Does HIPAA Apply to Therapists in Private Practice? The One Test That Decides It

Practical guidance for healthcare teams and business associates

Ask ten therapists in private practice whether HIPAA applies to them and most will say yes, because it feels like it should. A few will say no, because they never signed anything. Both groups are guessing. The regulation has a specific test, and it has nothing to do with how sensitive the work is.

The stakes are real either way. OCR (the HHS Office for Civil Rights) settled a HIPAA Privacy and Security Rule investigation with a behavioral health provider on July 7, 2025, entered a resolution agreement and corrective action plan with Green Ridge Behavioral Health on October 30, 2023, and imposed a $100,000 penalty against a mental health center for failure to provide timely access to patient records on November 19, 2024. Behavioral health is not a quiet corner of enforcement.

This article lays out the covered-entity test in plain language, applies it to the common private-practice setups including cash-only, explains what changes once HIPAA applies (psychotherapy notes most of all), and covers the state confidentiality and licensing duties that apply whether HIPAA does or not.

Does HIPAA Apply to Therapists in Private Practice: The Covered Entity Test

45 CFR 160.103 defines a covered entity as a health plan, a health care clearinghouse, or "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Two more definitions in the same section finish the test.

First, health care "includes, but is not limited to" any "counseling, service, assessment, or procedure with respect to the physical or mental condition, or functional status, of an individual." Psychotherapy is health care by definition. Second, a health care provider includes "any other person or organization who furnishes, bills, or is paid for health care in the normal course of business." A licensed therapist in private practice is a health care provider by definition, regardless of license type.

That leaves the only part that varies: the transmission. The transaction definition in 160.103 lists the covered exchanges, including "health care claims or equivalent encounter information," "eligibility for a health plan," "health care claim status," and "health care payment and remittance advice." Send any of those electronically to a health plan, and the practice is a covered entity. In practice that means:

How the practice gets paidCovered entity?Why
Bills insurance electronically through an EHR, clearinghouse, or payer portalYesElectronic claims are the core standard transaction
A billing service submits electronic claims on the therapist's behalfYesThe transmission is made for the practice; the biller is a business associate
Checks a client's benefits online before the first sessionYesAn eligibility inquiry is a standard transaction, even for an otherwise cash practice
Bills insurance only on paper claim forms, with no electronic eligibility checksGenerally noNo electronic transmission; rare, and worth confirming with counsel
Cash only, hands clients a superbill to submit themselvesNoThe client transmits, not the practice
Cash only, no insurance involvement at allNoNo transaction of any kind

Two things follow. Status is entity-wide: once the practice is a covered entity because of one insured client, every client's records are P.H.I. (Protected Health Information), cash-pay clients included. And status is about transmission, not about how the therapist feels about privacy. The covered entity guide covers the same test for other provider types.

The Cash-Only Practice

A therapist who takes no insurance, runs no eligibility checks, and lets clients file their own superbills is not a covered entity. HIPAA's Privacy, Security, and Breach Notification Rules do not apply to that practice. That is the honest federal answer, and it surprises people.

It is not a license to be careless, for three reasons. First, the state duties described below apply in full. Second, the practice can still be pulled into HIPAA sideways: a therapist who contracts with a hospital's employee assistance program or a covered group practice may be asked to sign a B.A.A. (Business Associate Agreement), and at that point the Security Rule applies to the contracted work directly. Third, the moment the practice runs one electronic eligibility check or lets a biller submit one electronic claim, it becomes a covered entity, and the whole program becomes due. Many practices cross that line without noticing.

What Changes Once HIPAA Applies

Psychotherapy notes get their own rule. 164.501 defines psychotherapy notes as notes "documenting or analyzing the contents of conversation during a private counseling session or a group, joint, or family counseling session and that are separated from the rest of the individual's medical record." The definition excludes "medication prescription and monitoring, counseling session start and stop times, the modalities and frequencies of treatment furnished, results of clinical tests, and any summary of the following items: Diagnosis, functional status, the treatment plan, symptoms, prognosis, and progress to date." Kept separate, those process notes need a specific authorization for almost any use or disclosure under 164.508(a)(2), and are excluded from the client's right of access under 164.524(a)(1)(i). Mixed into the progress note, they lose both protections. The separation is the whole trick.

Everything else in the chart is ordinary PHI. Intake forms, diagnoses, treatment plans, session dates, and billing records are the designated record set. Clients can inspect and copy them, and the practice must act on a request within 30 days under 164.524(b)(2). The right of access guide covers fees and the reviewable denial for danger to life or safety.

Telehealth needs a platform that will sign. A video platform that transmits sessions is a business associate. Consumer video tools without a BAA are out. The telehealth compliance guide covers the setup.

The Security Rule applies in full. Risk analysis, a named security official (the therapist), unique logins, an encrypted laptop and phone, a backup that has been restored at least once, and training documented for the practice's workforce, even when that workforce is one person and a part-time biller.

Substance use records may carry a second law. A practice that qualifies as a federally assisted program treating substance use disorder falls under 42 CFR Part 2 as well, which has its own consent rules. The Part 2 versus HIPAA article explains the difference.

Minors and parents. 164.502(g)(3) defers to state law on whether a parent is the personal representative for a minor's therapy records. There is no federal shortcut here; the answer is the state's minor-consent statute.

Duties That Apply Whether or Not HIPAA Does

HIPAA is a floor, not the whole building. 160.203(b) leaves in place any state law that is "more stringent" about privacy, and for mental health records most states have one. A private-practice therapist, covered or not, should expect all of the following, and should confirm the specifics with counsel or the licensing board:

  • Licensing board confidentiality rules. State boards for psychologists, counselors, social workers, and marriage and family therapists enforce confidentiality standards as a condition of the license. Violating them risks the license itself, which is a heavier penalty than most HIPAA settlements.
  • State mental health confidentiality statutes. Many states protect mental health and psychotherapy records more strictly than HIPAA, with their own consent forms and their own rules about what a subpoena can reach.
  • Mandated reporting and duty-to-protect obligations. State law defines when a therapist must report abuse or act on a threat. HIPAA's 164.512(j) permits disclosures to prevent a serious and imminent threat; state law is what requires them.
  • State record retention rules. How long records must be kept is a state and board question, and the answer differs by license.
  • State breach notification laws. These apply to any business holding personal information, covered entity or not. A stolen laptop with client names and payment details triggers state notice duties even for a cash-only practice.
  • Professional ethics codes. The ethics code the therapist signed at licensure covers confidentiality, informed consent, and records, and it does not check billing status.

A Short Program for a Covered Therapy Practice

  1. Confirm covered-entity status in writing, with the reason (which transaction, which vendor).
  2. Run a risk analysis under 164.308(a)(1)(ii)(A): the laptop, the phone, the EHR, the telehealth platform, the email, the notes, the biller.
  3. Separate psychotherapy notes from the progress notes, physically or in the EHR, and write the policy that says so.
  4. Sign BAAs with the EHR, the telehealth platform, the billing service, the cloud email and storage, and any AI note-taking tool.
  5. Post and hand out the Notice of Privacy Practices, and document the acknowledgment attempt.
  6. Encrypt the devices, use unique logins, turn on MFA, and back up.
  7. Write down the training, even when the trainer and the trainee are the same person.

The behavioral health page describes how One Guy Consulting works with therapy practices on each of these steps.

The Proposed Security Rule Update

HHS published a proposed Security Rule overhaul in January 2025. It has not been finalized and OCR is not enforcing it. As proposed, it would make encryption and multifactor authentication required rather than Addressable and would add a written asset inventory and network map, vulnerability scanning at least every six months, and penetration testing at least every 12 months. For a solo therapy practice the encryption and MFA items are already the right answer under the current rule. The Security Rule delay article tracks the timeline.

---

FAQ

Does HIPAA apply to a cash-only therapist?

No, as long as the practice transmits no standard transaction electronically: no electronic claims, no online eligibility checks, no biller submitting on its behalf. State confidentiality law, licensing board rules, and the professional ethics code still apply in full.

If a billing service files my insurance claims, am I a covered entity?

Yes. The claims are transmitted electronically on the practice's behalf, which meets the 45 CFR 160.103 test, and the billing service is a business associate that needs a signed agreement.

Are psychotherapy notes protected differently under HIPAA?

Yes, if they are kept separate from the rest of the record. 164.501 defines them narrowly, 164.508(a)(2) requires a specific authorization for almost any use or disclosure, and 164.524(a)(1)(i) excludes them from the client's right of access. Notes mixed into the progress note are ordinary PHI.

Does HIPAA apply if I only see clients by telehealth?

The same billing test decides it. If the practice is a covered entity, the video platform is a business associate and must sign a BAA, and the Security Rule covers the laptop, the connection, and the recordings.

Do state laws still apply if HIPAA does not?

Yes. Licensing board confidentiality rules, state mental health records statutes, mandated reporting and duty-to-protect laws, and state data breach notification laws apply regardless of HIPAA status, and 160.203(b) preserves stricter state privacy law even where HIPAA applies.

Conclusion

A therapist who is a covered entity needs a program sized for a therapy practice: a short risk analysis, policies that cover the telehealth platform and the psychotherapy notes, and B.A.A.s with the handful of vendors that matter. One Guy Consulting's Full-Scope plan covers all of it, with consulting time from someone who works with behavioral health practices. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading