Mental health patients have seven core HIPAA rights, but not every record or disclosure is treated the same.
In behavioral health, the main issues are access, corrections, disclosure limits, contact privacy, breach notice, and complaints.
Deadlines matter too: record access requests usually require a response within 30 days, accounting requests within 60 days, and breach notices within 60 days of discovery.
Things to remember:
Patients can usually access the designated record set, including progress notes, treatment plans, billing records, and consent forms.
Psychotherapy notes kept separately are generally not open to patient access.
Patients can ask for corrections, disclosure limits, and private communication methods.
Providers must track some disclosures, report certain breaches, and accept privacy complaints.
Family access is limited. In many cases, sharing with employers, schools, or other outside parties needs written authorization.
HIPAA allows narrower exceptions for safety risk, emergencies, serious threats, and legal requirements.
State law may give minors, teens, or other patients added privacy rights beyond HIPAA.A short operational takeaway stands out: rights under HIPAA are not just privacy policy language.
They shape release workflows, front-desk procedures, billing activity, chart management, and compliance risk across mental health practices, treatment centers, and multi-site behavioral health organizations.
7 HIPAA Patient Rights in Mental Health: Quick Reference Guide
|
Patient right |
What it covers |
Usual timing |
Main limit |
|---|---|---|---|
|
Access records |
View or get copies of records in the designated record set |
30 days |
Psychotherapy notes, some legal files, safety-based denial |
|
Request corrections |
Ask to amend errors or missing details |
30 days |
Same record limits, plus some denials allowed |
|
Request restrictions |
Ask to limit some uses or sharing |
No set HIPAA deadline listed here |
Providers do not have to agree in most cases |
|
Confidential communications |
Ask for contact by another method or location |
Must honor reasonable requests |
Request must be reasonable and clear |
|
Accounting of disclosures |
Ask for a list of certain past disclosures |
60 days |
Does not include treatment, payment, or health care operations |
|
Breach notification |
Receive notice after a breach of unsecured PHI |
Within 60 days of discovery |
Some narrow exceptions apply |
|
File a complaint |
Report a privacy concern to OCR or the provider |
No HIPAA filing deadline noted here |
Retaliation is barred |
This article works best as a practical HIPAA guide for behavioral health organizations that need clean record workflows, staff alignment, and tighter control over mental health information sharing.
HIPAA's Privacy Rule protects health information that identifies a patient and relates to physical health, mental health, care received, or payment for that care. In behavioral health settings, that often includes diagnoses, session records, prescriptions, intake assessments, and billing records.
For mental health providers and treatment centers, this matters because patient access rights usually turn on one basic issue: whether the information is part of the patient record under HIPAA.
Protected Health Information (PHI) is individually identifiable health information held by a covered entity.
In plain terms, PHI includes information that can be tied to a specific patient and used by a provider, payer, or other covered entity in the course of care or payment operations.
The Designated Record Set (DRS) is the set of records a provider uses to make care decisions, including medical, billing, claims, enrollment, and case management records.
In behavioral health, that usually means a patient can request access to diagnoses, treatment plans, medication lists, clinical progress notes, lab results, consent forms, and billing records. If a patient wants the broadest version of the chart, asking for the designated record set can help avoid receiving only visit notes.
This distinction matters for providers as well. Front-desk staff, HIM teams, and clinical leaders often need a shared understanding of what sits inside the DRS so responses to record requests stay consistent across locations and departments.
Not everything in a provider's files must be released to the patient. Psychotherapy notes - notes a mental health professional maintains separately from the medical record to document or analyze the contents of a counseling session - are specifically excluded under HIPAA [2].
These are not the same as standard progress notes, which are part of the DRS.
Other records are usually excluded too. That includes records prepared for legal proceedings and internal peer review or quality control files. A provider may also deny access if a licensed health care professional determines that the requested access is reasonably likely to endanger the life or physical safety of the patient or another person [3].
General concern that a patient may be upset by the information is not enough to deny access [4].
|
Record Type |
Accessible to Patients? |
|---|---|
|
Diagnoses, treatment plans, medication lists |
Yes |
|
Clinical progress notes |
Yes |
|
Billing and payment records |
Yes |
|
Lab results and consent forms |
Yes |
|
Psychotherapy notes (kept separately) |
No |
|
Information compiled for legal proceedings |
No |
|
Peer review and quality control files |
No |
These categories shape what patients can request, review, and seek to amend under HIPAA.
Under HIPAA, patients have the right to inspect and obtain copies of records in the designated record set. In mental health care, that often includes medical records, billing records, lab results, consent forms, and progress notes.
For electronic records, patients can request the format they want, such as a PDF, or ask for direct delivery to a third party through a written, signed request that names the recipient and address [5][6].
If a record appears wrong or incomplete, the next step is the amendment process.
Access rights are broad, but HIPAA draws a clear boundary around psychotherapy notes. Psychotherapy notes that are kept separate from the main medical record are not available under HIPAA.
A licensed health care professional may deny access only when release is reasonably likely to endanger the patient or another person [5][4].
Providers must respond within 30 days. One 30-day extension is allowed, but the provider must give a written reason and a new completion date [5].
Providers may charge a reasonable, cost-based fee for labor, supplies, and postage. They cannot charge for searching for or retrieving the records [5]. If the request brings an error to light, the amendment right becomes the next step.
If a mental health record contains an error or leaves out key details, HIPAA gives patients the right to request an amendment. That right applies to records in the designated record set. For example, if a progress note shows the wrong dosage, symptom, or diagnosis, a patient can ask the provider to correct it [2].
Some records are not included in this right. Psychotherapy notes and legal-proceeding files are excluded [2][7]. A provider may also deny the request if a licensed health care professional determines that approving it is reasonably likely to endanger the life or physical safety of the patient or another person. Simply expecting that the patient may feel upset does not justify a denial [4].
Providers are subject to the same 30-day deadline [4][3]. If the request is denied, the provider must issue that denial in writing and state the reason, explain any right to review, and describe how to file a complaint [4]. When the denial is tied to a safety concern, the patient has the right to have the decision reviewed by a different licensed health care professional chosen by the provider [4].
Patients can ask a mental health provider or health plan to limit how protected health information (PHI) is used or shared for treatment, payment, and health care operations (TPO). They can also ask that PHI not be shared with family members, friends, or other people involved in care or payment [1].
In many cases, covered entities can deny these requests. HIPAA does not require providers or health plans to accept every restriction a patient asks for. One key exception applies when a patient pays for a service out of pocket and wants that service kept from the health plan. In cases involving family members, friends, or caregivers, the request should be made in writing and should clearly name the person the patient does not want involved [1]. That step matters even more when insurance records, billing activity, or shared caregiving could expose details the patient wants kept private.
Providers must agree to a restriction request when three conditions are met: the patient paid in full out of pocket, the disclosure would be made to a health plan for payment or health care operations, and the disclosure is not otherwise required by law [8].
For behavioral health providers, this issue often comes up when a patient does not want a therapy visit or other mental health service to appear on an Explanation of Benefits (EOB). That concern can be especially serious when a spouse or parent is the primary policyholder and may see plan records. In that situation, paying in full and asking for the restriction is the path HHS describes [1].
"If you want a session to stay off your insurance EOB - which may be seen by a spouse or parent who is the primary policyholder - paying in full and requesting a restriction is the approach HHS describes" [1].
Even when a provider has agreed to a restriction, HIPAA still allows or requires disclosure in some situations. That can include emergencies, required reporting, serious threats, or HHS compliance reviews [1][8].
If restricted information is shared during an emergency, the provider should ask the emergency treatment provider not to use or disclose that information any further than needed for that treatment [1].
For mental health organizations, this is where policy, staff training, and documentation discipline matter. A restriction may help limit what reaches family members, insurers, or other third parties, but it does not block every disclosure under every circumstance.
Other HIPAA rights give patients added control over who can see their information and how disclosures are recorded.
For behavioral health providers, contact preferences are not a minor admin detail. They can play a direct role in patient privacy, trust, and day-to-day compliance.
HIPAA gives patients a way to lower the risk of unwanted disclosure by choosing how a provider contacts them. A patient may ask a mental health provider to use a different location or a different method for communication, such as a specific phone number or email address [6].
In behavioral health settings, that request can matter more than it might in other areas of care. A shared household, a strained family situation, or employer-related concerns may make routine outreach feel risky for the patient.
Providers must send communications to a reasonable alternate location or use a reasonable alternate method when the request is clear and the provider is able to comply.
That means front-desk teams, admissions staff, clinical teams, and billing staff all need a simple way to see and follow the patient’s stated preference. If that preference sits in one note field but never reaches the people sending reminders, statements, or care updates, the process can break down fast.
Common requests include:
A private phone number instead of a shared family lineFor treatment centers and mental health practices, these requests often show up in routine workflows like appointment reminders, billing statements, intake follow-up, and care coordination. The issue is simple on paper, but in practice, it depends on whether staff can spot the request and use it the same way across systems.
Patients do not only have rights over how providers contact them. They may also ask to see certain past disclosures of their protected health information.
Under HIPAA, this right allows patients to request an accounting of disclosures made by a covered entity or its business associates during the prior six years [9]. The accounting works like a disclosure log. It shows who received the information and why.
Each entry must include:
The date of the disclosure
The name and address of the recipient
A description of the PHI disclosed
The purpose of the disclosure [9]
The first accounting requested within a 12-month period must be provided at no charge. If a patient asks for another accounting during that same 12-month period, the provider may charge a reasonable, cost-based fee, as long as the patient receives advance notice [9].
This right is more limited than many patients expect. HIPAA does not require providers to include every disclosure in the accounting.
Disclosures for treatment, payment, and health care operations are excluded. The same is true for disclosures made directly to the patient, disclosures made under a signed patient authorization, and incidental disclosures allowed under the Privacy Rule [9][10]. Disclosures involving psychotherapy notes are also usually excluded because those notes generally require separate authorization before release [9].
For behavioral health providers, that distinction matters. A patient may expect to see a full record of every instance in which information moved across clinical, billing, and operational workflows. In practice, the accounting right covers a narrower set of disclosures.
Providers must respond within 60 days after receiving the request [9]. If more time is needed, HIPAA permits one 30-day extension. In that case, the provider must give the patient a written explanation for the delay and state the expected completion date [9]. Patients may also request a shorter timeframe.
For behavioral health organizations, this requirement calls for clean disclosure tracking and clear response workflows. The audit trail may be limited, but it can still help patients understand where information has already gone before deciding whether to seek tighter limits on future sharing. This right applies to past disclosures; the next section addresses when patients may still shape future information sharing.
An accounting of disclosures shows where information was sent. Breach notification addresses something different: information exposed without permission.
If unsecured mental health information is breached, HIPAA requires notice. A breach is an impermissible use or disclosure of unencrypted or otherwise unsecured PHI, unless a risk review finds a low probability that the information was compromised.
The notice must give patients enough detail to assess risk and decide what to do next. It must explain what happened, what information was involved, what steps the patient can take, how the provider responded, and who to contact.
For behavioral health providers, this right matters because it deals with privacy after a failure has already occurred. That makes it different from earlier HIPAA rights, which are meant to control access and disclosure before information is exposed.
Providers must notify affected patients within 60 days of discovering the breach. Notice must be sent by first-class mail, or by email if the patient agreed to receive electronic communications.
If mailed notices for 10 or more people are returned because the addresses are out of date, the provider must post a substitute notice on its website home page for at least 90 days. If a breach affects more than 500 residents of a state or jurisdiction, the provider must also notify prominent media outlets [11].
For behavioral health organizations, these timing and delivery rules can create pressure across compliance, operations, and communications teams. A missed deadline or incomplete notice can add risk at a time when patient trust is already under strain.
Not every privacy incident is a reportable breach.
HIPAA includes three narrow exceptions:
1.) An unintentional, good-faith access by a workforce member acting within the scope of their dutiesPsychotherapy notes are still PHI. Even though patients generally do not have a direct access right to those notes, an unauthorized disclosure of them still triggers breach notification duties [11].
When a privacy issue is not resolved through normal requests, HIPAA gives patients a formal way to act.
If a mental health provider, health plan, or business associate violates HIPAA privacy rights, a complaint can be filed with the Office for Civil Rights (OCR).
OCR reviews complaints under the Privacy Rule, Security Rule, and Breach Notification Rule. [12]
Patients can submit a complaint through the OCR Complaint Portal or by mail to HHS. They can also use the provider’s complaint process listed in the Notice of Privacy Practices. [12][14]
Complaints often stem from denied access requests, denied amendment requests, or unauthorized disclosures of protected health information. [2][12]
Retaliation is prohibited. That protection applies during treatment and after treatment ends. [13]
The next section explains when HIPAA still allows sharing with family members or other third parties.
HIPAA places clear limits on when mental health information can be shared and when a patient’s written authorization is required. For behavioral health providers, these rules often come into focus when information may be disclosed to family members, friends, employers, schools, or other outside parties.
Employers, schools, and other third parties outside treatment or payment generally need a patient’s written authorization before they can receive mental health information. [15]
If a service is being provided to create records for a third party, the provider may require that authorization before moving forward. [15]
HIPAA still allows limited sharing without written authorization in day-to-day care situations. Providers may share information with family members or friends involved in a patient’s care or payment if the patient does not object. If the patient is present and does not object, HIPAA usually treats that as agreement. [1]
A patient may revoke a written authorization in writing before the provider acts on it. [15]
Even when disclosure is allowed, providers should share only the minimum amount needed for the purpose. If a patient objects to sharing information with a family member or friend involved in care, the provider cannot make that disclosure. [1]
These limits can change in urgent situations. In an emergency, or when a patient is incapacitated, providers may share only the information needed for treatment. [1] Providers may also disclose the minimum needed to prevent or lessen a serious and imminent threat to health or safety. [1]
The line is fairly clear under HIPAA: patients can request most mental health records, but psychotherapy notes are handled under a separate rule.
Clinical progress notes are part of the designated record set and are generally available to the patient under HIPAA.
These records often include diagnosis, treatment plans, symptoms, medication-related details, and progress summaries. Psychotherapy notes, by contrast, are the private notes a mental health professional keeps to document or analyze a session. When those notes are kept separate from the medical record, HIPAA excludes them from patient access.[2]
For behavioral health providers, this distinction matters because documentation practices can affect both patient rights and compliance risk.
A note that belongs in the clinical record should not be treated like a private therapy note. At the same time, private psychotherapy notes must be stored separately if the organization intends to rely on HIPAA’s exclusion.[2]
Access can be denied only in narrow HIPAA exceptions.
|
Record Type |
Generally Accessible Under HIPAA |
Usually Excluded or Limited |
Notes for Mental Health Patients |
|---|---|---|---|
|
Clinical Progress Notes |
Yes |
No |
Include diagnosis, treatment plans, symptoms, and progress summaries. |
|
Psychotherapy Notes |
No |
Yes |
Must be kept separate from the medical record to be excluded. |
|
Safety-Restricted Records |
Limited |
Yes |
Access may be denied if it is reasonably likely to endanger the life or physical safety of a person. |
A denied document request does not automatically block access to the rest of the underlying record. If a provider denies access because disclosure is believed to create a safety risk, that decision can be reviewed by another licensed health care professional who was not involved in the first denial.[4]
Denials tied to psychotherapy notes are different. Under HIPAA, those denials are not reviewable.[4]
After the individual rights above, this table brings the main deadlines and provider duties into one place. For behavioral health providers, these timeframes matter because privacy requests often affect intake, documentation, release workflows, and patient trust.
|
Right |
Patient request |
Provider duty |
Key exceptions |
Timing or notice |
|---|---|---|---|---|
|
1. Access Records |
Inspect or copy records in the designated record set |
Must comply |
Psychotherapy notes; legal-proceeding files; safety risk |
30-day response; one 30-day extension allowed with written reason [4] |
|
2. Request Corrections |
Amend inaccurate or incomplete PHI |
Must consider |
Psychotherapy notes; legal-proceeding files; safety risk |
30-day response; one 30-day extension allowed [4] |
|
3. Request Restrictions |
Limit certain uses or disclosures |
Must consider; must comply for out-of-pocket, health-plan restriction [1] |
Only the out-of-pocket health-plan restriction is mandatory |
- |
|
4. Confidential Communications |
Use a specific method or location for contact |
Must accommodate reasonable requests |
- |
- |
|
5. Accounting of Disclosures |
List certain non-routine disclosures |
Must comply |
Excludes treatment, payment, and health care operations disclosures |
60-day response; one 30-day extension allowed [9] |
|
6. Breach Notification |
Be notified if unsecured PHI is breached |
Must notify |
If 10 or more notices are undeliverable, post substitute notice on the website home page for 90 days [11] |
No later than 60 days after breach discovery [11] |
|
7. File a Complaint |
Submit a privacy complaint to HHS or the covered entity |
Must accept and process |
Retaliation is prohibited [13] |
No HIPAA filing deadline |
These rules matter most when a patient wants tighter control over who can see the information and how fast a provider must act.
HIPAA gives mental health patients enforceable rights over access, corrections, restrictions, and complaints.
Those rights are not just policy language on a website. They carry legal weight, and providers can face penalties when they do not respond as required.
In 2024, a mental health center was fined $100,000 for failing to provide timely record access. At the same time, HIPAA does have limits. Psychotherapy notes, denials tied to safety concerns, and some restriction requests are still treated more narrowly under the law.
For patients trying to use these rights, the starting point is the provider’s Notice of Privacy Practices (NPP). That notice must be posted online and available in paper form on request. It explains how the provider uses and shares information, what rights the patient has, and how to file a complaint if a concern comes up.
Documentation also matters. Record requests, correction requests, and restriction requests should be submitted in writing so HIPAA response deadlines begin clearly and can be tracked. [4]
State law may provide stronger protections in some cases, with added focus on minors and teens. [16]
Patients have the right to inspect and receive a copy of their protected health information in a provider’s designated record set, including medical and billing records. Requests should be directed to the health care provider, which may require the request in writing.
The provider must respond within 30 days. This right does not extend to psychotherapy notes kept separate from the medical record or to information compiled for legal proceedings.
Under HIPAA, a therapist may share information with family members, friends, or other people involved in a patient’s care when that information relates to their role and the patient does not object.
If a patient is unable to state a preference, the therapist may share information when the therapist believes doing so is in the patient’s best interest. A patient can request limits by submitting a formal written request to the provider that names who should be excluded and what information should not be shared.
If a HIPAA request is denied, the covered entity must provide a written explanation in plain language.
That written notice should make the reason for the denial clear, rather than leaving patients or family members to sort through legal or clinical jargon.
If the denial is subject to review, the individual can ask for that decision to be reviewed by a licensed health care professional who was not involved in the original denial.
The written denial must also explain how to file a formal complaint with the covered entity or with the U.S. Department of Health and Human Services Office for Civil Rights.