
This lesson covers the federal privacy law most Oregon therapists assume applies to them, what it asks of a small practice, and why its six-year paperwork rule is a different clock from the seven-year clinical record rule your licensing board sets. It is for anyone setting up a first Oregon practice who would rather read the primary sources than a vendor's summary. The telehealth lesson picks up where this one stops.
Whether HIPAA covers you at all
HIPAA binds "covered entities," and the definition at 45 CFR 160.103 is narrower than most people expect. A health care provider is a covered entity only if it transmits health information in electronic form in connection with a transaction the rules cover, such as a claim sent to an insurer. A cash-only practice that never files an electronic claim or uses a clearinghouse may sit outside that definition.
I would not build a practice on that gap. One electronic claim, or a billing service sending one on your behalf, and you are in. Oregon's board rules and Oregon's own health information statute apply either way. If you believe you are outside HIPAA, check with an attorney before relying on it; the rest of this lesson assumes you are inside.
The three rules in plain terms
The Privacy Rule is about who may see and use protected health information (PHI) and on what terms: permitted uses and disclosures, the client's right to see their own record, the "minimum necessary" habit, and the notice of privacy practices you hand out at intake.
The Security Rule is narrower. It covers PHI in electronic form only (ePHI) and asks for administrative, physical, and technical safeguards around it: EHR, email, laptop, backups.
The Breach Notification Rule applies when either of the first two fails in a way that exposes PHI. It says whom you tell and how fast.
The risk analysis comes first
The Security Rule's opening standard is a "security management process," and its first required piece is the risk analysis. The rule asks for an "accurate and thorough assessment of the potential risks and vulnerabilities" to the confidentiality, integrity, and availability of the ePHI you hold. The same paragraph also requires risk management (acting on what you found), a sanction policy, and regular review of activity such as audit logs.
In practice this is a written, dated document that lists every place ePHI lives (EHR, billing software, email, phone, laptop, backups), what could go wrong with each, how likely that is, and what you did about it. A policy stating that you "will" perform a risk analysis is not one. The video above, from the HHS Office for Civil Rights, walks through what its investigators look for. The worksheet attached to this lesson follows that structure.
Business associate agreements
A vendor that creates, receives, stores, or transmits PHI on your behalf is a business associate, and you need written "satisfactory assurances" from it before the data changes hands. The Privacy Rule states the requirement at 45 CFR 164.504(e) and the Security Rule repeats it for ePHI at 164.308(b). The contract that carries those assurances is the business associate agreement, the BAA, and the obligation flows down to the vendor's own subcontractors.
For a therapy practice the list is short: the EHR, the telehealth video platform, a billing service or clearinghouse, cloud storage or backup, any transcription or note-writing tool, and email that carries client information. The recurring mistake is treating a "HIPAA compliant" badge on a vendor's site as the agreement. The signed BAA in your files is the compliance, and consumer tiers of well-known products often do not come with one.
Breach notification basics
A breach under 45 CFR 164.402 is an impermissible acquisition, access, use, or disclosure of PHI that compromises its security or privacy, unless a documented risk assessment shows a low probability that the information was compromised. The factors are the nature and extent of the PHI, who received it, whether anyone in fact viewed or acquired it, and mitigation.
If it is a breach, 164.404 requires notice to each affected person "without unreasonable delay and in no case later than 60 calendar days" after discovery. Under 164.408, a breach affecting fewer than 500 people goes into a log you report to HHS within 60 days after the calendar year ends; one affecting 500 or more people requires notice to HHS at the same time as the individuals. Media notice, under 164.406, applies only when more than 500 residents of one state or jurisdiction are involved. Oregon has a data breach statute of its own; ask an attorney about it.
Two clocks: HIPAA's six years and your board's seven
HIPAA sets no retention period for clinical records, only a six-year period for its own paperwork. The Security Rule at 164.316(b)(2)(i) requires you to keep the policies, procedures, and documented assessments it demands for six years from creation or from the date they were last in effect, whichever is later, and the Privacy Rule's 164.530(j)(2) says the same for its documentation. Risk analyses, BAAs, and your notice of privacy practices all run on that clock.
The clinical record clock comes from your licensing board, and in Oregon it is seven years at all three boards:
- LPCs, LMFTs, and registered associates: OAR 833-075-0070, seven years from the date of last service. The rule also requires legible records kept "in a secure, safe, and retrievable condition" and notice to the Board if records are destroyed or lost.
- Regulated social workers outside an agency setting: OAR 877-030-0100, seven years from the date of the last session, with the same minimum content. A social worker in private practice must also name a qualified person or records management company to step in on death or incapacity, and tell the Board who it is.
- Psychologists and psychologist associates: OAR 858-010-0060, seven years from the date of last service, with a longer content list (fee arrangement, each contact's date and substance, releases, signed consents). The qualified person must be an active or semi-active Oregon licensed psychologist.
The OBLPCT rule as amended August 12, 2026 includes a section (5): the seven years run from the last date of service by the treating provider whether the record is held by that provider or by a custodian of record under OAR 833-075-0080. Handing records to a custodian when you leave a practice neither restarts the clock nor shortens it. The retention quick sheet attached to this lesson lists all three.
The two clocks start on different days. A BAA signed in 2020 and replaced in 2024 stays on file until 2030; a client last seen in 2024 has a record you keep until 2031.
Oregon's own privacy layer
ORS 192.553 gives Oregonians the right to have their protected health information safeguarded from unlawful use or disclosure and the right to access and review it, and notes that the federal privacy regulations add further rights on top of it. The two sets of rights run side by side, one more reason not to lean on the covered-entity gap above.
The Security Rule update is still a proposal
On January 6, 2025, HHS published a proposed rule to strengthen the Security Rule, the first substantive rewrite since 2013 if finalized. The comment period closed on March 7, 2025. Proposed changes include removing the "addressable" versus "required" distinction, so nearly every safeguard would be mandatory, and requiring a written technology asset inventory and network map.
As of September 2026 there is no final rule. Trackers guess at a date; I will not repeat a guess. What the proposal shows is the direction: written inventories, encryption, multifactor authentication, and a risk analysis you could hand to an investigator. A practice doing those things now will have little to change if the rule is finalized.
Building the file
- Write and date the risk analysis, covering every system that holds ePHI, as 164.308(a)(1) requires.
- List every vendor that touches PHI and collect a signed BAA from each, per 164.504(e).
- Put your privacy and security policies in writing and mark each with a six-year retention date, per 164.316(b).
- Set the seven-year clinical record clock and, where your board requires it, name a custodian or qualified person, per OAR 833-075-0070, 877-030-0100, or 858-010-0060.
- Read the proposed Security Rule once so nothing in it surprises you later.
This is how I read these rules as a practicing LPC, with the primary texts linked and listed below; it is not legal advice, and an attorney, your board, or the HHS Office for Civil Rights gets the final word on your situation.
Further reading
- HHS Office for Civil Rights: Risk Management Under the HIPAA Security Rule (video). OCR's senior cybersecurity advisor on risk analysis and risk management, with examples from investigations.
Sources
- “45 CFR 160.103, Definitions.” eCFR, Sep 23, 2026. Current eCFR text (up to date as of 2026-09-23); section last amended by 91 FR 14404 (published 2026-03-24, effective 2026-05-26). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103 (accessed Sep 24, 2026).
- “45 CFR 164.308, Administrative safeguards.” eCFR, Sep 23, 2026. Current eCFR text (up to date as of 2026-09-23); section last amended by 78 FR 5694 (2013-01-25). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308 (accessed Sep 24, 2026).
- “45 CFR 164.316, Policies and procedures and documentation requirements.” eCFR, Sep 23, 2026. Current eCFR text (up to date as of 2026-09-23); section last amended by 78 FR 5695 (2013-01-25). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.316 (accessed Sep 24, 2026).
- “45 CFR 164.402, Definitions (breach notification).” eCFR, Sep 23, 2026. Current eCFR text (up to date as of 2026-09-23); section last amended by 78 FR 5695 (2013-01-25). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.402 (accessed Sep 24, 2026).
- “45 CFR 164.404, Notification to individuals.” eCFR, Sep 23, 2026. Current eCFR text (up to date as of 2026-09-23); section last amended at adoption, 74 FR 42767 (2009-08-24). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.404 (accessed Sep 24, 2026).
- “45 CFR 164.406, Notification to the media.” eCFR, Sep 23, 2026. Current eCFR text (up to date as of 2026-09-23); section last amended by 78 FR 5695 (2013-01-25). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.406 (accessed Sep 24, 2026).
- “45 CFR 164.408, Notification to the Secretary.” eCFR, Sep 23, 2026. Current eCFR text (up to date as of 2026-09-23); section last amended by 78 FR 5695 (2013-01-25). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.408 (accessed Sep 24, 2026).
- “45 CFR 164.504, Uses and disclosures: organizational requirements.” eCFR, Sep 23, 2026. Current eCFR text (up to date as of 2026-09-23); section last amended by 78 FR 5697 (2013-01-25); business associate contracts at 164.504(e). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504 (accessed Sep 24, 2026).
- “45 CFR 164.530, Administrative requirements.” eCFR, Sep 23, 2026. Current eCFR text (up to date as of 2026-09-23); section last amended by 74 FR 42769 (2009-08-24). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530 (accessed Sep 24, 2026).
- “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule, 90 FR 898).” Federal Register, Jan 6, 2025. Proposed rule published 2025-01-06; comments closed 2025-03-07. No final rule found in the Federal Register as of 2026-09-24. https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information (accessed Sep 24, 2026).
- “OAR 833-075-0070, Client Records.” Oregon Secretary of State, Oregon Administrative Rules Database, Aug 12, 2026. Amended BLPCT 3-2026, filed and effective 2026-08-12; current official text checked 2026-09-24. https://secure.sos.state.or.us/oard/view.action?ruleNumber=833-075-0070 (accessed Sep 24, 2026).
- “OAR 833-075-0080, Custodian of Record.” Oregon Secretary of State, Oregon Administrative Rules Database, Oct 8, 2021. In force as amended 2021-10-08 (BLPCT 5-2021, filed and effective); current official text checked 2026-09-24. https://secure.sos.state.or.us/oard/view.action?ruleNumber=833-075-0080 (accessed Sep 24, 2026).
- “OAR 877-030-0100, Retention of Client Records; Disposition of Client Records in Case of Death or Incapacity of Licensee.” Oregon Secretary of State, Oregon Administrative Rules Database, Jan 1, 2011. In force as amended 2011-01-01 (BLSW 3-2010, filed 2010-12-15, certified effective); current official text checked 2026-09-24. https://secure.sos.state.or.us/oard/view.action?ruleNumber=877-030-0100 (accessed Sep 24, 2026).
- “OAR 858-010-0060, Psychological Records.” Oregon Secretary of State, Oregon Administrative Rules Database, Sep 11, 2023. In force as amended 2023-09-11 (OBP 3-2023, filed and effective); current official text checked 2026-09-24. https://secure.sos.state.or.us/oard/view.action?ruleNumber=858-010-0060 (accessed Sep 24, 2026).
- “ORS 192.553, Policy for protected health information.” Oregon State Legislature. Official ORS 2025 Edition text; no date on page; checked 2026-09-24. Formerly ORS 192.518 (renumbered 2011). https://www.oregonlegislature.gov/bills_laws/ors/ors192.html (accessed Sep 24, 2026).
Documents
Templates and worksheets that go with this lesson.
HIPAA risk analysis worksheet (PDF)
Oregon record retention quick sheet (PDF)