Glossary14 min read

Confidentiality in Therapy: What Is Protected, Legal Limits, and Exceptions

Understand confidentiality in mental health treatment, including what information is protected, the legal framework (HIPAA, state laws, 42 CFR Part 2), mandatory exceptions, and what clients should expect from their therapist.

Last updated: 2026-04-09Reviewed by MoodSpan Clinical Team

Medical Disclaimer: This content is for informational and educational purposes only. It is not a substitute for professional medical advice, diagnosis, or treatment. Always seek the advice of a qualified health provider with any questions you may have regarding a medical condition.

Definition of Confidentiality in Therapy

Confidentiality in therapy refers to the ethical and legal obligation of mental health professionals to protect information shared by clients during the course of treatment. This obligation applies to all licensed clinicians — including psychologists, psychiatrists, licensed clinical social workers (LCSWs), licensed professional counselors (LPCs), and marriage and family therapists (LMFTs) — and extends to virtually everything a client communicates in a therapeutic setting.

Confidentiality is not merely a professional courtesy. It is a foundational requirement of the therapeutic relationship, codified in law, enforced by licensing boards, and embedded in every major mental health ethics code. Without it, the trust necessary for clients to disclose painful, stigmatized, or legally sensitive experiences would not exist, and treatment effectiveness would be severely compromised.

Specifically, confidentiality covers: the content of therapy sessions, clinical notes and records, diagnoses and treatment plans, psychological test results, billing and insurance records, and even the fact that someone is receiving treatment at all. A therapist cannot confirm or deny that a specific individual is their client without the client's explicit written authorization.

Mandatory Exceptions: When Therapists Must Disclose

Confidentiality in therapy is not absolute. There are legally defined circumstances in which a therapist is required to breach confidentiality — meaning they have no professional discretion and must act regardless of the client's wishes. These mandatory exceptions exist because society has determined that certain risks to safety outweigh the therapeutic interest in privacy.

  • Imminent danger to self: When a client presents with active suicidal ideation accompanied by a specific plan, access to means, and stated intent, the clinician is obligated to take protective action. This may include contacting emergency services, initiating involuntary hospitalization proceedings, or notifying designated emergency contacts. The threshold is clinical: passive ideation without plan or intent does not automatically trigger this exception, but a clinician who reasonably believes the client poses an imminent risk to their own life must act.
  • Imminent danger to others (Tarasoff duty to warn/protect): Following the landmark Tarasoff v. Regents of the University of California (1976) decision, clinicians in most jurisdictions have a legal duty to take reasonable steps to protect identifiable third parties when a client makes a credible threat of serious harm. The specific requirements vary by state — some mandate direct warning of the potential victim, others require notifying law enforcement, and some require both. Not all states have codified Tarasoff, but the principle has been widely adopted in clinical practice.
  • Mandatory reporting of child abuse or neglect: All 50 U.S. states designate mental health professionals as mandatory reporters of suspected child abuse or neglect. This obligation is triggered by reasonable suspicion — the clinician does not need to verify or investigate the allegation before reporting. Failure to report can result in criminal penalties and licensure action.
  • Mandatory reporting of elder abuse and vulnerable adult abuse: Most states extend mandatory reporting requirements to suspected abuse, neglect, or exploitation of elderly individuals or dependent adults. The specific age thresholds, definitions, and reporting mechanisms vary by jurisdiction.
  • Court orders and valid subpoenas: A court order issued by a judge can compel disclosure of therapy records or testimony. A subpoena alone (without a court order) does not automatically require disclosure — clinicians should consult legal counsel and, in many jurisdictions, can file a motion to quash — but a valid court order typically cannot be ignored without risk of contempt.
  • Workers' compensation claims: When a client files a workers' compensation claim for a work-related psychological injury, they may be required to waive certain confidentiality protections related to the specific condition at issue. This is a limited waiver — it does not open the entire therapy record to the employer or insurer, but it does permit disclosure of information directly relevant to the claim.
  • Military and government security clearances: Individuals holding or seeking security clearances may face limited confidentiality in the context of background investigations. While routine therapy is generally not a disqualifying factor, certain conditions or behaviors disclosed in treatment may be subject to inquiry. Clinicians treating active-duty military personnel should be aware of the additional reporting obligations under the Uniform Code of Military Justice.

Permissive Exceptions: When Therapists May Disclose

In addition to mandatory exceptions, there are circumstances where disclosure is permitted but not required. In these situations, the clinician exercises professional judgment about whether sharing information serves the client's interests or meets a legitimate clinical need.

  • Consultation with colleagues: Clinicians routinely consult with other professionals about clinical cases — for example, discussing diagnostic uncertainty with a supervisor or seeking guidance on a complex treatment situation. When consulting, the therapist is expected to de-identify the client's information to the greatest extent possible. Peer consultation is considered a standard component of competent practice and is generally permitted under ethics codes without requiring explicit client consent, provided identifying details are removed.
  • Insurance and billing: Submitting claims to insurance companies requires disclosure of certain clinical information, including diagnosis codes, dates of service, and treatment modality. This disclosure is governed by the minimum necessary standard — only the information required to process the claim should be shared. Importantly, detailed session content and psychotherapy notes are not required for billing purposes and should not be submitted to insurers.
  • Coordination of care: When a client is receiving treatment from multiple providers — for example, a therapist and a psychiatrist, or a therapist and a primary care physician — sharing relevant clinical information can improve treatment outcomes. However, this generally requires the client's written informed consent specifying which providers may communicate and what information may be shared. HIPAA permits certain disclosures for treatment purposes, but best practice involves obtaining explicit authorization.
  • Medical emergencies: In genuine medical emergencies, HIPAA permits disclosure of relevant health information to emergency personnel or other providers to the extent necessary to address the immediate health crisis, even without prior patient authorization.

Confidentiality with Minors

Confidentiality for minors in therapy is one of the most complex and jurisdiction-dependent areas of mental health law. Parents and legal guardians generally have a right to access their child's medical records, but this right is not unlimited, and many states carve out protections for adolescents in specific circumstances.

Key considerations include:

  • Age of consent for treatment: Many states allow minors above a certain age (commonly 12-16, depending on jurisdiction) to consent to their own mental health treatment without parental authorization. In these cases, the minor's confidentiality may be protected from parental access.
  • Exceptions for abuse and harm: Regardless of age or consent laws, mandatory reporting obligations override any confidentiality protections when a minor discloses abuse, neglect, or presents as a danger to themselves or others.
  • Clinical best practice: Most child and adolescent therapists discuss confidentiality expectations with both the minor and the parent(s) at the outset of treatment. A common approach is to explain that general themes may be shared with parents (e.g., "your child is working on managing anger") but specific session content will remain private unless safety is at risk.
  • Divorce and custody situations: When parents are separated or divorced, access to a child's therapy records can become contested. Custody agreements may specify which parent can authorize treatment or access records. Clinicians should request copies of custody orders and consult legal counsel when disputes arise.

The lack of national uniformity on minor confidentiality means that clinicians must know the specific laws of the state in which they practice, and clients (both minors and parents) should ask about these policies during the first session.

Confidentiality in Group Therapy

Group therapy introduces a significant confidentiality challenge that does not exist in individual treatment: the therapist cannot legally guarantee the confidentiality of information shared among group members. While the clinician leading the group is bound by all applicable confidentiality laws and ethics codes, other group members are not licensed professionals and are not subject to the same legal obligations.

In practice, this means:

  • Group agreements: Most group therapists establish a confidentiality agreement at the start of the group, requiring all members to commit to keeping shared information private. This is a moral and social agreement — it may carry some weight in civil proceedings, but it is not enforceable in the same way that a clinician's legal obligations are.
  • Informed consent: Clients considering group therapy should be explicitly informed that the therapist cannot prevent other members from disclosing information shared in sessions. This is a required element of informed consent for group treatment.
  • Risk mitigation: Therapists can reduce confidentiality risks by establishing clear norms, addressing breaches directly when they occur, and reminding members periodically of their confidentiality commitments. Some group therapists also limit the amount of identifying detail that members are asked to share.

Despite these limitations, research consistently demonstrates that group therapy is effective across a wide range of conditions, and confidentiality breaches in well-managed groups are relatively uncommon.

Telehealth Confidentiality Considerations

The rapid expansion of telehealth in mental health care — accelerated dramatically since 2020 — has introduced new dimensions to confidentiality that both clinicians and clients should understand.

  • Platform security: Clinicians are required to use HIPAA-compliant video platforms that provide end-to-end encryption, business associate agreements (BAAs), and appropriate access controls. Consumer-grade applications (standard Zoom without healthcare features, FaceTime, Skype) generally do not meet HIPAA requirements, although temporary regulatory flexibilities were granted during the COVID-19 public health emergency.
  • Client environment: Unlike an office with soundproofing and a closed door, a client's home may not be private. Clinicians should discuss with clients how to ensure their environment is confidential during sessions — such as using headphones, finding a private room, or using a white noise machine.
  • Recording risks: Sessions conducted over video are potentially recordable by either party. Most ethics codes and state laws address recording of therapy sessions, but enforcement in the telehealth context is more difficult. Clinicians should establish clear agreements about recording at the outset of telehealth treatment.
  • Cross-state practice: When a therapist and client are in different states, the question of which state's confidentiality laws apply becomes relevant. Most licensing boards require the clinician to be licensed in the state where the client is physically located at the time of the session, and that state's laws generally govern.
  • Electronic communication: Email, text messaging, and client portal communications all carry confidentiality implications. Clinicians should use encrypted communication channels and educate clients about the risks of communicating sensitive information through unsecured channels.

Privilege vs. Confidentiality

The terms confidentiality and privilege are often used interchangeably, but they refer to distinct legal concepts that clients and clinicians should understand.

  • Confidentiality is a broad ethical and legal obligation that governs how a therapist handles client information in everyday practice. It applies in all professional contexts and is maintained unless a specific exception applies.
  • Privilege (more precisely, therapist-client privilege or psychotherapist-patient privilege) is a narrower legal protection that specifically governs whether therapy communications can be compelled in legal proceedings — courts, depositions, and formal legal discovery. Privilege is a rule of evidence, not a general privacy right.

Several important distinctions follow from this:

  • Privilege belongs to the client, not the therapist. The client can waive privilege and authorize the therapist to testify or release records in legal proceedings. The therapist cannot independently waive privilege over the client's objection.
  • Privilege is narrower than confidentiality. Information that is confidential in the therapeutic relationship may not necessarily be privileged in court. For example, in some jurisdictions, privilege does not apply when a client's mental health is directly at issue in litigation (e.g., the client raises an insanity defense or sues for emotional damages).
  • Federal recognition: The U.S. Supreme Court recognized a federal psychotherapist-patient privilege in Jaffee v. Redmond (1996), establishing that confidential communications between a licensed psychotherapist and a patient are protected from compelled disclosure in federal proceedings.
  • Exceptions to privilege generally parallel the exceptions to confidentiality (danger to self/others, child abuse reporting, court-ordered evaluations), but the specific rules vary by jurisdiction and by the type of legal proceeding.

In practice, clients should understand that entering therapy creates a strong presumption of privacy, but that this protection has defined boundaries — particularly when legal proceedings intersect with mental health treatment.

Confidentiality in Couples and Family Therapy

Couples and family therapy present unique confidentiality challenges because the therapist is treating a relational system rather than an individual. The question of who holds the right to confidentiality — and from whom — becomes more complex when multiple people are in the room.

  • No-secrets policies: Many couples and family therapists adopt a "no-secrets" policy, meaning that information shared by one partner or family member in an individual communication (e.g., a phone call or individual session) will not be kept secret from the other participants in treatment. This policy should be clearly stated during informed consent.
  • Individual disclosures: Some therapists take the opposite approach and will hold individual disclosures in confidence. This can create ethical dilemmas — for example, if one partner discloses an affair during an individual session, the therapist may find themselves unable to conduct effective couples work while holding this secret. Clear policies, established in advance, help prevent these situations.
  • Record access: In couples therapy, both partners generally have a right to access the joint treatment record. Clinicians should not include information in the joint record that was shared in individual sessions under a confidentiality agreement without the disclosing party's consent.
  • Post-separation complications: If a couple separates during or after treatment, questions about record access and potential testimony can arise. Some clinicians address these contingencies in their initial informed consent documents.

Frequently Asked Questions

Can my therapist tell my family what I talk about in therapy?

No. Your therapist cannot share information about your treatment with family members — including a spouse, parent (of an adult client), or adult children — without your explicit written authorization. This includes not only session content but also whether you are in therapy at all. The only exceptions are situations involving imminent danger to yourself or others, or mandatory reporting obligations such as suspected child abuse. If you want your therapist to communicate with a family member, you would need to sign a specific release of information form.

What happens if my therapist breaks confidentiality?

If a therapist breaches confidentiality without legal justification, the consequences can be significant. The client may file a complaint with the therapist's licensing board, which can result in disciplinary action including suspension or revocation of the license. The client may also have grounds for a civil lawsuit alleging breach of fiduciary duty, negligence, or violation of privacy rights. In cases involving HIPAA violations, the therapist or their practice may face federal penalties including fines. However, if the therapist broke confidentiality because a legally recognized exception applied (such as reporting child abuse or responding to an imminent safety threat), the disclosure is generally considered legally and ethically justified.

Does confidentiality apply to what I said before I knew about the limits?

Yes, confidentiality protections apply from the moment the therapeutic relationship begins, regardless of when the limits were formally discussed. However, this is precisely why ethics codes require therapists to explain confidentiality limits at the start of treatment — ideally before any substantive clinical disclosure occurs. If a therapist failed to discuss limits and you later disclosed something that falls under a mandatory reporting exception, the therapist would still be legally obligated to report. This underscores the importance of asking about confidentiality policies during your first session if the therapist does not raise the topic themselves.

Can my employer access my therapy records?

In most circumstances, no. Your employer cannot access your therapy records without your written consent. HIPAA and state confidentiality laws protect mental health records from employer access. However, there are limited exceptions: if you file a workers' compensation claim for a psychological injury, you may be required to waive certain confidentiality protections related to that specific condition. If you are in a mandatory Employee Assistance Program (EAP) evaluation, the employer may receive limited information (typically only attendance and compliance, not session content). If you hold a government position requiring a security clearance, you may face additional inquiries, though routine therapy attendance is generally not disqualifying.

Is what I tell my therapist confidential if I pay out of pocket?

Paying out of pocket can enhance your privacy in one important way: it eliminates the need to share diagnostic and billing information with an insurance company. When you use insurance, your therapist must submit a diagnosis code, dates of service, and treatment type to the insurer, and this information becomes part of the insurer's records. Paying privately avoids this disclosure entirely. However, all other confidentiality rules and exceptions still apply regardless of payment method — mandatory reporting, duty to warn, and court orders are not affected by how you pay for treatment.

Are text messages and emails with my therapist confidential?

The content of communications with your therapist is confidential regardless of the medium, but the security of different communication channels varies significantly. Standard email and text messaging are not encrypted in a way that meets HIPAA standards, which means that even though the content is legally protected, it could potentially be intercepted or accessed by third parties (email providers, phone companies, or anyone with access to your devices). Most therapists advise limiting electronic communication to scheduling and logistical matters, and using a HIPAA-compliant patient portal or encrypted messaging platform for anything clinical. You should discuss your therapist's communication policies and the associated privacy risks during the informed consent process.

Related Articles

Sources & References

  1. U.S. Department of Health and Human Services. HIPAA Privacy Rule (45 CFR Parts 160, 164). (federal_regulation)
  2. Tarasoff v. Regents of the University of California, 17 Cal. 3d 425 (1976). (case_law)
  3. Jaffee v. Redmond, 518 U.S. 1 (1996). (case_law)
  4. 42 CFR Part 2 — Confidentiality of Substance Use Disorder Patient Records. (federal_regulation)
  5. American Psychological Association. (2017). Ethical Principles of Psychologists and Code of Conduct. (ethics_code)
  6. National Association of Social Workers. (2021). Code of Ethics. (ethics_code)
  7. Knapp, S., & VandeCreek, L. (2012). Practical Ethics for Psychologists: A Positive Approach. (academic_text)

Have questions about this topic?

Ask Kira for sourced, clinical answers grounded in our article library.

Ask Kira