The Field Note Behavioral Health · Under Healthcare · Last updated July 2026
Behavioral health practices: HIPAA compliance without drowning.
A solo therapist can eyeball where PHI lives. A ten-location ABA group cannot. Risk in behavioral health does not usually walk in through the EHR. It walks in through SMS reminders, session recordings, clinician chat, and consumer e-fax, and it accumulates one rooftop at a time.
6 min · Behavioral Health · Under Healthcare
Questions this article answers
- What HIPAA surfaces do multi-location behavioral health groups miss most often?
- What does a BAA actually need to cover for behavioral health specifically?
- Why does 42 CFR Part 2 matter separately from HIPAA?
- How should a growing ABA or IOP group think about SMS and texting compliance?
- Is signing a BAA enough for a texting or telehealth vendor to be compliant?
- What seven questions belong in a behavioral health vendor RFP?
The BAA is not the compliance program. It is a signature on a document that says the vendor agrees to be regulated. What the vendor actually does with SMS bodies, session audio, and chat logs is a separate engineering question you have to ask.
Behavioral health is the fastest-growing subsegment of PE-backed healthcare rollups. Outpatient mental health, addiction and SUD treatment, IOP and PHP programs, and ABA platforms are consolidating 3 to 30-location groups every quarter, and the tech stack under those rollups is almost always under-specified. The HIPAA surface is different from primary care because of what sits on it: session content is more sensitive than a lab result, delivery is telehealth-first, and coordination outside session hours runs on text. More rooftops mean more phone systems, more e-fax accounts, more messaging apps, and more SaaS logins per employee. The compliance program cannot inventory data it does not know exists.
The HIPAA surfaces multi-location behavioral health groups actually miss
Not the EHR. The EHR is the surface every buyer inspects. What gets missed:
- SMS appointment reminders sent from the front-desk phone system rather than the EHR, often Twilio-backed automations a practice manager spun up without a BAA on the eligible product set.
- Group text threads between RBTs and ABA parents, sometimes on personal phones, containing the child's name and behavior data.
- Telehealth session recordings retained in a Zoom cloud account that is not covered by a Zoom for Healthcare BAA.
- Clinician-to-clinician chat in a workspace on a consumer Slack, Teams, or WhatsApp tier — case coordination containing PHI outside a healthcare plan.
- E-fax to insurers and referring PCPs routed through a consumer e-fax account with no BAA in place.
The pattern: risk lives where communication crosses org boundaries in a hurry, not where the EHR sits.
What a BAA actually needs to cover for behavioral health
A generic BAA is not enough for this vertical. The instrument has to name the workload: content of SMS bodies (not just delivery metadata), session recordings as ePHI with retention and deletion terms specified, chat and messaging content if the vendor supports internal team messaging, and an explicit acknowledgement of 42 CFR Part 2 if the vendor will touch SUD records. Part 2 is more restrictive than HIPAA — the Final Rule compliance date was February 16, 2026, OCR now enforces it alongside HIPAA, and a new SUD counseling notes category carries heightened protection analogous to psychotherapy notes. Flow-down clauses have to reach subcontractors — Twilio inside a texting vendor, AWS inside a UCaaS, an off-shore transcription vendor inside a telehealth product.
Buyer-side. Supplier-paid. Buyers pay zero. Compensation has zero weight in the Cardinal Index scoring. We scope the BAA surface first under the Cardinal Method, then evaluate vendor fit against how the group actually communicates with patients and clinicians.
The phone system and texting question, for a growing group
The practical stack question is which vendor will sign a BAA that covers the specific workload, and whether the routing architecture works across rooftops. Twilio offers a BAA on a specifically eligible subset of products, and the customer has to sign it AND configure only the eligible surfaces AND avoid logging message bodies into non-covered analytics. It is a developer platform, not a turnkey compliance product. OhMD, Klara, Spruce Health, and Weave sell turnkey texting layers at healthcare practices — each signs a BAA, each has different depth on group messaging, video, and EHR integration. Fit for ABA is different from fit for outpatient mental health because ABA runs on ongoing parent coordination, not just appointment confirmations. On the video side, Doxy.me, SimplePractice's built-in tool, Zoom for Healthcare with a BAA, Google Meet under a Google Workspace HIPAA amendment, and Microsoft Teams for Healthcare all cover the workload — the buyer-side question is whether recording, transcription, and voicemail on the same tenant are all covered under the same signed instrument.
What breaks: two structural failure modes
Failure mode one. HIPAA compliant usually means the vendor will sign a BAA. That is legal cover, not an engineering guarantee. PHI still leaks into product analytics, session-replay tools, error logs in Sentry or Datadog, and third-party integrations that a growth-stage team spun up before compliance review. The BAA does not fix engineering choices. In behavioral health the leak surface is worse because session content, texting content, and clinician chat are all normal product-telemetry targets.
Failure mode two. A solo therapist has one phone, one texting tool, one e-fax, one telehealth link. A ten-location group inherits whatever each acquired practice was already using. Six months post-close the group is running three UCaaS tenants, two texting tools, four e-fax accounts, and a dozen personal Google accounts sending PHI to insurers. No single incident, no single vendor at fault — but the compliance program cannot inventory what it does not know exists. The fix is a surface census before sourcing, not a bigger BAA folder.
Seven questions to ask any vendor before you sign
Paste this straight into the RFP:
- Do you offer a BAA, and does it name the specific products we will use — SMS content, video, chat, e-fax, call recording, voicemail transcription?
- If we treat SUD patients, do you acknowledge 42 CFR Part 2 obligations in writing, including the restrictions on use in legal proceedings and the new SUD counseling notes category?
- Where do message bodies, session recordings, and transcripts live geographically, and who inside your company can access them?
- What is your breach-notification SLA to us in the event of an incident touching our data?
- Which of your subcontractors and sub-processors touch our PHI — Twilio, AWS, OpenAI, a transcription vendor — and are they under flow-down BAA terms?
- Do you retrain your staff annually on our BAA specifically, or only on a generic HIPAA module?
- Can we review your most recent SOC 2 Type 2 report and HITRUST certification, if applicable, under NDA before we sign?
If a vendor cannot answer questions one and five in writing, the compliance surface is not scoped and the group is buying legal exposure.
What to do this week
Run the surface census before you renew any vendor. Enumerate every place PHI is created, transmitted, stored, or logged across every rooftop — including the SMS lines, the group chats, the e-fax accounts, and the ad-hoc SaaS tools that clinicians actually use. Compare that inventory against the BAAs you have signed. Wherever there is a surface without a matching BAA, that is a control gap you already own. Behavioral health nests under our Healthcare coverage, where the same discipline governs every multi-location clinical group, from primary care to multi-location connectivity to vendor-side BAA audits.
In short
- The HIPAA surface in behavioral health does not usually run through the EHR. It runs through SMS bodies, session recordings, clinician chat, and consumer e-fax — the coordination that happens outside the clinical record.
- A generic BAA is not enough. The instrument has to name the specific workloads (SMS content, video, recording, chat) and acknowledge 42 CFR Part 2 explicitly if you treat SUD.
- OCR began enforcing the 42 CFR Part 2 Final Rule on February 16, 2026, aligning breach notification with HIPAA and adding SUD counseling notes as a heightened-protection category.
- HIPAA compliant usually means a vendor will sign a BAA. That is legal cover, not an engineering guarantee. PHI still leaks into analytics, session-replay, error logs, and unmapped third-party integrations.
- Multi-location groups accumulate compliance risk by surface count. Run a data-surface census across every rooftop before renewing any vendor, and use the seven-question screen in the RFP.
Sources
- HHS Office for Civil Rights, “Information Related to Mental and Behavioral Health, including Opioid Overdose,” reviewed February 13, 2026. hhs.gov
- HHS Office for Civil Rights, “Understanding Confidentiality of SUD Patient Records (42 CFR Part 2),” reviewed February 13, 2026. hhs.gov
- HHS Office for Civil Rights, “Fact Sheet: 42 CFR Part 2 Final Rule,” updated January 30, 2026. hhs.gov
- HHS Office for Civil Rights, “HIPAA and Telehealth,” reviewed October 18, 2023. hhs.gov
- Twilio, HIPAA Eligible Products and BAA policy. twilio.com
All linked sources were live at time of publish (July 2026). Verify before quoting in a procurement document.
Want a calibration on your group's BAA and surface inventory?
Run the Tier 1 benchmark.
Submit your current multi-location phone, telehealth, and messaging contracts. We return a benchmark PDF in five business days showing where the BAA coverage does not match the surfaces you actually use, and where you are paying above peer median across rooftops. Free. No follow-up sales drip.
Run the Tier 1 benchmark →