As AI tools become standard in mental health practice, therapists need clear policies governing how they use them. This article covers what belongs in a therapist's AI use policy, from informed consent to data privacy, and how mePro supports compliant, ethical AI integration.
AI tools are no longer a future consideration for mental health practitioners. They are active parts of clinical workflows right now, handling documentation, scheduling, billing summaries, and even session note generation. That shift has created a practical and ethical gap: most therapists are using AI in some capacity, but very few have a written policy that governs how they do it. A formal AI use policy is not a bureaucratic formality. It is a clinical and professional document that protects your clients, your license, and your practice.
The absence of a clear policy creates real exposure. When a client asks whether their session is being recorded or processed by an AI, the answer cannot be vague. When a licensing board investigates a complaint involving documentation, the question of what tools were used and how they were governed will matter. Therapists, counselors, psychologists, social workers, and coaches are all navigating this terrain with very little standardized guidance. Existing ethics codes were written before AI session tools existed, which means practitioners are largely left to construct their own frameworks.
That is exactly the kind of problem the team at mePro built around. mePro's AI session notes and practice management tools were designed with the understanding that ethical use requires more than good intentions. It requires structure, documentation, and clear process. This article walks through the core components every therapist should include in an AI use policy, with practical language you can adapt for your own practice.
Defining the Scope: What AI Tools Does Your Practice Actually Use?
The first step in writing any effective policy is inventory. Practitioners often underestimate how many AI-powered tools they are already using. Scheduling assistants that predict no-shows, billing platforms that flag claim errors, transcription services that convert session audio to text, EHR systems with auto-generated documentation prompts, and client portal chatbots all qualify. If you are not sure whether a tool uses AI, read the vendor's data processing agreement. The answer is almost always yes.
Your AI use policy should begin with a clear and specific list of every tool your practice uses that involves AI processing of any kind. This list should include the name of the tool, the vendor, the type of data it handles (scheduling data, clinical content, billing information), and whether it processes protected health information (PHI). This is not a one-time exercise. It requires a review process, typically at least annually, to account for updates vendors make to their own systems and for any new tools you add to your workflow.
Scope also includes how you use AI within sessions versus outside of them. An AI transcription tool that runs during a therapy session raises different consent considerations than a billing automation tool that processes claims after the fact. Your policy should distinguish between these uses and address each one separately. Clients have a right to understand what happens to their information at every stage of their care, and that clarity starts with you knowing your own systems well enough to explain them.
A well-defined scope section of your AI use policy should address:
- A complete inventory of AI-enabled tools currently in use, updated at least annually
- Classification of each tool by the type of data it processes (PHI, administrative, financial)
- Distinction between in-session AI use (transcription, note generation) and back-office AI use (billing, scheduling)
- Identification of which tools are covered under your Business Associate Agreements (BAAs) and which are not
Defining scope early does more than clarify your own practices. It gives you the foundation for every other section of the policy. Informed consent language, data handling procedures, and staff training all depend on knowing exactly what tools are in play. Practitioners who skip this step often find themselves backtracking when a client raises a specific question they cannot answer with confidence.
Scope is also where you surface gaps. If you discover that a tool you have been using for months does not have a signed BAA, that is a compliance issue you need to address immediately. A thorough scope section forces that kind of audit and creates a paper trail showing that your practice takes AI governance seriously.
Client Consent and Transparency: What Clients Need to Know Before AI Enters the Room
Informed consent has always been a cornerstone of ethical practice. AI tools add a new dimension to that obligation. When any AI-powered tool touches the therapeutic process, including session note generation, audio transcription, or even AI-assisted treatment planning templates, clients have a right to know before it happens. That right is not just ethical. In many jurisdictions, it is a legal requirement that intersects with both HIPAA and state privacy statutes.
Your AI use policy should include a specific informed consent protocol for AI tools that process clinical content. This means updating your intake paperwork to describe, in plain language, what AI tools your practice uses, what they do, and what happens to the data they generate. Avoid technical jargon. A client does not need to understand how a large language model works. They do need to understand that a software tool may process notes about their session, that the data is handled securely, and that they have the right to ask questions or decline specific uses where clinically and operationally feasible.
Transparency also extends beyond the initial intake. If you add a new AI tool mid-treatment, that change requires updated consent. If the vendor for an existing tool changes its data processing practices, you may need to revisit consent with current clients. Your policy should specify a process for ongoing consent review rather than treating it as a one-time checkbox. This is especially important for long-term clients whose original intake paperwork may predate your current AI stack entirely.
A strong client consent and transparency section should include:
- Plain-language disclosure language describing which AI tools process client information
- A defined process for obtaining and documenting AI-specific informed consent at intake
- A protocol for re-consenting existing clients when AI tools or vendor practices change
- A clear statement of what clients can do if they have concerns or wish to opt out of specific AI uses
Clients who understand how their information is handled tend to feel more secure in the therapeutic relationship, not less. Transparency around AI does not undermine trust. Handled well, it reinforces it. Practitioners who avoid this conversation often find themselves managing larger ruptures later when clients discover AI involvement through other means.
Documentation of consent matters as much as the consent itself. Your policy should specify where and how AI consent is recorded in the client file so that you have a clear record if questions ever arise. This is the kind of workflow detail that mePro's practice management tools are designed to support, keeping consent documentation organized and accessible within the same system where clinical records live.
Data Security, Vendor Accountability, and What Happens When Things Go Wrong
Even the most ethically designed AI workflow carries risk if the underlying data handling is not secure. Therapists have a professional and legal obligation to protect client information, and that obligation extends to every vendor they authorize to process PHI on their behalf. AI tools that handle session content are particularly high-stakes because the data involved is among the most sensitive that exists. A breach involving therapy notes is not the same as a breach involving appointment times.
Your AI use policy should include a data security section that addresses vendor vetting, BAA requirements, and breach response. Every vendor whose AI tool touches PHI must have a signed BAA in place before use begins. That agreement transfers specific HIPAA obligations to the vendor and creates legal accountability if a breach occurs. Vendor vetting should go beyond the BAA itself to include a review of the vendor's security certifications (SOC 2 Type II is a standard benchmark), data retention policies, and whether data is used to train the vendor's AI models. That last point is critical. Some AI tools use client data to improve their algorithms unless you explicitly opt out.
Breach response is an area many solo and small-group practices overlook in their AI governance planning. Your policy should specify what steps you will take if an AI vendor reports a data breach, including how quickly you will notify affected clients, what your state reporting obligations are, and who in your practice is responsible for coordinating the response. HIPAA's Breach Notification Rule has specific timelines that do not pause because you are a one-person practice or because the breach originated with a vendor rather than with you directly.
A complete data security section of your AI use policy should cover:
- BAA requirements for every AI vendor that handles PHI, confirmed before use begins
- A vendor vetting checklist that includes security certifications, data retention terms, and AI training data policies
- A clearly defined breach response protocol with assigned responsibilities and HIPAA-compliant notification timelines
- A policy on staff access to AI-generated clinical content, including who can view, edit, and finalize AI-drafted notes
Accountability does not end at the vendor level. Your policy should also address how AI-generated content is reviewed and approved before it becomes part of the clinical record. AI session notes, for example, should always be reviewed and edited by the treating clinician before they are finalized. No AI output should enter a client's permanent record without human clinical oversight. This is both an ethical standard and a quality of care issue.
The reality is that AI tools are only as trustworthy as the governance structures around them. Writing and maintaining a clear AI use policy is how therapists demonstrate that they are using these tools intentionally and responsibly. It is also how they protect themselves when questions arise, whether from clients, licensing boards, or insurers. The experts at mePro consistently emphasize that ethical AI use in clinical settings is not about avoiding the technology. It is about building the right structures around it so that the technology serves clients and practitioners well.
Frequently asked questions
Do I need a separate AI use policy, or can I just update my existing privacy notice?
+
Updating your privacy notice is a good starting point, but it is not sufficient on its own. A standalone AI use policy covers ground that a standard privacy notice does not, including vendor accountability, in-session versus back-office AI use distinctions, breach response protocols, and clinician review requirements for AI-generated content. The team at mePro designed mePro's practice management tools to support structured documentation workflows, making it easier to maintain separate, organized policy documents and link them to client intake records without duplicating administrative work across your system.
How do I explain AI session notes to clients without alarming them?
+
Plain language and context go a long way. Most clients understand that technology handles parts of their healthcare experience. What matters is being specific: explain what the tool does, confirm that their information is handled securely, and let them know they can ask questions at any time. The team at mePro built mePro's AI session notes with therapist transparency in mind, generating draft notes that the clinician reviews and edits before finalizing. That human review step is something you can communicate directly to clients as a clear reassurance that no AI output enters their record unchecked.
What should I look for in a vendor's Business Associate Agreement before using their AI tool?
+
A BAA should explicitly name the type of PHI the vendor will access, describe the safeguards they use to protect it, define their breach notification obligations and timelines, and state whether your data is used to train AI models. That last point is frequently buried in supplemental terms. mePro's AI session notes operate under a BAA framework built for mental health practice specifically, with data handling policies designed around clinical privacy requirements. Before signing any BAA, review it with your practice attorney if possible, and confirm that AI training data exclusions are explicitly documented.
How often should I update my AI use policy?
+
At minimum, review your AI use policy annually. In practice, any of the following should trigger an earlier review: adding a new AI-powered tool to your workflow, receiving notice that a vendor has changed its data processing terms, a change in applicable state or federal privacy regulations, or a reported breach by any vendor you use. mePro's practice management tools include workflow features that help practitioners track administrative tasks like policy reviews, so these scheduled obligations do not fall through the cracks during busy clinical periods. Building the review into your annual compliance calendar is the most reliable approach.
If I use AI to help draft treatment plans or progress notes, am I still clinically responsible for the content?
+
Yes, fully and without exception. AI-generated clinical content is a draft, not a final document. The treating clinician is responsible for reviewing, editing, and approving everything that enters the client record, and that clinical judgment cannot be delegated to an algorithm. This is one reason the team at mePro built an edit-before-finalize step directly into the AI session notes workflow. Practitioners review the AI-generated draft, make clinical adjustments, and sign off before the note is saved. That structure reinforces the standard that clinician oversight is always the final step in any AI-assisted documentation process.
What should my AI use policy say about staff and supervisees who use AI tools in my practice?
+
Your policy should define exactly which AI tools staff and supervisees are authorized to use, under what conditions, and what review process applies to any AI-generated clinical content they produce. Supervisors carry accountability for work produced under their license, which means AI-assisted documentation by a supervisee still requires the same clinical review as anything else. mePro's EHR capabilities include user-level access controls and note review workflows that make it practical for supervisors to oversee AI-assisted documentation across a team without creating significant additional administrative burden. Clear role-based expectations in your written policy are the foundation for that oversight structure.
See why therapists are switching to mePro
Start free in minutes, or take a guided tour with our team.