← Back to blog

Is HIPAA Sufficient for AI in Mental Health?

Summary

HIPAA is a starting point to protect consumer information. But due to the dynamic and emerging technology there needs to be federal regulation, states can't do it all. Until then clinicians must do their own investigation to determine the risks and benefits to protect client information.

HIPAA is a Starting Point

Every day, I look at the latest developments in AI, particularly as they affect mental health. The pace of change can be dizzying.

One question I frequently hear from mental health professionals is: "How do I protect my clients' privacy when using technology and AI?"

My answer is: HIPAA is important, but HIPAA alone is not enough.

HIPAA protects protected health information (PHI) when it is handled by covered entities and business associates. But not every AI tool, mental health app, wearable device, or technology company is covered by HIPAA.

For example, consumer health information collected through apps or wearable devices may fall outside HIPAA when the company collecting it is not a HIPAA-covered entity or business associate. Other protections, such as the FTC's Health Breach Notification Rule, may apply.

AI Regulation Is Still Evolving

The FDA regulates certain AI-enabled medical technologies, and its 2026 guidance addresses Clinical Decision Support Software. However, there is not one comprehensive federal framework governing all AI applications in mental health. (fda.gov)

States are also developing their own protections. Illinois, California, New York, and others have enacted or proposed legislation addressing different aspects of AI, including mental health and AI companions. Colorado's AI legislation against algorithmic bias was challenged by xAI and a new AI Litigation Task Force created by President Trump to challenge state legislation that impedes federal AI policies. Colorado enacted a less restrictive law.

https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/

https://mental.jmir.org/2026/1/e96389

https://www.justice.gov/opa/pr/justice-department-intervenes-xai-lawsuit-challenging-colorados-algorithmic-discrimination

This means clinicians may need to consider federal law, state law, professional ethics, and the specific technology being used.

Health Data Is Not Always HIPAA Data

A common misconception is that all health information is protected by HIPAA.

It isn't.

Health information may be collected through:

  • AI chatbots
  • Mental health apps
  • Wearables and fitness trackers
  • Online assessments
  • Wellness platforms and consumer technology

HIPAA-protected PHI and general health information are not necessarily the same thing.

Similarly, "deidentified" does not mean "risk-free." Properly deidentified information is generally no longer PHI under HIPAA, but research has demonstrated that information considered anonymous can sometimes be reidentified when combined with other information. (hhs.gov) https://techscience.org/a/2018100901/

So, What Should Clinicians Do?

Before using an AI tool with client information, ask questions about the data collected:

  • What information does it collect?
  • Where is it stored?
  • How long is it retained?
  • Who can access it?
  • Is it shared or sold?
  • Is it used to train AI models?
  • Is it used for advertising or product development?
  • Can the information be completely deleted?
  • Does the vendor provide a BAA when one is required?
  • What happens if the company changes its privacy policy? Are providers and consumers notified?

Read the privacy policy and terms of service.

And yes—AI can help.

You can use AI to summarize a vendor's privacy policy or identify provisions related to data collection, retention, sharing, AI training, and deletion.

But never upload client PHI into a consumer AI tool simply to analyze a vendor agreement. Upload the vendor agreement—not your client's therapy notes.

And always verify AI-generated analysis against the original document. AI can make mistakes.

HIPAA Is the Floor—Not the Ceiling

When evaluating AI, ask four questions:

  • Is it legal?
  • Is it HIPAA compliant, when HIPAA applies?
  • Is it ethical?
  • Is it clinically safe?

A tool can potentially meet HIPAA requirements and still raise concerns about bias, transparency, informed consent, confidentiality, or clinical safety.

Our responsibility isn't to avoid technology.

It is to understand enough to use it responsibly.

A Tech-Savvy Clinician might ask:

  • What does it do?
  • What data does it collect?
  • Who can access it?
  • How is the data used?
  • What laws apply?
  • What could go wrong?

And most importantly:

Could I clearly explain to my client what happens to their information?

If the answer is no, we're not ready to use the technology.

AI is moving quickly. Our responsibility is to move thoughtfully.