Stay OCR Ready: Telepsychiatry Privacy and HIPAA for U.S. Clinicians

U.S. clinicians: telepsychiatry privacy and HIPAA steps. Match HHS/OCR expectations with BAAs, secure platforms, consent and breach checks.

Quick Links

Private telepsychiatry appointment in clinic room

Yes, HIPAA applies to telepsychiatry whenever care is delivered by a covered entity or its business associate. Our immediate priorities are a documented risk analysis, Business Associate Agreements with any vendor touching electronic protected health information, and a secure platform paired with documented patient consent for sessions and recordings.


TL;DR:

  • Conduct a risk analysis specifically focused on telehealth vulnerabilities and update it whenever vendors or workflows change.
  • Ensure all vendors have current Business Associate Agreements that specify breach notification timelines and coverage of electronic protected health information.
  • Require encryption, role-based access controls, and review logs on your telepsychiatry platform, and avoid using public Wi-Fi for sessions.
  • Verify patient identity and privacy at each session’s start, document consent for telehealth and recordings, and remind patients about privacy practices.
  • Recognize that HIPAA applies to all electronic health data, including audio-only visits, and only platforms with signed BAAs, encryption, and proper use support compliance.

Nortexpsychiatry
Access Psychiatric Care From Anywhere
Nortex Psychiatry offers personalized psychiatric care through in-person and telehealth appointments across North Dallas, including Allen, Frisco, McKinney, and Plano.

Table of Contents

What HIPAA covers in telepsychiatry: privacy, security, and enforcement

In our work, we have found that administrators often conflate HIPAA’s three rules, and that confusion creates real exposure. The Privacy Rule governs how protected health information may be used and disclosed. The Security Rule sets the administrative, physical, and technical safeguards for electronic PHI. The Breach Notification Rule tells us what happens when something goes wrong. The HHS Office for Civil Rights enforces all three and investigates complaints.

A covered entity is a provider, health plan, or clearinghouse that transmits health information electronically. A business associate is any vendor that creates, receives, maintains, or transmits PHI on our behalf, and the HITECH Act made that distinction matter a great deal. Before HITECH, business associates faced little direct liability. Now they carry direct legal responsibility for specific HIPAA obligations, which is part of why a signed Business Associate Agreement is non-negotiable before any vendor relationship goes live.

A few other things sit alongside HIPAA, not underneath it:

  • State privacy laws can impose stricter requirements than HIPAA and must be layered on top.
  • The Federal Trade Commission can pursue vendors and apps that fall outside HIPAA’s covered-entity definition but still mishandle health data.
  • Minimum-necessary and role-based access principles apply to telepsychiatry just as they do to in-person care, shaping who on staff can see what.

Administrative must-dos: risk analysis, policies, BAAs, and training

We think of administrative compliance as a sequence, not a checklist you complete once and forget.

  1. Scope and document a telehealth-focused risk analysis. HHS guidance on risk analysis treats this as required under 45 CFR § 164.308(a)(1)(ii)(A), and it should specifically examine video platform vulnerabilities, home Wi-Fi exposure, and where session recordings live.
  2. Confirm every BAA is current and complete. Check that it names subcontractors, states breach-notification timelines, and covers any vendor that stores or transmits ePHI, per the BAA framework HHS outlines.
  3. Build policies for identity verification, minimum necessary access, recording consent, and incident response, then train staff against them and log completion.

Pro Tip: Re-run your risk analysis every time you add a vendor or change a workflow, not just on an annual calendar.

Technical controls and platform selection for telepsychiatry

The technical side of compliance is where good intentions meet real infrastructure. We have learned that the strongest programs treat encryption, access, and logging as baseline requirements, not upgrades.

  • Require encryption for ePHI both in transit and at rest, including any stored recordings or session notes.
  • Insist on role-based access controls so staff only see what their job requires.
  • Confirm the platform generates audit logs you can actually review, not just a vendor promise that logging “exists.”
  • Ask directly whether the vendor will sign a BAA, offer data residency options, and support end-to-end encryption before you commit.
  • On your end, avoid public Wi-Fi for clinical sessions, keep devices updated, and enforce password protection and device encryption on anything used for care.

A platform comparison matters here, and our guide to telepsychiatry platforms walks through the feature checklist in more depth for behavioral health workflows specifically.

Every session starts the same way for us, and that consistency is the point. We verify identity at the start of each visit, document informed consent for telehealth, and obtain explicit, separate consent before any recording. Telehealth recommends this same sequence, along with a quick scan of the patient’s physical space.

  • Confirm the patient’s name, date of birth, and current location at the start of every visit.
  • Ask who else is in the room and whether the space is private before clinical content begins.
  • Remind patients to use headphones, keep devices updated, and choose a private location for each session.
  • Tell patients plainly how to report a privacy concern if one comes up later.

Pro Tip: A 30 to 60 second privacy check at the start of each visit, noted in the chart, protects both the patient and your documentation.

Patients preparing for an appointment can find more on what to expect in our psychiatric appointment checklist, and clinicians looking for sample consent language may find the Revive Health Therapy privacy guide useful as a starting template.

Breach notification, psychotherapy notes, and 42 CFR Part 2

Breach response has a clock attached to it, and that clock starts the moment discovery happens, not the moment you confirm the full scope. The Breach Notification Rule requires notice to affected individuals and to HHS without unreasonable delay, and no later than 60 days after discovery for breaches affecting a large number of people. A low-probability-of-compromise risk assessment can sometimes avoid formal notification, but that judgment needs documentation of its own.

Behavioral health carries extra layers worth naming directly:

  • Psychotherapy notes kept separate from the general medical record require their own authorization for release, distinct from standard treatment, payment, and operations disclosures.
  • 42 CFR Part 2 governs substance use disorder records and recent HHS alignment brings parts of it closer to HIPAA, though special disclosure restrictions remain.
  • Where a patient’s record touches both psychotherapy notes and SUD treatment, the more protective rule generally governs that portion of the chart.

Operational checklist: quick governance and tech checks to run today

Administrators tell us the hardest part is knowing where to start on a Monday morning. This order works:

  1. Pull your documented risk analysis and confirm the date of its last update.
  2. Inventory every vendor BAA, checking for named subcontractors and stated breach-notification windows.
  3. Verify your telehealth platform supports encryption, logging, and role-based access as promised.
  4. Confirm consent forms for telehealth and recordings are signed, current, and stored correctly.
  5. Check that staff training on identity verification and incident response is complete and logged.
  6. Review patient-education materials for clarity on privacy and device setup.

Our own telehealth setup guide for 2026 walks through this same sequence with more detail for clinics building the process from scratch.

How this looks in daily telepsychiatry practice

Every visit here starts with identity verification and a brief scan of the room, and we have come to see that habit as a clinical safeguard, not a formality. We treat our risk analysis as living documentation, revisiting it whenever we add a vendor or shift a workflow rather than waiting for a fixed date. Consent for recording, when it happens at all, gets documented the same way each time, which has made our supervision and quality reviews far steadier.

— Felix

Where Nortex Psychiatry fits into your compliance planning

We built our telepsychiatry workflow around the same priorities outlined here: signed BAAs with every vendor that touches patient data, encrypted platforms, and a risk analysis we revisit regularly instead of as a yearly form. If you are evaluating your own clinic’s readiness or weighing whether a telehealth-first approach fits your practice, our telehealth setup guide lays out the same sequence we follow internally. For patients exploring treatment options alongside psychiatric care, our Transcranial Magnetic Stimulation (TMS) Therapy page outlines how that service fits into a broader treatment plan, and our front page at Nortex Psychiatry is the best place to start a conversation about care.

This article is general information, not a substitute for advice from a qualified doctor. Consult a qualified healthcare professional about your own circumstances before acting on anything here.

Where Nortex Psychiatry fits into your compliance planning — overview diagram

FAQ

Does HIPAA apply to telehealth?

Yes. HIPAA applies to telehealth whenever a covered entity or its business associate transmits or stores protected health information electronically, including during video visits. HHS guidance on telehealth confirms this coverage extends to audio-only visits as well, now that earlier enforcement discretion has ended.

Does HIPAA apply to psychiatric patients?

Yes, HIPAA protects psychiatric patients the same way it protects any other patient’s health information, with one added layer. Psychotherapy notes kept separate from the general record require their own authorization before release, distinct from standard treatment disclosures.

What are the new telehealth guidelines for 2026?

There is no single new federal telehealth rule specific to 2026. Providers should instead watch for ongoing HHS alignment between 42 CFR Part 2 and HIPAA for substance use disorder records, and continue following existing Privacy, Security, and Breach Notification Rule requirements.

What telehealth platforms are HIPAA compliant?

No platform is automatically HIPAA compliant on its own. A platform supports compliance only when the vendor signs a Business Associate Agreement and offers encryption, access controls, and audit logging, and when your practice configures and uses it correctly.

Sources

Schedule Your Appointment

Complete the form below to schedule your appointment or consultation. We take your privacy seriously. Information will never be shared and is always encrypted. 

Preferred Time

Coverage Information (If required)
Allen Location

Self Assessment Test

This assessment is not designed to serve as a diagnostic instrument, nor should it substitute for an accurate diagnosis. It is merely intended for providing information. It’s crucial to remember that only a certified mental health professional or a physician should diagnose mental health issues. Irrespective of the outcome of our evaluation, we strongly recommend consulting with a doctor regarding your mental health.

Your information will not be shared.

Recent Articles