Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Clinical care providers

Privacy & Security for Mental Health & Counselling Practices

A psychotherapy note is among the most sensitive records any custodian holds, and the practices that generate them are usually small businesses run by the clinician who is also the privacy officer. Privacy Horizon builds the security and privacy program around that reality: PHIPA custodian duties, CRPO's record-keeping standards, and the AI scribes now sitting inside the therapy hour, without asking a solo Registered Psychotherapist to become a compliance department.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

We work with solo Registered Psychotherapists and psychologists building their first program, clinic directors running group practices of five to fifty clinicians, and the operations lead of a virtual-first counselling network or EAP-affiliated group. In almost every case, the owner-clinician carries the PHIPA custodian obligation personally, alongside a full caseload.

Engagements start at recognizable moments: a practice adopts an AI note-taker and needs to know what happens to the recording, a subpoena or custody dispute exposes thin records practices, an EAP network or insurer demands security representations before referrals begin, or a therapist reads about a psychotherapy platform breach and wants an honest answer about their own exposure.

What sets this niche apart from other health providers is the record itself. A process note documents a person's inner life, not a diagnosis code or a lab value, and the harm from its exposure cannot be undone by a refund or an apology. Regulators treat it accordingly, with no threshold for how minor a disclosure has to be before notification is owed.

Cheerful counselor works with married couple

Services

Privacy & security services for mental health & counselling practices

Each service below is scoped for how mental health & counselling practices actually operate — their systems, their regulators and the reviews they face.

What you hold

What a counselling practice is actually protecting

The asset list in a therapy practice is short but unusually sensitive, concentrated in a handful of systems a small team manages directly.

Psychotherapy and process notes

The clinician's working record of a client's disclosures, formulations and risk observations, which most jurisdictions treat as carrying no notification threshold at all.

Test protocols and assessment data

Psychological testing instruments and scored results, which combine clinical sensitivity with the added weight of licensed, copyrighted materials.

Risk and safety plans

Documentation tied to duty-to-warn situations and suicide or violence risk, where both under-protection and over-sharing carry real consequences.

Couples, family and collateral information

Notes that name a partner, child or family member who never consented to being part of anyone's chart create access questions unique to relational therapy.

Session recordings kept for supervision

Audio or video captured for clinical supervision or training holds everything a written note does, plus the client's voice and likeness.

Billing, EAP and sliding-scale financial data

Invoices, insurer claim submissions and sliding-scale arrangements sit next to diagnosis codes, often visible to administrative staff who never see the clinical chart.

Regulatory map

The regulatory layers a Canadian practice answers to

Ontario practices sit inside PHIPA and a college standard at once; other provinces route the same duties through different statutes, but the underlying expectation is consistent.

Custodian status under PHIPA

A psychotherapist, psychologist or clinical social worker providing care is a health information custodian, with associates and staff acting as agents under the same statute.

Read our guide →

No harm threshold for notice

Ontario's regime requires notice to affected individuals for essentially any theft, loss or unauthorized use or disclosure, regardless of how contained the practice believes the exposure was.

Primary source →

CRPO's record-keeping standard

Standard 5.6 requires protection against theft, loss and unauthorized use, tested and automated backups, secure destruction logs, and an audit trail showing who viewed a record and when.

Primary source →

The Electronic Practice standard

CRPO 3.4 requires secure technology, informed consent before delivering services electronically, and filing treatment-related emails and texts inside the clinical record itself.

Primary source →

March 1 statistics and IPC notice

O. Reg. 329/04 requires custodians to notify the IPC of qualifying breaches and to file annual statistics by March 1, a filing many small practices discover only once it is overdue.

Primary source →

Quebec, Alberta and BC variations

Quebec's Law 25 applies to a psychotherapy office like any enterprise, with a named person in charge and an incident register; Alberta and BC route counselling practices through PIPA unless the clinic is a designated health custodian.

Primary source →

What goes wrong

How therapy practices actually get hurt

The incidents that define this niche are not generic ransomware stories; they target the person in the chair, not just the organization.

  • Extortion aimed at patients, not the clinic

    Finland's Vastaamo breach saw roughly 36,000 psychotherapy patients' notes stolen from an unencrypted database and individual patients extorted directly with their own session content, a pattern this niche cannot treat as a foreign curiosity.

    Source →

  • Ad-tech sharing of intake data

    The FTC's action against BetterHelp, over sharing email addresses and intake answers with Facebook, Snapchat and Pinterest for advertising, shows regulators now treat therapy marketing stacks as a live enforcement target.

    Source →

  • Snooping by staff

    Unauthorized viewing of a chart, by a curious employee rather than an outside attacker, was Ontario's most commonly self-reported health-sector breach cause in 2024, and shared logins in small practices make it easy to miss.

    Source →

  • Custody and family-law weaponization

    Access and correction requests tied to custody disputes are routine enough that the Information and Privacy Commissioner has issued repeated decisions on psychologists' records, and a practice without a lock-box process feels every one of them.

When organisations call us

When counselling practices call us

Demand is steady year-round, with intake spikes each January and September, but a handful of specific moments push practices to act.

  • Adopting an AI scribe

    A practice starts trialing an AI note-taker to save documentation time and suddenly needs answers on consent, recording custody and vendor vetting before the first session is captured.

  • A subpoena or access request

    A court, lawyer or client's own access request lands on a desk and exposes that retention, redaction and lock-box practices were never written down.

  • Joining an EAP or insurer network

    Panel agreements increasingly ask for written security representations before referrals start flowing, catching solo and small-group practices off guard.

  • Expanding telepractice across provinces

    CRPO's Electronic Practice standard ties telepractice growth to licensing rules wherever the client happens to be sitting that day, a detail that changes as caseloads go virtual.

  • Cyber-insurance renewal

    Renewal applications now ask pointed questions about encryption, backups and audit logging that a first-time applicant often cannot answer confidently.

  • News of a peer practice's breach

    A Vastaamo headline or a local incident story is often what finally moves a practice from meaning to get around to it to booking the work.

Mental Health & Counselling Practices: privacy & security questions, answered

Yes, in Ontario a psychotherapist, psychologist or clinical social worker providing care to individuals is a health information custodian under section 3(1) of PHIPA the moment they open a practice, regardless of how small it is. Associates, contractors and administrative staff working under that practice are agents of the custodian, not custodians themselves, which places the compliance obligation squarely on the clinician who owns the practice.

Psychotherapy notes carry a level of sensitivity that most physical-health records do not, since they document a client's inner disclosures rather than a physiological fact, and Ontario's PHIPA regime reflects that by requiring notice for essentially any unauthorized access or disclosure, with no minimum-harm test to clear first. Combined with CRPO's audit-trail and electronic-practice standards, the bar sits higher than in most other clinical settings.

Running on Owl Practice, Jane or a similar cloud platform removes the server-room problem but not the custodian obligation, and it adds new ones: vendor vetting, consent for electronic delivery of services, and audit trails over who viewed a record and when. A virtual-first practice typically needs a leaner but still deliberate program, built around the platforms and vendors actually in use rather than owned infrastructure.

BetterHelp was fined and banned from sharing health data for advertising after sending intake answers and identifiers to social platforms, and Canadian practices running the same kind of marketing stack, a pixel-tagged website, a US email newsletter tool, a directory listing with tracking, inherit the identical exposure under PIPEDA even without a US regulator watching. The lesson is that the leak vector here is marketing technology, not a billing system.

Yes, because the moment a breach happens is the worst possible time to design a notification process for the first time, particularly given PHIPA's no-threshold notice duty and the reputational stakes of a therapy-specific incident. A written plan assigns who notifies clients, who contacts the IPC, and how a platform-level breach at a vendor like a scheduling or video tool gets handled differently than a stolen laptop.

A group practice of ten or thirty clinicians multiplies every risk a solo practitioner carries: more people with system access, supervision arrangements that create their own viewing rights, and EAP or insurer panels that expect a named security lead rather than an informal understanding. Group practices typically need ongoing oversight and a documented program, where a solo practitioner can often start with a narrower foundational build.

Start with an honest inventory: which platform holds the clinical record, who can access it, what your consent language says about electronic practice, and whether a retention schedule exists for notes and test protocols. From there, a gap review against PHIPA and CRPO's standards tells you which foundational pieces are missing and in what order to build them.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.