Get in touch

Is your therapy schedule protected health information?

Usually, yes. This guide explains why a schedule counts as PHI under HIPAA, where schedules tend to leak, and what to ask any vendor that will hold yours.

Yes. In most cases a CHIS therapy schedule is protected health information. A line that says which child gets services, on what day, and at which address tells anyone reading it that this child is receiving health care. Under HIPAA, that is what PHI is. So the paper calendar on your office wall, the week you text to your BIs (behavior interventionists), and the spreadsheet your scheduler keeps all need the same care as a client file.

This guide is general education, not legal advice. Talk to your compliance lead or a health care attorney about your own agency.

Why a schedule counts as PHI

The HIPAA Privacy Rule protects "individually identifiable health information" held or sent by a covered entity or its business associate, "in any form or media, whether electronic, paper, or oral." HHS defines that as information, including demographic data, that relates to a person's health, "the provision of health care to the individual," or payment for that care, and that identifies the person or could reasonably be used to identify them.

A schedule entry is about the provision of health care. It records that a service happens, for whom, when and where. Add a name and it identifies the child. That is why HHS lists names, street addresses, dates tied to a person, and phone numbers among the identifiers that must come off before health information counts as de-identified.

Take a typical line from the week at Sagebrush Behavioral Services, our fictional agency:

What is on the lineWhy it matters
The child's full nameIdentifies the child directly
Tuesday, 3:30 to 5:30A date of service tied to that child
A home street addressA location smaller than a state, and often identifying on its own
"CHIS, habilitative intervention"Shows the child receives a health service
BI: DanaStaff names are not the child's PHI, but they link the child to a care team

Even without a diagnosis on it, that row tells a reader a named child receives therapy at a known address on a known day. A paper calendar or a voice message carries the same information. The rule covers oral and paper information too.

Does this apply to your agency? HIPAA applies to "covered entities." HHS says every health care provider, regardless of size, that electronically sends health information in connection with certain transactions, such as claims or eligibility checks, is covered. That holds whether you send them yourself or through a service that sends them for you. If your agency bills Idaho Medicaid electronically, assume it applies to you.

The minimum-necessary idea

HHS calls "minimum necessary" a central part of the Privacy Rule. A covered entity "must make reasonable efforts to use, disclose, and request only the minimum amount of protected health information needed to accomplish the intended purpose." Your policies should say which people or roles need access to what, and on what terms.

There is an important exception: the standard does not apply to disclosures to, or requests by, a health care provider for treatment. A BI delivering a session needs to know who, where and when, and your clinical team needs clinical detail. Minimum necessary leaves room for your own staff to have what the work needs.

For a schedule, it means asking one question about each view of it: what does this person need to see to do their job?

  • A BI needs their own sessions, with the address and time. They usually do not need every other child on the roster.
  • A front-desk person confirming a time may need a name and a slot, and no treatment notes.
  • A parent needs their own child's week, and nobody else's.
  • Nobody needs a diagnosis in a calendar title to show up on time.

The HIPAA Security Rule points the same way. HHS summarizes it as requiring policies for "authorizing access to ePHI only when such access is appropriate for the user or recipient's role," and procedures so that workforce members who work with ePHI have appropriate authorization and access.

Where schedules tend to leak

Most agencies do not lose schedule information through a dramatic hack. It drifts out through everyday tools that were never set up for health information. HIPAA does not ban any one of these tools outright. The trouble is how teams tend to use them.

Group texts

A group text with the whole team is quick, which is why it is everywhere. It also sends every child's name and address to every phone in the thread, including BIs who do not serve that child. Texts sit on personal phones, often without a passcode, and get backed up to personal cloud accounts. When someone leaves the agency, the thread leaves with them. You usually can't take a message back.

Personal calendars

A BI who copies sessions into a personal calendar has moved PHI into an account the agency does not control. Those calendars sync to other devices, show reminders on lock screens, and are sometimes shared with a partner or family member. A title like "J.M. home session" on a lock screen reveals far less than a child's full name and diagnosis.

Shared spreadsheets

A spreadsheet in a consumer file-sharing account is easy to forward, download and copy. Link-sharing settings are easy to get wrong, one tab often holds the whole roster, and old copies pile up in inboxes and download folders. It is also hard to tell who opened it and when.

The common thread: each tool spreads the full schedule wider than any one person needs, onto devices and accounts the agency cannot manage, and usually with a company that has not signed a Business Associate Agreement with you.

What a Business Associate Agreement is

HHS describes a business associate as a person or organization, other than your own workforce, that creates, receives, maintains or transmits PHI to carry out certain functions or services for a covered entity. Among HHS's examples: a cloud service provider that stores or processes electronic PHI, an IT vendor whose support work involves ePHI, and an app developer that handles patients' PHI for services like patient messaging on a covered entity's behalf.

Before a business associate handles your PHI, HIPAA requires a written Business Associate Agreement (BAA). HHS says the BAA must describe the business associate's permitted and required uses and disclosures of PHI, and must provide that it will not use or disclose PHI beyond what the agreement allows or the law requires. The Security Rule adds that business associates, and their subcontractors, must comply with applicable Security Rule requirements.

When a scheduling or messaging vendor needs one

If a scheduling or messaging service stores your schedule, client names or messages about clients on its servers, it is maintaining PHI for you. That generally makes it a business associate. HHS is direct about this for cloud services: a provider that stores electronic PHI is a business associate "even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data."

Vendors sometimes point to the "conduit" exception. HHS limits it to services that only transmit PHI, like the postal service or its electronic equivalents, with at most temporary storage incident to that transmission. A service that keeps your schedule or message history is not a conduit.

No BAA is needed to share PHI with another health care provider for the child's treatment, such as coordinating care. That exception covers providers treating the child. It doesn't cover software companies.

Everyday habits that lower the risk

None of these replaces your agency's written policies or a risk analysis, which the Security Rule also expects. They are small habits that reduce what gets exposed when something goes wrong.

  • Use initials where full names are not needed. On a wall calendar, in a shared view or in a quick message, "J.M., Tuesday 3:30" is enough for the people who already know the family.
  • Keep diagnoses and clinical notes out of calendar titles. A calendar is for when and where. Clinical detail belongs in the clinical record.
  • Send each person only their own sessions. A BI gets their own week, and the roster stays with the scheduler.
  • Lock every device that shows the schedule. A passcode or biometric lock on phones, tablets and laptops, and a short auto-lock time. HHS's summary of the Security Rule calls for policies on proper use of, and physical safeguards for, workstations that can access ePHI.
  • Turn off lock-screen previews for any app that shows client information.
  • Remove access the day someone leaves. Take them out of group threads, shared folders and every app account. Write down who does this and check it off.
  • Keep work information in agency accounts. Keep it out of personal email, personal calendars and personal cloud storage.
  • Train new staff on these habits. HHS says covered entities must train all workforce members on their privacy policies and procedures.
  • Shred printed schedules instead of tossing them. HHS gives shredding as an example of a reasonable safeguard.

Questions to ask any scheduling or messaging vendor

When you look at software that will hold your schedule or client messages, ask these questions and get the answers in writing:

  1. Will you sign a Business Associate Agreement with us? If they will, ask to read it before you sign up. If they won't, the tool should not hold PHI.
  2. Which subcontractors handle our data, and do you have BAAs with them? HHS says a business associate must have a BAA with its subcontractors before disclosing PHI to them.
  3. Can we limit what each role sees? Can BIs see only their own sessions, and parents only their own child?
  4. Is our data kept separate from other agencies' data?
  5. What goes into emails, texts or notifications you send? Could a child's name or other client information show up on a lock screen?
  6. How do we remove a departing staff member's access, and how fast does it take effect?
  7. Can we see who viewed or changed a schedule?
  8. What happens to our data if we leave? Can we export it, and will you delete it?
  9. How will you tell us about a breach? HHS notes that business associates must notify the covered entity of breaches of unsecured PHI.

Our guide on what to look for in Idaho CHIS scheduling software covers the other questions worth asking.

Where Pairing fits

Pairing is a scheduling and team-messaging app for Idaho CHIS DDAs, and it treats the whole schedule as protected information. What each person sees depends on their role: a BI sees their own sessions, and a parent sees only their own child's week. Notifications stay inside the app and only say that something needs attention; the details appear after you sign in. Team boards, group threads and direct messages, with read receipts, live inside Pairing on the web and on the iPhone app, which is in testing. Our FAQ sets out how Pairing protects client information, including what is in place today and what comes before any agency goes live.

How this page was made

We based the regulatory statements on HHS's own HIPAA guidance pages, listed in the sources below, and checked them in September 2026. This page is general education about HIPAA, not legal advice. Drafted with AI assistance and reviewed by the Pairing team.

Other questions

Is a schedule still PHI if it has no diagnosis on it?

Usually, yes. HHS defines protected health information to include information about the provision of health care to an identifiable person. A child's name with a session date and address shows that the child receives care, even without a diagnosis.

Can our BIs text each other about sessions?

HIPAA does not ban texting outright, but group texts tend to spread every child's details to every phone in the thread, sit on personal devices, and stay with staff after they leave. If you text, keep it to initials and times, send each person only their own sessions, and make sure phones are locked.

Does a scheduling app need to sign a Business Associate Agreement?

If it stores your schedule, client names or messages about clients, it generally does. HHS says a cloud service that stores electronic PHI for a covered entity is a business associate, even if the data is encrypted and the service has no key.

Does minimum necessary mean BIs cannot see client details?

No. HHS says the minimum necessary standard does not apply to disclosures to a health care provider for treatment. It is about not spreading information wider than each role needs, such as showing a BI their own sessions rather than the whole roster.

Is this legal advice?

No. This guide is general education about HIPAA. Talk to your compliance lead or a health care attorney about your own agency's situation.

Sources

  1. HHS: Summary of the HIPAA Privacy Rule · checked September 26, 2026
  2. HHS: Minimum Necessary Requirement · checked September 26, 2026
  3. HHS: Business Associates · checked September 26, 2026
  4. HHS: Guidance on HIPAA & Cloud Computing · checked September 26, 2026
  5. HHS: Summary of the HIPAA Security Rule · checked September 26, 2026
  6. HHS: Guidance Regarding Methods for De-identification of PHI · checked September 26, 2026

Keep going