> ## Documentation Index
> Fetch the complete documentation index at: https://handbook.helendelovely.com/llms.txt
> Use this file to discover all available pages before exploring further.

# HIPAA and Our Obligations

> What HIPAA requires of a therapy practice, and what it requires of you.

Everything a client tells us is protected health information. The federal Health Insurance Portability and Accountability Act (HIPAA), Utah law, and our professional ethics all say the same thing: it stays with us, and we handle it carefully.

This part of the manual is the longest because it matters the most. Read all of it before your first client contact. Your training completion is recorded, and it's the record an auditor asks for first.

## Who we are under HIPAA

The practice is a covered entity. That means the HIPAA Privacy Rule and Security Rule apply to us directly, and to you as a member of our workforce. Vendors that handle client information on our behalf (our practice management system, our clearinghouse, Google Workspace) are business associates, and we have signed agreements with them that require them to protect it too.

A note on wording: we don't describe ourselves as "HIPAA-compliant" as if it were a badge. Compliance is a set of practices we do every day, not a status we've achieved. Don't use the phrase in marketing, on the phone, or in writing.

## What counts as PHI

Protected health information is any information that identifies a client, or could reasonably identify them, and relates to their health, their care, or payment for their care. That includes the obvious (diagnosis, notes) and the less obvious (the fact that someone is a client at all, their appointment time, their phone number in our system, a voicemail from them).

If it identifies a client and it came to us because they're a client, treat it as PHI.

## The three rules, in one paragraph each

**Privacy Rule.** Governs when PHI can be used and disclosed. Treatment, payment, and running the practice are permitted without a separate authorization. Almost everything else needs the client's written authorization, and every use is limited to the minimum necessary. See [Privacy Rule and minimum necessary](/privacy-and-security/privacy-rule-and-minimum-necessary).

**Security Rule.** Governs how electronic PHI is protected: who can access it, on what devices, with what passwords, and how we know. See [Security Rule and ePHI](/privacy-and-security/security-rule-and-ephi).

**Breach Notification Rule.** Governs what happens when PHI is exposed. Short version: you tell us immediately, and the practice handles notification. See [Breach and incident reporting](/privacy-and-security/breach-and-incident-reporting).

## What HIPAA requires of you

* Complete privacy and security training at hire and annually, and sign the completion record.
* Sign the practice's confidentiality agreement before you get access to any client information.
* Follow the practices in this manual and the SOPs.
* Report anything that looks like a privacy problem, immediately.
* Never access a record you don't need for your work, including your own family members', colleagues', or anyone you're curious about.

## Utah adds to this

Utah's rules for mental health professionals, and the psychotherapist-patient privilege, add protections on top of HIPAA. In practice, the strictest rule wins. When HIPAA would permit a disclosure but Utah law or professional ethics wouldn't, we don't disclose.

## Consequences

Privacy violations are treated seriously here, up to immediate termination for a knowing violation, because the consequences to clients and to the practice are severe. But most privacy problems are mistakes, and a mistake reported promptly is handled as a mistake. The one thing we can't work with is a problem we don't know about.
