HIPAA Compliance for Mental Health and Behavioral Health
Mental health and behavioral health providers must comply with HIPAA regulations that impose stricter requirements than those for other healthcare providers, including additional protections for psychotherapy notes under 45 CFR 164.508 and substance use disorder records under 42 CFR Part 2.
Why Behavioral Health Has Different HIPAA Rules
Under 45 CFR 164.508, psychotherapy notes are notes recorded by a mental health professional documenting or analyzing the contents of a counseling session. These notes must be stored separately from the medical record and require patient authorization for most disclosures.
Records from federally assisted substance use disorder treatment programs are subject to 42 CFR Part 2, which requires written patient consent for most disclosures - a stricter standard than HIPAA's treatment/payment/operations exception.
Therapists, counselors, psychologists, and psychiatrists must follow these added rules on top of the standard Privacy and Security Rules.
What We Focus On for Behavioral Health Providers
These are the highest-risk gaps we see across therapy practices, counseling centers, and behavioral health programs.
- Risk and gap reviews for sessions, care handoffs, and records based on the security risk assessment rules in 45 CFR §164.308(a)(1)
- Policies for intake, notes, and patient messages, including psychotherapy note controls under 45 CFR §164.508(a)(2). See our guide on HIPAA authorization form requirements
- Staff HIPAA training by role with clear privacy and security duties
- Vendor and BAA controls under 45 CFR §164.308(b) for your EHR, telehealth platform, billing service, and any other vendor that touches PHI
Required HIPAA Compliance Steps for Behavioral Health
Every behavioral health covered entity must complete these steps. Each ties to a specific CFR rule. For cost details, see our HIPAA compliance cost breakdown.
- Security Risk Assessment (SRA) - Required under §164.308(a)(1)(ii)(A). You must find threats to all ePHI your practice creates, stores, or sends. A documented risk assessment is the item OCR looks for first when it investigates a behavioral health practice.
- Written policies and procedures - Required under §164.316(a). Must cover privacy, security, breach notification, and staff conduct. Your policy templates should also cover psychotherapy notes, SUD record consent, and telehealth protocols.
- Workforce training - Required under §164.308(a)(5)(i). Everyone with PHI access must complete HIPAA training at hire and when policies change. Keep training records for six years.
- Business Associate Agreements - Required under §164.308(b)(1). You need signed BAAs with your EHR vendor, telehealth platform, billing service, cloud storage, and any other vendor that handles PHI.
- Psychotherapy notes protections - Under §164.508(a)(2), therapy notes kept separate from the medical record need written authorization before almost any disclosure. Standard TPO exceptions do not apply.
- 42 CFR Part 2 review - If your practice treats substance use disorders with federal funding, those records have stricter consent rules than HIPAA. The more protective standard always wins.
Common HIPAA Compliance Gaps in Behavioral Health
Many practices have no documented risk assessment. They use generic policies that skip psychotherapy note rules. They lack BAAs with telehealth or EHR vendors. They do not keep training records. A gap analysis maps each gap to the CFR rule it violates and ranks fixes by risk.
Group practices face extra challenges. Therapists use different tools, keep notes differently, and work from different locations. A gap analysis at the organization level is the right starting point.
Telehealth Compliance for Behavioral Health
Telehealth platforms used for behavioral health sessions must implement encrypted transmission, access controls, and require a signed BAA. The platform vendor is a business associate under HIPAA.
The same technical safeguards under §164.312 apply here: unique user IDs, automatic logoff, and encryption. Which platform you pick and how you set it up matters more than most practices think. See our guide on HIPAA and telehealth compliance for the full list.
Regulatory Standards Specific to Behavioral Health
These federal rules govern HIPAA for behavioral health providers. Knowing which ones apply to your practice is step one.
HIPAA Enforcement for Behavioral Health
OCR enforces HIPAA for all covered entities, including behavioral health providers. Fines range from $145 to $2,190,294 per violation type per year under 45 CFR §160.404. OCR has investigated therapy practices for unauthorized record sharing, missing risk assessments, and slow patient record access (the 30-day rule under §164.524(b)(2)). See our breakdown of 2026 HIPAA penalty amounts for recent trends.
Behavioral Health HIPAA FAQ
Can we improve compliance without disrupting patient care?
Yes. We build safeguards into your current workflow, not on top of it. The rules under 45 CFR §164.308 are meant to fit into daily operations. We focus on changes that cut risk without slowing down care.
Are psychotherapy notes treated differently under HIPAA?
Yes. Under 45 CFR §164.508(a)(2), therapy notes kept separate from the medical record need written authorization before almost any disclosure, even for treatment. The usual TPO exceptions do not apply. Your forms, EHR setup, and staff training must all account for this.
How do 42 CFR Part 2 records interact with HIPAA?
Part 2 covers records from federally funded SUD treatment programs. It has stricter consent rules than HIPAA. When both apply, the tighter rule wins, which is almost always Part 2. Most practices that treat SUD need separate consent workflows for those records.
What about telehealth HIPAA compliance?
You need a HIPAA-compliant video platform with a signed BAA. Document patient consent for remote sessions. Set up access controls under 45 CFR §164.312 to block unauthorized access to session data. Which platform you pick and how you configure it matters.
How does HIPAA handle PHI for minors in behavioral health?
State law controls a minor's right to consent to behavioral health services. That affects who can see their records. HIPAA defers to state law under 45 CFR §164.502(g). Your privacy practices and access controls must reflect your state's rules on minor confidentiality.
Who We Help With Behavioral Health HIPAA Compliance
We work with behavioral health providers across the United States, including:
- Licensed therapists and clinical social workers (LCSW) in private practice
- Psychologists and psychiatrists managing patient records
- Group counseling practices with multiple providers
- Substance use disorder treatment programs subject to 42 CFR Part 2
- Integrated behavioral health programs within larger health systems
- Telehealth-only therapy practices needing platform compliance
Whether you are a solo therapist or a multi-location organization with dozens of providers, the same HIPAA rules apply. The difference is scale. We tailor our approach to your practice size, budget, and risk level.
Chuck Weiselberg, Certified HIPAA Professional (C.H.P.). Zero client fines. Zero failed audits.
“One Guy Consulting is super easy to work with. I actually look forward to my implementation meetings for HIPAA.” — Samantha M.