Training · Clinical care providers
Privacy & Security Training for Mental Health & Counselling Practices
This training builds a confidentiality culture specific to a therapy practice, where the person most likely to see a diagnosis first is not the clinician but the front-desk staff member processing an invoice. Sessions cover what admin staff can and cannot do with what they see, what a clinical supervisor may access in a supervisee's charts, and the rules around recording a session, tailored to your practice's actual roles rather than a generic privacy-awareness deck.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What training in this niche has to address
The risks in a small practice come from ordinary daily tasks performed by people who never intended any harm, which is why role-specific training matters more here than in most workplaces.
Administrative staff who see clinical information incidentally
Front-desk and billing staff routinely see diagnosis codes on invoices and insurer claims without being clinicians, and need clear rules on what they may discuss and with whom.
Clinical supervisors reviewing a supervisee's work
Supervision requires access to case material, but that access has limits, and both supervisor and supervisee need to understand where they sit.
Session recording practices
Staff and clinicians need shared understanding of when a session may be recorded, what consent is required, and how the recording is stored and eventually deleted.
Everyday confidentiality outside the chart
Waiting-room conduct, what is visible on an unlocked screen, and what gets said in a hallway or shared office all carry as much risk as the electronic record.
Regulatory map
The standards training is built to satisfy
Training exists to make abstract obligations concrete for the people actually handling the information day to day.
Agent obligations under PHIPA
Staff and associates act as agents of the custodian, and PHIPA expects the custodian to take reasonable steps to ensure agents are informed of their duties, which training documents.
CRPO's audit-trail expectation
Standard 5.6 expects a record of who accessed a chart and when, which only functions as a safeguard if staff understand that access is logged and reviewed.
Electronic Practice consent requirements
CRPO 3.4 requires informed consent before electronic service delivery, which includes staff understanding what that consent covers when scheduling or supporting virtual sessions.
Quebec's incident-register duty
Law 25 requires an incident register, which depends on every team member recognizing and reporting a potential incident, something training establishes as a habit rather than a rule read once.
What goes wrong
What untrained staff and clinicians expose
The failure pattern in this niche is rarely malicious; it is a well-meaning person who was never told where the line sits.
Snooping as the leading self-reported cause
In 2024, unauthorized viewing outranked every other self-reported cause of health-sector breaches in Ontario, and it is precisely the failure training is built to prevent: staff who know exactly where the boundary sits are far less likely to cross it out of curiosity.
Shared logins hiding who did what
A small practice that shares one login for convenience makes any snooping or accidental access impossible to trace back to a person, undermining the audit trail CRPO expects.
A supervisor overstepping supervisee access
Without clear guidance, a supervisor may access more of a supervisee's caseload than the supervisory relationship actually requires, creating exposure neither party intended.
Casual talk in shared or open spaces
Waiting rooms, shared offices and video calls taken in earshot of others are common, low-tech ways confidential information leaks without any system being involved at all.
Our training for mental health & counselling practices
What the training program covers, by role
Modules are built around who is actually in the room, from the clinician to the person answering the phone.

Front-desk and billing staff module
What administrative staff may access, discuss and record, including how to handle a phone call from someone claiming to be a client's family member.
Clinician and associate module
Documentation practices, electronic-consent requirements, and the boundaries of what belongs in a shared practice platform versus a private working note.
Supervisor and student module
Clear guidance on the scope of chart access appropriate to a supervisory relationship, and how to handle case material in group supervision without over-disclosing.
Session recording guidance
Rules for consent, storage and deletion of recordings made for supervision, training or client review, and who is authorized to make that recording in the first place.
Incident recognition
How to recognize and report a potential privacy incident immediately, whether it is a misdirected email or an odd access pattern noticed on the shared platform.
How the engagement runs
How training is delivered to your practice
Step 1
Assess your roles and risks
We identify who touches client information and how, from reception to clinical supervision, before building the content.
Step 2
Build role-specific modules
Content is written around your practice's actual platforms, supervision structure and telepractice setup rather than generic scenarios.
Step 3
Deliver live or on-demand
Sessions can run live for a full team meeting or on-demand for staff joining outside a scheduled training window.
Step 4
Reinforce and refresh
Periodic refreshers keep the training current as the practice grows, adopts new tools, or brings on new associates and students.
What it costs
What shapes training pricing for a counselling practice
Cost depends on team size, how many distinct roles need separate modules, and whether live delivery is preferred over on-demand. A five-person solo-adjacent practice needs a lighter program than a thirty-clinician group with supervisors, students and administrative staff all requiring different content.
Recurring training and human-risk assessments come standard inside the Virtual Privacy Officer retainer for practices that want this handled without a separate booking each time. Tell us your team makeup and we will scope the sessions.
Mental Health & Counselling Practices: Training questions, answered
Training for this role focuses on the fact that seeing information incidentally does not authorize discussing or acting on it beyond the billing task at hand. Staff learn what they may say to insurers, family members or callers, how to handle a request they cannot verify, and why even casual mention of a diagnosis outside its billing purpose is a confidentiality breach, not a harmless aside.
Generally, access appropriate to the supervisory relationship, case material relevant to the cases being supervised, rather than blanket access to a supervisee's entire caseload. Training establishes this boundary explicitly for both parties, and clarifies that supervision access should be documented and time-limited to the supervisory arrangement, not left open indefinitely after it ends.
A recording made for supervision, training or client review needs specific informed consent naming that purpose, storage separate from general practice files where the platform allows it, and a defined point at which it is deleted. Training covers who is authorized to initiate a recording, how consent is documented, and what happens if a client withdraws consent partway through.
Yes. Under PHIPA, associates typically act as agents of the custodian regardless of their contractual status, and the same confidentiality expectations and audit-trail responsibilities apply to them as to any staff member with system access. Treating associate training as optional leaves a gap in exactly the population most likely to be handling client records independently.
At least annually, and immediately when the practice adopts a new platform, expands telepractice, or brings on new clinicians, students or administrative staff. A one-time onboarding session does not account for how quickly a small practice's tools and team can change, and refreshers keep confidentiality expectations current rather than fading into habit.
More for mental health & counselling practices
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.