By the Editorial Team. Reviewed and updated on August 8, 2026.
This article is educational and independent. It is not medical, legal, or insurance advice, and it is not a diagnosis or a treatment recommendation. Coverage rules, benefit programs, and legal rights vary by state, by plan, and by individual circumstance. Confirm details with your plan, a licensed professional, or the official sources named in this article.
If you are in crisis or thinking about harming yourself, help is available right now, free and confidential. Call or text 988 to reach the 988 Suicide & Crisis Lifeline, or chat at 988lifeline.org. You can also text HOME to 741741 to reach the Crisis Text Line. For substance use or mental health treatment referrals, SAMHSA’s National Helpline is 1-800-662-4357. If someone is in immediate danger, call 911.
Almost every question about HIPAA and mental health records starts from the same worry: who else is going to find out. A hiring manager. A parent. A spouse in a custody dispute. A supervisor who already treats you differently. The worry is reasonable, and the answer is more protective than most people assume, though not in the shape people imagine.
The rule people picture is a vault. The rule that exists is a permission system. It defines a specific set of organizations that must follow it, a specific category of information, and a list of situations where sharing is allowed with your authorization, allowed without it, or prohibited outright. Learning where those lines sit is what turns a vague fear into a set of things you can actually check.
What follows covers who is bound by the rule and who is not, the right to get a copy of your own file and how long a provider or plan has to respond, why psychotherapy notes sit in a category of their own, when information moves without you signing anything, the extra layer that protects substance use disorder records, how parental access works for minors, what an employer can and cannot see, and how to file a complaint when something goes wrong.
What HIPAA and mental health records protection actually covers
HIPAA is the Health Insurance Portability and Accountability Act of 1996. The privacy piece most people mean is the HIPAA Privacy Rule, enforced by the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS.gov).
It protects protected health information, usually abbreviated PHI. That means individually identifiable health information held or transmitted by a covered entity or its business associate, in any form: paper, electronic, or spoken aloud. Your diagnosis, your appointment dates, your billing records, and the fact that you are a patient at all are PHI.
Three types of organizations are covered entities:
- Health plans. Commercial insurers, employer-sponsored group health plans, Medicare, Medicaid, and marketplace plans.
- Health care providers who transmit health information electronically in connection with certain standard transactions. That sweeps in nearly every therapist, psychiatrist, clinic, and hospital that bills insurance.
- Health care clearinghouses, the intermediaries that process claim data between providers and plans.
Business associates are the vendors that handle PHI on a covered entity’s behalf: billing companies, electronic record systems, transcription services, cloud storage. They are directly liable under the rule and must sign a business associate agreement.
Now the part that surprises people. The list above is exhaustive. Plenty of organizations that hold sensitive information about your mental health are simply not covered:
- Most consumer wellness and mood-tracking apps. If an app has no relationship with a covered entity, HIPAA does not apply to it, no matter what its marketing says. Its privacy policy is the governing document, and privacy policies can change.
- Employers, in their capacity as employers. Employment records held by your employer are outside HIPAA, even if they contain medical information. A separate group health plan the employer sponsors is covered; the HR file is not.
- Schools, where student health records are generally governed by the Family Educational Rights and Privacy Act instead.
- Life insurers, most workers’ compensation carriers, and disability insurers in many contexts.
- Peer support groups, coaches, and anyone not practicing as a licensed provider billing electronically.
- Your own friends and family, who can repeat anything you tell them.
A therapist who takes no insurance at all and bills only by paper may fall outside HIPAA, though state confidentiality law and professional licensing rules still bind them. State law matters constantly here. Where a state law is more protective of privacy than HIPAA, the state law generally governs.
Your right to see and get a copy of your own record
This is the most useful right in the whole rule, and the least used. Under the HIPAA right of access, you can inspect and get a copy of the information in your designated record set held by a covered provider or plan (HHS.gov).
The designated record set includes medical and billing records, and the records a plan uses to make decisions about you: enrollment, claims, case management, and utilization review files. That last category is the one people forget. If a plan denied a residential stay after a utilization review, the file behind that decision is generally something you can request.
The mechanics that matter:
- Put the request in writing. A provider may require this and may require its own form, but it cannot make the process unreasonably difficult or require you to explain why you want it.
- Name the format. If the records are kept electronically, you can ask for an electronic copy, and the entity must provide it in the form you request if it can readily do so.
- 30 calendar days is the general outer limit to act on the request, with one 30-day extension allowed if the entity tells you in writing why it needs more time. Many providers respond far faster. Thirty days is a ceiling, not a target.
- Fees are limited to a reasonable, cost-based charge covering labor for copying, supplies, and postage. Search and retrieval time cannot be billed to you.
- Denials must be in writing, and certain denials carry a right to have the decision reviewed by a licensed professional who was not involved in the original decision.
There is a narrow exception built specifically for mental health care. A licensed health care professional may deny access if, in their professional judgment, access is reasonably likely to endanger the life or physical safety of you or another person. This exception is meant to be narrow and it is reviewable. It is not a general permission to withhold a chart because the contents are uncomfortable, and a denial on this ground is one you can ask to have reviewed.
| Record type | Right of access | Usual response window | Note |
|---|---|---|---|
| Treatment notes in the main chart | Yes | Within 30 days | Includes diagnoses, medication lists, session summaries in the chart |
| Billing and claim records | Yes | Within 30 days | Held by both provider and plan |
| Plan case management and utilization review file | Generally yes | Within 30 days | Often the file behind a coverage denial |
| Psychotherapy notes kept separately | No right of access under HIPAA | Not applicable | A provider may still choose to share; state law may give more |
| Substance use disorder treatment records from a Part 2 program | Yes, with an added federal layer on disclosure to others | Varies | See the 42 CFR Part 2 section below |
| Records the entity does not use to make decisions about you | Not part of the designated record set | Not applicable | Quality assurance and peer review materials, for example |
Getting your own file is also the single most practical step before an appeal. If a plan cut off coverage mid-treatment, the review notes and the criteria applied are usually requestable, and our guide to what to do when a mental health claim is denied explains how that documentation gets used.

Psychotherapy notes: the category with its own rules
People use “therapy notes” loosely. HIPAA does not. Psychotherapy notes is a defined term, and the definition is narrow. It is also the piece of HIPAA and mental health records law that generates the most confident wrong answers.
They are notes recorded by a mental health professional documenting or analyzing the contents of a private counseling session, kept separate from the rest of the individual’s record. That separation requirement does real work. A clinician’s impressions typed into the main chart are not psychotherapy notes, regardless of how personal the content is.
The definition specifically excludes medication prescription and monitoring, session start and stop times, the modality and frequency of treatment, results of clinical tests, and any summary of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress to date. Those items live in the regular record.
| Question | Psychotherapy notes | Rest of the mental health record |
|---|---|---|
| Where kept | Separate from the chart, by definition | In the designated record set |
| Your right to a copy under HIPAA | No | Yes |
| Shared for treatment, payment, or operations without authorization | Generally no, with limited exceptions | Generally yes |
| Authorization form | Must be a separate authorization, cannot be bundled with others | May be combined with other authorizations |
| Can a plan condition coverage on release | Generally no | Sometimes, in limited circumstances |
| Typical content | The clinician’s private analysis of a session | Diagnosis, treatment plan, medications, progress, test results, dates |
The practical effect is real but narrower than the folklore. Your insurer generally cannot demand psychotherapy notes as a condition of paying a claim. What it can and does review is everything else: the diagnosis, the treatment plan, the frequency, the progress. That is usually enough for a utilization review, which is why “they can’t see my therapy notes” gives less comfort than people hope.
Note also that many clinicians do not keep separate psychotherapy notes at all. Everything goes in one chart. In that case the special category is empty, and the ordinary rules apply to all of it. Asking a provider how they document is a fair question at intake, and a normal one.
When information moves without your signature
The Privacy Rule permits certain uses and disclosures without authorization. This is where people feel most exposed, so it is worth being precise rather than alarming.
The everyday category is treatment, payment, and health care operations, often shortened to TPO. Your psychiatrist can send records to your primary care doctor for treatment. Your provider can bill your plan. Your plan can run quality review and utilization management. None of that requires a signed authorization, and the system could not function otherwise.
The rule adds a general expectation of minimum necessary: covered entities should limit use and disclosure to the least information needed for the purpose. Treatment disclosures between providers are exempt from that limit, because clinicians need the full picture.
Other permitted disclosures without authorization include:
- Required by law, including a court order, and specific reporting duties such as suspected child abuse.
- Judicial and administrative proceedings, where the rules differ sharply. A court order allows disclosure. A subpoena alone generally does not, unless satisfactory assurances were given that you were notified or a protective order was sought. That distinction is worth knowing, because subpoenas arrive looking authoritative.
- Public health activities and certain oversight functions.
- Serious and imminent threat to health or safety, where a provider may disclose to someone reasonably able to prevent or lessen the threat, consistent with applicable law and ethical standards.
- Persons involved in your care, where a provider may share information directly relevant to that involvement if you agree, or do not object when given the chance, or in an emergency where professional judgment says it is in your best interest.
The safety exception deserves calm handling, because it is misunderstood in a way that keeps people from asking for help. It is permissive, not mandatory, and it is limited to information shared with someone who can actually reduce a serious and imminent threat. It does not put your record into a database. It does not notify your employer. It does not follow you around afterward. Reaching out for support does not hand your privacy away, and the routine content of therapy is not the trigger for anything here.
HHS has published specific guidance on how the Privacy Rule applies to mental health information, including sharing with family members and the professional judgment standard (HHS.gov).
42 CFR Part 2 and substance use disorder records
Substance use treatment records carry a second federal layer on top of HIPAA. It comes from 42 CFR Part 2, a regulation administered by the Substance Abuse and Mental Health Services Administration (SAMHSA.gov).
Part 2 does not apply to every provider who ever discusses substance use. It applies to federally assisted programs that hold themselves out as providing, and do provide, substance use disorder diagnosis, treatment, or referral for treatment. A general hospital’s emergency department is usually not a Part 2 program; a specialty treatment program usually is.
At a general level, Part 2 has historically been stricter than HIPAA on redisclosure. Records from a Part 2 program generally cannot be shared without written patient consent, with narrow exceptions, and recipients have historically been prohibited from passing them along further without permission. The regulation has gone through significant revision in recent years to align parts of it with HIPAA, including changes to how a single consent can operate for treatment, payment, and operations, and how notices and enforcement work.
Two things follow from that.
First, the details here change, and any article stating them as fixed is a poor source. SAMHSA’s own pages are the place to check the current version.
Second, the practical takeaway does not change: substance use records held by a Part 2 program are treated more restrictively than ordinary mental health records, and a general medical release form is often not sufficient to move them. If a form seems unusually specific about substance use treatment, that is why.
Minors, parents, and why the answer is a state answer
Federal law does not settle this one. HIPAA generally treats a parent as the minor’s personal representative, with the same access rights the patient would have. Then it steps back and defers to state law in the situations that matter most.
A parent is generally not the personal representative when:
- The minor consented to the care themselves and no other consent was required by law, which many states allow for mental health or substance use services beginning at a specified age.
- A court or another person has been authorized to consent to the care.
- The parent agreed to a confidential relationship between the minor and the provider.
Even then, where state law expressly addresses parental access to a minor’s records, whether granting it or limiting it, that state law controls. Where state law is silent, a licensed provider may use professional judgment about disclosure to a parent.
The result is a genuine patchwork. The consent age for outpatient mental health care differs by state, and so does whether a parent can see the record afterward. There is no clean national answer, and any source that gives you one is oversimplifying. Ask the provider directly at intake what their state requires, and ask before the first session rather than after.
What your employer can and cannot see
Start with the fact that reframes everything about HIPAA and mental health records at work: HIPAA does not regulate your employer as an employer. It regulates health plans and providers. So the question is never “does HIPAA stop my boss from knowing,” it is “how would the information get to them in the first place.”
The realistic routes, and what limits each:
- Through the group health plan. A self-funded employer plan is a covered entity, and the Privacy Rule requires firewalls between plan administration functions and employment functions. Plan staff cannot hand PHI to management for employment decisions without your authorization.
- Through a leave or accommodation request. Documentation you or your provider submits goes to the employer directly, so HIPAA is not the operative rule. The Americans with Disabilities Act is: medical information must be kept confidential and stored separately from the personnel file. Our guides to ADA accommodations for mental health at work and FMLA for mental health cover what those forms can ask for.
- Through a disability claim. Short- and long-term disability carriers require broad medical authorizations. What flows back to the employer varies with how the plan is administered, and the authorization you sign is the document that controls.
- Through an employee assistance program. EAP counseling is typically confidential, with the employer receiving aggregate usage data rather than names. The details depend on the contract, and asking for the confidentiality terms in writing before a first session is reasonable.
- Through a workers’ compensation claim, where disclosure rules are set largely by state workers’ compensation law rather than by HIPAA.
What an employer generally may see for an accommodation is that a covered condition exists, how it limits you at work, and why the requested change helps. Not the chart. Not the notes. If a form asks a provider to attach everything, asking what specifically is needed and why is a fair response.
Amendments and the accounting of disclosures
Two rights that almost nobody uses, and both are worth knowing.
The right to request an amendment lets you ask a covered entity to correct information in your record that you believe is inaccurate or incomplete. The entity has 60 days to act, with one 30-day extension. It can deny the request, including when the entity did not create the record or when it determines the information is accurate and complete, but a denial must be in writing and must explain how to file a statement of disagreement. That statement then travels with the record.
This matters more in mental health than in most areas. A diagnosis entered early and never revisited can follow a chart for years and shape how later clinicians and reviewers read it. You cannot force a clinician to change their opinion. You can make sure your disagreement is attached to it.
The right to an accounting of disclosures lets you request a list of certain disclosures a covered entity made in the six years before your request. It has a large carve-out: disclosures for treatment, payment, and operations are generally excluded, as are those you authorized. What remains is often the interesting part, such as disclosures required by law or made to public health or oversight agencies. The first accounting in any 12-month period is free.
You can also request restrictions on use and disclosure. An entity generally does not have to agree, with one exception people should know about: if you pay in full out of pocket for a service, you can require that the provider not disclose that information to your health plan. That is a real, enforceable right, and it is the cleanest privacy tool available for a single sensitive visit. Our piece on how much therapy costs without insurance covers what paying directly involves.
An illustrative scenario: one record request, start to finish
The following is a composite illustration created for this article. It is not a real person, a real provider, a real insurer, or a real case, and it is not a prediction of any outcome.
Picture someone who spent nine days in an intensive outpatient program before their plan stopped authorizing further sessions. They want to appeal, and they want to know what the reviewer actually saw.
They send two written requests on the same day. One goes to the treatment program for the complete designated record set, specified as an electronic copy on a USB drive or through the patient portal. The other goes to the health plan for the utilization review file, the medical necessity criteria applied, and the reviewer’s notes.
The program responds in 11 days with a portal download. The chart includes intake assessment, treatment plan, progress notes filed in the chart, group attendance, and discharge summary. It does not include a set of separately kept psychotherapy notes, because the clinician confirms she keeps none. Nothing was withheld.
The plan takes longer. On day 28 it sends a written notice extending by 30 days, which the rule permits when the reason is explained. The file arrives on day 46: claim history, the review determination, the criteria set used, and the reviewer’s credentials.
Reading the file turns up an error. The intake assessment lists a prior hospitalization that never happened, apparently carried over from a records import. The person files a written amendment request with the program, attaching a short factual statement.
The program’s response comes 24 days later. It agrees to amend the entry and to notify the plan, which had received the record. Had it denied the request, the person’s statement of disagreement would have been attached to the record instead, and the plan would have seen that alongside the original entry.
They also file an accounting-of-disclosures request. The list is short, since treatment and payment disclosures are excluded, but it confirms that no disclosure went to any employer or third party outside the claim process. That answered the question that had been keeping them up.
The appeal itself is a separate process on a separate clock. What the record request did was make the appeal possible to write, because you cannot argue with criteria you have never read.
Your records and privacy checklist
Work through this once, and keep the results somewhere outside any account your employer controls.
- ☐ Get the Notice of Privacy Practices from each provider and your health plan; it states how they use and share information and how to complain
- ☐ Ask each mental health provider whether they keep separate psychotherapy notes, and how they document sessions
- ☐ Submit a written right-of-access request for your full designated record set, naming the format you want
- ☐ Calendar the 30-day mark, and note whether a written extension notice arrives
- ☐ Read every authorization form before signing; check what information, to whom, for what purpose, and the expiration date
- ☐ Strike anything unnecessary from an authorization, or ask for a narrower one; authorizations are negotiable more often than people think
- ☐ Note that most authorizations can be revoked in writing going forward
- ☐ Ask about the restriction right if you plan to pay out of pocket for a visit
- ☐ Confirm with any app or digital tool whether it is covered by HIPAA or governed only by its privacy policy
- ☐ For a minor’s care, ask the provider at intake what your state’s consent and parental access rules are
- ☐ Keep a dated log of every request, response, and denial, plus the name of who you spoke to
- ☐ Note the 180-day window for filing an OCR complaint if something goes wrong
When something goes wrong: complaints and timelines
Two paths run in parallel, and starting with the first often resolves things faster. Most disputes about HIPAA and mental health records are handled at the provider or plan level without any agency involvement.
- Complain to the covered entity. Every provider and plan must have a privacy official and a complaint process, described in the Notice of Privacy Practices. Put it in writing. Retaliation for filing a complaint is prohibited.
- File with the HHS Office for Civil Rights. Complaints can be filed through the OCR Complaint Portal, by mail, or by fax, and they are free. Name the entity, describe what happened, and state when.
- Meet the deadline. A complaint generally must be filed within 180 days of when you knew or should have known about the problem. OCR can extend that for good cause, but the extension is discretionary.
- OCR reviews and may investigate. Outcomes range from technical assistance to a corrective action plan to a settlement with a monetary payment. Investigations frequently take many months.
- Understand the limit. HIPAA does not give individuals a private right to sue for a violation. Some state privacy, confidentiality, or negligence claims may exist depending on the state, which is a question for someone licensed there.
If the problem is a breach of unsecured PHI, separate notification rules apply. Affected individuals must generally be notified without unreasonable delay and no later than 60 days after discovery, and larger breaches involve notice to HHS and, above a threshold, to media in the affected area.
Where to get free, unbiased help
- HHS Office for Civil Rights, for the complaint portal, the right-of-access guidance, and the mental health topic pages. The frequently asked questions section is unusually specific and answers most edge cases.
- SAMHSA, for the current state of 42 CFR Part 2 and for treatment locator services.
- Your state health department or attorney general’s office, which may enforce a state privacy law stronger than HIPAA.
- Your state’s Protection and Advocacy agency, which handles disability and mental health rights matters, including records access disputes.
- Legal aid organizations and law school clinics, for people who meet income guidelines.
- Your provider’s privacy official, whose contact details are on the Notice of Privacy Practices. This is the fastest route for a records problem, and it is free.
For questions about what a treatment program or level of care actually involves, rather than how the records are handled, our sibling site at learn.kalmausam.in covers the clinical side.
Frequently Asked Questions
Can my employer see my therapy records?
Not through the health plan, which must keep plan information walled off from employment functions. What an employer does receive is whatever you or your provider submit for a leave or accommodation request, and that material is limited to the condition, the limitation, and the need. Employment records are outside HIPAA, though the ADA requires medical information to be kept confidential and filed separately.
Are psychotherapy notes really off limits to my insurer?
Generally yes, and a plan usually cannot condition coverage on their release. The catch is that everything else is available: diagnosis, treatment plan, session frequency, medications, and progress. That is typically what a utilization review uses, so the protection is real but narrower than most people picture.
How long does a provider have to give me my records?
Generally 30 calendar days from the request, with one 30-day extension if the entity notifies you in writing and explains why. Many providers respond within a week or two. Fees are limited to reasonable cost-based charges, and you cannot be billed for the time spent searching for the file.
Does HIPAA apply to mental health apps?
Usually not. An app that has no relationship with a covered entity is governed by its own privacy policy and by consumer protection law, not by HIPAA. If an app is offered through your provider or health plan, the picture can change. Reading what an app says it shares, and with whom, is the only reliable check.
Can my therapist tell my family what we talked about?
Only in defined circumstances: with your agreement, when you have been given the chance to object and do not, or when you are not present or able to agree and professional judgment says limited sharing is in your best interest. The disclosure is limited to information directly relevant to that person’s involvement in your care.
What happens to my privacy if I tell a provider I am in crisis?
Ordinary treatment information stays protected under the same rules as everything else. A provider is permitted, not required, to share limited information with someone who can help lessen a serious and imminent threat to safety, consistent with law and professional ethics. That permission is narrow and situation-specific. Asking for help does not create a record anyone else routinely sees, and it does not notify your employer.
Can a court order my mental health records?
A court order can require disclosure. A subpoena signed only by an attorney generally is not sufficient on its own, unless the party gives satisfactory assurances that you were notified or that a protective order was sought. Records from a substance use treatment program under 42 CFR Part 2 have their own, stricter court order requirements.
Do my parents have a right to my mental health records if I am 16?
It depends on your state. HIPAA generally treats a parent as the personal representative, then defers to state law where the minor lawfully consented to the care themselves or where state law addresses parental access. Consent ages for outpatient mental health care and parental access rules both vary widely, so ask the provider at intake.
How do I correct something wrong in my record?
Submit a written amendment request to the entity that holds the record. It has 60 days to act, with one 30-day extension. If it denies the request, the denial must be in writing and must tell you how to file a statement of disagreement, which is then kept with the record and shared when that part of the record is disclosed.
Can I stop my insurer from finding out about a visit?
If you pay for the service in full out of pocket, you can require the provider not to disclose that information to your health plan for payment or operations purposes. This is one of the few restriction requests a provider must honor. Tell the front desk before the visit, not after the claim is filed.
What is the deadline to file a HIPAA complaint?
Generally 180 days from when you knew or should have known about the violation. The Office for Civil Rights can extend that for good cause, but treating the 180 days as firm is the safer approach. Filing is free and does not require a lawyer.
Can I sue over a HIPAA violation?
HIPAA itself does not give individuals a private right to sue. Enforcement runs through the Office for Civil Rights and, in some cases, state attorneys general. Depending on the state, separate claims under state privacy or confidentiality law may exist. This article does not evaluate individual situations, and only someone licensed in your state can advise on yours.
Final Thoughts
One request today does more than a week of reading. Ask each provider and your health plan for a copy of your complete designated record set, in writing, in the format you want. It is free or close to it, the clock is 30 days, and you never have to say why.
Most people who feel uneasy about HIPAA and mental health records have never actually seen what is in their file. Reading it usually replaces a large vague worry with a small specific one, sometimes an error worth amending, and occasionally with relief. The rights to amend, to restrict, and to complain are all easier to use once you know what the record says.
This article is for general informational purposes only and does not constitute medical, legal, insurance, or financial advice. It is not a diagnosis, a treatment recommendation, or an evaluation of any individual claim. Mental health coverage rules, parity requirements, appeal rights, disability standards, and employment protections vary by plan, by state, and by individual circumstance, and they change over time. This site is independently operated. It is not a law firm, an insurance company or advisor, a healthcare provider, a government agency, or an advocacy organization, and it does not represent anyone. Reading this article creates no professional relationship of any kind. Always confirm current requirements with your plan documents, a licensed professional in your state, or the official government sources cited above before making any decision.