Get in touch

Is your therapy schedule protected health information?

Usually, yes. Here is why a schedule counts as PHI under HIPAA, where schedules tend to leak, and what to ask any vendor that will hold yours.

Yes. In most cases a CHIS therapy schedule is protected health information. A line that says which child gets services, on what day, and at which address tells anyone reading it that this child is receiving health care. Under HIPAA, that is exactly what PHI is. So the calendar on your office wall, the week you text to technicians, and the spreadsheet your scheduler keeps all need the same care as a client file.

This guide explains why, what the "minimum necessary" idea means for a schedule, where schedules tend to leak, when a software vendor needs a Business Associate Agreement, and some habits that lower the risk. It is educational, not legal advice; talk to your compliance lead or a health care attorney about your own agency.

Why a schedule counts as PHI

The HIPAA Privacy Rule protects "individually identifiable health information" held or sent by a covered entity or its business associate, "in any form or media, whether electronic, paper, or oral." HHS defines that as information, including demographic data, that relates to a person's health, "the provision of health care to the individual," or payment for that care, and that identifies the person or could reasonably be used to identify them.

A schedule entry is about the provision of health care. It records that a service happens, for whom, when and where. Add a name and it identifies the child. That is why HHS lists names, street addresses, dates tied to a person, and phone numbers among the identifiers that must come off before health information counts as de-identified.

Take a typical line from the week at Sagebrush Behavioral Services, our fictional agency:

What is on the lineWhy it matters
The child's full nameIdentifies the child directly
Tuesday, 3:30 to 5:30A date of service tied to that child
A home street addressA location smaller than a state, and often identifying on its own
"CHIS, habilitative intervention"Shows the child receives a health service
Technician: MariaStaff names are not the child's PHI, but they link the child to a care team

Even without a diagnosis on it, that row tells a reader a named child receives therapy at a known address on a known day. Paper, a whiteboard or a voice message does not change that. The rule covers oral and paper information too.

Does this apply to your agency? HIPAA applies to "covered entities." HHS says every health care provider, regardless of size, that electronically sends health information in connection with certain transactions, such as claims or eligibility checks, is covered. That holds whether you send them yourself or through a billing service. If your agency bills Idaho Medicaid electronically, assume it applies to you.

The minimum-necessary idea

HHS calls "minimum necessary" a central part of the Privacy Rule. A covered entity "must make reasonable efforts to use, disclose, and request only the minimum amount of protected health information needed to accomplish the intended purpose." Your policies should say which people or roles need access to what, and on what terms.

There is an important exception: the standard does not apply to disclosures to, or requests by, a health care provider for treatment. A technician delivering a session needs to know who, where and when, and your clinical team needs clinical detail. Minimum necessary is not about starving your own staff of what they need to do the work.

For a schedule, it usually means asking a simple question about each view of it: what does this person need to see to do their job?

  • A technician needs their own sessions, with the address and time. They usually do not need every other child on the roster.
  • A front-desk person confirming a time may need a name and a slot, not treatment notes.
  • A parent needs their own child's week, and nobody else's.
  • Nobody needs a diagnosis in a calendar title to show up on time.

The HIPAA Security Rule points the same way. HHS summarizes it as requiring policies for "authorizing access to ePHI only when such access is appropriate for the user or recipient's role," and procedures so that workforce members who work with ePHI have appropriate authorization and access.

Where schedules tend to leak

Most agencies do not lose schedule information through a dramatic hack. It drifts out through everyday tools that were never set up for health information. HIPAA does not ban any one of these tools outright. The trouble is how they are usually used.

Group texts

A group text with the whole team is quick, which is why it is everywhere. It also sends every child's name and address to every phone in the thread, including staff who do not serve that child. Texts sit on personal phones, often without a passcode, and get backed up to personal cloud accounts. When someone leaves the agency, the thread leaves with them. There is usually no way to take a message back.

Personal calendars

A technician who copies sessions into a personal calendar has moved PHI into an account the agency does not control. Those calendars sync to other devices, show reminders on lock screens, and are sometimes shared with a partner or family member. A title like "J.M. home session" on a lock screen is far less revealing than a child's full name and diagnosis.

Shared spreadsheets

A spreadsheet in a consumer file-sharing account is easy to forward, download and copy. Link-sharing settings are easy to get wrong, one tab often holds the whole roster, and old copies pile up in inboxes and download folders. It is also hard to tell who opened it and when.

The common thread: each tool spreads the full schedule wider than any one person needs, onto devices and accounts the agency cannot manage, and usually with a company that has not signed a Business Associate Agreement with you.

What a Business Associate Agreement is

HHS describes a business associate as a person or organization, other than your own workforce, that creates, receives, maintains or transmits PHI to carry out certain functions or services for a covered entity. Among HHS's examples: a cloud service provider that stores or processes electronic PHI, an IT vendor whose support work involves ePHI, and an app developer that handles patients' PHI for services like patient messaging on a covered entity's behalf.

Before a business associate handles your PHI, HIPAA requires a written Business Associate Agreement (BAA). HHS says the BAA must describe the business associate's permitted and required uses and disclosures of PHI, and must provide that it will not use or disclose PHI beyond what the agreement allows or the law requires. The Security Rule adds that business associates, and their subcontractors, must comply with applicable Security Rule requirements.

When a scheduling or messaging vendor needs one

If a scheduling or messaging service stores your schedule, client names or messages about clients on its servers, it is maintaining PHI for you. That generally makes it a business associate. HHS is direct about this for cloud services: a provider that stores electronic PHI is a business associate "even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data."

Vendors sometimes point to the "conduit" exception. HHS limits it to services that only transmit PHI, like the postal service or its electronic equivalents, with at most temporary storage incident to that transmission. A service that keeps your schedule or message history is not a conduit.

No BAA is needed to share PHI with another health care provider for the child's treatment, such as coordinating care. That exception is for providers treating the child, not for software companies.

Everyday habits that lower the risk

None of these replaces your agency's written policies or a risk analysis, which the Security Rule also expects. They are small habits that reduce what gets exposed when something goes wrong.

  • Use initials where full names are not needed. On a wall calendar, in a shared view or in a quick message, "J.M., Tuesday 3:30" is enough for the people who already know the family.
  • Keep diagnoses and clinical notes out of calendar titles. A calendar is for when and where. Clinical detail belongs in the clinical record.
  • Send each person only their own sessions. A technician's week, not the whole roster.
  • Lock every device that shows the schedule. A passcode or biometric lock on phones, tablets and laptops, and a short auto-lock time. HHS's summary of the Security Rule calls for policies on proper use of, and physical safeguards for, workstations that can access ePHI.
  • Turn off lock-screen previews for any app that shows client information.
  • Remove access the day someone leaves. Take them out of group threads, shared folders and every app account. Write down who does this and check it off.
  • Keep work information in agency accounts. Not personal email, personal calendars or personal cloud storage.
  • Train new staff on these habits. HHS says covered entities must train all workforce members on their privacy policies and procedures.
  • Shred printed schedules instead of tossing them. HHS gives shredding as an example of a reasonable safeguard.

Questions to ask any scheduling or messaging vendor

When you look at software that will hold your schedule or client messages, ask these questions and get the answers in writing:

  1. Will you sign a Business Associate Agreement with us? If they will, ask to read it before you sign up. If they will not, the tool should not hold PHI.
  2. Which subcontractors handle our data, and do you have BAAs with them? HHS says a business associate must have a BAA with its subcontractors before disclosing PHI to them.
  3. Can we limit what each role sees? Can technicians see only their own sessions, and parents only their own child?
  4. Is our data kept separate from other agencies' data?
  5. What goes into emails, texts or notifications you send? Do they include client names or details that could show on a lock screen?
  6. How do we remove a departing staff member's access, and how fast does it take effect?
  7. Can we see who viewed or changed a schedule?
  8. What happens to our data if we leave? Can we export it, and will you delete it?
  9. How will you tell us about a breach? HHS notes that business associates must notify the covered entity of breaches of unsecured PHI.

Our guide to choosing CHIS scheduling software in Idaho covers the other questions worth asking.

Where Pairing fits

Pairing is scheduling software for Idaho CHIS providers, and it is still in development. We are building it with these risks in mind: anything it sends outside the app, such as an email, is built to leave client details out; each agency's data is kept separate from every other agency's; and what each person can see depends on their role, so a parent sees only their own child's week. Team messages with read receipts live inside the app, on the web and on an iPhone app that is currently in testing. We are talking with Idaho providers now, and you can get in touch if you would like to be part of that.

How this page was made

We based the regulatory statements on HHS's own HIPAA guidance pages, listed in the sources below, and checked them in September 2026. This page is general education about HIPAA, not legal advice. Drafted with AI assistance and reviewed by the Pairing team.

Other questions

Is a schedule still PHI if it has no diagnosis on it?

Usually, yes. HHS defines protected health information to include information about the provision of health care to an identifiable person. A child's name with a therapy session date and address shows that the child receives care, even without a diagnosis.

Can our technicians text each other about sessions?

HIPAA does not ban texting outright, but group texts tend to spread every child's details to every phone in the thread, sit on personal devices, and stay with staff after they leave. If you text, keep it to initials and times, send each person only their own sessions, and make sure phones are locked.

Does a scheduling app need to sign a Business Associate Agreement?

If it stores your schedule, client names or messages about clients, it generally does. HHS says a cloud service that stores electronic PHI for a covered entity is a business associate, even if the data is encrypted and the service has no key.

Does minimum necessary mean technicians cannot see client details?

No. HHS says the minimum necessary standard does not apply to disclosures to a health care provider for treatment. It is about not spreading information wider than each role needs, such as showing a technician their own sessions rather than the whole roster.

Is this legal advice?

No. This guide is general education about HIPAA. Talk to your compliance lead or a health care attorney about your own agency's situation.

Sources

  1. HHS: Summary of the HIPAA Privacy Rule · checked September 26, 2026
  2. HHS: Minimum Necessary Requirement · checked September 26, 2026
  3. HHS: Business Associates · checked September 26, 2026
  4. HHS: Guidance on HIPAA & Cloud Computing · checked September 26, 2026
  5. HHS: Summary of the HIPAA Security Rule · checked September 26, 2026
  6. HHS: Guidance Regarding Methods for De-identification of PHI · checked September 26, 2026

Keep going