HIPAA Compliance for Mental Health and Behavioral Health
HIPAA compliance for mental health practices requires attention to unique regulatory layers that go beyond standard healthcare requirements. Need a HIPAA consultant for your therapy or counseling practice? You are in the right place. We help behavioral health teams guard patient privacy without slowing down care.
Why Behavioral Health Has Different HIPAA Rules
Behavioral health records carry unique obligations that go beyond standard HIPAA rules. Psychotherapy notes get heightened protections under 45 CFR §164.508. Substance use disorder records fall under the stricter consent rules of 42 CFR Part 2. Therapists, counselors, psychologists, and psychiatrists in private practice all face these layered requirements on top of the standard Privacy and Security Rules that apply to every covered entity.
What We Focus On for Behavioral Health Providers
Behavioral health practices face a distinct compliance landscape. The following areas represent the highest-risk gaps we see across therapy practices, counseling centers, and integrated behavioral health programs.
- Risk and gap review for sessions, care handoffs, and records - grounded in the security risk assessment requirements of 45 CFR §164.308(a)(1)
- Policies that fit your intake, notes, and patient messages, including authorization controls for psychotherapy notes under 45 CFR §164.508(a)(2) - see our guide on HIPAA authorization form requirements for what these forms must include
- Staff HIPAA training by role with clear ownership of privacy and security responsibilities
- Vendor and BAA controls - required under 45 CFR §164.308(b) - covering your EHR, telehealth platform, billing service, and any other vendor that handles PHI
Required HIPAA Compliance Steps for Behavioral Health
These steps apply to every behavioral health covered entity. Each ties to a specific CFR requirement. For a detailed look at what practices typically spend, see our HIPAA compliance cost breakdown.
- Security Risk Assessment (SRA) - Required under §164.308(a)(1)(ii)(A). Must identify threats and vulnerabilities to all ePHI your practice creates, receives, stores, or sends. A documented risk assessment is the most common missing item when OCR investigates behavioral health practices.
- Written policies and procedures - Required under §164.316(a). Must cover privacy, security, breach notification, and staff conduct. Behavioral health-specific policy templates should address psychotherapy note handling, substance use disorder record consent, and telehealth session protocols.
- Workforce training - Required under §164.308(a)(5)(i). All staff with PHI access - therapists, counselors, intake coordinators, billing staff, and administrative personnel - must complete HIPAA training at hire and when policies change. Training records must be kept for six years.
- Business Associate Agreements - Required under §164.308(b)(1). Must be signed with EHR vendors, telehealth platforms, billing services, cloud storage providers, and any other entity that handles PHI for the practice.
- Psychotherapy notes protections - Under §164.508(a)(2), psychotherapy notes stored separately from the medical record require specific written authorization for nearly all disclosures - including for treatment by another provider. Standard TPO exceptions do not apply.
- 42 CFR Part 2 review - If your practice provides federally assisted substance use disorder treatment, records are subject to stricter consent requirements than HIPAA. Where both regulations apply, the more protective standard governs.
Common HIPAA Compliance Gaps in Behavioral Health
Many behavioral health practices lack a documented Security Risk Assessment. They rely on generic policies that do not address psychotherapy note protections, have no BAAs with telehealth or EHR vendors, and do not keep staff training records. A structured gap analysis ties each gap to the CFR rule it violates and ranks fixes by risk level.
Group practices and multi-provider organizations face added complexity when coordinating compliance across therapists who use different tools, maintain different note-keeping habits, and work from different locations. A gap analysis at the organization level is the right starting point before aligning policies across providers.
Telehealth Compliance for Behavioral Health
Most therapy and counseling practices now offer remote sessions. HIPAA requires that your telehealth platform has a signed Business Associate Agreement. Technical safeguards under §164.312 - including unique user identification, automatic logoff, and encryption - apply to telehealth platforms the same way they apply to any system handling ePHI. Platform selection and configuration matter more than most practices realize. See our guide on HIPAA and telehealth compliance for the full requirements.
Regulatory Standards Specific to Behavioral Health
The following federal regulations govern HIPAA compliance for behavioral health providers. Understanding which standards apply to your practice is the starting point for any compliant implementation.
HIPAA Enforcement for Behavioral Health
The Office for Civil Rights (OCR) enforces HIPAA for all covered entities, including behavioral health providers. Fines range from $141 to $2,134,831 per violation type per year under 45 CFR §160.404. OCR has investigated behavioral health practices for complaints about unauthorized disclosure of therapy records, missing risk assessments, and failure to provide patients access to their records within 30 days per §164.524(b)(2). For more on recent enforcement trends, see our breakdown of 2026 HIPAA penalty amounts.
Behavioral Health HIPAA FAQ
Can we improve compliance without interrupting patient care workflows?
Yes. We build safeguards into your current workflow. Administrative safeguards under 45 CFR §164.308 are designed to be integrated into existing operations - not added as a separate layer. We focus on changes that reduce risk while keeping care quality high.
Are psychotherapy notes treated differently from other mental health records under HIPAA?
Yes. Under 45 CFR §164.508(a)(2), psychotherapy notes held separately from the medical record carry heightened protections and generally require specific written authorization before disclosure, even for treatment purposes. The standard TPO exceptions that apply to most PHI do not apply to psychotherapy notes. Your authorization forms, EHR configuration, and staff training all need to account for this distinction.
How do substance abuse records under 42 CFR Part 2 interact with HIPAA?
42 CFR Part 2 governs records from federally assisted substance use disorder treatment programs and imposes stricter consent requirements than HIPAA. Where both regulations apply, the more protective rule governs - which is almost always Part 2. Most practices that treat SUD alongside other behavioral health conditions need to maintain separate consent workflows for Part 2 records.
What do behavioral health providers need to address for telehealth HIPAA compliance?
Key areas include using a HIPAA-compliant video platform covered under a signed BAA, documenting patient consent for remote sessions, and implementing access controls under 45 CFR §164.312 to prevent unauthorized access to session data. Platform selection and configuration matter more than most practices realize.
How does HIPAA handle PHI for minor patients in behavioral health settings?
State law generally controls a minor's right to consent to certain behavioral health services, and that affects who can access records. HIPAA defers to applicable state law under 45 CFR §164.502(g). Your privacy practices, Notice of Privacy Practices, and access control policies all need to reflect your state's rules on minor confidentiality - particularly for sensitive services where minors may have independent consent rights.
One Guy Consulting helps therapists, counselors, psychologists, psychiatrists, and behavioral health organizations of all sizes with HIPAA compliance - solo practitioners, group practices, and multi-location programs.