HIPAA Compliance Requirements for Music and Art Therapy Practices: What Therapists Need to Know

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance Requirements for Music and Art Therapy Practices: What Therapists Need to Know

Kevin Henry

HIPAA

September 30, 2026

8 minutes read
Share this article
HIPAA Compliance Requirements for Music and Art Therapy Practices: What Therapists Need to Know

HIPAA Applicability to Therapy Practices

HIPAA applies to covered entities and their business associates. Most music and art therapy practices qualify as covered entities when they transmit standard electronic transactions such as insurance claims or eligibility checks, or when they use a clearinghouse on their behalf. If you serve as a contractor to a covered entity, you may be a business associate and must follow HIPAA-aligned safeguards.

Creative arts settings introduce unique records—session recordings, photographs of artwork, lyric sheets, and composition files—that can be tied to an identifiable client. These materials are Protected Health Information (PHI) when they relate to a person’s health or care and include any identifiers. Psychotherapy notes, if kept separate and used only for personal clinical reflection, receive special protection and are treated differently from the general record set.

  • You are likely a covered entity if you submit electronic claims or eligibility inquiries.
  • You use a billing service or clearinghouse to handle electronic transactions.
  • You provide services within facilities that require HIPAA alignment for all onsite providers.

Common practice scenarios

  • Private practice: direct billing and digital records typically trigger HIPAA obligations.
  • School, hospital, or agency contracts: you may be a business associate to the sponsoring entity.
  • Cash-pay only: HIPAA may still apply if you handle PHI for a covered entity; aligning with HIPAA remains best practice.

Managing Protected Health Information

Identify PHI and ePHI in creative therapies

  • Session notes, treatment plans, progress metrics, and assessment results.
  • Audio/video of sessions, music compositions, lyric sheets, and therapist annotations.
  • Images of artwork, process photos, and scanned creative artifacts.
  • Billing data, appointment logs, and secure messages containing client identifiers.
  • Group rosters and materials from group or family sessions, including minors and guardianship details.

Collection, storage, and retention

Define what belongs in the designated record set and keep psychotherapy notes separate when appropriate. Use a consistent file-naming and indexing scheme so you can retrieve, amend, and disclose records accurately while preventing unnecessary exposure.

  • Physical materials: label with de-identified codes when feasible, store in locked cabinets, and set clear return-or-disposal policies for client-created works.
  • Digital materials: store ePHI within your EHR or an encrypted repository; enable access controls, audit logs, backups, and Encryption of ePHI at rest and in transit.

Use, disclosure, and Breach Notification Procedures

Use and disclosure for treatment, payment, and operations is permitted under the HIPAA Privacy Rule. For education, marketing, publications, or public display of creative works, obtain written authorization or fully de-identify materials so no client can be recognized.

If an incident occurs, follow Breach Notification Procedures: contain the issue, perform a risk assessment, document findings, notify affected individuals and authorities as required, mitigate harm, and update safeguards. Maintain an incident log and train staff to escalate concerns immediately.

Implementing Minimum Necessary Standard

The minimum necessary standard requires you to limit PHI access, use, and disclosure to the least amount needed to accomplish a task. While disclosures to the individual, to HHS, and many treatment-related exchanges have special considerations, you should still design workflows that naturally minimize exposure.

Practical steps for creative arts settings

  • Role-based access: interns, assistants, and billing staff see only what they need.
  • Data minimization: tailor intake forms; avoid collecting identifiers you will never use.
  • Labeling: apply coded identifiers to artwork and recordings instead of full names.
  • Communications: keep appointment reminders brief and free of diagnosis or sensitive details.
  • Sharing: disclose only relevant excerpts (e.g., a short audio clip) rather than full recordings.

Session recordings and images

Record only when therapeutically necessary and with informed consent. Store recordings in encrypted systems, restrict access to a small, documented group, and follow a retention and deletion schedule aligned with clinical, legal, and payer requirements.

Ensuring Patient Rights Compliance

Under the HIPAA Privacy Rule, clients have rights to receive a Notice of Privacy Practices, access and obtain copies of their designated record set, request amendments, request restrictions, choose confidential communications, and obtain an accounting of certain disclosures. Psychotherapy notes kept separate and purely for personal clinical use are generally excluded from the access right.

Rights-focused workflows

  • Standardize intake forms and verify identity for record requests.
  • Provide copies through secure portals, encrypted email, or mail when requested.
  • Explain when items cannot be disclosed (e.g., separate psychotherapy notes) and offer summaries if appropriate.
  • Handle minors by confirming legal guardianship and documenting any restrictions.
  • Maintain clear timelines and cost-based copying fees consistent with law.

Documentation and consistency

Log requests, responses, and rationales for any denials. Keep templates for amendments and disclosures so your team responds consistently and on time across individual, family, and group therapy contexts.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Establishing Business Associate Agreements

Business Associate Agreements define how vendors that handle PHI on your behalf will safeguard it. Execute BAAs before sharing PHI and ensure that subcontractors of your vendors are also bound to HIPAA requirements.

Common business associates for art and music therapists

  • EHRs and practice management platforms.
  • Telehealth platforms and secure messaging tools.
  • Cloud storage, backup, and email encryption providers.
  • Billing companies, clearinghouses, and payment processors handling PHI.
  • Transcription, e-signature, appointment reminder, and faxing services.
  • IT support with system-level access and records destruction/shredding vendors.

What your BAA should cover

  • Permitted uses/disclosures and the minimum necessary standard.
  • Administrative, physical, and technical safeguards with Encryption of ePHI.
  • Incident reporting and Breach Notification Procedures, including timelines.
  • Subcontractor compliance, right to audit/assess, and workforce training.
  • Return or destruction of PHI and termination rights upon noncompliance.

Vendor due diligence

Perform a vendor Risk Assessment that evaluates data flows, access levels, encryption practices, authentication (e.g., MFA), logging, and data location. Keep security summaries and BAAs on file and review them during annual audits or when the service changes.

Conducting Risk Assessments

A Risk Assessment is the backbone of HIPAA Security Rule compliance. It identifies threats to the confidentiality, integrity, and availability of PHI and ePHI so you can prioritize safeguards and prove due diligence.

Structured approach

  1. Inventory systems and map where PHI resides, including artwork images and recordings.
  2. Identify threats and vulnerabilities across administrative, physical, and technical safeguards.
  3. Rate likelihood and impact, then determine overall risk levels.
  4. Select controls (encryption, access control, training, facility security) and assign owners.
  5. Document an action plan with milestones and evidence of completion.
  6. Monitor, test backups, and update after incidents, new vendors, or service expansions.

High-risk areas in creative practices

  • Storage and sharing of audio/video recordings and high-resolution artwork images.
  • Mobile devices used for capturing sessions or scanning creative works.
  • Group sessions, shared studios, and offsite services (schools, hospitals, clients’ homes).
  • Intern and volunteer access; role clarity and supervision controls.

Training and culture

Build a privacy-first culture through onboarding, periodic refreshers, phishing awareness, and sanctions for violations. Rehearse incident response and restore-from-backup steps so you can recover quickly without losing ePHI.

Applying Telehealth Security Measures

Telehealth Compliance starts with choosing a platform that offers a BAA, strong authentication, and Encryption of ePHI. Establish policies for identity verification, client location checks, emergency procedures, and consent for remote care and any recording.

Telehealth security checklist

  • Enable waiting rooms, unique meeting links, and multi-factor authentication.
  • Disable recordings by default; if recorded, store within an encrypted, access-controlled system.
  • Use updated devices, patched operating systems, and reputable endpoint protection.
  • Connect via private networks or VPN; avoid public Wi‑Fi for sessions.
  • Ensure auditory and visual privacy with headphones, neutral backgrounds, and secure storage of chat transcripts.
  • Integrate secure messaging and e-signature for consents, sharing only the minimum necessary.

Special considerations for creative sessions

For minors, confirm guardian presence and communication preferences. In group tele-sessions, review confidentiality rules, prohibit screenshots, and use first names or de-identified labels. For remote art/music activities, plan how files are exchanged securely and how finished works are stored.

Conclusion

By clarifying HIPAA applicability, tightly managing PHI, applying the minimum necessary standard, honoring patient rights, executing solid Business Associate Agreements, performing ongoing Risk Assessments, and hardening telehealth, your practice can protect clients and maintain compliant, creative care.

FAQs

What types of client information are considered PHI in art and music therapy?

PHI includes any identifiable information about a client’s health or care. In creative therapies this spans session notes, treatment plans, billing data, and ePHI such as audio/video recordings, photos of artwork, lyric sheets, and composition files that include names, faces, voices, or other identifiers. De-identify or obtain authorization before using materials outside treatment.

How do therapists comply with the minimum necessary standard?

Limit access by role, collect only data you will use, and share only the smallest relevant portion—such as a brief clip or redacted image—when coordinating care or billing. Keep psychotherapy notes separate, use coded labels on artwork, keep reminders generic, and design workflows that naturally minimize PHI exposure under the HIPAA Privacy Rule.

What are the requirements for business associate agreements?

Business Associate Agreements must be in place before sharing PHI and should define permitted uses, safeguards including Encryption of ePHI, incident reporting and Breach Notification Procedures, subcontractor compliance, and return/destruction of PHI. Vet vendors with a documented Risk Assessment and retain signed BAAs in your compliance files.

How should therapists handle breach notifications?

Act quickly: contain the incident, preserve evidence, and perform a risk assessment to determine the likelihood of compromise. Follow your Breach Notification Procedures to inform affected individuals and, when required, regulators and other parties. Document actions taken, provide mitigation, update safeguards, and retrain staff to prevent recurrence.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles