Eating Disorder Treatment Center HIPAA Compliance Guide: Requirements, Best Practices, and Checklist

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Eating Disorder Treatment Center HIPAA Compliance Guide: Requirements, Best Practices, and Checklist

Kevin Henry

HIPAA

September 30, 2026

10 minutes read
Share this article
Eating Disorder Treatment Center HIPAA Compliance Guide: Requirements, Best Practices, and Checklist

This Eating Disorder Treatment Center HIPAA Compliance Guide gives you a practical path to protect patient privacy while enabling coordinated, high-quality care. Because eating disorder programs handle uniquely sensitive details—weights, meal plans, photos, labs, therapy notes, and family communications—you need clear rules for Protected Health Information (PHI), robust safeguards for electronic PHI (ePHI), and airtight processes for Incident Reporting and breach response.

  • Map PHI flows across intake, therapy, nutrition, nursing, billing, and telehealth.
  • Apply the Minimum Necessary standard with Role-Based Access Control (RBAC).
  • Harden systems under the HIPAA Security Rule and test contingency plans.
  • Operationalize the Breach Notification Rule with a documented, timed workflow.
  • Segment Psychotherapy Notes and Substance Use Disorder (SUD) records under 42 CFR Part 2.
  • Execute and manage Business Associate Agreements (BAAs) with vendors.
  • Train your workforce and retain required records for audit readiness.

HIPAA Privacy Rule Requirements

What the Privacy Rule covers

The Privacy Rule protects PHI—any individually identifiable health information in any form. You may use or disclose PHI without patient authorization for treatment, payment, and health care operations (TPO), and when required by law. Outside these purposes, obtain a valid authorization.

Core requirements in an eating disorder setting

  • Minimum Necessary: Disclose or access only the PHI needed for the task. Pair this with Role-Based Access Control so dietitians, therapists, nurses, and billing staff see only what they require.
  • Notice of Privacy Practices (NPP): Provide at intake, post in your facility and online, and keep versions on file.
  • Patient rights: Enable timely access to records, amendments, restrictions where applicable, confidential communications, and an accounting of certain disclosures.
  • Authorizations: Use separate, specific authorizations for non-TPO purposes such as marketing, external research, or sharing photos.

Privacy best practices for eating disorder programs

  • Protect sensitive situations: private weigh-ins, discreet scheduling, and careful voicemail/email content.
  • Family involvement: confirm the patient’s preferences and any applicable consent rules for minors and personal representatives before sharing PHI.
  • Standardize releases of information (ROI): use templated forms for schools, athletic programs, or outside therapists.

Privacy checklist

  • Document PHI inventories and data maps across clinical and administrative workflows.
  • Publish and version-control the NPP; maintain ROI templates.
  • Implement RBAC and enforce the Minimum Necessary standard.
  • Enable patient access processes with clear timelines and tracking.

HIPAA Security Rule Safeguards

Administrative safeguards

  • Risk analysis and risk management: assess threats to ePHI, prioritize risks, and track remediation.
  • Assigned security official, policies, and procedures: cover access, encryption, mobile device use, and Incident Reporting.
  • Workforce security and training: role-specific training, sanctions for violations, and regular phishing simulations.
  • Contingency planning: data backup, disaster recovery, and emergency-mode operations with documented tests.

Physical safeguards

  • Facility controls: secure server rooms and records storage; visitor sign-in.
  • Workstation security: screen privacy filters, auto-locks, and clean-desk rules.
  • Device and media controls: inventory laptops/phones, encrypt drives, and certify proper disposal.

Technical safeguards

  • Access control: unique user IDs, MFA, RBAC, and automatic logoff.
  • Encryption: in transit (TLS) and at rest for ePHI wherever feasible.
  • Audit controls: centralized logging, regular log reviews, and alerts for anomalous access.
  • Integrity and authentication: safeguards to prevent improper alteration and to verify user identity.

Security checklist

  • Complete and update your Security Risk Analysis annually or after major changes.
  • Mandate MFA, device encryption, and patch management across the environment.
  • Log and monitor access to EHR, file shares, and telehealth platforms.
  • Test backups and disaster recovery plans; document the results.

Breach Notification Procedures

What counts as a breach

A breach is an impermissible use or disclosure of unsecured PHI that compromises privacy or security. If ePHI is encrypted to recognized standards or data is properly destroyed, safe-harbor may apply. Conduct a documented risk assessment for every incident.

Risk assessment and decisioning

  • Nature and extent of PHI involved (e.g., diagnoses, SSNs, treatment plans).
  • Unauthorized person who used/received the PHI.
  • Whether the PHI was actually viewed or acquired.
  • Extent to which the risk has been mitigated (e.g., recipient attests to deletion).

Who to notify and when

  • Affected individuals: without unreasonable delay and no later than 60 calendar days after discovery.
  • HHS: for 500+ individuals in a state/jurisdiction, notify within 60 days of discovery; for fewer than 500, report no later than 60 days after the end of the calendar year.
  • Media: for breaches affecting 500+ residents of a single state/jurisdiction.
  • Business Associates: must notify the covered entity per contract terms; set shorter notice windows than the statutory maximum in your BAAs.

Incident Reporting and response workflow

  • Detect and contain: secure accounts, isolate devices, preserve logs.
  • Report immediately: staff submit an Incident Reporting ticket or hotline call to privacy/security officials.
  • Assess and decide: complete the breach risk assessment, consult counsel as needed.
  • Notify: prepare compliant notices; track dates to meet the Breach Notification Rule.
  • Remediate: patch gaps, retrain staff, update policies, and document everything.

Breach checklist

  • Time-stamp the discovery date to start the 60-day clock.
  • Retain risk assessments, notices, and mitigation records.
  • Coordinate with Business Associates and insurers where applicable.

Managing Protected Health Information

PHI lifecycle management

  • Collect: limit intake forms to necessary data for eating disorder diagnosis, treatment, and coordination.
  • Use and disclose: follow TPO rules; scrutinize any non-TPO disclosures.
  • Store: encrypt systems, lock paper files, and document retention schedules.
  • Dispose: shred paper and securely wipe media before reuse or disposal.

Minimum Necessary and Role-Based Access Control

Translate Minimum Necessary into RBAC profiles in your EHR and file repositories. Map typical roles—therapist, dietitian, nurse, case manager, billing—and restrict each to the least privilege required. Review privileges quarterly and upon job changes.

De-identification and limited data sets

For analytics and quality improvement, use a limited data set with a Data Use Agreement or fully de-identify data. Only share what’s needed and track disclosures when required.

Patient preferences and special communications

Honor requests for confidential communications (e.g., alternate addresses). Obtain explicit authorization before using PHI for marketing. For minors, determine who is the personal representative under state law before sharing PHI with parents or schools.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

PHI management checklist

  • Data map and record of disclosures process.
  • RBAC reviews and access recertifications.
  • Standardized ROI and authorization workflows.
  • Secure destruction procedures and logs.

Handling Psychotherapy and SUD Records

Psychotherapy Notes

Psychotherapy Notes are the therapist’s separate notes analyzing conversation content and must be stored apart from the designated medical record. They generally require the patient’s specific authorization for use or disclosure and are not available for routine TPO. Keep them physically and electronically segregated, with extra access controls and auditing.

Substance Use Disorder records under 42 CFR Part 2

Programs that provide SUD diagnosis, treatment, or referral are subject to 42 CFR Part 2. In most cases, you need written patient consent that specifies what information may be shared, with whom, and for what purpose. Include the prohibition on re-disclosure notice when Part 2 information is released. Segment or tag Part 2 data in the EHR, limit access to staff with a need to know, and maintain detailed disclosure logs. Emergency and court-order pathways are tightly controlled; consult policy and counsel before disclosing without consent.

Practical storage and access controls

  • Segment psychotherapy and Part 2 records in the EHR; apply stricter RBAC and “break-glass” workflows with alerts.
  • Use separate storage locations or encrypted containers for Psychotherapy Notes.
  • Train staff on what qualifies as Psychotherapy Notes versus progress notes and how 42 CFR Part 2 differs from HIPAA.

Special-records checklist

  • Dedicated policies for Psychotherapy Notes and SUD records.
  • Consents that meet HIPAA and 42 CFR Part 2 requirements.
  • Segmentation, enhanced auditing, and re-disclosure warnings.

Implementing Business Associate Agreements

Who is a Business Associate

Any vendor that creates, receives, maintains, or transmits PHI on your behalf—EHRs, telehealth platforms, billing services, cloud storage, email providers, labs, call centers, and shredding vendors—needs a Business Associate Agreement.

Due diligence before signing

  • Review security posture: encryption, access controls, logging, and breach history.
  • Confirm subcontractor management and data location practices.
  • Validate Incident Reporting and breach response capabilities.

Essential BAA terms

  • Permitted uses/disclosures and Minimum Necessary obligations.
  • Safeguards aligned to the Security Rule and prompt breach reporting (set notice windows shorter than the statutory maximum).
  • Subcontractor flow-down, right to audit, return or destruction of PHI at termination.
  • Cooperation on the Breach Notification Rule and Incident Reporting.

BAA management checklist

  • Inventory all vendors; obtain executed BAAs before data sharing.
  • Centralize BAA storage and track renewal dates.
  • Test vendor incident contacts at least annually.

Workforce Training and Record Retention

Training program essentials

  • Onboarding and annual refreshers covering Privacy Rule, Security Rule, RBAC, secure messaging, social engineering, and Incident Reporting.
  • Role-based modules for therapists, dietitians, nurses, residential staff, admissions, and billing.
  • Scenario drills: misdirected fax, lost device, snooping, and telehealth mishaps.

Documentation and retention

  • Retain HIPAA-required documents (policies, NPP versions, risk analyses, training rosters, BAAs, breach files) for at least six years from creation or last effective date.
  • Follow state laws for medical record retention; set policies for adults and minors that meet or exceed state minimums.
  • Maintain access logs and disclosure logs where required, including for 42 CFR Part 2 data.

Audit-ready file checklist

  • Current policy set with version history and approvals.
  • Completed Security Risk Analysis and remediation plan.
  • Training records, attestations, and sanction documentation.
  • Vendor inventory with executed Business Associate Agreements.
  • Incident Reporting register and any breach notifications with timelines.

Conclusion

By mapping PHI, enforcing RBAC, hardening systems, and operationalizing the Breach Notification Rule, your program can protect privacy without slowing care. Segmentation of Psychotherapy Notes and 42 CFR Part 2 records, strong BAAs, and continual training keep you compliant and audit-ready while supporting patient trust.

FAQs.

What safeguards are required under the HIPAA Security Rule?

You must implement administrative (risk analysis, policies, training, contingency plans), physical (facility, workstation, and device/media controls), and technical safeguards (access control with MFA and RBAC, encryption, audit logging, integrity protections). Document how each safeguard applies to your ePHI systems and review them regularly.

How should psychotherapy notes be stored and accessed?

Store Psychotherapy Notes separately from the medical record in an encrypted, access-restricted location. Limit access to the originating therapist or a narrowly defined group, require specific patient authorization for disclosures, and maintain enhanced auditing and “break-glass” alerts for any emergency access.

When must breach notifications be issued?

Notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. For breaches affecting 500 or more residents of a state or jurisdiction, also notify HHS within 60 days and local media. For fewer than 500, report to HHS no later than 60 days after the end of the calendar year.

Records covered by 42 CFR Part 2 generally require written patient consent that specifies what information is disclosed, to whom, and for what purpose, along with a prohibition on re-disclosure notice. Segment Part 2 data, limit access to staff with a need to know, keep detailed disclosure logs, and follow strict rules for any emergency or court-ordered disclosures.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles