Protect Client Privacy
Understand how HIPAA’s Privacy Rule governs the use and disclosure of Protected Health Information, and learn how to apply confidentiality standards in everyday clinical decisions.
Apply Practical Security Safeguards
Learn concrete strategies to secure PHI and ePHI, including encrypted communication, password protection, telehealth security, and device safeguards to reduce risk.
Respond Effectively to Security Risks and Breaches
Develop the skills to recognize phishing, prevent common compliance mistakes, and take appropriate action if a privacy or security incident occurs.
About the course
Welcome to HIPAA Privacy and Security Training for Mental Health Professionals. This course is designed to help clinicians understand how to protect client information in a modern clinical environment, where documentation, communication, and care increasingly rely on electronic systems. In mental health, clients share deeply personal and vulnerable information, and protecting that information is both an ethical obligation and a legal requirement. Drawing from federal regulations, state confidentiality law, and contemporary clinical practice, this course translates complex legal and technical requirements into practical, usable safeguards. We’ll examine how the Privacy Rule, Security Rule, and Breach Notification Rule function as an integrated framework for protecting Protected Health Information, and how these standards apply to everyday clinical decisions, communication tools, and electronic systems. HIPAA establishes national standards governing when information may be shared and how electronic data must be protected, while requiring practices to implement administrative, physical, and technical safeguards to ensure confidentiality and prevent unauthorized access. We’ll also explore privacy as an evolving challenge within modern mental health care. As documentation, telehealth, and communication increasingly move into digital environments, clinicians must navigate risks that extend beyond traditional confidentiality concerns, including cybersecurity threats, electronic access controls, and data breaches. This course reframes HIPAA not as a bureaucratic obstacle, but as a living structure designed to preserve trust, autonomy, and ethical care in an increasingly interconnected world. By the end of this training, you’ll have a deeper understanding of how privacy and security function within contemporary clinical practice, how to confidently apply HIPAA standards in real-world situations, and how to safeguard both your clients and your professional integrity. Rather than memorizing rules, you’ll develop a practical framework for making thoughtful, ethical decisions that protect confidentiality while supporting meaningful therapeutic work. Learning Objectives 1. Identify the three primary HIPAA rules (Privacy, Security, and Breach Notification) and their purposes in protecting client information. 2. Differentiate between administrative, physical, and technical safeguards under the HIPAA Security Rule. 3. Describe how Protected Health Information (PHI) and Electronic PHI (ePHI) must be handled according to federal regulations and practice policy. 4. Apply secure communication practices for transmitting PHI via email, phone, and telehealth platforms. 5. Recognize potential security threats (e.g., phishing, social engineering, data breaches) 6. Evaluate scenarios involving privacy or security risks and determine appropriate preventive or corrective actions.
Presented by David Meer
David is a licensed professional counselor with a focus on neurodiversity-affirming care. He leads a group practice dedicated to supporting neurodivergent individuals through inclusive, client-centered approaches. David is passionate about challenging conventional models in mental health and promoting compassionate, equity-driven practices in both clinical work and education.
Curriculum
-
1
Introduction
-
(Included in full purchase)
Course Overview
-
(Included in full purchase)
CE Information
-
(Included in full purchase)
Introduction
-
(Included in full purchase)
Objectives
-
(Included in full purchase)
General HIPAA Guidelines
-
(Included in full purchase)
-
2
Privacy Rule
-
(Included in full purchase)
Privacy Rules (transition slide)
-
(Included in full purchase)
The Privacy Rule
-
(Included in full purchase)
Client Rights
-
(Included in full purchase)
Case Example
-
(Included in full purchase)
Minimum Necessary Standard
-
(Included in full purchase)
Permitted Uses and Disclosures
-
(Included in full purchase)
Notice of Privacy Practices
-
(Included in full purchase)
Deidentification of PHI
-
(Included in full purchase)
Business Associate Agreements
-
(Included in full purchase)
-
3
Security Rule
-
(Included in full purchase)
Security Rule (transition slide)
-
(Included in full purchase)
Areas of Security
-
(Included in full purchase)
Risk Management and Monitoring
-
(Included in full purchase)
Transmission of PHI via Email
-
(Included in full purchase)
Transmission of PHI via Phone
-
(Included in full purchase)
Electronic Health Records
-
(Included in full purchase)
Access Control and Authorization
-
(Included in full purchase)
Internet and Remote Access
-
(Included in full purchase)
Internet and Remote Access
-
(Included in full purchase)
Internet and Remote Access
-
(Included in full purchase)
Telehealth
-
(Included in full purchase)
Electronic Devices
-
(Included in full purchase)
Electronic Devices
-
(Included in full purchase)
Secure Disposal of Devices & Data
-
(Included in full purchase)
Phishing and Fraud Prevention
-
(Included in full purchase)
Phishing and Fraud Prevention
-
(Included in full purchase)
-
4
Breach Notification Rule
-
(Included in full purchase)
Breach Notification (transition slide)
-
(Included in full purchase)
Security Incident and Breach Response
-
(Included in full purchase)
-
5
Social Media and Online Public Spaces
-
(Included in full purchase)
Social Media and Online Public Spaces (transition slide)
-
(Included in full purchase)
Social Media and Online Public Spaces
-
(Included in full purchase)
Social Media and Online Public Spaces
-
(Included in full purchase)
Social Media and Online Public Spaces
-
(Included in full purchase)
References
-
(Included in full purchase)
-
6
Assessment
-
(Included in full purchase)
Assessment
-
(Included in full purchase)
Feedback
-
(Included in full purchase)
Protect Client Privacy in a Digital World
This course provides mental health clinicians with practical guidance on HIPAA privacy and security. Participants will learn how to protect client information, use secure communication tools, prevent breaches, and apply federal and state confidentiality laws in practice.
$15.00
Neurodiverse Counseling Services: ACEP No. 7531
Neurodiverse Counseling Services has been approved by NBCC as an Approved Continuing Education Provider, ACEP No. 7531. Programs that do not qualify for NBCC credit are clearly identified. Neurodiverse Counseling Services is solely responsible for all aspects of the programs. Neurodiverse Counseling Services 6424 East Greenway Parkway, Scottsdale, AZ, 85254 (480) 531-1076 [email protected]