HIPAA Compliance for Peer Support Specialists: What You Need to Know
HIPAA Applicability to Peer Support Specialists
When HIPAA applies
HIPAA applies to you when you are part of the workforce of a covered entity (such as a clinic, hospital, or health plan) or you provide services on behalf of a covered entity or its business associates under a contract that involves access to Protected Health Information (PHI). In these roles, you must follow the organization’s HIPAA policies and procedures.
- You work on a care team and access the electronic health record to support clients.
- You are contracted by a provider or health plan and have a Business Associate Agreement (BAA).
- You handle billing details, coordination notes, or communications that include PHI.
When HIPAA may not apply
HIPAA typically does not apply when you volunteer or work for a peer‑run, community, or mutual‑aid organization that is not a covered entity, does not act as a business associate, and does not receive PHI from one. Even then, you still must honor confidentiality standards, program rules, and any applicable federal confidentiality laws or state privacy statutes.
Key definitions you should know
- Protected Health Information (PHI): Individually identifiable health information in any form that relates to a person’s health, care, or payment for care.
- Covered Entities: Health plans, most health care providers that transmit standard electronic transactions, and health care clearinghouses.
- Business Associates: Vendors or individuals who perform services for a covered entity and need PHI to do so (for example, care coordination platforms or transcription services).
- Workforce: Employees, volunteers, trainees, and others under the direct control of a covered entity or business associate.
Covered Entities and Business Associates
Understand your role before you share or document
Clarify whether you are a workforce member of a covered entity, an independent contractor acting as a business associate, or neither. Your status determines what agreements, safeguards, and documentation practices you must follow before you view, receive, or disclose PHI.
- If you are a workforce member: Follow the host organization’s HIPAA policies, role‑based access limits, and security rules.
- If you are a business associate: Ensure a signed BAA is in place and extend equivalent protections to any subcontractors.
- If you are neither: Do not accept PHI from covered entities unless a compliant pathway (e.g., BAA) exists.
BAAs, vendors, and real‑world examples
- Scheduling, secure messaging, cloud storage, or data dashboards used for care coordination generally require BAAs if they handle PHI.
- Personal email, texting, or consumer apps are not acceptable for PHI unless your organization has approved them and required safeguards are in place.
Where 42 CFR Part 2 fits
In substance use disorder settings, service providers may need a Qualified Service Organization Agreement (QSOA) under 42 CFR Part 2 in addition to or instead of a BAA. Know which agreement your program uses before handling SUD records.
Confidentiality and Privacy Protections
Permitted uses and disclosures
Within HIPAA, you may use or disclose PHI for treatment, payment, and health care operations (TPO) consistent with your role and organizational policies. Most other disclosures require the client’s written authorization or a specific legal basis. Always apply the minimum necessary standard for non‑treatment tasks.
Practical safeguards you should consistently apply
- Verify identity before discussing PHI and confirm who else is present on calls or video sessions.
- Use only approved, secure systems; avoid personal devices or enable required protections (strong passcode, encryption, auto‑lock, remote wipe).
- Keep conversations private, control your surroundings, and avoid public spaces for sensitive discussions.
- Limit notes to what your role requires; do not include unnecessary details, diagnoses, or third‑party information.
- Store, transmit, and dispose of PHI according to policy; report suspected breaches immediately—do not investigate on your own.
Group, family, and community settings
In groups, set clear ground rules about privacy and sharing outside the session. When family or supporters are involved, obtain the client’s permission before sharing PHI and document that permission when policy requires it.
Code of Ethics for Peer Support Specialists
Core commitments
- Peer Support Ethics center on mutuality, respect, self‑determination, and hope—never coercion or control.
- Honor lived experience while maintaining confidentiality and clear boundaries.
- Use plain language; avoid clinical labeling or role drift into diagnosis or therapy.
Boundaries and role clarity
- Share your story purposefully and only to support the person’s goals.
- Avoid dual relationships that could impair judgment or create pressure to disclose PHI.
- Follow social media and texting guidelines; keep private messages professional and policy‑compliant.
Safety and exceptions
Know mandated reporting rules and how your program handles imminent risk. Explain limits of confidentiality up front, including when law requires disclosure.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Training and Education Requirements
What training is expected
If you are part of a covered entity or business associate, HIPAA requires workforce training that matches your duties. You should receive onboarding training and additional instruction when policies, systems, or laws change. Annual refreshers and ongoing security awareness are widely adopted best practices.
Essential topics to cover
- Privacy Rule basics, PHI handling, minimum necessary, and client rights.
- Security Rule practices: device security, passwords, phishing, secure messaging, and data disposal.
- Breach recognition and reporting steps.
- 42 CFR Part 2 requirements if your work touches SUD records.
- State‑specific confidentiality standards and mandated reporting.
Documentation and accountability
Keep records of completed modules, dates, and assessments. Follow your organization’s sanction policy for violations and participate in periodic audits or drills to reinforce learning.
Substance Use Disorder Records Compliance
How 42 CFR Part 2 protects SUD information
42 CFR Part 2 imposes stricter rules on records created by federally assisted programs that provide SUD diagnosis, treatment, or referral. These records generally cannot be disclosed without written consent that specifies the recipient, purpose, and scope. Redisclosure is tightly limited.
Working in or with a Part 2 program
- Confirm whether your setting is a Part 2 program; if so, follow program‑specific policies for consent, documentation, and redisclosure warnings.
- Use QSOAs or BAAs, as applicable, before vendors or partners handle Part 2 data.
- Segment SUD information in shared systems and label it so only authorized team members can access it.
- Know limited exceptions (for example, medical emergencies or court orders) and escalate questions to compliance immediately.
Alignment with HIPAA and your day‑to‑day practice
Recent updates align Part 2 more closely with HIPAA, allowing broader TPO sharing after a valid, initial consent. Your responsibilities remain the same: obtain or verify required consent, follow minimum necessary for non‑treatment uses, and report potential breaches promptly.
State-Specific Regulations for Peer Support Specialists
Why states matter
States can add protections that go beyond HIPAA—especially for mental health, HIV, reproductive health, and minors. You must follow the most protective rule that applies to a given situation.
Common state‑level requirements
- Mandated reporting and “duty to warn/protect” standards vary by state.
- Special consent rules for adolescents, sensitive services, or psychotherapy notes may apply.
- Some states regulate peer specialist certification, supervision, and documentation practices.
Action steps
- Ask your program for a HIPAA/Part 2/state “crosswalk” and follow it when documenting or sharing information.
- Use approved scripts and forms to obtain and record permissions.
- When uncertain, pause and consult your privacy officer or legal counsel before disclosing PHI.
Conclusion
HIPAA compliance for peer support specialists starts with knowing your role, limiting PHI to what is needed, and using approved, secure workflows. In SUD settings, 42 CFR Part 2 adds stricter rules that require careful consent and segmentation. Layer in state‑specific requirements, follow Peer Support Ethics, and collaborate with compliance to keep people’s information safe while providing effective support.
FAQs.
When does HIPAA apply to peer support specialists?
HIPAA applies when you are part of a covered entity’s workforce or you act as a business associate and handle PHI for that entity. If you work for a peer‑run group that is not a covered entity or business associate and does not receive PHI from one, HIPAA generally does not apply—though other confidentiality standards and laws may.
How must peer support specialists protect confidentiality under HIPAA?
Use or disclose PHI only for permitted purposes (such as TPO), apply the minimum necessary rule for non‑treatment tasks, use approved secure tools, keep conversations private, document only what policy requires, and report suspected breaches immediately.
What training is required for HIPAA compliance?
Workforce members of covered entities and business associates must receive HIPAA training tailored to their duties at onboarding and when policies change. Regular refreshers, security awareness, and—if applicable—training on 42 CFR Part 2 and relevant state laws are expected best practices.
Are substance use disorder records handled differently under HIPAA?
Yes. SUD records from Part 2 programs are protected by 42 CFR Part 2, which sets stricter disclosure and redisclosure limits than HIPAA. After a valid initial consent, certain TPO sharing may be allowed under recent alignment, but programs still require careful consent management, segmentation, and strong safeguards.
Table of Contents
- HIPAA Applicability to Peer Support Specialists
- Covered Entities and Business Associates
- Confidentiality and Privacy Protections
- Code of Ethics for Peer Support Specialists
- Training and Education Requirements
- Substance Use Disorder Records Compliance
- State-Specific Regulations for Peer Support Specialists
- FAQs.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.