New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs
Clinical care providers
Privacy & Security for Mental Health & Counselling Practices
A psychotherapy note is among the most sensitive records any custodian holds, and the practices that generate them are usually small businesses run by the clinician who is also the privacy officer. Privacy Horizon builds the security and privacy program around that reality: PHIPA custodian duties, CRPO's record-keeping standards, and the AI scribes now sitting inside the therapy hour, without asking a solo Registered Psychotherapist to become a compliance department.
Reviewed by the Privacy Horizon team · Last reviewed
Who this is for
We work with solo Registered Psychotherapists and psychologists building their first program, clinic directors running group practices of five to fifty clinicians, and the operations lead of a virtual-first counselling network or EAP-affiliated group. In almost every case, the owner-clinician carries the PHIPA custodian obligation personally, alongside a full caseload.
Engagements start at recognizable moments: a practice adopts an AI note-taker and needs to know what happens to the recording, a subpoena or custody dispute exposes thin records practices, an EAP network or insurer demands security representations before referrals begin, or a therapist reads about a psychotherapy platform breach and wants an honest answer about their own exposure.
What sets this niche apart from other health providers is the record itself. A process note documents a person's inner life, not a diagnosis code or a lab value, and the harm from its exposure cannot be undone by a refund or an apology. Regulators treat it accordingly, with no threshold for how minor a disclosure has to be before notification is owed.

Services
Privacy & security services for mental health & counselling practices
Each service below is scoped for how mental health & counselling practices actually operate — their systems, their regulators and the reviews they face.
Virtual CISO
Virtual CISO for Mental Health & Counselling Practices
Virtual CISO for counselling practices: security leadership for group and virtual therapy groups facing EAP-network scrutiny and AI scribe adoption.
Virtual Privacy Officer
Virtual Privacy Officer for Mental Health & Counselling Practices
Virtual Privacy Officer for therapy practices: custodian support for lock-boxes, couples files, associate agents and March 1 IPC statistics, from $2,200/month.
Incident Response Planning
Incident Response Planning for Mental Health & Counselling Practices
Incident response plans for therapy practices: notification roles for a breached practice platform, a stolen laptop, or Vastaamo-style patient extortion.
Privacy & Security Policy Development
Privacy & Security Policy Development for Mental Health & Counselling Practices
Privacy policy development for therapy practices: PHIPA information-practices statements, note retention schedules, and advertising rules after BetterHelp.
Privacy & Security Training
Privacy & Security Training for Mental Health & Counselling Practices
Privacy and security training for therapy practices: confidentiality for admin staff who see diagnoses, supervisor chart access, and session-recording rules.
Vendor Security Review & Questionnaire Support
Vendor Security Review & Questionnaire Support for Mental Health & Counselling Practices
Vendor security review for therapy practices: vet Owl Practice, Jane, video and AI note-taker vendors before they touch a client's session notes.
AI Privacy Impact Assessment
AI Privacy Impact Assessment for Mental Health & Counselling Practices
AI-PIA for therapy practices: assess AI scribes listening to live sessions, transcript custody, consent, and chatbot screening tools before you adopt them.
Minimum Viable Privacy Program
Minimum Viable Privacy Program for Mental Health & Counselling Practices
Minimum Viable Privacy for solo Registered Psychotherapists: a packaged $5,499/year program covering PHIPA custodian duties before your first client.
What you hold
What a counselling practice is actually protecting
The asset list in a therapy practice is short but unusually sensitive, concentrated in a handful of systems a small team manages directly.
Psychotherapy and process notes
The clinician's working record of a client's disclosures, formulations and risk observations, which most jurisdictions treat as carrying no notification threshold at all.
Test protocols and assessment data
Psychological testing instruments and scored results, which combine clinical sensitivity with the added weight of licensed, copyrighted materials.
Risk and safety plans
Documentation tied to duty-to-warn situations and suicide or violence risk, where both under-protection and over-sharing carry real consequences.
Couples, family and collateral information
Notes that name a partner, child or family member who never consented to being part of anyone's chart create access questions unique to relational therapy.
Session recordings kept for supervision
Audio or video captured for clinical supervision or training holds everything a written note does, plus the client's voice and likeness.
Billing, EAP and sliding-scale financial data
Invoices, insurer claim submissions and sliding-scale arrangements sit next to diagnosis codes, often visible to administrative staff who never see the clinical chart.
Regulatory map
The regulatory layers a Canadian practice answers to
Ontario practices sit inside PHIPA and a college standard at once; other provinces route the same duties through different statutes, but the underlying expectation is consistent.
Custodian status under PHIPA
A psychotherapist, psychologist or clinical social worker providing care is a health information custodian, with associates and staff acting as agents under the same statute.
No harm threshold for notice
Ontario's regime requires notice to affected individuals for essentially any theft, loss or unauthorized use or disclosure, regardless of how contained the practice believes the exposure was.
CRPO's record-keeping standard
Standard 5.6 requires protection against theft, loss and unauthorized use, tested and automated backups, secure destruction logs, and an audit trail showing who viewed a record and when.
The Electronic Practice standard
CRPO 3.4 requires secure technology, informed consent before delivering services electronically, and filing treatment-related emails and texts inside the clinical record itself.
March 1 statistics and IPC notice
O. Reg. 329/04 requires custodians to notify the IPC of qualifying breaches and to file annual statistics by March 1, a filing many small practices discover only once it is overdue.
Quebec, Alberta and BC variations
Quebec's Law 25 applies to a psychotherapy office like any enterprise, with a named person in charge and an incident register; Alberta and BC route counselling practices through PIPA unless the clinic is a designated health custodian.
What goes wrong
How therapy practices actually get hurt
The incidents that define this niche are not generic ransomware stories; they target the person in the chair, not just the organization.
Extortion aimed at patients, not the clinic
Finland's Vastaamo breach saw roughly 36,000 psychotherapy patients' notes stolen from an unencrypted database and individual patients extorted directly with their own session content, a pattern this niche cannot treat as a foreign curiosity.
Ad-tech sharing of intake data
The FTC's action against BetterHelp, over sharing email addresses and intake answers with Facebook, Snapchat and Pinterest for advertising, shows regulators now treat therapy marketing stacks as a live enforcement target.
Snooping by staff
Unauthorized viewing of a chart, by a curious employee rather than an outside attacker, was Ontario's most commonly self-reported health-sector breach cause in 2024, and shared logins in small practices make it easy to miss.
Custody and family-law weaponization
Access and correction requests tied to custody disputes are routine enough that the Information and Privacy Commissioner has issued repeated decisions on psychologists' records, and a practice without a lock-box process feels every one of them.
When organisations call us
When counselling practices call us
Demand is steady year-round, with intake spikes each January and September, but a handful of specific moments push practices to act.
Adopting an AI scribe
A practice starts trialing an AI note-taker to save documentation time and suddenly needs answers on consent, recording custody and vendor vetting before the first session is captured.
A subpoena or access request
A court, lawyer or client's own access request lands on a desk and exposes that retention, redaction and lock-box practices were never written down.
Joining an EAP or insurer network
Panel agreements increasingly ask for written security representations before referrals start flowing, catching solo and small-group practices off guard.
Expanding telepractice across provinces
CRPO's Electronic Practice standard ties telepractice growth to licensing rules wherever the client happens to be sitting that day, a detail that changes as caseloads go virtual.
Cyber-insurance renewal
Renewal applications now ask pointed questions about encryption, backups and audit logging that a first-time applicant often cannot answer confidently.
News of a peer practice's breach
A Vastaamo headline or a local incident story is often what finally moves a practice from meaning to get around to it to booking the work.
Mental Health & Counselling Practices: privacy & security questions, answered
Yes, in Ontario a psychotherapist, psychologist or clinical social worker providing care to individuals is a health information custodian under section 3(1) of PHIPA the moment they open a practice, regardless of how small it is. Associates, contractors and administrative staff working under that practice are agents of the custodian, not custodians themselves, which places the compliance obligation squarely on the clinician who owns the practice.
Psychotherapy notes carry a level of sensitivity that most physical-health records do not, since they document a client's inner disclosures rather than a physiological fact, and Ontario's PHIPA regime reflects that by requiring notice for essentially any unauthorized access or disclosure, with no minimum-harm test to clear first. Combined with CRPO's audit-trail and electronic-practice standards, the bar sits higher than in most other clinical settings.
Running on Owl Practice, Jane or a similar cloud platform removes the server-room problem but not the custodian obligation, and it adds new ones: vendor vetting, consent for electronic delivery of services, and audit trails over who viewed a record and when. A virtual-first practice typically needs a leaner but still deliberate program, built around the platforms and vendors actually in use rather than owned infrastructure.
BetterHelp was fined and banned from sharing health data for advertising after sending intake answers and identifiers to social platforms, and Canadian practices running the same kind of marketing stack, a pixel-tagged website, a US email newsletter tool, a directory listing with tracking, inherit the identical exposure under PIPEDA even without a US regulator watching. The lesson is that the leak vector here is marketing technology, not a billing system.
Yes, because the moment a breach happens is the worst possible time to design a notification process for the first time, particularly given PHIPA's no-threshold notice duty and the reputational stakes of a therapy-specific incident. A written plan assigns who notifies clients, who contacts the IPC, and how a platform-level breach at a vendor like a scheduling or video tool gets handled differently than a stolen laptop.
A group practice of ten or thirty clinicians multiplies every risk a solo practitioner carries: more people with system access, supervision arrangements that create their own viewing rights, and EAP or insurer panels that expect a named security lead rather than an informal understanding. Group practices typically need ongoing oversight and a documented program, where a solo practitioner can often start with a narrower foundational build.
Start with an honest inventory: which platform holds the clinical record, who can access it, what your consent language says about electronic practice, and whether a retention schedule exists for notes and test protocols. From there, a gap review against PHIPA and CRPO's standards tells you which foundational pieces are missing and in what order to build them.
Related industries
Answers & guides
- What is PIPEDA, and does it apply to my business?
- What should I do after a data breach?
- VPO vs vCISO: do you need one, the other, or both?
- When do you need an AI Privacy Impact Assessment (AI-PIA)?
- How much does a Virtual Privacy Officer (VPO) cost?
- The First 24 Hours After a Privacy Breach: A Canadian Response Playbook
- The Canadian Privacy Law Landscape in 2026: PIPEDA, PHIPA, and Quebec Law 25
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.