Industry

HIPAA compliance for behavioral & mental health

Psychotherapy notes carry heightened protection, and most telehealth stacks were never configured with that in mind.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

Psychotherapy notes carry heightened protection, and most telehealth stacks were never configured with that in mind.

What usually goes wrong

  • Psychotherapy notes segregation under §164.508(a)(2)
  • 42 CFR Part 2 overlap for substance use disorder records
  • Solo and group practices on consumer-grade video tools
  • State laws stricter than HIPAA

What SuperHIPAA does about it

  • Separate handling and access control for psychotherapy notes
  • Telehealth platform evaluation and BAA verification
  • Multi-jurisdiction policy layering
  • Practice-sized training and documentation

Your obligations in one paragraph

As a covered entity, you must conduct an accurate and thorough risk analysis, implement the required Security Rule specifications (and either implement or document a rationale for each addressable one), maintain policies and procedures, train your workforce, execute business associate agreements with everyone who touches ePHI on your behalf, and be able to detect, assess, and report breaches. All of it must be evidenced. None of it is a one-time project.

Where most behavioral & mental health actually stand

The pattern we see in this vertical: policies exist, training happens sporadically, BAAs are partially in place, and the risk analysis is either missing or several years stale. That last one is the finding that turns an incident into a penalty, because it is the first document OCR requests.

Getting started

  1. Free readiness assessment — scored report, no call required
  2. Gap assessment — if the score shows real exposure
  3. Implementation — we fix it with you, or hand your team the plan
  4. Platform — keeps it true after we leave

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Are behavioral & mental health covered entities or business associates?

Typically **Covered Entity**. It matters because it changes which obligations are yours directly and which flow through a BAA. The readiness assessment determines your scope in the first three questions.

How long does it take to get compliant?

For an organisation starting from near zero, 8–12 weeks to a defensible position: risk analysis complete, required safeguards implemented, policies live, workforce trained. Anyone promising two weeks is selling you a certificate.

What does it cost?

Platform starts at a published monthly price — see pricing. Services are fixed-fee. There is no 'contact us for a quote' wall on this site.

Do you replace our IT provider?

No. We tell your IT provider exactly what to configure and then verify they did it.

Are therapy notes treated differently under HIPAA?

Psychotherapy notes kept separate from the medical record get extra protection — most uses and disclosures require a specific authorization under §164.508, and patient access rights differ. Your documentation practice determines whether notes qualify, so we cover it in policy.

Does 42 CFR Part 2 apply to us?

If you provide substance use disorder treatment in a federally assisted program, Part 2's stricter consent rules stack on top of HIPAA. We flag where it applies and build the HIPAA layer; Part 2 specifics belong with specialized counsel.

Can I text or email clients between sessions?

Yes, with safeguards and a documented client preference on file. Unencrypted channels need a documented warning-and-consent trail, and appointment reminders should carry the minimum necessary — a time, not a diagnosis.

I am a solo practitioner — is a full program really necessary?

The obligations do not shrink with practice size, but the program does. A solo practice needs a risk analysis, a core policy set, training, and BAAs with its EHR and telehealth vendors — a much smaller lift than a group, and we scope it that way.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo