Does HIPAA Apply to Your California Therapy Practice, and What Governs Your Records If It Does Not?

Key points

  • HIPAA coverage is not a status a therapist holds by virtue of the license. Under federal regulation a health care provider becomes a covered entity by transmitting health information in electronic form in connection with one of the standard transactions the rule lists, and a practice that never conducts one of those transactions is outside the definition.
  • California law applies either way. The Confidentiality of Medical Information Act binds every provider of health care licensed or certified under Division 2 of the Business and Professions Code, so a cash-pay practice that falls outside HIPAA is still governed by a state confidentiality statute with its own disclosure rules and its own penalties.
  • The two breach clocks do not match, and both can run at once. HIPAA gives a covered entity 60 days from discovery to notify affected individuals, while Civil Code section 1798.82, as amended effective January 1, 2026, requires disclosure within 30 calendar days of discovery or notification and, where more than 500 California residents are notified, a sample copy to the Attorney General within 15 calendar days of those notices going out.

A Guide to the Two Privacy Laws That Reach a California Therapy Practice

Two separate bodies of law govern the confidentiality of a California therapist's records, and they do not switch on and off together. The federal Health Insurance Portability and Accountability Act reaches a provider only under a condition the regulation defines precisely, and a good many California therapists do not meet it. The state Confidentiality of Medical Information Act reaches a provider by virtue of the license itself, so it applies whether or not the federal rule does. The practical result is that a clinician who concludes correctly that HIPAA does not apply has answered one question and not the other, and the second question is the one that governs the day-to-day handling of a client file.

What follows sets out what makes a therapist a covered entity, what happens when the answer is no, what each law requires when records are exposed, and how long California requires records to be kept. The question arises most often in private practice, because an agency or clinic usually settles the covered-entity question at the organizational level and tells its clinicians the answer.

The breach notification clocks and the retention period described here appear alongside the rest of a California therapist's obligations on California Therapist Rules & Deadlines.

This guide summarizes published statutes, regulations and agency guidance, and it is not legal advice. Anyone who needs to know how a rule applies to a particular practice should consult their own attorney. Rules verified as of September 20, 2026.

What Makes a Therapist a HIPAA Covered Entity?

The definition sits in 45 CFR 160.103, and it names three kinds of covered entity: a health plan, a health care clearinghouse, and "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." A therapist is a health care provider, so the whole question turns on the second half of that sentence, and specifically on the word "transaction," which the same section defines as "the transmission of information between two parties to carry out financial or administrative activities related to health care."

The regulation then lists the transaction types. They are health care claims or equivalent encounter information, health care payment and remittance advice, coordination of benefits, health care claim status, enrollment and disenrollment in a health plan, eligibility for a health plan, health plan premium payments, referral certification and authorization, first report of injury, health care claims attachments, health care electronic funds transfers and remittance advice, and other transactions the Secretary may prescribe by regulation.

Read together, the two definitions describe a specific event rather than a general posture. Coverage attaches when a provider sends or receives one of those transactions electronically, most commonly an electronic insurance claim, an electronic eligibility check, or an electronic claim status inquiry. A therapist who bills no insurance, checks no benefits electronically and submits no claims has not conducted a covered transaction, and the definition does not reach that practice. A therapist who submits a single electronic claim has.

A Sentio University faculty member teaching MFT students, the setting where confidentiality law and record-keeping duties are taught before graduation

Two features of how that definition is written are where the reasoning usually goes wrong. The first is that it is built around the transaction rather than around the keyboard, since the words are "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter," and where a billing service, a practice management platform or a clearinghouse submits electronic claims for a practice, the claims being transmitted concern that practice's own patients. Whether a particular billing arrangement leaves a practice inside or outside the definition is a question for the practice's own counsel, and the regulation does not settle it on its face. The second is that the definition describes a provider rather than a record, which is why a practice that bills electronically for some clients and takes cash from others is weighing its own transactions rather than sorting client files.

Does Email, an Electronic Record System, or a Telehealth Platform Make You Covered?

No, and this is the most persistent misreading of the rule. The definition turns on an electronic standard transaction with a health plan or a clearinghouse, not on the use of electronic technology in the practice. Sending an appointment reminder by email, keeping progress notes in software, storing an intake form in cloud storage and holding a session over video are none of them on the list of transactions in 45 CFR 160.103. A wholly paperless cash-pay practice can sit outside HIPAA while a paper-heavy practice that faxes nothing but files one electronic claim a month sits inside it.

The confusion has a commercial source. Software marketed to therapists is routinely described as HIPAA compliant, and the description is accurate as far as it goes, because a vendor that may serve covered entities needs to be able to sign a business associate agreement and meet the Security Rule. What the label does not do is tell a clinician whether their own practice is covered. That determination comes from the transactions the practice conducts, and a vendor has no way of knowing them.

The reverse error runs in the other direction and is more consequential. A clinician who assumes that HIPAA does not apply because the practice is small, or because it takes no insurance directly, may still be sending covered transactions through someone else. Where a client takes a superbill and submits it to their own insurer, the practice has not itself transmitted anything electronically to a health plan. Where the practice sends the same information to the payer electronically, or engages a service to send it, something has been transmitted on the practice's behalf, and that is the fact pattern worth putting in front of an attorney rather than resolving from a vendor's marketing page.

What Governs Your Records When HIPAA Does Not?

California's Confidentiality of Medical Information Act, at Civil Code section 56 and following, applies on its own terms. Section 56.05 defines a provider of health care as "a person licensed or certified pursuant to Division 2 (commencing with Section 500) of the Business and Professions Code," together with several other categories, and Division 2 is where the licensing statutes for marriage and family therapists, clinical social workers, professional clinical counselors, psychologists and educational psychologists all sit. Nothing in that definition depends on billing, on technology, or on federal coverage.

What the Act requires of a provider begins at section 56.10, which states that a provider of health care "shall not disclose medical information regarding a patient of the provider of health care ... without first obtaining an authorization," subject to the exceptions the section then sets out. Those exceptions include disclosure compelled by a court order, by a board, commission or administrative agency acting within its lawful authority, by a subpoena or other discovery in a proceeding, and by an investigative subpoena. The structure is worth noticing: the default is no disclosure, and every route out of it is named.

Section 56.101 adds a handling duty that has no exact federal counterpart for a small practice. It requires that every provider "who creates, maintains, preserves, stores, abandons, destroys, or disposes of medical information shall do so in a manner that preserves the confidentiality of the information contained therein," and it makes negligent handling subject to the remedies and penalties in section 56.36. The same section requires that an electronic health record system protect and preserve the integrity of electronic medical information, and that it "automatically record and preserve any change or deletion" of stored medical information, including the identity of the person who made the change, the date and time, and what was changed.

The Act also defines what it protects more broadly than a clinician might expect. Medical information under section 56.05 is "any individually identifiable information, in electronic or physical form, in possession of or derived from a provider of health care ... regarding a patient's medical history, mental health application information, reproductive or sexual health application information, mental or physical condition, or treatment." Separately, section 56.05 defines sensitive services to include all health care services related to mental or behavioral health, and names the minor consent provisions of Family Code section 6924 and Health and Safety Code section 124260 among them.

One question the statute leaves open deserves a flat answer, which is that it is open. Section 56.05 reaches a person "licensed or certified" under Division 2. An AMFT, ASW or APCC is registered rather than licensed or certified, and no published guidance resolving whether the Act reaches registrants in their own right was located. What is not in doubt is that the supervising licensee and the employing entity are providers under the definition, so records generated in supervised practice sit inside the Act through them.

What Counts as a Breach, and Who Gets Notified Under HIPAA?

For a covered entity, the federal starting point is a presumption. The Department of Health and Human Services describes a breach as "an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information," and states that such a use or disclosure "is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the following factors." The four factors are the nature and extent of the information involved, including the types of identifiers and the likelihood of re-identification; the unauthorized person who used the information or to whom it was disclosed; whether the information was actually acquired or viewed; and the extent to which the risk has been mitigated.

Where the presumption is not rebutted, three notifications can follow, on different triggers.

  • Individual notice. Affected individuals are notified in writing by first-class mail, or by email where the individual has agreed to electronic notice, "without unreasonable delay and in no case later than 60 days following the discovery of a breach." Where contact information is insufficient or out of date for 10 or more individuals, substitute notice is required, either on the home page of the entity's website for at least 90 days or through major print or broadcast media where the affected individuals likely reside, with a toll-free number active for at least 90 days.
  • Notice to the Secretary. A breach affecting 500 or more individuals is reported to the Secretary "without unreasonable delay and in no case later than 60 days following a breach." A breach affecting fewer than 500 individuals may be reported annually, and those reports "are due to the Secretary no later than 60 days after the end of the calendar year in which the breaches are discovered." Both are filed through the breach report form on the HHS website.
  • Media notice. A breach affecting more than 500 residents of a state or jurisdiction also requires notice to prominent media outlets serving that area, on the same 60-day clock and carrying the same information as the individual notice.

The two thresholds sit close enough together to be misquoted, and they are not the same test. Notice to the Secretary is triggered at 500 or more individuals, while media notice is triggered at more than 500 residents of a single state or jurisdiction, so a breach affecting exactly 500 individuals reaches the first and not the second.

What Does California Require After a Data Breach?

California's breach notification statute reaches a therapy practice through its data rather than through its license. Section 1798.82(a)(1) applies to "An individual or business that conducts business in California, and that owns or licenses computerized data that includes personal information," and requires disclosure of a breach of the security of the system to a resident of California whose unencrypted personal information was, or is reasonably believed to have been, acquired by an unauthorized person. It therefore applies to a cash-pay solo practice with a laptop and a scheduling system as readily as to a large group.

The statute was amended by Senate Bill 446, Statutes of 2025, Chapter 319, effective January 1, 2026, and the amendment is the reason the older guidance in circulation is now wrong. Before the change, the obligation ran in "the most expedient time possible and without unreasonable delay." The section now states that "the disclosure required by this subdivision shall be made within 30 calendar days of discovery or notification of the data breach," subject to a delay for the legitimate needs of law enforcement. That is a fixed outer limit, and it is half the federal one.

A second duty runs to the state. Where a single breach requires notification to more than 500 California residents, the section requires that a sample copy of the notice, excluding personally identifiable information, be submitted electronically to the Attorney General "within 15 calendar days of notifying affected consumers." The Attorney General's own reporting page states the same 500-resident threshold.

For a covered entity the two regimes run together rather than in sequence, and the shorter deadline governs in practice. A breach discovered on the first of a month that affects 600 California residents carries a California notification deadline 30 days out, a sample copy to the Attorney General 15 days after the notices go out, a federal individual-notice deadline 60 days out, media notice on the federal clock, and a report to the Secretary. Building a response around the 60-day figure alone misses the state deadline by a month.

How Long Must a California Therapist Keep Client Records?

Business and Professions Code section 4980.49 sets the retention period for marriage and family therapists, and sections 4993 and 4999.75 do the same for clinical social workers and professional clinical counselors. The rule is that a licensee "shall retain a client's or patient's health service records for a minimum of seven years from the date therapy is terminated," and, where the client is a minor, for a minimum of "seven years from the date the client or the patient reaches 18 years of age."

Two features of that rule matter in practice. The clock for an adult client runs from termination rather than from the last session or from the date a file was opened, so an inactive file is not the same as a terminated one. The clock for a minor can run far longer than seven years from the work itself, because it does not begin until the client turns 18. A course of therapy with a ten-year-old produces a file that is retained for fifteen years.

The retention rule and the confidentiality rule meet at the disposal end. Section 56.101 of the Civil Code requires that a provider who destroys or disposes of medical information do so in a manner that preserves confidentiality, so the end of the retention period is the beginning of a disposal duty rather than the end of all duty.

Two therapists working together in a deliberate practice exercise, the training format Sentio University uses to teach clinical and ethical judgment

What This Means for Your Practice

The covered-entity question has one correct answer for any given practice at any given time, and it is answerable from the practice's own billing arrangements rather than from its software. A practice that submits no electronic standard transaction, directly or through a service, is not a covered entity, and a practice that submits one is. Where the arrangement changes, for example when a clinician joins a panel or engages a billing service, the answer changes with it.

Whichever way that question resolves, the Confidentiality of Medical Information Act applies to a licensed California clinician, and it is the statute that governs disclosure, handling and disposal in the ordinary course. A clinician who reasons from HIPAA alone will have a rule for breaches and no rule for the subpoena that arrives on a Tuesday, which is the more common event.

Where a practice is covered, both regimes run at once and the state deadlines fall earliest, so a response timeline built from the 60-day federal figure will already have passed them. For questions about where a telehealth session legally takes place and what consent it requires, the Sentio guide to California telehealth rules covers that ground, and for the agency that enforces the professional-conduct side of all of this, see what the California Board of Behavioral Sciences is and what it does.

A Closer Look at One Program: Sentio University's MFT Track

The following description of one specific MFT program is offered as a concrete example of how a program can prepare students for the legal and ethical demands of practice, not as a recommendation against evaluating other programs. Students should research multiple options and ask each one direct questions about how clinical skill is built and measured.

Sentio University, a nonprofit graduate school based in Los Angeles with a hybrid delivery model that serves students throughout California, offers a Master of Arts in Marriage and Family Therapy that meets the Board of Behavioral Sciences educational requirements for the LMFT. The program runs 20 months across 60 units at $1,120 per unit, with weekly online classes and one intensive in-person residency at the start of each semester, in cohorts capped at 24 students at a 4:1 student-to-faculty ratio. It is designed around deliberate practice methodology and is described in peer-reviewed work as the first graduate psychotherapy program to thoroughly integrate deliberate practice, with roughly half of nearly every class session dedicated to active skills training rather than lecture (Rousmaniere and Vaz, 2025, p. 2).

Confidentiality law is taught before students hold their own caseloads. The 2026-2027 Academic Catalog lists Ethical and Legal Issues (MFT542) in the first semester, and students begin seeing clients at the Sentio Counseling Center during practicum, where records are kept under the clinic's own policies and supervision. Practicum provides more than 400 hours of supervised clinical experience during the degree. Sentio also integrates AI literacy training through its AI certification program for therapists, which is where questions about what a clinical tool does with client data are taken up directly.

Sentio is a small, newer institution, admits only applicants who are California residents or willing to relocate to California and who intend to license in California, and its alumni network is still developing. Prospective students weighing Sentio alongside larger or older programs should factor that into their decision. Learn more at the Sentio MFT program overview, the tuition and fees page, and the Sentio FAQ page.

Making Your Decision

Settle the covered-entity question in writing, from the billing arrangements rather than from the software, and revisit it whenever those arrangements change. Read the Confidentiality of Medical Information Act as the statute that governs the ordinary week, because it applies regardless of how the federal question came out. Write the breach timeline with the California deadlines at the top, since they are the earliest. If you are still choosing a graduate program, ask how and when it teaches law and ethics, and whether students handle real records under supervision before they graduate. Program websites describe clinical training in similar language regardless of what is actually happening in classrooms and supervision rooms. Ask every program you are seriously considering whether you can attend a live or online class session before enrolling, and ask to speak with current students and recent graduates about how supervision and skill development function in practice. Reputable programs should welcome the request. Hesitation or refusal is informative on its own. Trust what you see in a classroom over what you read in promotional copy.

Frequently Asked Questions

Is every therapist in California a HIPAA covered entity?

No. Under 45 CFR 160.103 a health care provider becomes a covered entity by transmitting health information in electronic form in connection with one of the standard transactions the rule lists, such as a claim, an eligibility check or a claim status inquiry. A practice that never conducts one of those transactions electronically, in either direction and including through a billing service, does not meet the definition.

Does using email or an electronic health record make a therapist a HIPAA covered entity?

Not by itself. The trigger in 45 CFR 160.103 is an electronic standard transaction with a health plan or clearinghouse, not electronic technology in general. Email with a client, notes kept in software, and video sessions are not among the transactions the definition lists.

Does a billing service change whether HIPAA applies?

The definition reaches a provider who transmits health information electronically in connection with a covered transaction. Where a billing service or clearinghouse submits electronic claims for a practice, the claims concern that practice's own patients, and the regulation does not say on its face whether the arrangement leaves the practice outside the definition. That is the point at which the question is worth taking to an attorney rather than assuming an answer.

What law protects client records in California if HIPAA does not apply?

The Confidentiality of Medical Information Act, Civil Code section 56 and following. Section 56.05 defines a provider of health care as a person licensed or certified pursuant to Division 2 of the Business and Professions Code, which includes marriage and family therapists, clinical social workers, professional clinical counselors and psychologists. Section 56.10 bars disclosure of medical information without an authorization except in the circumstances the statute lists.

How long does California require a therapist to keep client records?

Business and Professions Code section 4980.49 requires an LMFT to retain a client's health service records for a minimum of seven years from the date therapy is terminated, and where the client is a minor, for a minimum of seven years from the date the client reaches 18 years of age. Sections 4993 and 4999.75 impose the same rule on the LCSW and the LPCC.

How fast must a California therapist report a data breach?

Two clocks can run at once. A HIPAA covered entity notifies affected individuals without unreasonable delay and no later than 60 days after discovery. Civil Code section 1798.82, as amended effective January 1, 2026, requires disclosure within 30 calendar days of discovery or notification, and a sample copy of the notice goes to the Attorney General within 15 calendar days of notifying consumers where more than 500 California residents are notified.

Does the Confidentiality of Medical Information Act cover AMFTs, ASWs and APCCs?

The statute is not clear on the point. Civil Code section 56.05 defines a provider of health care as a person licensed or certified pursuant to Division 2 of the Business and Professions Code, and a registrant is registered rather than licensed or certified. No published guidance resolving the question for registrants was located, and a supervisor and employer remain bound in their own right.

References

California Department of Justice, Office of the Attorney General. (2026). Submit data breach report to Attorney General. https://oag.ca.gov/privacy/databreach/reporting

California Legislature. (2026a). Business and Professions Code section 4993. https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=4993.

California Legislature. (2026b). Business and Professions Code section 4999.75. https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=4999.75.

California Legislature. (2026c). Business and Professions Code section 4980.49. https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC&sectionNum=4980.49.

California Legislature. (2026d). Civil Code section 56.05. https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.05.

California Legislature. (2026e). Civil Code section 56.10. https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.10.

California Legislature. (2026f). Civil Code section 56.101. https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=56.101.

California Legislature. (2026g). Civil Code section 1798.82 (amended by Stats. 2025, Ch. 319, SB 446, effective January 1, 2026). https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.82.

Rousmaniere, T., & Vaz, A. (2025). Sentio's clinic-to-classroom method: Bridging deliberate practice and clinical training. Society for the Advancement of Psychotherapy. https://societyforpsychotherapy.org/sentios-clinic-to-classroom-methodbridging-deliberate-practice-and-clinical-training/

Sentio University. (2026). Academic catalog 2026-2027. https://sentio.org/academic-catalog-1

U.S. Department of Health and Human Services, Office for Civil Rights. (2026a). Breach notification rule. https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html

U.S. Department of Health and Human Services, Office for Civil Rights. (2026b). Does the HIPAA Privacy Rule permit health care providers to use e-mail to discuss health issues and treatment with their patients? (FAQ 570). https://www.hhs.gov/hipaa/for-professionals/faq/570/does-hipaa-permit-health-care-providers-to-use-email-to-discuss-health-issues-with-patients/index.html

U.S. National Archives and Records Administration. (2026). 45 CFR 160.103, Definitions. Electronic Code of Federal Regulations. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103

About the Authors

Tony Rousmaniere, PsyD is the President of Sentio University and Executive Director of the Sentio Counseling Center. He is Past-President of the psychotherapy division of the American Psychological Association and the author of over 20 books on deliberate practice and psychotherapy training, including The Essentials of Deliberate Practice book series (APA Books). He is a licensed psychologist in California and Washington. Learn more

Alexandre Vaz, PhD is the Chief Academic Officer of Sentio University and cofounder of the Deliberate Practice Institute. He is co-editor of The Essentials of Deliberate Practice book series (APA Books) and the author of over a dozen books on deliberate practice and psychotherapy training. Dr. Vaz is the founder and host of Psychotherapy Expert Talks. He is a licensed clinical psychologist in Portugal. Learn more

Previous
Previous

Is Malpractice Insurance Required for California Therapists, and What Do Payers Require?

Next
Next

What a California Therapist Must Report to the BBS, and When