HIPAA BinderGet my forms

HIPAA forms for psychologists

Usually a covered entity

A psychologist in private practice is generally a HIPAA covered entity when the practice transmits health information electronically in connection with a HIPAA covered transaction, most commonly submitting insurance claims, verifying eligibility, or receiving electronic remittance. Under 45 CFR 160.103 the trigger is the electronic covered transaction, not the act of being a mental-health provider. Many psychologists who bill third-party payers meet this test; a strictly self-pay practice that never files electronically may not. Confirm your own status.

Researched and written by Larry Osakwe · Last verified June 30, 2026

Not a lawyer, not a certified compliance professional, and not affiliated with HHS.

How we research thisReport an error

Are you even a covered entity?

The dividing line is whether you actually file electronic claims. Submit even one electronic claim to insurance, Medicare, or Medicaid, or use a billing service/clearinghouse that converts your superbills into electronic claims, and you are generally a covered entity. Handing a client a paper superbill to seek their own out-of-network reimbursement does NOT by itself make you a covered entity. A genuinely cash-only practice that never electronically bills may fall outside HIPAA, though state mental-health confidentiality laws (often stricter) still apply.

The test (45 CFR 160.103) is whether you electronically transmit a HIPAA covered transaction, not your job title. HHS and CMS publish a free covered-entity decision tool; when in doubt, run it or ask an attorney. This page is educational, not legal advice.

New to the vocabulary? See plain-language definitions in the HIPAA glossary, starting with covered entity and business associate.

HIPAA considerations specific to psychologists

Psychotherapy notes get heightened protection under 45 CFR 164.508(a)(2): a separate written authorization is required to disclose them, but only if kept in a file physically/logically separate from the rest of the record.
If session notes are commingled in the main chart with diagnoses, medication, and billing, they lose psychotherapy-note status and are treated as ordinary ePHI, so file separation is a deliberate choice.
Psychotherapy notes EXCLUDE medication/monitoring, session start/stop times, modality and frequency, test results, and any summary of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress.
Mental-health records draw sensitive disclosures (subpoenas, custody disputes, duty-to-warn), so the Notice of Privacy Practices and disclosure-accounting carry extra weight.
State law frequently grants stronger protection than HIPAA for mental-health records; where it's more protective, it controls, so your policies must reconcile both.

Vendors psychologists usually need a BAA with

If you’re a covered entity, any vendor that can create, receive, maintain, or transmit your patients’ PHI needs a signed Business Associate Agreement before it touches that data. For psychologists, that commonly includes:

SimplePracticeTheraNestTherapyNotesValantTebra (Kareo)HeadwayAlma

Using a “HIPAA-compliant” tool does not by itself make your practice compliant. The signed BAA, your policies, and your Security Risk Analysis are still yours to maintain.

Weighing your options? Compare us honestly against a standalone NPP generator and against monthly compliance software, or see what HIPAA compliance actually costs a small practice.

The HIPAA documents a covered psychologist practice needs

Notice of Privacy Practices

The notice you must give patients and post in your office and online.

45 CFR 164.520

Business Associate Agreements

Required with every vendor that can access patient data: EHR, billing, cloud, email.

45 CFR 164.502(e)

Security Risk Analysis

The most-cited deficiency in OCR enforcement: required, annual, and documented.

45 CFR 164.308(a)(1)(ii)(A)

Privacy & security policies

Your written rulebook for access, minimum-necessary use, sanctions, and incidents.

Privacy & Security Rules

Patient-rights & authorization forms

Access, amendment, accounting of disclosures, and release forms.

45 CFR 164.508

Breach procedure & Privacy Officer docs

A breach-notification procedure and log, plus the Privacy/Security Officer designation.

Breach Notification Rule

See what you actually get

Not a checklist or a link to a free template: a finished, formatted document set, cited to the rule. A page from a psychologist binder:

Illustrative: a page from your binder, delivered as editable Word + PDF
Notice of Privacy Practices45 CFR § 164.520

Your Rights. When it comes to your health information, you have the right to:

  • Get a copy of your records, usually within 30 days (§ 164.524).
  • Ask us to correct information you believe is incomplete (§ 164.526).
  • Ask us to limit what we use or share (§ 164.522).
  • File a complaint with us or the HHS Office for Civil Rights; we will not retaliate.
Self-prepared document, not legal advice · [Your Practice]Page 1

Generate your Notice of Privacy Practices now →Generate your BAA →Document your risk analysis →See the full sample binder →

Free 2-minute HIPAA gap check

Answer 10 questions and see where a psychologist practice most often has gaps. Educational, not legal advice.

01Have you completed a documented Security Risk Analysis in the last 12 months?
02Do you have a signed BAA with every vendor that can access client data?
03Is your Notice of Privacy Practices updated for the current rules?
04Do you have written privacy and security policies and procedures?
05Have you designated a Privacy Officer and a Security Officer (even if it’s you)?
06Do you keep psychotherapy notes separate, with their own authorization process?
07Do you have a written breach-notification procedure and log?
08Are your devices encrypted, with unique logins and auto-logoff?
09Do you have a workforce training record and a sanctions policy?
10Can you produce a client’s records within the required timeframe if asked?

Answer all 10 questions to see your results (0/10).

The binder is hand-prepared and customized to your psychologistpractice, with the same documents, organized to your specialty’s records and vendors.

Made to order · Founding pricing: first 25 practices

Lock in founding pricing

Every document is made to order at locked-in founding pricing, built from your practice details and delivered within 30 days, with a full refund anytime before then. Each binder is built by hand, so founding pricing is limited to the first 25 practices; after that the Complete Binder is $249. Preview any document free before you decide.

Single document
$49one-time

Founding price · $79 after the first 25 practices

Just the one document you need, built for your practice.
Choose your document

Instant: answer a short wizard, watch your document fill in live, and unlock the files for the same $49.

  • Built for your practice: profession, state, and billing setup shape every clause
  • Every policy cites the regulation that requires it
  • Editable Word + annotated PDF
  • See your finished notice before you pay
  • Instant download after checkout
The Complete Binder
Most complete
$129one-time

Founding price · $249 after the first 25 practices

Every HIPAA document a private practice needs, in one place.
  • Notice of Privacy Practices (current rules)
  • Covered-entity determination for your billing setup
  • BAA template + filled vendor table for your actual stack
  • Security Risk Analysis workbook + full policy set
  • Breach procedure: federal + your state's statute
  • Print-ready patient forms, annotated PDF, editable Word
  • Free revisions for 30 days after delivery
Binder + Always-Current
Stays current
$129+ $99/yr after 30 days

Founding price · $249 after the first 25 practices

The full binder, plus an annual refresh that keeps it current.
  • Everything in the Complete Binder
  • When a cited rule changes, we update the affected documents and send them to you
  • Every update comes with a note: what changed, why, and the citation
  • Annual refresh: every citation in your binder re-verified
  • Annual risk-assessment and training reminders
  • BAA tracker for your vendors
  • First year of updates starts 30 days after your order
  • Cancel anytime, the binder is yours

Opening a dental office? HIPAA + OSHA Binder Bundle: $299 $328 separately

Add the OSHA binder: exposure control plan, hazard communication, sharps and training documentation, every policy citing the regulation that requires it.

Founding price · $449 after the first 25 practices

Order both binders

Your documents are built to order and delivered within 30 days, with a full refund anytime before delivery. The subscription then keeps every document current as HIPAA rules change and reminds you when your annual risk assessment is due. Cancel anytime.

HIPAA FAQ for psychologists

HIPAA forms for other professions

Sources

Reviewed June 30, 2026. Educational self-help information about HIPAA documentation, not legal advice and not a covered-entity determination for any specific practice. The binder is a document layer; it never handles patient information (PHI) and does not by itself make a practice HIPAA compliant. Confirm your status with HHS/CMS resources and, where appropriate, a qualified attorney. State law may add stronger requirements.