Back to articles
Healthcare Operations

HIPAA for Mental Health Professionals: What Solo, Remote, and Growing Practices Need to Know

Dr. Jose I. Delgado
11 min read
HIPAA Rules Photo

Mental health care no longer happens only in a traditional office. Psychiatrists, psychologists, counselors, social workers, psychiatric nurses, substance use disorder professionals, and other behavioral health clinicians may work from a clinic, a home office, a shared professional space, or an entirely virtual practice. Even a one-person practice may rely on cloud-based scheduling, electronic billing, telehealth, electronic health records, secure messaging, virtual receptionists, outsourced billing, and outside IT support.

That flexibility can improve access to care, but it also creates a common compliance misunderstanding: some professionals assume that HIPAA does not apply because the practice is small, cash-pay, home-based, or telehealth-only. None of those facts, by themselves, create a HIPAA exemption. For a health care provider, the key federal question is whether the provider transmits health information electronically in connection with a transaction for which HHS has adopted a standard, such as certain claims, eligibility, payment, or referral authorization transactions.

Once HIPAA applies, the compliance program should be scaled to the practice without becoming a checkbox exercise. A solo therapist will not operate like a multi-state hospital system, but the practice still needs a defensible way to protect protected health information (PHI), secure electronic PHI (ePHI), manage vendors, train the workforce, respond to incidents, and document its risk decisions.

Who in behavioral health may fall under HIPAA?

The source material identifies a broad range of mental health professionals and organizations that may function as HIPAA covered entities when the covered-entity test is met, including:

  • Psychiatrists and psychiatric nurses

  • Clinical psychologists

  • Licensed clinical social workers (LCSWs)

  • Licensed professional counselors (LPCs) and marriage and family therapists (LMFTs)

  • Substance use disorder and addiction professionals

  • Psychiatric clinics, hospitals, treatment centers, and behavioral health practices

Professional title alone does not determine status. A provider that uses a billing service to submit standard electronic claims may still be a covered entity even if the provider never personally transmits the claim. Conversely, simply using an EHR, email, telehealth, or electronic payment technology does not by itself establish covered-entity status. The operational facts matter.

Size and location: what changes and what does not

The attached source emphasizes three scenarios that frequently create confusion. The practical takeaway is that practice size and location affect how controls are implemented, but they do not replace the legal covered-entity analysis.

Table 1

A small practice can therefore have a smaller compliance footprint without having a smaller responsibility. The goal is a right-sized program that reflects the actual technology, workforce, vendors, and patient-information flows used by the practice.

The workforce includes more than the clinician

HIPAA responsibilities extend to the workforce members whose work involves PHI. Depending on the practice, that can include administrative staff, receptionists, schedulers, billing and coding personnel, interns, students, volunteers, and other people under the practice’s direct control. Training and access should be appropriate to each person’s role rather than giving every user the same level of access.

Business associates and subcontractors: the compliance chain

Mental health practices often rely on outside companies that create, receive, maintain, or transmit PHI on the practice’s behalf. Those vendors may be business associates, and downstream vendors used by those business associates may be subcontractors with HIPAA responsibilities of their own.

Common examples from the source material include:

  • EHR, telehealth, and practice-management vendors

  • Cloud storage, backup, data-center, managed security, and IT service providers

  • Medical billing agencies, clearinghouses, and certain collections services

  • Attorneys, accountants, consultants, or other professional services that require PHI access to perform their work

  • Virtual receptionists, answering services, or scheduling vendors that receive patient information

A Business Associate Agreement (BAA) should not be treated as a substitute for due diligence. The practice should know which vendors touch PHI, what they do with it, what systems or subcontractors they rely on, how incidents are reported, and how access is terminated when the relationship ends.

Mental health information and psychotherapy notes

The HIPAA Privacy Rule generally protects mental health information in the same framework as other PHI, but psychotherapy notes receive special treatment. HIPAA defines psychotherapy notes narrowly: they are notes recorded by a mental health professional documenting or analyzing the contents of a counseling conversation and kept separate from the rest of the medical record.

Psychotherapy notes do not include routine treatment information such as medication records, session times, treatment modalities and frequency, test results, diagnosis, treatment plan, symptoms, prognosis, and progress. With limited exceptions, patient authorization is generally required before psychotherapy notes are used or disclosed, including for many treatment disclosures to another provider.

The four core HIPAA areas mental health practices should understand

Table 2

The Security Rule: risk analysis is the foundation

The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. For a mental health provider, that means looking beyond the firewall or antivirus software and examining the full environment in which patient information is used.

A meaningful Security Risk Analysis should consider, as applicable:

  • Where ePHI is created, received, maintained, transmitted, backed up, and accessed

  • Laptops, desktops, phones, tablets, removable media, printers, and home-office equipment

  • EHR, telehealth, email, cloud storage, billing, scheduling, backup, and file-sharing systems

  • User accounts, passwords, authentication, access privileges, termination procedures, and audit logging

  • Physical workspaces, paper records, screen placement, overheard conversations, and remote-work arrangements

  • Vendors, business associates, subcontractors, and integrations that can access ePHI

  • Threats such as phishing, credential theft, ransomware, lost devices, unauthorized access, outages, and human error

  • Existing safeguards, remaining vulnerabilities, likelihood and impact, assigned corrective actions, and follow-up documentation

Cybersecurity practices such as encryption and multi-factor authentication are increasingly central to a defensible security program. Under the current Security Rule, however, leaders should distinguish current requirements from proposed changes. HHS has proposed significant Security Rule revisions, including broader mandatory cybersecurity controls. Until a final rule changes the standard, the current Security Rule remains in effect.

How HIPAA scales to a solo or small practice

The attached source makes a useful distinction: the legal obligations do not disappear for a small practice, but the implementation can be scaled. The following table preserves that concept while avoiding a one-size-fits-all formula.

Table 3

Breach response cannot be created after the breach

A stolen laptop, compromised email account, ransomware event, misdirected record, or vendor incident can move quickly from an IT problem to a compliance event. When unsecured PHI is breached, HIPAA’s Breach Notification Rule establishes notification duties and deadlines. Individual notice generally must be provided without unreasonable delay and no later than 60 days after discovery. Breaches involving more than 500 residents of a state or jurisdiction also trigger notice to prominent media outlets serving that area, in addition to HHS reporting requirements.

A small practice should decide in advance how it will preserve evidence, contain the incident, coordinate with vendors, determine what information was involved, assess whether a reportable breach occurred, document the analysis, and manage any required notifications.

A practical HIPAA action plan for mental health providers

  1. Confirm your HIPAA status. Determine whether the practice functions as a covered entity and whether it also performs any business-associate functions. Do not use size, office location, or “cash pay” as the only test.

  2. Map PHI and ePHI. Document where patient information enters the practice, where it is stored, who can access it, where it is transmitted, and how it is backed up or disposed of.

  3. Complete a meaningful Security Risk Analysis. Identify threats and vulnerabilities, document existing safeguards, rank risk, assign remediation, and retain evidence of the decisions made.

  4. Review vendors and BAAs. Build a vendor inventory, determine which relationships require BAAs, and evaluate whether contractual promises match the vendor’s actual access and services.

  5. Strengthen access and device security. Use unique accounts, strong authentication, secure configuration, screen locks, appropriate encryption, backups, and remote-device protections based on the risk analysis.

  6. Protect psychotherapy notes correctly. Use the HIPAA definition. Keep qualifying notes separate and apply the heightened authorization requirements when that category truly applies.

  7. Train the workforce. Train clinicians and support personnel according to their responsibilities and document completion.

  8. Prepare for incidents. Maintain an incident and breach response process that identifies responsibilities, documentation steps, vendor escalation, patient notification, and reporting.

  9. Reassess when the practice changes. A new EHR, telehealth platform, office, workforce arrangement, vendor, merger, security incident, or material workflow change can alter the risk environment.

From assessment to ongoing compliance: where Taino Consultants and EPI Compliance fit

A frequent weakness in small-practice compliance is fragmentation. A practice may have training certificates but no current risk analysis, an SRA but no remediation tracking, policies but no evidence they are reviewed, or a BAA folder that is not tied to an actual vendor inventory. The Taino Consultants and EPI Compliance model is designed to address different parts of that lifecycle: Taino Consultants focuses on assessment, strategy, remediation, governance, and implementation support, while EPI Compliance provides a structured platform for recurring compliance activities, documentation, training, and operational follow-through.

What Taino Consultants offers

Current Taino Consultants service descriptions emphasize moving healthcare organizations from advisory work into execution. For mental health practices, that can include a practical Security Risk Analysis and a prioritized plan for closing the gaps that the assessment identifies.

  • A current-state HIPAA security review that examines how ePHI is actually created, received, maintained, transmitted, accessed, and protected.

  • Threat and vulnerability identification across people, technology, physical spaces, vendors, and daily workflows.

  • Risk scoring and prioritization so a small practice can distinguish urgent exposure from lower-priority improvement opportunities.

  • Gap analysis, remediation planning, and a corrective-action roadmap with accountable next steps rather than a generic checklist.

  • Governance and follow-up guidance to help leadership document decisions and maintain the program after the initial assessment.

  • Certified HIPAA Security Officer (CHSO) training pathways that can help a practice designate and develop an internal owner for HIPAA Security responsibilities.

  • Broader healthcare operational and start-up support where compliance must be integrated with real business processes rather than treated as an isolated document exercise.

For a solo or small mental health practice, this approach can be scaled. The objective is not to recreate a hospital compliance department. It is to produce defensible documentation, identify the most important risks, establish ownership, and create a realistic remediation path the practice can maintain.

What EPI Compliance offers

EPICompliance Pro is positioned as an all-in-one online healthcare compliance platform. Its current service descriptions emphasize recurring compliance administration and documentation - the work that has to continue after the initial assessment is complete.

  • Online compliance training covering HIPAA Privacy, HIPAA Security, OSHA for Healthcare, and healthcare billing/waste, fraud and abuse topics, with course administration and completion documentation.

  • A library of HIPAA, OSHA, and healthcare compliance policies, forms, and standardized documents maintained in a cloud-based document repository.

  • Automated monthly compliance task lists and security reminders designed to keep recurring responsibilities visible.

  • Business Associate Agreement tools and a Business Associate management center to support vendor documentation.

  • Compliance officer assignments, employee attestations, compliance gap identification, and document-management functions.

  • Audit-defense platform assistance intended to help an organization organize and produce compliance documentation when it is reviewed.

  • Optional support services described on the current platform pages, including onboarding assistance, compliance-advisor support, incident-management assistance, and risk-management/remediation-plan assistance depending on the selected service level.

EPI Compliance also offers stand-alone compliance training and higher service tiers. Current published materials list EPICompliance Pro starting at $95 per month and a training bundle starting at $36 per user, with enterprise pricing after 50 users. Pricing and included services should be confirmed directly before publication because packages can change.

How the two services can work together

Table 4

The value of the combined model is the division of labor. An SRA identifies and prioritizes risk; policies and training establish expectations; recurring tasks and documentation help prove that the program is active; and follow-up consulting helps the practice respond when operations, technology, vendors, or regulatory expectations change. For a mental health practice that does not have a full-time privacy, security, or compliance department, that combination can provide structure without requiring an enterprise-sized internal team.

What a mental health practice should be able to show

If a complaint, incident, payer review, credentialing request, or regulatory inquiry occurs, the practice should be able to produce more than a policy binder. Depending on its circumstances, useful evidence may include:

  • A documented Security Risk Analysis and risk-management or remediation plan

  • Current policies and procedures that reflect actual workflows

  • Training records and workforce acknowledgements

  • A vendor inventory and executed BAAs where required

  • Evidence of periodic access review, account management, backups, and security monitoring

  • Incident and breach documentation, including decisions that were evaluated and why

  • Records showing corrective actions were assigned, completed, or actively tracked

  • Documentation of meaningful changes to technology, vendors, or workflows and the resulting risk review

Conclusion: small practice does not mean small responsibility

Mental health providers often work in intimate, highly confidential settings, and many now operate with the same digital dependencies as much larger organizations. The most effective compliance strategy is not to copy a hospital’s program or to purchase a checklist and call it complete. It is to understand whether HIPAA applies, map where patient information actually moves, identify the risks that matter most, implement reasonable safeguards, manage vendors, train the workforce, and document what the practice is doing over time.

For organizations that need help turning those expectations into an operating system, Taino Consultants can support the Security Risk Analysis, remediation strategy, governance, and leadership-development side of the work, while EPI Compliance can support the ongoing platform, training, policy, documentation, BAA, task-management, and compliance-administration functions. The goal is a program that is practical enough to maintain and documented well enough to defend.

CALL TO ACTION
Mental health providers should not wait for a complaint, breach, credentialing request, or audit to discover where their HIPAA Security program is weak. Contact Taino Consultants to discuss a practice-specific HIPAA Security Risk Analysis and remediation roadmap. Explore EPI Compliance for the policies, training, documentation, Business Associate management, recurring tasks, and compliance workflow needed to keep the program active after the assessment.

Sources

About Dr. Jose I. Delgado

Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.

Need help with healthcare compliance?

Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.

Schedule a consultation