guides · · 8 min read

How to Implement AI in Your Therapy Practice Without Violating HIPAA

HIPAA compliance is the first concern every therapist raises when considering AI tools — and rightly so. Here is a practical, step-by-step guide to implementing AI in your practice the right way.

Forge Momentum

Digital Transformation Team

HIPAAAI compliancetherapy practicedata privacyBAA

The Ethics Are Not Optional

Every licensed therapist operates under an ethical code — whether from the APA, NASW, AAMFT, or their state licensing board. These codes were written before AI tools existed at scale. That doesn't mean they don't apply.

The principles that matter most — client welfare, confidentiality, informed consent, and professional competence — apply directly to AI adoption decisions.

Informed Consent Comes First

If you are using any AI tool that touches client information — session recordings, transcripts, intake forms, billing data — clients must be informed and must consent.

Your informed consent paperwork should specify:

  • What AI tools are used in your practice
  • What data those tools process
  • Where that data is stored and for how long
  • The client's right to opt out

Verbal consent is not sufficient. Get it in writing, and update your consent forms before deploying new tools.

HIPAA is a Floor, Not a Ceiling

HIPAA sets minimum standards for PHI protection. It does not guarantee that a tool is appropriate for clinical use. A tool can be technically HIPAA-compliant and still carry ethical risks — for example, if it uses de-identified session data to improve its models in ways clients didn't anticipate.

Read Business Associate Agreements carefully. Ask vendors directly: does client data improve your model? Can I opt out? What is your data retention policy?

Competence Means Understanding What You're Using

Ethical codes require therapists to practice within their competence. Using AI tools without understanding how they work — what they do with data, what their error rates are, how they handle edge cases — is an ethical issue, not just a practical one.

You don't need to be a machine learning engineer. You do need to understand the tool well enough to supervise its outputs and recognize when it's wrong.

The Supervisory Relationship With AI

Think of AI-generated clinical content — notes, summaries, risk assessments — the way you'd think of work from an unsupervised trainee. You would not sign off on a trainee's note without reviewing it. The same standard applies here.

Clinician review is not a formality. It is the ethical safeguard that makes AI-assisted documentation acceptable.

When to Decline AI Entirely

Some clinical contexts warrant extra caution or complete avoidance of AI tools:

  • High-risk clients: Suicidality, acute trauma, mandated reporting situations
  • Court-involved cases: Where notes may be subpoenaed and AI provenance could be questioned
  • Clients who have explicitly declined consent

The Opportunity in Getting This Right

Therapists who engage thoughtfully with AI ethics — who update their consent forms, vet their tools carefully, and maintain rigorous clinical oversight — are better positioned than those who either avoid AI entirely or adopt it uncritically.

The profession will develop clearer guidance over the next few years. The therapists who build good habits now will find that guidance easy to meet.

Frequently Asked Questions

Can I use general AI tools like ChatGPT for therapy documentation?
No. General-purpose AI tools like ChatGPT, Claude, and Gemini do not sign BAAs and are not designed for HIPAA compliance. Entering client information into these tools — even for documentation purposes — constitutes an unauthorised disclosure of PHI. Use only tools specifically designed for healthcare and willing to sign a BAA.
Does HIPAA require that I tell my clients I use AI tools?
HIPAA does not explicitly require disclosure of specific technology tools. However, your Notice of Privacy Practices must accurately describe how you use and disclose PHI, and informed consent best practices strongly favour transparency about AI use. Most liability-conscious therapists — and their malpractice insurers — recommend explicit disclosure in consent forms.
What happens to session recordings after my AI documentation tool generates notes?
This varies by vendor and configuration. Best practice is to configure the tool to delete session audio as soon as notes are generated — retaining audio longer than necessary increases your risk exposure without clinical benefit. Review your chosen tool's data retention settings and confirm deletion timelines in the BAA.
Are there AI tools that are formally HIPAA certified?
HIPAA does not have a formal certification programme — there is no government-issued HIPAA certification for technology products. When vendors claim to be HIPAA certified, they typically mean they have completed a third-party compliance assessment. What matters is their willingness to sign a BAA and their ability to demonstrate appropriate security controls. Ask for their SOC 2 report if you want independent verification.
Can a solo practitioner realistically manage HIPAA compliance for AI tools without a compliance officer?
Yes. Solo practitioners are held to the same HIPAA standards as large organisations, but the practical burden is proportional. For a solo practice, HIPAA compliance for AI tools comes down to: sign a BAA before use, configure the tool appropriately, update your consent forms, and document what you have done. You do not need a formal compliance officer to achieve this — you need a checklist and the discipline to follow it.