HIPAA Compliance Guide for Your Marriage and Family Therapy Practice

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance Guide for Your Marriage and Family Therapy Practice

Kevin Henry

HIPAA

October 04, 2026

9 minutes read
Share this article
HIPAA Compliance Guide for Your Marriage and Family Therapy Practice

HIPAA Compliance Overview

As a marriage and family therapist, you handle protected health information every day—from intake forms to progress notes and billing. HIPAA sets national standards for how you use, disclose, and secure this information across paper and digital formats. Your compliance program should be practical, documented, and scaled to your practice size.

Who is covered and what is PHI?

HIPAA applies to covered entities (providers who transmit claims or health information electronically) and their business associates (vendors that create, receive, maintain, or transmit PHI on your behalf). PHI includes any information that identifies a client and relates to their health, care, or payment. Psychotherapy notes kept separate from the medical record receive heightened protection.

Core HIPAA rules for therapists

  • Privacy Rule: Governs when you may use or disclose PHI and outlines patient consent requirements and rights.
  • Security Rule: Requires administrative, physical, and technical measures to safeguard electronic PHI (ePHI), including risk analysis and management.
  • Breach Notification Rule: Establishes what to do—and by when—if PHI is compromised.

Program building blocks

  • Designate a Privacy/Security Officer (in solo practice, that can be you) and maintain written policies and procedures.
  • Issue a Notice of Privacy Practices, execute business associate agreements with vendors, and train all workforce members.
  • Conduct an initial and periodic security risk analysis, implement risk management, and document everything.

Privacy Rule Requirements

The Privacy Rule balances client confidentiality with care coordination. For therapists, the focus is limiting disclosures, honoring client choices, and documenting authorizations when needed.

Permitted uses and minimum necessary

You may use and disclose PHI without authorization for treatment, payment, and health care operations. Apply the minimum necessary standard to non-treatment disclosures by sharing only what is reasonably needed.

For most non-TPO purposes—such as marketing, releasing records to third parties not involved in care, or sharing psychotherapy notes—you need a valid, written authorization. Verbal permission may suffice for disclosures to persons involved in a client’s care when the client agrees or does not object, but document your decision-making each time.

Psychotherapy notes and couples/family dynamics

Keep psychotherapy notes separate from the medical record if you use them; they generally require a distinct authorization to disclose. In couples or family therapy, clarify confidentiality boundaries at the outset, agree on what may be shared among participants, and document each individual’s preferences.

Notice of Privacy Practices and client choices

Provide and document acknowledgment of your Notice of Privacy Practices. Honor reasonable requests for confidential communications (for example, contacting a spouse at work or using an alternate email) and consider client requests to restrict disclosures, especially for self-paid services.

Security Rule Requirements

The Security Rule applies to electronic PHI and expects you to put electronic PHI safeguards in place that are reasonable for your size and risks. Think people, processes, and technology working together.

Administrative safeguards

  • Risk analysis and management: Identify where ePHI lives (EHR, email, cloud storage, mobile devices), rank threats, and implement controls; revisit at least annually or after major changes.
  • Workforce measures: Role-based access, onboarding/offboarding checklists, sanctions for violations, and security awareness training.
  • Contingency planning: Encrypted backups, disaster recovery procedures, and downtime workflows.

Physical safeguards

  • Secure workstations and paper files; limit office access; use privacy screens in shared spaces.
  • Maintain an inventory of devices that store ePHI; enable automatic logoff and lockable storage.

Technical safeguards

  • Access control: Unique user IDs, strong passwords, and multi-factor authentication for systems with ePHI.
  • Encryption: Encrypt data in transit and at rest wherever feasible; use secure messaging instead of standard SMS.
  • Audit and integrity: Enable audit logs, review them periodically, and use anti-malware and patch management.

Vendors and business associate agreements

Before using an EHR, telehealth platform, billing service, cloud storage, or e-fax provider, confirm they will sign business associate agreements and can support your security requirements.

Patient Rights under HIPAA

Clients have specific rights that you must enable and document. Build workflows so these requests are straightforward and timely.

Access and copies

Clients can access and obtain copies of their records in the format requested if readily producible, including electronic copies. Provide access promptly, charge only cost-based fees, and note that psychotherapy notes kept separate are typically excluded from access requests.

Amendments and restrictions

Clients may request amendments to their records; you must respond in writing and, if you deny the request, allow a statement of disagreement. Clients can also ask you to restrict disclosures; you must honor certain restrictions, such as when services are fully self-paid and the client asks not to share with their health plan.

Confidential communications and accounting

Accommodate reasonable requests for confidential communications (alternate address, phone, or email). Upon request, provide an accounting of certain disclosures not related to treatment, payment, or operations within required timeframes.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Breach Notification Rule

A breach is an impermissible use or disclosure of unsecured PHI that compromises privacy or security. When an incident occurs, act quickly, investigate, and document your analysis.

Assessing incidents

Determine whether there is a low probability that PHI was compromised by considering the type of PHI, who received it, whether it was actually viewed, and how the risk was mitigated. If encrypted PHI remains unreadable, it may not be a breach.

Required notices and breach notification timelines

  • Individuals: Notify affected clients without unreasonable delay and no later than 60 days after discovery.
  • HHS: If 500 or more individuals in a state or jurisdiction are affected, notify HHS within 60 days; for fewer than 500, report to HHS no later than 60 days after the end of the calendar year.
  • Media: If 500 or more individuals in a state/jurisdiction are affected, notify prominent media outlets as required.

Notices must include a description of what happened, the types of PHI involved, steps clients should take, what you are doing to mitigate harm and prevent recurrence, and your contact information.

Business associates and mitigation

Business associates must notify you of breaches they discover. Your business associate agreements should define responsibilities, timelines, and cooperation in investigations. Mitigate harm promptly and document corrective actions.

Documentation and Training

HIPAA expects robust documentation and a trained workforce. If it isn’t written down, regulators will assume it didn’t happen.

What to document

  • Policies and procedures covering Privacy, Security, and Breach Notification Rules, retained for at least six years from the date last in effect.
  • Risk analysis findings, risk management plans, and periodic reviews.
  • Training dates, topics, and attendees; sanction and incident logs.
  • Business associate agreements, access role matrices, and audit log reviews.

Training that works

  • Onboard training before accessing PHI; refresh annually and when policies change.
  • Scenario-based exercises (misdirected email, lost device, family member requesting information) to build practical competence.
  • Telehealth privacy protocols, including verifying client identity, private environments, and secure communications.

Compliance Challenges for Therapists

Marriage and family therapy presents unique privacy complexities: multiple participants, family involvement in care, and frequent use of mobile and telehealth tools. Address these risks head-on with clear policies and client education.

Couples and family confidentiality

Set expectations during informed consent: what information will be part of the designated record set, when information may be shared among participants, and how you will handle unilateral disclosures. Document choices and revisit them as therapy evolves.

Everyday communication risks

Confirm phone numbers and emails before use, and record communication preferences. Use secure messaging for clinical content, avoid standard texting, and verify identities before discussing PHI by phone. Limit calendar invites and voicemail content to the minimum necessary.

Telehealth privacy protocols

Use platforms that offer a signed BAA, enforce strong authentication, and encrypt sessions. In each visit, confirm the client’s location and privacy of their environment, discourage recording, and advise clients to use private networks and headphones. Update risk analysis to include remote work and mobile devices.

Practical technology safeguards

  • Enable device encryption, automatic locking, and remote wipe on phones, tablets, and laptops.
  • Segment personal and work data, back up ePHI securely, and keep systems patched.
  • Review access logs for anomalies and remove access promptly when roles change.

Conclusion

Effective HIPAA compliance for therapy practices rests on clear Privacy Rule workflows, right-sized Security Rule controls, disciplined documentation, and swift breach response. By formalizing patient consent requirements, executing business associate agreements, and maintaining electronic PHI safeguards through ongoing risk analysis and management, you protect clients, your license, and your practice.

FAQs.

What are the key HIPAA requirements for marriage and family therapists?

You must follow the Privacy Rule for permissible uses and disclosures, honor client rights, apply the Security Rule to protect ePHI with administrative, physical, and technical controls, and comply with the Breach Notification Rule. Core tasks include issuing a Notice of Privacy Practices, conducting risk analysis and management, executing business associate agreements, training your workforce, and documenting policies and actions.

For treatment, payment, and health care operations, you generally do not need written authorization, but you should document professional judgment when clients agree or do not object to involved-person disclosures. For non-TPO uses—marketing, most third-party releases, and psychotherapy notes—obtain a written authorization describing the information, purpose, recipients, expiration, and the client’s right to revoke. File signed forms in the record and track expirations.

What steps should be taken after a breach of PHI?

Immediately secure systems, stop further disclosure, and investigate. Perform a four-factor risk assessment, decide if breach notification is required, and follow breach notification timelines: notify affected individuals without unreasonable delay and no later than 60 days from discovery; notify HHS and, if applicable, media based on the number of individuals affected. Mitigate harm, update safeguards, and document every step.

How can therapists ensure compliance in telehealth services?

Choose a telehealth platform that signs a BAA, uses end-to-end encryption, and supports access controls and audit logs. Establish telehealth privacy protocols: verify identity and location at each session, ensure both parties are in private spaces, avoid recording, and use secure messaging for follow-up. Include telehealth in your risk analysis and workforce training, and document client communication preferences and consents.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles