Module 4
Confidentiality
a. Introduction
Perhaps the central right of the client is knowing that disclosures in therapy
sessions will be protected. However, you cannot promise your clients that everything they
talk about will always remain confidential. In this we consider the ethical and legal
ramifications of confidentiality and explore the process, importance, and impact of
informing your clients from the outset of therapy of those circumstances that limit
confidentiality.
The more you consider the legal ramifications of confidentiality, the clearer it
becomes that most situations cannot be neatly defined. Even if therapists have become
familiar with local and state laws that govern their profession, this legal knowledge alone
is not enough to enable them to make sound decisions. Each case is unique. There are
many subtle points in the law and at various times conflicting ways to interpret the law.
Professional judgment is indeed a cornerstone of resolving cases in various fields,
encompassing both ethical and legal dimensions. This nuanced decision-making process
requires practitioners to draw upon their expertise, experience, and ethical principles to
navigate complex situations and arrive at fair and just outcomes.
From an ethical standpoint, professional judgment involves assessing the moral
dimensions of a situation and determining the course of action that is most consistent
with ethical principles and values. Ethical decision-making often involves balancing
competing interests, values, and obligations, as well as considering the potential
consequences of different courses of action on all stakeholders involved. Professionals
must weigh factors such as beneficence, nonmaleficence, autonomy, justice, and fidelity
in determining the most ethical response to a given situation.
For example, consider a case where a therapist is faced with a client who is
considering self-harm. In exercising professional judgment, the therapist must consider
the ethical imperative to protect the client's safety while also respecting their autonomy
and confidentiality. This may involve engaging in a careful assessment of risk,
collaborating with the client to develop a safety plan, and, if necessary, breaching
confidentiality to ensure the client's well-being.
From a legal perspective, professional judgment involves interpreting and
applying relevant laws, regulations, and professional standards to the specific facts of a
case. Legal decision-making often requires a thorough understanding of legal precedents,
statutes, case law, and professional codes of conduct, as well as the ability to apply this
knowledge to real-world scenarios. Professionals must ensure that their actions are in
compliance with legal requirements and that they uphold their duty of care to clients and
other stakeholders.
For example, in a legal case involving allegations of professional misconduct, a
counselor's professional judgment may be crucial in determining whether their actions
complied with ethical standards and legal obligations. This may involve reviewing
relevant laws and regulations, consulting with legal experts or professional associations,
and providing evidence to support their decision-making process.
In resolving cases, professionals must also consider practical considerations such
as resource availability, time constraints, and organizational policies and procedures.
Balancing these practical considerations with ethical and legal considerations requires a
high degree of discernment and discretion.
Furthermore, professional judgment is not a static process but evolves over time
through experience, reflection, and ongoing professional development. Professionals
must continuously hone their judgment skills, stay informed about changes in laws and
regulations, and seek guidance and support from colleagues, supervisors, and
professional associations when faced with challenging cases.
In conclusion, professional judgment plays a significant role in resolving cases
from both ethical and legal perspectives. By drawing upon their expertise, experience,
and ethical principles, professionals can navigate complex situations, uphold their duty of
care to clients, and contribute to the integrity and credibility of their profession. Through
ongoing reflection and learning, professionals can continually refine their judgment skills
and enhance their ability to make sound and ethical decisions in their practice.
b. Confidentiality, Privileged Communication, and Privacy
Confidentiality is a complex responsibility, with both legal and ethical
implications. See the Ethics Codes box titled “Confidentiality in Clinical Practice” for
some specific guidelines on the obligations mental health practitioners have to maintain
the confidentiality of their relationships with clients. Therapists must become familiar
with concepts of confidentiality, privileged communication, and privacy, as well as the
legal protection afforded to the privileged communications of clients and the limits of this
protection.
Confidentiality, privileged communication, and privacy are related concepts, but
there are important distinctions among them. Confidentiality, which is rooted in a client’s
right to privacy, is at the core of effective therapy; it “is the counselor’s ethical duty to
protect private client communication” (Wheeler & Bertram, 2015, p. 104). Mental health
professionals have an ethical responsibility, as well as a legal and professional duty, to
safeguard clients from unauthorized disclosures of information given in the therapeutic
relationship. Professionals must not disclose this information except when authorized by
law or by the client to do so. Hence, there are limitations to the promise of
confidentiality. Court decisions have underscored that there are circumstances in which a
therapist has a duty to warn and to protect the client or others, even if it means breaking
confidentiality. Also, because confidentiality is a client’s right, psychotherapists may
legally and ethically reveal a client’s confidences if a client waives this right.
Confidentiality belongs to the client, and counselors generally do not find it problematic
to release information when the client requests that they do so.
Preparation. To inform your clients about the limits of confidentiality, you must
understand the limits yourself. This involves doing your legal homework and engaging in
personal soul searching regarding your own moral principles. Clarify your ethical
position about confidentiality and its limits, and devise an informed consent document
that reflects your policies and intentions. Discuss confidentiality and its limits with your
clients in clear language, and document this discussion. Provide clients with an
opportunity to address any questions they have about confidentiality at the outset of
therapy, and continue to share the limits of confidentiality when necessary. Just as
informed consent is an ongoing process, clients must also understand the limits of
confidentiality throughout the counseling relationship.
Tell clients the truth. Inform your clients about the limits you intend to impose on
confidentiality, and obtain your client’s consent to accept these limits as a condition of
entering into a professional relationship with you. Explain any roles that might affect
confidentiality. Obtain “truly informed consent” before disclosing voluntarily. Make
disclosures only if legally unavoidable. Obtain and document your client’s signed consent
before disclosing this information. Respond ethically to legal demands for information.
Notify your client of a pending legal demand for disclosure without his or her consent.
Limit disclosure of confidential information to the extent that is legally possible.
Avoid preventable breaches of confidentiality. Avoid making unethical
exceptions to the confidentiality rule; establish and maintain policies aimed at protecting
confidentiality; monitor your note taking and record keeping practices; avoid dual roles
that create conflicts of interest in the courtroom; anticipate legal demands and your
response to such requirements; empower clients to act protectively on their own behalf;
and do not confuse laws that permit disclosure with laws that require disclosure. Talk
about confidentiality. Model ethical behavior and practice; invite a dialogue with clients
about confidentiality as needed; teach ethical practices to students and supervisees; and
educate attorneys, judges, and consumers.
Privileged communication is a legal concept that generally bars the disclosure of
confidential communications made to a psychotherapist from any judicial proceedings or
court of law (Knapp & VandeCreek, 2012). All states have enacted into law some form
of psychotherapist–client privilege, but the specifics of this privilege vary from state to
state. Clinicians need to understand the privilege laws in the states in which they practice.
Some privileged communication statutes protect client–counselor relationships to the
fullest extent that the law allows; statutes in other jurisdictions are quite weak (Remley &
Herlihy, 2016). When a client– therapist relationship is covered as privileged
communication by statute, clinicians may not disclose confidential information.
Therapists can refuse to answer questions in court or refuse to produce a client’s records
in court. These laws ensure that personal and sensitive client information will be
protected from exposure by therapists in legal proceedings.
Again, this privilege belongs to the client and is designed for the client’s
protection rather than for the protection of the counseling professional. If a client
knowingly and rationally waives this privilege, the professional has no legal grounds for
withholding the information. Professionals are obligated to disclose information that is
necessary and sufficient when the client requests it, but only the information that is
specifically requested and only to the individuals or agencies that are specified by the
client. In some circumstances, the therapist can make a clinical decision to withhold all or
some information if the client waves his or her privilege. For example, if the therapist
believes the client is not mentally competent to make such a decision, the therapist may
not abide by the client’s request to waive privilege.
The legal concept of privileged communication generally does not apply to group
counseling, couples counseling, family therapy, or child and adolescent therapy.
However, the therapist is still bound by confidentiality with respect to circumstances not
involving a court proceeding. Statements made in the presence of a third party may not be
protected in a court proceeding. Members of a counseling group can assume that they
could be asked to testify in court concerning certain information revealed in the course of
a group session, unless there is a statutory exception. In states where no law exists to
cover confidentiality in group therapy, courts may use the ethics codes of the professions
regarding confidentiality. If a situation arises, therapists may need to demonstrate the
means they used to create safety for the group members. A written group contract
defining members’ responsibility for maintaining confidentiality of whatever takes place
in a group can be used for this purpose.
Similarly, couples therapy and family therapy are not subject to privileged
communication statutes in many states. In the case of child and adolescent clients, there
are restrictions on the confidential character of disclosures in the counseling relationship.
No clear judicial trend has emerged for communications that are made in the presence of
third persons. Clients have a right to be informed about any limitations on confidentiality
in group work, child and adolescent therapy, and couples and family therapy. Ambiguity
may exist regarding who the client is and the specific nature of the therapy goals when
counseling couples or families. When more than one client is in the consulting room at a
time, the confidentiality mandate can become complex. Confidentiality and its exceptions
must be addressed at the outset of treatment and at any time during treatment when
confidentiality issues become salient. Furthermore, therapists working with couples or
families should clearly communicate their policy about keeping, or not keeping, secrets
disclosed by one of the partners or family members in advance of starting counseling
(Barnett & Johnson, 2015). Some therapists may choose to provide their clients with this
policy in writing to be sure that clients are fully informed.
The basic principles of privileged communication have been reaffirmed by case
law. On June 13, 1996, the United States Supreme Court ruled that communications
between licensed psychotherapists and their clients in the course of diagnosis or treatment
are privileged and therefore protected from forced disclosure in cases arising under
federal law. The Supreme Court ruling in Jaffee v. Redmond (1996), written by Justice
John Paul Stevens, states that “effective psychotherapy depends upon an atmosphere of
confidence and trust in which the patient is willing to make frank and complete disclosure
of facts, emotions, memories, and fears.” The 7–2 decision in this case represented a
victory for mental health organizations because it extended the confidentiality privilege.
In the Jaffee case, an on-duty police officer, Mary Lu Redmond, shot and killed a
suspect while attempting an arrest. The victim’s family sued in federal court, alleging that
the victim’s constitutional rights had been violated. The court ordered Karen Beyer, a
licensed clinical social worker, to turn over notes she made during counseling sessions
with Redmond after the shooting. The social worker refused, asserting that the contents
of her conversations with the police officer were protected against involuntary disclosure
by psychotherapist–client privilege. The court rejected her claim of psychotherapist–
client privilege, and the jury awarded the family $545,000.
The Court of Appeals for the Seventh Circuit reversed this decision and
concluded that the trial court had erred by refusing to afford protection to the confidential
communications between Redmond and Beyer. Jaffee, an administrator of the victim’s
estate, appealed this decision to the Supreme Court. The Supreme Court upheld the
appellate court’s decision, clarifying for all federal court cases, both civil and criminal,
the existence of the privilege. The Court recognized a broadly defined psychotherapist–
client privilege and further clarified that this privilege is not subject to the decision of a
judge on a case-bycase basis. The Court’s decision to extend federal privilege (which
already applied to psychologists and psychiatrists) to licensed social workers leaves the
door open for inclusion of other licensed psychotherapists, such as licensed marriage and
family therapists, licensed professional counselors, and mental health counselors.
Privacy, as a matter of law, refers to the constitutional right of individuals to be
left alone and to control their personal information (Wheeler & Bertram, 2015). Privacy
is the right to be protected from visibility, access, or intrusion by others (Fisher, 2016).
Practitioners should exercise caution with regard to the privacy of their clients. It is easy
to invade a client’s privacy unintentionally. Examples of some of the most pressing
situations in which privacy is an issue include an employer’s access to an applicant’s or
an employee’s psychological tests, parents’ access to their child’s school and health
records, and a third-party payer’s access to information about a client’s diagnosis and
prognosis. If counselors have occasion to meet clients outside of the professional setting,
it is essential that they do not violate their privacy. This is especially true in small towns,
where such meetings can be expected. In the course of treatment, you may realize that
you and the client belong to the same house of worship, that your children attend the
same school, or that your children play on the same soccer team. It is a good practice to
let your client know that encounters may occur and to talk with your client about how
you might interact when you meet. Consider what you might do in the following case.
Practitioners who also teach courses, offer workshops, write books and journal
articles, and give lectures must ensure that client privacy is protected. It is of the utmost
importance that practitioners take measures to adequately disguise their clients’ identities
when using examples from clinical practice, and it is prudent not to use current clients as
examples. Sperry and Pies (2010) discuss the ethical considerations in writing about
clients. They identify three options for presenting case material: (1) seek the client’s
permission to publish, which some consider ethically questionable because it entails
inserting the clinician’s professional agenda into the client’s treatment; (2) disguise case
material for publication, which may or may not release the therapist from needing to
secure the client’s permission; or (3) develop composite case material from two or more
clients. Most of the case examples and commentaries we include in this book are fictional
cases we have created. In the few actual clinical examples, we have taken care to disguise
any identifying details. Students should be advised to adequately disguise identities of
their clients in any reports they give in class. Of course, students’ personal comments in
class are also to be kept confidential.
Managing confidentiality is a challenge most school counselors face. School
counselors need to balance their ethical and legal responsibilities with three groups: the
students they serve, the parents or guardians of those students, and the school system.
When minors are unable to give informed consent, parents or guardians provide this
informed consent, and they may need to be included in the counseling process.
Counselors have an ethical obligation to safeguard the confidentiality of minors to the
extent that it is possible, but in most states their discussions with students are not
privileged communication (Stone & Dahir, 2016). School counselors are ethically obliged
to respect the privacy of minor clients and maintain confidentiality, yet this obligation
may be in conflict with laws regarding parental rights to be informed about the progress
of treatment and to decide what is in the best interests of their children. The ASCA
(2016) ethics code states that school counselors “recognize their primary ethical
obligation for confidentiality is to the student but balance that obligation with an
understanding of the parents’/guardians’ legal and inherent rights to be the guiding voice
in their children’s lives”
School counselors have an ethical responsibility to ask for client permission to
release information, and they should clearly inform students of the limitations of
confidentiality and how and when confidential information may be shared. The ASCA
(2016) guideline regarding parents is that the school counselor “informs
parents/guardians of the counselor’s role to include the confidential nature of the school
counseling relationship between the school counselor and student” (B.1.f.). Although
school counselors may be required to provide certain information to parents and school
personnel, they need to do so in a manner that will minimize intrusion of the child’s or
adolescent’s privacy and in a way that demonstrates respect for the counselee.
To the degree possible, school counselors aim to establish collaborative
relationships with parents and school personnel. Laws regarding confidentiality in school
counseling differ. In some states, therapists in private practice are required to demonstrate
that attempts have been made to contact the parents of children who are younger than 16,
whereas school counselors are not required to do so. Schools that receive federal funding
are generally bound by the provisions of the Family Educational Rights and Privacy Act
of 1994 (FERPA). It is necessary that school counselors exercise discretion in the kind
and extent of information they reveal to parents or guardians about their children.
School personnel and administrators may operate under different guidelines
regarding confidentiality, and they may not understand the mental health professions’
requirements. When a school counselor withholds information from school personnel and
administrators about students in counseling, especially with regard to risk-taking
behaviors, the counselor “may be seen as something other than a team player (i.e., school
administrators may view school counselors’ protecting the confidentiality of students as
insubordination)”. This is a complex area that requires careful thought and consideration,
as the following case examples illustrate.
Clients in counseling are involved in a deeply personal relationship and have a
right to expect that what they discuss will be kept private. The compelling justification
for confidentiality is that it is necessary in order to encourage clients to develop the trust
needed for full disclosure and for the other work involved in therapy. For example, the
school counselor has the task of providing a safe and trusting environment for counseling
relationships to take root. If students do not believe their communications with a
counselor will be kept confidential, they may not participate in counseling services
(Stone & Dahir, 2016). Clients must feel free to explore all aspects of their lives without
fear that these disclosures will be released outside the therapy room. Counselors are
ethically obligated to help clients appreciate the meaning of confidentiality by presenting
it in language the client can understand and that respects the cultural experiences of the
client (Barnett & Johnson, 2015). The meaning of confidentiality may be interpreted in
different ways depending on the client’s culture. By encouraging an ongoing dialogue
about how, when, and with whom information will be shared, counselors establish a
collaborative spirit in their relationships with clients.
When it does become necessary to break confidentiality, it is good practice to
inform the client of the intention to take this action and also to invite the client to
participate in the process. For example, all states now have statutes that require
professionals who suspect any form of child abuse to report it to the appropriate agencies,
even when the knowledge was gained through confidential communication with clients.
A professional who reports suspected child abuse, in good faith, is immune from civil
liability and criminal prosecution as a mandated reporter.
The limitations of confidentiality may be greater in some settings and agencies
than in others. In addition, exceptions to confidentiality vary by jurisdiction, and
counselors are required to know the laws that govern their area of practice. If clients are
informed about the conditions under which confidentiality may be compromised, they are
in a better position to decide whether or not to enter counseling. If clients are involved in
involuntary counseling, they can decide what they will disclose in their sessions. It is
generally accepted that clients have a right to understand in advance the circumstances
under which therapists are required or allowed to communicate information about them to
third parties. Unless clients understand the exceptions to confidentiality, their consent to
treatment is questionable. In an addiction treatment center, the policy may be “what is
said to one staff member is said to all.”
One reason for this practice may be to avoid triangulation of the staff, which
would be detrimental to patients. This frees the entire treatment staff to share information
about patients as a part of the treatment process, and it eliminates concerns about
breaching confidentiality. When a crisis occurs and the therapist is not available, other
staff members can step in to handle the situation. Of course, the patients should be made
aware of this policy. When patients suffer a relapse during addiction treatment and public
safety is jeopardized, counselors have a duty to report.
The duty to disclose a counselor's awareness of a client's intoxication on the job,
particularly in professions where public safety is at risk, is a complex ethical issue that
requires careful consideration of multiple factors. While there may be instances where
disclosure is warranted to protect the safety and well-being of others, counselors must
also balance their ethical obligations to maintain confidentiality, respect client autonomy,
and uphold the therapeutic relationship.
In professions such as airline piloting or bus driving, where public safety is
paramount, the consequences of a pilot or driver being intoxicated on the job can be
catastrophic. In such cases, the duty to warn or protect may supersede the duty of
confidentiality, as counselors have a responsibility to take reasonable steps to prevent
foreseeable harm to others.
However, the decision to disclose a client's intoxication on the job should not be
taken lightly and should be guided by ethical principles and professional guidelines.
Counselors must carefully assess the severity of the risk posed by the client's
intoxication, the likelihood of harm occurring, and the potential benefits and drawbacks
of disclosure.
Furthermore, counselors should consider whether there are alternative courses of
action that may mitigate the risk of harm without breaching confidentiality. For example,
counselors may explore options such as encouraging the client to seek treatment for their
substance use disorder, providing support and resources to help the client address the
underlying issues contributing to their intoxication, or collaborating with other
professionals or authorities to intervene in a non-disclosure manner.
It is also essential for counselors to adhere to relevant laws, regulations, and
professional standards when considering disclosure. In some jurisdictions, counselors
may be legally obligated to disclose information about a client's intoxication if it poses a
serious risk to public safety. However, even in jurisdictions where there is no legal
mandate for disclosure, counselors may still have an ethical obligation to do so based on
the principles of beneficence and nonmaleficence.
Moreover, counselors must approach the issue of disclosure with sensitivity and
compassion, recognizing the potential impact on the client's trust and therapeutic
relationship. Open and honest communication with the client about the reasons for
disclosure, the potential consequences, and the steps taken to mitigate risk can help
minimize harm and maintain the integrity of the therapeutic process.
In conclusion, the duty to disclose a client's intoxication on the job is a complex
ethical issue that requires careful consideration of multiple factors. While counselors
have a duty to protect public safety, they must also balance this obligation with their duty
to maintain confidentiality, respect client autonomy, and uphold the therapeutic
relationship. By approaching the issue with ethical awareness, sensitivity, and
professionalism, counselors can navigate this challenging dilemma in a manner that
prioritizes both the safety of others and the well-being of their clients.
If you breach confidentiality in an unprofessional manner (in the absence of a
recognized exception), you open yourself to both ethical and legal sanctions, including
expulsion from a professional association, loss of certification, license revocation, and a
malpractice suit. To protect yourself against such liability, it is essential to become
familiar with all applicable ethical and legal guidelines pertaining to confidentiality,
including state privilege laws and their exceptions, child and elder abuse reporting
requirements, and the parameters of the duty-to-protect exceptions in your state.
c. Privacy Issues With Telecommunication Devices
Digital technology in the helping professions is wide ranging. Computers
(including email and online chat), smartphones, tablets, and other electronic instruments
are being used to deliver services to and communicate with clients, manage confidential
case records, and access information about clients (Reamer, 2015). Telephone, answering
machine, voice mail, fax, cellular phone, text messaging, and email all pose a number of
potential ethical problems with regard to protecting client privacy. Counselors in private
practice may find text messaging with their clients to be an inexpensive and convenient
tool; however, they must be mindful of the ethical issues that can arise from the use of
this technology. Potential concerns related to privacy, confidentiality, documentation,
appropriateness of use, counselor competence, boundary issues, and misinterpretation
must be considered.
Barros-Bailey and Saunders (2010) point out that “when communication can be
easily captured, copied, transferred, disseminated, and stored in written text (e.g., email,
text messaging), through picture or video means (e.g., smart phone cameras, VoIP
technology such as Skype), or verbally (e.g., recording devices in all sorts of portable
media from cell phones to MP3 players or recorders), the danger for a breach of
confidentiality substantially increases” (p. 256). Rummell and Joyce (2010) recommend
“password protection, data encryption, use of secure socket layer encryption for Internet
traffic between psychotherapist and client computers, and use of a firewall” to promote
confidentiality of client information (p. 488). Yet they admit that even these measures
cannot guarantee confidentiality. Accidental interception, unauthorized email access, and
email snooping are potential mishaps that can occur. Reamer (2015) advises practitioners
not to assume that Internet sites and electronic tools they use are necessarily encrypted;
the ethical burden is on clinicians to ensure trustworthy encryption by cautiously
examining statements and guarantees made by software vendors.
Compared to other forms of electronic technology, Brenes, Ingram, and Danhauer
(2011) suggest the telephone may be the preferred method for providing psychological
services. Neither therapists nor clients need instructions on how to use the telephone,
which reduces the barriers to service. A few phone sessions may be appropriate when a
client is seriously ill and cannot come to an office. However, more research is needed to
determine who might benefit most from telephonedelivered therapy, and in what
situations it is appropriate. Brenes and colleagues point out a number of challenges of
telephone-delivered therapy. Mental health practitioners must exercise caution in
discussing confidential or privileged information with anyone over the telephone and
especially when employing digital and mobile technologies. Therapists must set firm
boundaries with clients from the beginning and address matters such as avoiding
interruptions and privacy. It is critical to disclose the limits of confidentiality with clients
if wireless telephones are used; Brenes and colleagues recommend land lines to ensure
greater privacy and confidentiality for clients.
Therapists should discuss the use of technology and the method for securing,
protecting, and handling data with clients in the informed consent process and as needed
throughout the therapeutic sessions. It is important that the informed consent document
clearly explain, justify, and present accurate risks to data storage and communication
(Lustgarten, 2015). Using fax machines and email to send confidential material is another
source of potential invasion of a client’s privacy. It is the counselor’s responsibility to
make sure fax and email transmissions arrive in a secured environment in such a way as
to protect confidential information. Tran-Lien (2012) recommends that therapists who
plan to exchange emails with their clients provide clients with a statement (as part of the
informed consent process) that details the therapist’s guidelines and limitations on the use
of email, the potential risks to confidentiality, and the expected turnaround time. She
notes that “communicating with your clients via e-mail can be done, but careful
consideration should be given to the guidelines and relevant legal and ethical issues” (p.
22). Both the challenges and the safeguards in using email as a mode of communication
should be clearly explained.
Therapists and their clients should carefully consider privacy issues before
agreeing to send email messages to clients’ workplaces or homes. If emails are sent
directly to your smartphone, the risks to privacy and confidentiality increase. A good
policy is to limit email and text message exchanges to basic information such as an
appointment time. Courts have ruled that email sent or received on computers used by
employees is considered to be the property of the company; therefore, privacy and
confidentiality do not exist. It is important to take appropriate measures to safeguard
privacy and security when using email.
This discussion of privacy may seem to be just a matter of common sense, but we
have become so accustomed to relying on technology that careful thought is not always
given to the subtle ways privacy can be violated. Exercise caution and pay attention to
ways you could unintentionally breach the privacy of your clients when using various
forms of communication. Apprise your clients of potential problems of privacy regarding
a wide range of technology and discuss how they might best contact you between office
visits and how you might leave messages for them. Take preventive measures so that
both you and your clients understand and have a signed agreement detailing these
important concerns. You may face legal problems due to violations of privacy and
confidentiality in this era of electronic communication, so it is important to determine
whether your liability insurance covers email and other electronic communications with
clients.
d. Implications of HIPAA for Mental Health Providers
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) was
passed by Congress to promote standardization and efficiency in the health care industry
and to give patients more rights and control over their health information. HIPAA is a
federal law that contains detailed provisions regarding client privacy, informed consent,
and transfer of records. HIPAA regulations require practitioners who are covered entities
under HIPAA to provide prospective clients with a clear written explanation of how
health information is used, disclosed, and kept (Fisher, 2016). HIPAA includes
provisions designed to encourage electronic transactions and requires certain new
safeguards to protect the security and confidentiality of health information. The HIPAA
Privacy Rule was designed to provide a uniform level of privacy and security on the
federal level. This Privacy Rule, which applies to both paper and electronic transmissions
of protected health information by covered entities, developed out of the concern that
transmission of health care information through electronic means could lead to
widespread gaps in the protection of client confidentiality. The Privacy Rule requires
health plans and other covered entities to establish policies and procedures to protect the
confidentiality of health information about their patients. It requires technical,
administrative, and physical safeguards to protect security of protected health information
in electronic form (Wheeler & Bertram, 2015).
The Privacy Rule, established under the Health Insurance Portability and
Accountability Act (HIPAA), is a crucial component of ensuring patients' rights to
privacy and confidentiality regarding their health information. This comprehensive
regulation sets forth standards for the use and disclosure of protected health information
(PHI) by covered entities, such as healthcare providers, health plans, and healthcare
clearinghouses, thereby safeguarding individuals' sensitive medical data.
Overall, the Privacy Rule serves to protect patients' privacy and confidentiality
rights while also facilitating the exchange of health information necessary for quality
healthcare delivery. By empowering patients with greater control over their health
information and holding covered entities accountable for compliance with HIPAA
regulations, the Privacy Rule helps to build trust and confidence in the healthcare system
and promotes the privacy and security of individuals' health information.
Health care providers need to determine whether they are covered entities under
HIPAA. If providers transmit any protected health information in electronic form (such
as health care claims, health plan enrollment, or coordination of benefits), or if they hire
someone to electronically transmit protected health care information, they must comply
with all applicable HIPAA regulations (Wheeler & Bertram, 2015). If you submit a claim
electronically, even once, you are likely to be considered a covered entity for HIPAA
purposes.
Privacy requirements. The Privacy Rule requires practitioners to take reasonable
precautions in safeguarding patient information. Licensed health care providers are
expected to have a working knowledge of and guard patients’ rights to privacy in
disclosure of information, health care operations, limiting the disclosure of protected
information, payment matters, protected health information, psychotherapy notes and a
patient’s medical record, and treatment activities.
HIPAA, the Health Insurance Portability and Accountability Act, is indeed
instrumental in standardizing electronic transactions in the healthcare industry. One of its
key objectives is to promote interoperability by establishing a common language or set of
standards for electronic communication among healthcare providers, health plans, and
other entities involved in the exchange of health information.
Electronic transactions in healthcare encompass a wide range of activities,
including the electronic transmission of claims, payments, eligibility inquiries, remittance
advice, and other administrative transactions. Prior to HIPAA, the lack of uniform
standards for electronic transactions led to inefficiencies, errors, and inconsistencies in
communication between healthcare entities, resulting in increased administrative burdens
and costs.
HIPAA's standardized electronic transaction requirements seek to address these
challenges by defining specific formats, code sets, and data elements that must be used in
electronic transactions. These standards ensure that health information is transmitted in a
consistent and structured manner, facilitating seamless communication and data exchange
across different healthcare systems and organizations.
For example, HIPAA mandates the use of standardized code sets, such as ICD-10
for diagnosis codes and CPT/HCPCS for procedure codes, in electronic transactions
related to medical billing and claims processing. By adopting these standardized code
sets, healthcare providers and payers can accurately identify and classify medical
diagnoses, procedures, and services, streamlining the billing and reimbursement process.
Furthermore, HIPAA's electronic transaction standards include requirements for
electronic data interchange (EDI) formats, such as the X12N transaction sets, which
define the structure and content of electronic transactions. These EDI formats ensure that
electronic transactions are transmitted in a consistent and machine-readable format,
allowing healthcare systems and software applications to seamlessly exchange data
without manual intervention.
In addition to promoting interoperability, HIPAA's standardized electronic
transaction requirements also enhance data security and privacy protections. Covered
entities are required to implement technical safeguards, such as encryption and
authentication mechanisms, to protect the confidentiality, integrity, and availability of
electronic health information during transmission.
Moreover, HIPAA's electronic transaction standards play a crucial role in
supporting other healthcare initiatives, such as electronic health records (EHRs), health
information exchange (HIE), and telehealth services. By providing a common framework
for electronic communication, HIPAA enables healthcare providers to integrate disparate
systems, share patient information securely, and deliver coordinated and patient-centered
care.
Overall, HIPAA's efforts to standardize electronic transactions in healthcare are
essential for promoting efficiency, interoperability, and data security across the
healthcare ecosystem. By establishing a common language for electronic communication,
HIPAA helps to streamline administrative processes, improve patient care coordination,
and advance the adoption of digital health technologies in the modern healthcare
landscape.
The requirement for covered entities to have national identification numbers
under HIPAA is a significant aspect of promoting efficient communication and
interoperability within the healthcare system. These unique identifiers serve as a means
of accurately identifying healthcare providers, health plans, and other entities involved in
standard transactions, thereby facilitating seamless data exchange and coordination of
care.
National identification numbers, also known as National Provider Identifier (NPI)
for healthcare providers and National Health Plan Identifier (HPID) for health plans, play
a crucial role in streamlining administrative processes, improving accuracy, and reducing
errors in electronic transactions. By assigning a unique identifier to each covered entity,
HIPAA ensures that entities can be reliably identified and distinguished from one another
across different healthcare systems and transactions.
For healthcare providers, obtaining an NPI is a mandatory requirement under
HIPAA for conducting standard transactions, such as electronic claims submission,
eligibility inquiries, and electronic remittance advice. The NPI serves as a consistent and
standardized identifier that allows healthcare providers to be accurately identified by
payers, clearinghouses, and other entities involved in electronic transactions. This
simplifies the billing and reimbursement process, reduces administrative burdens, and
enhances the efficiency of healthcare operations.
Similarly, health plans are required to obtain an HPID to uniquely identify
themselves when conducting standard transactions, such as processing claims, verifying
patient eligibility, and providing coverage information. The HPID enables health plans to
be accurately identified by healthcare providers, vendors, and other stakeholders,
facilitating smooth and efficient communication and data exchange.
In addition to promoting efficiency and accuracy in electronic transactions,
national identification numbers also support efforts to enhance patient privacy and
security. By using standardized identifiers, covered entities can reduce the risk of errors,
misidentification, and unauthorized access to patient information during electronic
transactions. This helps to safeguard patient confidentiality and protect against potential
breaches of protected health information (PHI).
Furthermore, national identification numbers play a critical role in supporting
other healthcare initiatives, such as interoperability, population health management, and
value-based care. By providing a standardized means of identifying healthcare providers
and health plans, HIPAA enables the integration of disparate systems, the sharing of
electronic health information, and the delivery of coordinated and patient-centered care.
Overall, the requirement for covered entities to have national identification
numbers under HIPAA is essential for promoting efficient communication,
interoperability, and data exchange within the healthcare system. By establishing
standardized identifiers for healthcare providers and health plans, HIPAA helps to
streamline administrative processes, improve accuracy, and support the delivery of high-
quality and cost-effective care to patients.
Only mental health providers who fall within the definition of covered entity are
subject to HIPAA requirements. Those providers who do not fall within this scope of
practice are not required to comply with HIPAA requirements, unless they choose to do
so (Jensen, 2003e). Wheeler and Bertram (2015) suggest that some HIPAA requirements
could be good practices from a risk management perspective even if the practitioner is
not technically a covered entity. Handerscheid, Henderson, and Chalk (2002) state that
HIPAA privacy requirements are meant to protect confidential patient information
irrespective of the form in which the information is stored.
To comply, covered entities first need to review their routine business practices to
assess how well patient information is protected against inappropriate disclosures.
Policies and procedures need to be in place. The second step involves modifying business
policies or practices once any problems are detected. The third step involves working
with consumers to inform them of their rights, advise them about providing written
authorization for release of information, and describe grievance procedures clients can
use if they believe their privacy has been violated.
e. The Duty to Warn and to Protect
Mental health professionals, spurred by the courts, have come to realize that they
have a dual professional responsibility: to protect other people from potentially
dangerous clients and to protect clients from themselves. Balancing client confidentiality
and protecting the public is a major ethical challenge that mental health professionals
must assess in considering these competing interests. The American Psychiatric
Association (2013b) provides this standard: “When, in the clinical judgment of the
treating psychiatrist, the risk of danger is deemed to be significant, the psychiatrist may
reveal confidential information disclosed by the patient.”
One of the most difficult tasks therapists grapple with is deciding whether a
particular client is dangerous. It is extremely difficult to decide when it is justified to
breach confidentiality and notify and protect potential victims. Although practitioners are
not generally legally liable for their failure to render perfect predictions of violent
behavior of a client, an inadequate assessment of client dangerousness can result in
liability for the therapist, harm to third parties, and inappropriate breaches of client
confidentiality. Therapists faced with potentially dangerous clients should take specific
steps to protect the public and to minimize their own liability. They should take careful
histories, advise clients of the limits of confidentiality, keep accurate notes of threats and
other client statements, seek several consultations, and record steps they have taken to
protect others. Practitioners should consult with a supervisor or an attorney because they
may be subject to liability for failing to notify those who are in danger. If a determination
is made that an individual poses a high risk for harming an identifiable third party, mental
health practitioners must develop and implement an intervention plan.
Mossman (2009) suggests that “violence prediction alone may be a futile
approach to reducing violence” (p. 137). Referencing rampage shootings in the United
States, Mossman points out that in hindsight we often perceive tragedies as being more
easily foreseeable than they really were. Mossman points out that the risk factors we have
are imperfect indicators of actual future violent acts. He believes clinical attention should
be paid to risk prevention (rather than risk prediction) and that society should seek broad
measures aimed at addressing known risks for violent behaviors among people who have
and who do not have mental health problems.
Nearly every jurisdiction has a different interpretation of the duty to warn and the
duty to protect, with some having no statute or case law related to the issues and others
with very specific legal guidelines (Welfel, Werth, & Benjamin, 2009). Most states
permit (if not require) therapists to breach confidentiality to warn or protect victims.
Some states specify how that duty is to be discharged. Some states grant mental health
practitioners immunity or protection from being sued for breaching confidentiality if they
can demonstrate that they acted in good faith to notify or protect third parties. A few
states have no mandatory duty to warn and to protect third parties, and therapists have no
specific grant of immunity from civil suits for breaching confidentiality in those states.
Some practitioners are concerned that laws requiring, rather than permitting, a warning
may dissuade potentially violent individuals from seeking treatment or fully revealing
their intentions, or that potential liability may discourage therapists from treating such
clients because their ability to predict violent behavior is limited (Widgery & Winterfeld,
2013). Despite these concerns, counselors must be prepared to handle such disclosures.
In 1999 in the case of Thapar v. Zezulka, the Texas Supreme Court ruled that
mental health workers do not have a duty to warn and protect their clients’ known and
intended victims. Basing its decision on the Texas statute governing the legal duty of
mental health professionals to protect clients’ confidentiality, the court found that it was
unwise to impose a duty to warn on mental health practitioners. This decision reflected
the justices’ reluctance to violate existing state confidentiality statutes. Given the fact that
various states have different interpretations of the duty to warn and protect, the most
important message is to know the law in your state.
Welfel, Werth, and Benjamin (2009) differentiate between the duty to warn and
the duty to protect. The duty to warn applies to those circumstances where case law or
statute requires the mental health professional to make a reasonable effort to contact the
identified victim of a client’s serious threats of harm, or to notify law enforcement of the
threat. The duty to protect applies to situations in which the mental health professional
has a legal obligation to protect an identified third party who is being threatened; in these
cases the therapist generally has other options in addition to warning the person of harm.
The duty to protect provides ways of maintaining the client’s confidentiality; the duty to
warn requires a disclosure of confidential information to the person who is being
threatened with harm.
Exercising a duty to warn can result in inappropriate breaches of confidentiality
that damage the therapeutic relationship, which can end treatment. Furthermore, this
course of action cannot guarantee another person’s safety. Most mental health
practitioners assume that they are mandated to take reasonable steps to warn an identified
person of a foreseeable and imminent danger of serious harm when a client
communicates an intention to harm a victim. However, in many situations, warning is not
the only option or the best course to follow. Other appropriate actions include
hospitalizing the client, increasing the frequency of therapy sessions, notifying the police,
or referring a client for a psychiatric consult or for prescribing medication (DeMers &
Siegel, 2016). Absent specific state laws mandating the duty to warn and to protect,
Wheeler and Bertram (2015) believe mental health professionals may have an ethical
duty to disclose information when it is necessary “to prevent clear and imminent danger
to the client or others” (p. 145). They suggest the real question for counselors to ponder
is: “How can I fulfill my legal and ethical duties to protect human life, act in the best
interest of the client, and remain protected from potential liability?”
The responsibility to protect the public from dangerous acts of violent clients
entails liability for civil damages when practitioners neglect this duty by (1) failing to
diagnose or predict dangerousness, (2) failing to warn potential victims of violent
behavior, (3) failing to commit dangerous individuals, or (4) prematurely discharging
dangerous clients from a hospital (APA, 1985). The first two of these legally prescribed
duties are illustrated in the case of Tarasoff v. Board of Regents of the University of
California (1976), which has been the subject of extensive analysis in the psychological
literature. As noted by Bersoff (2014), due to “the proliferation of mass shootings in the
recent past, the ongoing push for legislation to control access to firearms, and the alleged
connection between mental illness and violence, it may be particularly timely to revisit
Tarasoff v. Regents of the University of California” (p. 461). The other two duties are set
forth in additional landmark court cases. These cases provide case law governing the duty
to warn only for the states in which the judgments were made. There is no overarching
federal framework regarding these issues.
In August 1969 Prosenjit Poddar was a voluntary outpatient at the student health
service at the University of California, Berkeley and was in counseling with a
psychologist named Moore. Poddar had confided to Moore his intention to kill an
unnamed woman (who was readily identifiable as Tatiana Tarasoff) when she returned
from an extended trip in Brazil. In consultation with other university counselors, Moore
made the assessment that Poddar was dangerous and should be committed to a mental
hospital for observation. Moore later called the campus police and told them of the death
threat and of his conclusion that Poddar was dangerous. The campus officers did take
Poddar into custody for questioning, but they later released him when he gave evidence
of being “rational” and promised to stay away from Tarasoff. He was never confined to a
treatment facility. Moore followed up his call with a formal letter requesting the
assistance of the chief of the campus police. Later, Moore’s supervisor asked that the
letter be returned, ordered that the letter and Moore’s case notes be destroyed, and asked
that no further action be taken in the case. Tarasoff and her family were never made
aware of this potential threat.
Shortly after Tarasoff’s return from Brazil, Poddar killed her. Her parents filed
suit against the Board of Regents and the employees of the university for having failed to
notify the intended victim of the threat. When a lower court dismissed the suit in 1974,
the parents appealed, and the California Supreme Court ruled in favor of the parents in
1976, holding that a failure to warn an intended victim was professionally irresponsible.
The court’s ruling requires that therapists breach confidentiality in cases where the
general welfare and safety of others is involved. This was a California case, and courts in
other states are not bound to decide a similar case in the same way. Under the Tarasoff
decision, the therapist must first accurately diagnose the client’s tendency to behave in
dangerous ways toward others. This first duty is judged by the standards of professional
negligence. In this case the therapist did not fail in this duty. He even took the additional
step of requesting that the dangerous person be detained by the campus police. However,
the court held that merely notifying the police was not sufficient to protect the
identifiable victim.
In the first ruling, in 1974, the lower court cited a duty to warn, but this duty was
expanded by the 1976 California Supreme Court ruling, which said: “When a therapist
determinesO.O.O. that his patient presents a serious danger of violence to another, he incurs
an obligation to use reasonable care to protect the intended victim against such danger.”
Richard Leslie (2008) states that the “duty” created by the California Supreme Court in
the Tarasoff decision was not a “duty to warn.” According to Leslie, the court described
the duty simply as a “duty to exercise reasonable care to protect the foreseeable victim”
from the serious danger of violence against him or her. According to Jensen (2012), the
duty to protect can be discharged in a variety of ways, one of which involves
hospitalization, whether voluntary or involuntary.
Therapists can protect others through traditional clinical interventions such as
reassessment, medication changes, and referral. Other steps therapists may take include
warning potential victims, calling the police, or informing the state child protection
agency. Negligence lies in the practitioner’s failure to conduct an assessment for potential
violence, failure to warn a third party of imminent danger, not in failing to predict any
violence that may be committed. The goal of doing an assessment of dangerousness is to
arrive at a reasoned and informed judgment about a client’s capacity for seriously
harming or killing another person: “In other words, you do not have to be perfect in
predicting what will happen; you just have to be reasonably competent in assessing for
what could happen”
The Tarasoff decision made it clear that client confidentiality can be readily
compromised; indeed, “the protective privilege ends where the public peril begins” (as
cited in Perlin, 1997). Mental health professionals have ethical and legal responsibilities
to their clients, and they also have legal obligations to society. These dual responsibilities
sometimes conflict, and they can create ambiguity in the therapeutic relationship. Welfel
(2016) points out that courts interpret the duty to warn and protect to include situations in
which therapists should have known about the danger. If ignorance about a dangerous
situation is the result of incompetent or negligent practice, then professionals have
neglected this duty. State courts and legislatures vary in their interpretations of Tarasoff,
and practitioners remain uncertain about the nature of their duty to protect or to warn.
However, the codes of ethics of most mental health professions incorporate this concept,
and it is generally assumed that the duty to warn and to protect is a federal legal
requirement. Although state laws differ on the specifics of notifying intended victims, for
the most part, psychotherapists are required to take proactive steps when a client reveals a
serious intention of harming another person (Knapp & VandeCreek, 2012). “A lawsuit
alleging breach of this duty has been filed against the psychiatrist whose patient allegedly
killed 12 people and injured dozens more in a movie theater in Aurora, Colorado”
Mandatory reporting laws only apply to threats regarding future violence. Reports
by clients of past violence may not be reported and are protected as confidential
information (Barnett & Johnson, 2015). A study conducted by Walfish, Barnett,
Marlyere, and Zielke (2010) examined the incidence of client disclosures to their
therapists of violent crimes they had committed for which they had not been prosecuted.
Crimes such as murder, sexual assault, and physical assault were revealed. Based on their
findings, Walfish et al. commented, “during the course of clinicians’ careers there is a
very high likelihood (69%) that a client will tell them he or she has physically assaulted
someone, a moderate likelihood (33%) that a client will tell them that he or she has
sexually assaulted someone, and a small (13%) but not infinitesimal chance that he or she
has even murdered someone, outside of killing a person in the line of duty in the military
or as a public peace officer, without being reported to the proper authority and/or
prosecuted”
e A second case illustrates the duty not to negligently release a dangerous client.
In Bradley Center v. Wessner (1982) the patient, Wessner, had been voluntarily admitted
to a Georgia facility for psychiatric care. Wessner was upset over his wife’s extramarital
affair. He had repeatedly threatened to kill her and her lover and had even admitted to a
therapist that he was carrying a weapon in his car for that purpose. He was given an
unrestricted weekend pass to visit his children, who were living with his wife. He met his
wife and her lover in the home and shot and killed them. The children filed a wrongful
death suit, alleging that the psychiatric center had breached a duty to exercise control
over Wessner. The Georgia Supreme Court ruled that a physician has a duty to take
reasonable care to prevent a potentially dangerous patient from inflicting harm.
A fourth legal ruling, Hedlund v. Superior Court (1983), extends the duty to warn
in California to a foreseeable, identifiable person who might be near the intended victim
when the threat is carried out and thus might also be in danger. LaNita Wilson and
Stephen Wilson had received psychotherapy from a psychological assistant, Bonnie
Hedlund. During treatment Stephen Wilson told the therapist that he intended to harm
LaNita Wilson. Later he did assault her, in the presence of her child. The allegation was
that the child had sustained “serious emotional injury and psychological trauma.” In
keeping with the Tarasoff decision, the California Supreme Court held (1) that a therapist
has a duty first to exercise a “reasonable degree of skill, knowledge, and care ordinarily
possessed and exercised by members [of that professional specialty] under similar
circumstances” in making a prediction about the chances of a client’s acting dangerously
to others; and (2) that therapists must “exercise reasonable care to protect the foreseeable
victim of that danger.” One way to protect the victim is by giving a warning of peril. The
court held that breach of such a duty with respect to third persons constitutes
“professional negligence”
In the Hedlund case the duty to warn of potentially dangerous conduct applied to
the mother, not to her child, against whom no threats had been made. However, the court
found that a therapist could be held liable for injuries sustained by the intended victim’s
child if the violent act was carried out. The court held that a therapist must consider the
welfare of the intended victim as well as the welfare of persons in close relationship to
the victim when determining how to best protect the potential victim.
Most counseling centers and community mental health agencies now have
guidelines regarding the duty to warn and protect when the welfare of others is at stake.
These guidelines generally specify how to deal with emotionally disturbed individuals,
violent behavior, threats, suicidal possibilities, and other circumstances in which
counselors may be legally and ethically required to breach confidentiality. In response to
the April 16, 2007, school shooting on the Virginia Tech campus in which 33 people
were killed, task forces were formed in several states to create significant changes to the
policies and procedures at college counseling centers and campus security offices
(Davenport, 2009). According to Davenport, “what constitutes ‘risk’ on our college
campuses is continually changing and intensifying” (p. 181), leading college counselors
to increasingly adopt the role of risk managers. Despite measures taken by secondary
schools and postsecondary institutions to prepare for such crisis situations, devastating
acts of violence and mass shootings continue to plague the United States. There have
been 215 school shootings in the United States since the massacre of 20 children and six
adults at Sandy Hook Elementary School in Newtown, Connecticut.
As clinicians, we believe one of the problems with being able to piece together a
true picture of potential for violence is a lack of communication between all parties
working with, or on behalf of, a potentially violent client. Counselors working with
potentially high-risk clients should have a release of information in place so a more
complete picture of the client’s level of functioning can be determined. The dangerous
behaviors or warning signs may be witnessed in one or more arenas, but key health care
workers often do not have permission to speak to one another.
The basic standard of care for school counselors is clear; courts have uniformly
held that school personnel have a duty to protect students from foreseeable harm
(Hermann & Remley, 2000). The duty to protect vulnerable children is also a well-
articulated standard in the field of psychology. School personnel may need to act on
student reports of their peers’ plans related to intended violence. Furthermore, school
officials may be held accountable if a student’s writing assignments contain evidence of
premeditated violence. Hermann and Finn (2002) contend that school counselors are
legally and ethically obligated to work toward preventing school violence. They state that
school counselors may find themselves legally vulnerable because of their role in
determining whether students pose a risk of harm to others and deciding on appropriate
interventions with these students. Current case law reveals that all indicators of potential
violence should be taken seriously.
Moyer and coauthors (2012) suggest that ethics codes “provide no explanation as
to what constitutes a potentially disruptive or damaging behavior, and individual school
counselors are likely to interpret this differently” (p. 98). Despite the lack of guidance in
the codes, preventing students from harming other students seems to be implicit in the
duty of school personnel. Courts have consistently found that school counselors have a
duty to exercise reasonable care to protect students from foreseeable harm, but they are
only exposed to legal liability if they fail to exercise reasonable care.
School counselors try to provide a safe place for students to disclose their
personal problems, but these counselors also have a reporting duty in many instances.
School counselors need to assess a student’s dangerousness by evaluating the student’s
plans for implementing the violent act and his or her ability to carry out the act. Moyer
and colleagues (2012) surveyed school counselors to get their impressions of when it is
ethical to inform administrators about risky student behaviors. In their study, counselors
deemed it more ethical to break confidentiality when the behaviors were directly
observed rather than when reported by students and when the risk-taking behaviors
occurred during school hours on the school campus. These counselors also showed a
greater willingness to breach confidentiality when they were supported by written school
policies guiding their interventions. Given the context of emerging case law and the
violent climate of today’s schools, school counselors would do well to take threats of
violence seriously. The central ethical concern surrounding this issue involves the
commitment of mental health professionals to develop organized prevention efforts in
response to school violence.
School counselors and mental health professionals must be prepared to respond to
crises when they do occur. Given the high level of visibility of school violence today,
Fein, Carlisle, and Isaacson (2008) suggest that school counselors be prepared to lead and
to assume responsibilities that may be beyond the scope of their formal training. They
may have to respond to the needs and demands of students, staff, and administrators and
adopt multiple roles, which may create inherent role conflicts.
In the preceding discussion we emphasized the therapist’s obligation to protect
others from dangerous individuals. The guidelines and principles outlined in that
discussion often apply to the client who poses a danger to self. As part of the informed
consent process, therapists must inform clients that they have an ethical and legal
obligation to break confidentiality when they have good reason to suspect suicidal
behavior. Even if clients argue that they can do what they want with their own lives,
including taking them, therapists have a legal duty to protect suicidal clients. The crux of
the issue is knowing when to take a client’s hints seriously enough to report the
condition. Certainly not every mention of suicidal thoughts or feelings justifies
extraordinary measures. The evaluation and management of suicidal risk can be a source
of great stress for therapists. Clinical practitioners must face many troublesome issues,
including their degree of influence, competence, level of involvement with a client,
responsibility, legal obligations, and ability to make life-or-death decisions.
If a client dies by suicide, the risk of a malpractice action is greatly reduced if the
therapist can demonstrate that a reasonable assessment and intervention process took
place; professional consultation was sought; clinical referrals were made when
appropriate; and thorough and current documentation was done (Jobes & O’Connor,
2009). Counselors can be accused of malpractice for neglecting to take action to prevent
harm when a client is likely to take the step of suicide, yet they are also liable if they
overreact by taking actions that violate a client’s privacy when there is not a justifiable
basis for doing so.