. Requires explicit patient consent for most disclosures. Prohibits disclosure even to other healthcare providers without separate written consent. Applies even if only treating addiction (not general mental health).
Key Difference: HIPAA vs. 42 CFR Part 2
Understanding the difference is critical:
- HIPAA: Permits disclosures to other healthcare providers with general healthcare authorization; disclosure for treatment purposes permitted
- 42 CFR Part 2: Requires explicit written consent for ANY disclosure of substance use treatment records; prohibits redisclosure by recipient
- When both apply: Use most restrictive requirements (42 CFR Part 2)
42 CFR Part 2: Substance Abuse Treatment Records
What Triggers 42 CFR Part 2?
42 CFR Part 2 applies if you treat patient for:
- Alcohol use disorder or alcohol dependence
- Drug use disorder or drug dependence
- Addiction to controlled substances
- Even if patient comes for other reason but you discover/treat substance use
It does NOT apply to:
- General mental health (anxiety, depression, PTSD) without substance component
- General medical conditions
- Testing positive for drugs (without treatment)
42 CFR Part 2 Core Requirements
- Written consent: Explicit written patient consent required before any disclosure
- Specific consent: Patient must know what's being disclosed and to whom
- Separate records: Maintain substance abuse treatment records separately from other medical records
- No re-disclosure: Recipient cannot re-disclose substance abuse information to third parties without new consent
- Federal penalties: Criminal penalties for unauthorized disclosure (up to $10,000 fines)
- Stricter than HIPAA: Confidentiality protections exceed HIPAA requirements
42 CFR Part 2 Consent Form Requirements
Consent must be specific and include:
- Explicit statement of what information is being disclosed (not general)
- Name/role of person/organization receiving information
- What the recipient can do with information
- Patient's right to withdraw consent
- NOT valid for general healthcare authorization
- Separate consent for each recipient/purpose
Sample: "I consent to disclosure of my substance abuse treatment records to [specific person/organization] for [specific purpose]. I understand this is required in addition to general medical authorization. I can revoke this consent in writing at any time."
Psychotherapy Notes and Enhanced Privacy
Psychotherapy Notes Definition
HIPAA recognizes "psychotherapy notes" as having heightened privacy protection:
- Personal notes kept by mental health professional
- Contains therapist's personal observations/impressions
- NOT the same as treatment/clinical notes
- Examples: notes about therapeutic approach, personal observations, process notes
- NOT included: medication records, test results, diagnoses, treatment plans
Psychotherapy Notes Storage and Access
- Separate storage: Keep separate from rest of medical record
- Access limits: Only treating therapist can access (not medical staff, billing, etc.)
- Encryption: Additional encryption layer beyond standard HIPAA
- No auto-disclosure: Never disclose without explicit patient consent
- Patient access: Can be restricted (even patient cannot access automatically)
- Insurance billing: Cannot share with insurance for payment without consent
Exception: When Psychotherapy Notes Must Be Disclosed
- Explicit patient authorization (signed consent)
- Court order (subpoena, warrant)
- Danger to self/others (emergency—even then, limited disclosure)
- Prevent/lessen serious threat to health/safety
- Most business/administrative disclosures prohibited
Telehealth Psychotherapy Notes Considerations
- Document psychotherapy notes post-session (don't keep session recordings as notes)
- Keep separate from session recordings
- Consider whether video/audio recordings are "psychotherapy notes" (likely yes)
- Never store session recordings with patient EHR
- Separate encryption for sensitive psychotherapy materials
Crisis Protocols and Emergency Procedures
Legal Duty to Warn/Protect
Mental health providers have special obligations during crisis:
- Duty to warn: Warn identifiable third parties if patient threatens violence
- Duty to protect: Warn/protect when patient poses danger to others
- Suicidal ideation: Mandatory reporting in many states; emergency assessment
- Crisis hotlines: Have emergency backup procedures
- State variation: Laws vary by state; know your state's specific requirements
Telehealth-Specific Crisis Protocols
- Suicidal risk assessment: Assess risk before session; have protocol
- Emergency contact: Obtain patient's emergency contact and crisis hotline numbers
- Crisis hotline resources: Have 988 Suicide & Crisis Lifeline info ready
- Coordinating in-person care: Procedure for directing patient to emergency services
- Calling 911: Know when/how to contact emergency services for patient location
- Crisis documentation: Document crisis assessment, interventions, referrals
Safety Planning
- Develop safety plans with suicidal/dangerous patients
- Include emergency contact, crisis hotline, warning signs
- Document safety plan in record
- Review/update at each session
- Consider involving family/support in telehealth (with consent)
Limitations of Telehealth for Crisis
- Cannot physically restrain or monitor patient
- May not know patient's exact location
- Technology failures could disconnect during crisis
- Limited ability to assess severity in-person
- Ensure consent addresses these limitations
Mental Health Platform Requirements
HIPAA-Compliant Platform Essentials
- Encryption: TLS 1.2+ in transit, AES-256 at rest
- BAA: Business Associate Agreement in place
- Access controls: Role-based access limits
- Audit logging: Track all access to patient records
- Session recording: If recorded, encrypted storage with access controls
- Data location: US-based data centers preferred
Mental Health-Specific Features
- Separate note types: Support for psychotherapy notes vs. clinical notes
- Access restrictions: Ability to limit access to therapist only
- Emergency protocols: Clear crisis escalation/documentation capabilities
- Consent management: Support for 42 CFR Part 2 consent tracking
- Appointment notes: Mandatory fields for crisis screening
Documentation for Mental Health Telehealth
Required Documentation
- Telehealth consent: Specific to telehealth modality and limitations
- 42 CFR Part 2 consent: If treating substance use (separate, specific)
- Crisis protocol: Written procedures for handling emergencies
- Session notes: Standard clinical documentation
- Psychotherapy notes: Separate from clinical record if kept
- Safety assessment: Documented risk/safety evaluation
- Treatment limitations: Acknowledge telehealth limitations documented
Record Retention for Mental Health
- Standard medical record retention applies (typically 7+ years)
- Psychotherapy notes may have different retention requirements
- Some states require longer retention for mental health
- Substance abuse records under 42 CFR Part 2 same retention
- Document retention policy and follow consistently
Ensure Your Mental Health Telehealth Program Is Fully Compliant
Get expert guidance on HIPAA, 42 CFR Part 2, psychotherapy notes, and crisis protocols. Our assessment includes review of consents, platforms, and documentation procedures.
Start Your Assessment