BUILD YOUR PRACTICE
HIPAA and Privacy Setup for Therapy Practices
HIPAA setup for therapists is not a product purchase or a one-time checklist. It begins by determining which rules apply, mapping where client information moves, assessing risks, choosing safeguards, documenting decisions, reviewing vendors, and preparing for access requests and incidents. This guide turns those responsibilities into a practical implementation sequence.
By Gabriel Benaim, LMHC | Information checked: September 6, 2026
This guide is national in scope with Florida callouts. It does not determine whether your practice is a HIPAA covered entity or whether a specific product, workflow, disclosure, incident, or record-retention period satisfies every applicable rule. Use it with the Florida private-practice roadmap and startup checklist.
On this page
- Determine which privacy rules apply
- Map client information
- Conduct and document a risk analysis
- Choose administrative, physical, and technical safeguards
- Review vendors and BAAs
- Configure email, phone, texting, and telehealth
- Review website forms and tracking technology
- Build the records lifecycle
- Prepare for incidents and breaches
- Use the vendor due-diligence checklist
- Create a maintenance calendar
- Frequently asked questions
1. Determine which privacy rules apply
Do not begin by assuming that every therapist is covered by HIPAA, or that being outside HIPAA removes privacy duties. HHS says the HIPAA Rules apply to covered entities and business associates. A health care provider is a covered entity only if the provider transmits health information electronically in connection with a transaction for which HHS has adopted a standard.
Document how the practice bills, submits claims, checks eligibility, receives remittance information, and works with clearinghouses, platforms, group practices, or payers. The entity that owns the practice, the clinician, and a vendor can have different roles. When the determination is uncertain, use the CMS covered-entity decision resources and obtain qualified legal guidance.
| Area | Question | Do not assume |
|---|---|---|
| HIPAA | Is the practice a covered entity, business associate, or neither? | Providing health care alone answers the question. |
| Florida law | What confidentiality, records, professional, breach, and consumer rules apply? | HIPAA replaces stricter or separate state duties. |
| Payer and platform contracts | What security, notice, audit, access, and retention terms were accepted? | A vendor’s default configuration satisfies the contract. |
| Special records | Do substance-use-disorder, minor, couple, family, legal, or other special rules apply? | One authorization or retention rule covers every record. |
| Non-HIPAA health data | Could the FTC Act, Health Breach Notification Rule, or state consumer-health law apply? | Data outside HIPAA is unregulated. |
Florida clinicians should review current Chapter 491, Division 64B4, and other laws applicable to the practice and record type. Use qualified counsel for conflicts among federal law, Florida law, professional duties, contracts, and client circumstances.
2. Map every place client information moves
A private practice privacy setup begins with a data inventory. Include information from prospective clients, not only established-client charts. Map each point where information is created, received, maintained, transmitted, displayed, printed, discussed, backed up, exported, or destroyed.
- Website inquiry and scheduling forms
- Email, voicemail, calls, text messages, portal messages, and faxes
- EHR, telehealth, screening, measurement, and documentation systems
- Billing, claims, eligibility, clearinghouse, payment, banking, and accounting systems
- Laptops, phones, tablets, printers, scanners, external drives, and paper files
- Cloud storage, backups, calendars, password managers, and support tools
- Directories, analytics, advertising pixels, call tracking, and referral records
- Clinicians, contractors, employees, billers, consultants, vendors, and emergency coverage
For each system, record the data involved, purpose, owner, users, access level, storage location, transmission method, authentication, backup, retention, deletion, contract, BAA status when applicable, and offboarding method. Include forgotten pathways such as email attachments, downloaded reports, screenshots, browser autofill, notification previews, and printer queues.
3. Conduct and document a risk analysis
For organizations subject to the HIPAA Security Rule, HHS describes risk analysis as foundational and requires an accurate and thorough assessment of risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. It does not prescribe one universal method.
- Define scope. Identify all electronic protected health information the organization creates, receives, maintains, or transmits.
- Collect information. Document devices, software, accounts, vendors, locations, users, networks, and workflows.
- Identify threats and vulnerabilities. Consider human mistakes, unauthorized access, malware, theft, device loss, power failure, fire, water, vendor failure, and unavailable records.
- Assess existing measures. Verify that safeguards are configured and used, not merely available.
- Estimate likelihood and impact. Use a consistent qualitative or quantitative method.
- Prioritize corrective action. Assign an owner, due date, interim measure, and evidence of completion.
- Finalize documentation. Retain the analysis, decisions, and risk-management work.
HHS also emphasizes that risk analysis is ongoing. Revisit it when introducing technology, changing ownership or staffing, adding a location or payer, responding to an incident, changing workflows, or discovering a new threat. A downloaded checklist can support the process, but it is not the documented analysis of your environment.
4. Choose administrative, physical, and technical safeguards
For a covered practice, organize Security Rule work under administrative, physical, and technical safeguards. Some implementation specifications are labeled required and others addressable. HHS explains that “addressable” does not mean optional: if an addressable specification is not reasonable and appropriate, the organization documents why and adopts an equivalent measure when reasonable and appropriate.
Administrative practices
- Assign responsibility for privacy and security, even in a solo practice.
- Create written access, authorization, incident, backup, downtime, device, vendor, and termination procedures.
- Use role-based access and review it when a worker or vendor changes.
- Train workforce members for their real responsibilities and document training.
- Review logs, incidents, risk work, and sanctions according to written procedures.
- Plan continuity and emergency access without creating an unrestricted back door.
Physical practices
- Control access to offices, devices, screens, paper, networking equipment, and backups.
- Position screens and conduct conversations to reduce unintended disclosure.
- Define secure device reuse, transfer, repair, and disposal.
- Address home offices, shared spaces, travel, cars, visitors, cleaning, and building access.
Technical practices
- Use unique accounts, strong authentication, and multifactor authentication where supported.
- Configure automatic locking, supported operating systems, updates, malware protection, and device encryption as appropriate.
- Limit notifications and synchronization to the minimum information needed.
- Protect information in transmission and at rest according to the assessed risk and applicable requirements.
- Back up necessary information and test restoration instead of assuming a backup succeeded.
- Enable appropriate audit logs and know how long they remain available.
Do not state that one safeguard is universally sufficient. For example, encryption is important, but it does not fix excessive access, unsafe recovery methods, misleading website collection, weak procedures, or an unreviewed vendor relationship.
5. Review vendors and business associate agreements
A business associate is determined by the relationship and functions, not by a vendor’s preferred label. When a covered entity engages a business associate, HHS says a written business associate contract or other arrangement is required. Business associates also have direct obligations under parts of the HIPAA Rules.
Review EHRs, telehealth services, cloud storage, email, texting, billing, clearinghouses, answering services, IT support, shredding, transcription, backup, analytics, scheduling, payment, and other tools according to what information they create, receive, maintain, or transmit.
A willingness to sign a BAA is not a product certification. Read the agreement and the underlying service terms. Confirm which product tier and features it covers, permitted uses, subcontractors, safeguards, incident notification, return or destruction, termination, data ownership, exports, support access, and conflicts with other contract terms. HHS notes that a cloud service provider can be a business associate even when it stores only encrypted electronic protected health information and lacks the decryption key.
6. Configure email, phone, texting, and telehealth
Choose communication methods from the risk analysis and applicable rules. Document what each channel is for, what it is not for, how identity is checked, how consent or preferences are recorded, how messages enter the clinical record, who monitors them, and what happens outside business hours.
- Email: review account ownership, access, encryption options, forwarding, recovery, retention, attachments, and mobile synchronization.
- Phone and voicemail: review greetings, caller verification, shared access, transcription, message retention, notification previews, and call recording.
- Texting: review platform terms, message content, consent or preferences, device access, backups, urgent-message limits, and documentation.
- Telehealth: review the platform relationship, BAA when applicable, meeting settings, waiting rooms, recordings, links, chat, file transfer, privacy at both locations, and a technology-failure plan.
Do not rely on expired pandemic enforcement discretion. Use current HHS HIPAA and telehealth guidance and verify state licensure, consent, prescribing, records, and payer rules separately.
7. Review website forms, analytics, and tracking technology
A visitor can reveal sensitive information before intake through a search, URL, form field, appointment request, chat, payment page, or directory link. Inventory every technology that receives website or app data, including analytics, pixels, session recording, embedded scheduling, advertising, CAPTCHA, chat, maps, video, fonts, and form processors.
For each tool, identify what data it receives, why it is necessary, where it goes, what contract governs it, whether it is used for advertising or profiling, who can access it, how long it remains, and whether a less revealing configuration is available. Do not add a tracking tool solely because a website plugin recommends it.
HHS’s online-tracking guidance has been affected by litigation and remains an area requiring careful, current review. Avoid reducing the issue to a slogan such as “every IP address is PHI” or “public pages never involve PHI.” Analyze the particular data, context, user relationship, disclosure, and current law with qualified guidance. Entities outside HIPAA should also evaluate the FTC’s consumer-health-information guidance.
8. Build the complete records lifecycle
Privacy setup must cover the record from creation through final disposition. Define:
- What belongs in the designated record set, clinical record, billing record, correspondence, and administrative files
- Who may create, correct, amend, sign, access, disclose, export, or destroy information
- How client identity and authority are verified for access, amendment, restriction, confidential-communication, and authorization requests
- How requests are received, dated, tracked, reviewed, fulfilled, denied, and documented
- How records are retained after termination, death, disability, closure, vendor change, or practice sale
- How paper and electronic information are securely destroyed when permitted
Do not use one universal retention number. HIPAA documentation-retention requirements, Florida professional rules, malpractice considerations, payer contracts, tax records, minors’ records, and special categories can involve different periods. Create a schedule that identifies the authority for each record class and the event that starts the retention period.
Covered providers also need an applicable Notice of Privacy Practices and distribution workflow. HHS provides model notices, but a model is a starting point, not a complete intake packet or privacy program.
9. Prepare for security incidents and potential breaches
Write the response procedure before an event. It should tell the practice how to preserve safety and evidence, contain the problem, avoid destructive improvisation, restore essential operations, document decisions, involve insurers or counsel, evaluate reporting duties, communicate, and correct the cause.
- Receive and time-stamp the report.
- Protect clients and maintain necessary care operations.
- Contain access or exposure while preserving relevant evidence.
- Identify the information, people, systems, vendors, and time period involved.
- Activate qualified privacy, security, legal, insurance, and vendor support.
- Assess applicable HIPAA, state, contractual, payer, and non-HIPAA notification duties.
- Document the analysis, decisions, notices, remediation, and follow-up risk work.
Not every security incident is a reportable breach, and a solo practitioner should not make that determination from a generic internet checklist. HHS provides current breach-notification guidance. If the FTC Health Breach Notification Rule may apply, use the current FTC rule materials.
10. Vendor due-diligence checklist
- Function What exact workflow and information will the vendor handle?
- Role Is it a business associate, subcontractor, conduit, or another type of recipient?
- Contract Which service terms, privacy terms, BAA, data-processing terms, and product tier apply?
- Access Can the practice create unique users, roles, MFA, session controls, and timely termination?
- Data Where is information stored, backed up, processed, supported, and transferred?
- Security What current documentation addresses encryption, logging, testing, patching, recovery, and independent assessments?
- Incidents How and when will the vendor notify the practice, preserve evidence, and support investigation?
- Subcontractors Who else handles information, and how are changes communicated?
- Portability Can the practice export usable clinical, billing, audit, communication, and configuration records?
- Exit What happens to access, copies, backups, fees, and records at termination?
- Evidence Who reviewed the vendor, on what date, using which documents, and when is the next review?
11. Create the privacy maintenance calendar
Assign an owner, date, evidence, and next review for each recurring task. A solo practice still needs named responsibility, even when the same person holds every role.
| Review | Suggested trigger | Evidence |
|---|---|---|
| Risk register and safeguards | At least periodically and after material change or incident | Updated analysis, decisions, completed actions |
| Users and access | Regularly and immediately after role or relationship changes | User list, roles, removal confirmation, log review |
| Vendors and agreements | Before purchase, at renewal, and after material term or feature changes | Reviewed terms, BAA decision, export test |
| Backups and continuity | On a scheduled basis and after system changes | Successful restore or recovery test |
| Policies and training | Periodically and after rule, workflow, workforce, or risk changes | Version history and training record |
| Official guidance | Quarterly; more often for active rulemaking | Source, check date, change decision |
Frequently asked questions
Does using a “HIPAA-compliant” EHR make my practice compliant?
No product can complete the practice’s applicability analysis, risk analysis, policies, training, access decisions, incident response, records workflow, and correct daily use. Evaluate the vendor and configure the service within the larger privacy program.
Do cash-pay therapists have to follow HIPAA?
Payment method alone does not answer the question. Determine whether the provider conducts a covered electronic transaction and assess any covered-entity or business-associate relationships. Even when HIPAA does not apply, Florida confidentiality, professional, contractual, consumer-protection, breach, and other duties may remain.
Is an addressable Security Rule specification optional?
No. HHS explains that if an addressable implementation specification is not reasonable and appropriate, the organization documents why and adopts an equivalent measure when reasonable and appropriate. The decision should come from the risk analysis, not convenience alone.
Can I text clients if they consent?
Consent does not automatically resolve Security Rule, state-law, contractual, documentation, identity, device, vendor, emergency, or minimum-necessary questions. Define and review the specific channel and workflow rather than relying on a blanket sentence.
How often should I update the risk analysis?
The current Security Rule does not prescribe one universal frequency. HHS describes risk analysis as ongoing and identifies changes in technology, operations, ownership, workforce, or incidents as reasons to reassess. Set a documented review cadence and event-based triggers that fit the practice.
Next step
Need a different part of the setup? Return to the Build Your Practice hub.
Work out what it actually pays
Most offers are written to foreground the flattering number. The guide gives you the math to work out what reaches your account, for any offer, on any platform.
Related DegreeToLicense guides
- How to Start a Therapy Private Practice in Florida
- Therapist Private Practice Startup Checklist
- Therapist Private Practice Startup Costs
- Practice Tools
After completing the privacy and data-flow analysis, use How to Choose an EHR for Your Therapy Practice to evaluate controls, contracts, portability, and workflow fit.
Use the therapy practice policies and forms checklist to connect privacy procedures to notices, authorizations, communication preferences, and records requests.
Official sources and review scope
Official information checked September 6, 2026. Federal and Florida requirements can change, and applicability depends on the provider, entity, transactions, data, relationships, services, clients, and contracts.
- HHS covered entities and business associates
- HHS Security Rule overview and risk-analysis guidance
- HHS business-associate guidance and cloud-computing guidance
- HHS breach-notification guidance, telehealth guidance, and online-tracking guidance
- HHS Security Rule NPRM fact sheet: proposed changes only
- FTC consumer-health-information guidance and Health Breach Notification Rule
- Florida Statutes, Chapter 491 and Florida Administrative Code, Division 64B4

About the author
Gabriel Benaim is a Florida Licensed Mental Health Counselor. DegreeToLicense helps clinicians understand licensure, compensation, and the practical decisions involved in independent practice.
Disclaimer: Educational information, not individualized legal, privacy, security, records, technology, billing, insurance, or clinical advice. Confirm current requirements and incident-specific duties with the relevant government agency, board, payer, insurer, attorney, security professional, vendor, or other qualified professional.
