When Can Mental Health Providers Share Information With Family Members Under HIPAA?
Mental health providers can share certain patient information with family members and other people involved in a patient’s care without a written HIPAA authorization when the patient agrees or does not object, when professional judgment supports a disclosure for an incapacitated or unavailable patient, or when another HIPAA provision permits the disclosure. The HIPAA Privacy Rule protects the confidentiality of mental health information, but it does not require providers to refuse every communication with family members. Correct application requires providers to distinguish between disclosures that require authorization, disclosures permitted by the HIPAA Privacy Rule, information that family members can provide to the treatment team, and the separate rights of legally authorized personal representatives.
Problems can arise when healthcare organizations respond to uncertainty by adopting a blanket rule against communicating with families. This approach is sometimes described as “HIPAA handcuffs.” The restriction may come from organizational policy, misunderstanding, or insufficient training rather than from the HIPAA Privacy Rule itself.
HIPAA Does Not Require a Written Authorization for Every Conversation
A signed authorization is one way to establish permission to disclose PHI, but it is not required for every communication involving a patient’s family or other care partners. The HIPAA Privacy Rule contains provisions allowing certain disclosures to people involved in the patient’s care or payment for care.
When the patient is present and has the capacity to make healthcare decisions, a provider can ask whether the patient agrees to information being shared with a family member. The patient can agree expressly or, depending on the circumstances, have an opportunity to object and not do so.
This can support ordinary communications without requiring a formal authorization for every interaction. The information disclosed should be directly relevant to the family member’s involvement in the patient’s care or payment for care.
Providers Can Use Professional Judgment When a Patient Is Incapacitated
Mental health treatment can involve circumstances in which a patient is temporarily unable to make decisions about information sharing. A psychiatric crisis, unconsciousness, severe impairment, or another condition can make it impracticable to obtain the patient’s agreement.
When the patient is not present or cannot practicably agree or object, the HIPAA Privacy Rule permits a provider to use professional judgment to determine whether disclosure to a family member or another person involved in care is in the patient’s best interests.
This does not create unrestricted access to the patient’s medical record. The disclosure should concern information directly relevant to the person’s involvement in the patient’s care or payment for care.
Family Members Can Give Information to a Mental Health Provider
A provider’s inability to disclose PHI to a family member does not prevent the family member from providing information to the provider. This distinction can be particularly relevant during a psychiatric crisis when relatives possess information that the treatment team does not have.
A family member can provide information about previous hospitalizations, medications, treatment responses, behavioral changes, substance use, functional impairment, previous suicide attempts, threats, or other facts that could affect treatment and safety decisions.
The communication can identify the person’s relationship to the patient and role in the patient’s care. Providing dates and factual descriptions can make the information more useful to the treatment team than conclusions about the patient’s condition.
Families can also provide information in writing and ask the facility to place it in the appropriate patient record. The provider’s ability to respond with patient information remains a separate HIPAA question.
Receiving Information and Disclosing Information Are Different HIPAA Issues
Confusion can arise when a healthcare employee tells a relative that HIPAA prevents the employee from discussing the patient and the relative interprets this to mean that no communication can occur in either direction.
The provider can listen even when the provider cannot disclose PHI in return. A family member can therefore provide treatment history or communicate a safety concern without first establishing a right to receive information from the provider.
This distinction can affect mental health treatment because family members may have observed behavior outside the clinical setting that is not documented in the medical record.
Safety Concerns Can Affect Information Sharing
The HIPAA Privacy Rule contains provisions permitting disclosures in circumstances involving serious and imminent threats to health or safety, subject to the applicable requirements. Mental health providers need to distinguish these circumstances from routine family involvement in care.
A family member who believes a patient presents a risk of suicide or other serious harm can communicate that concern to the treatment team. Specific information about statements, behavior, previous attempts, access to means, or recent changes can assist the provider in assessing the situation.
Putting serious concerns in writing can also create a record of the information supplied to the organization. The treatment team remains responsible for making clinical decisions based on the information available and applicable professional standards.
Discharge Planning Can Require Communication With Care Partners
Information sharing can become particularly relevant when a family member will participate in a patient’s care after discharge. A relative may be expected to provide housing, transportation, supervision, medication support, or assistance obtaining follow-up treatment.
The fact that a family member will provide support does not create unrestricted access to the patient’s medical information. It can, however, affect what information is directly relevant to that person’s involvement in the patient’s care.
Providers can consider what the care partner needs to know to perform the role. This can include appropriate information about care instructions, warning signs, follow-up arrangements, or actions to take if the patient’s condition deteriorates, depending on the circumstances and the applicable basis for disclosure.
General Guidance Can Be Different From Disclosure of PHI
A family member who cannot obtain patient-specific information can still ask a healthcare organization for general information that does not disclose the patient’s PHI. The distinction can allow useful communication without revealing confidential details from the medical record.
For example, a family member can ask for general guidance about responding to symptoms associated with a condition, available crisis resources, procedures for contacting the facility, or actions to take during an emergency.
A provider should distinguish a request for general educational information from a request to confirm a patient’s diagnosis, treatment, medication, or other PHI.
Family Members and Personal Representatives Have Different Rights
A family relationship does not automatically make a person the patient’s personal representative under HIPAA. A spouse, parent of an adult patient, sibling, adult child, or other relative can be involved in care without having legal authority to act for the patient.
A personal representative is a person who has authority under applicable law to make healthcare decisions for the individual. The authority can arise through arrangements such as guardianship, healthcare powers of attorney, or other legal mechanisms recognized under applicable law.
Subject to exceptions, the HIPAA Privacy Rule requires a Covered Entity to treat a personal representative as the individual with respect to PHI relevant to the matters within the representative’s authority. The scope of the underlying legal authority therefore needs to be established.
A document granting limited authority should not be treated as granting unrestricted rights over every aspect of the patient’s healthcare information.
Provider Policies Can Be More Restrictive Than HIPAA
A healthcare organization’s refusal to disclose information does not necessarily establish that HIPAA prohibits the disclosure. Organizations can adopt policies that restrict how employees exercise permissions available under the HIPAA Privacy Rule.
This distinction matters when explaining a decision to a patient or family member. Saying that “HIPAA does not allow it” can inaccurately describe a situation in which HIPAA permits the disclosure but organizational policy restricts it.
Healthcare employees need to understand both sets of requirements. They should know what the HIPAA Privacy Rule permits and what their organization authorizes them to do within those permissions.
Overly Restrictive HIPAA Practices Can Affect Mental Health Care
Protecting psychiatric information requires controls against unauthorized uses and disclosures, but avoiding every possible disclosure is not the standard established by the HIPAA Privacy Rule. The rule contains provisions that recognize treatment, care involvement, professional judgment, and specified health and safety circumstances.
An overly restrictive approach can leave a treatment team without information held by family members. It can also leave care partners without information they are permitted to receive and need for the role they are expected to perform.
The operational task is to identify the legal basis for each disclosure and limit the information accordingly rather than treating all communication with families as prohibited.
HIPAA Training Should Cover Permitted Disclosures
HIPAA training for mental health staff should address what employees are permitted to disclose as well as what they must protect. Training focused exclusively on confidentiality can encourage employees to treat non-disclosure as the safest response to every uncertain situation.
Staff should understand how the HIPAA Privacy Rule applies when a patient agrees to family involvement, when the patient does not object, when the patient is incapacitated or unavailable, when a person is involved in the patient’s care, and when a legally authorized personal representative is involved.
Training should also distinguish receiving information from disclosing information. Employees who cannot disclose PHI to a family member can still need to receive and appropriately document information the family member provides about treatment history or safety concerns.
Mental health scenarios can make these distinctions operational. Staff can be trained to identify what information is being requested, who is requesting it, the person’s role in the patient’s care, whether the patient has agreed or objected, whether professional judgment applies, and what information is directly relevant to the person’s involvement.
HIPAA Privacy and Appropriate Information Sharing Can Operate Together
The HIPAA Privacy Rule establishes protections for mental health information without creating a universal prohibition on communication with families and other care partners. Different rules apply depending on the patient’s capacity, involvement of the care partner, legal authority, safety circumstances, and information being disclosed.
Healthcare organizations can address unnecessary “HIPAA handcuffs” by training staff to make these distinctions and by developing policies that reflect the disclosures permitted by the HIPAA Privacy Rule. This allows patient confidentiality to remain protected while permitted information sharing supports treatment, continuity of care, and appropriate involvement of care partners.
HIPAA Training for Mental Health Providers
The HIPAA Journal provides three specialist HIPAA training courses for mental health providers that combine training on the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule with scenarios specific to mental health practice. HIPAA Training for Therapists and Counselors addresses issues such as multi-party treatment relationships, third-party requests for PHI, psychotherapy notes, mandated reporting, and overlapping confidentiality laws. HIPAA Training for Psychologists addresses the privacy and confidentiality requirements encountered in psychological practice, including circumstances in which federal confidentiality frameworks apply alongside HIPAA. HIPAA Training for Psychiatrists focuses on psychiatric practice, including risk assessments, information received from family members and other collateral sources, documentation decisions, patient safety, and telepsychiatry. Each course provides accredited HIPAA certification with 5.0 CEUs on successful completion.
