Skip to content
All resources
AI in Mental Health Practice

What Should Be in a Therapist's AI Use Policy?

mePro helps mental health practitioners manage what should be in with secure EHR, AI-powered documentation, and practice management tools built for therapists.

August 26, 2026 11 min read
Summary

As AI tools become standard in mental health practice, therapists need clear policies governing how they use them. This article covers what belongs in a therapist's AI use policy, from informed consent to data privacy, and how mePro supports compliant, ethical AI integration.

AI tools are no longer a future consideration for mental health practitioners. They are active parts of clinical workflows right now, handling documentation, scheduling, billing summaries, and even session note generation. That shift has created a practical and ethical gap: most therapists are using AI in some capacity, but very few have a written policy that governs how they do it. A formal AI use policy is not a bureaucratic formality. It is a clinical and professional document that protects your clients, your license, and your practice.

The absence of a clear policy creates real exposure. When a client asks whether their session is being recorded or processed by an AI, the answer cannot be vague. When a licensing board investigates a complaint involving documentation, the question of what tools were used and how they were governed will matter. Therapists, counselors, psychologists, social workers, and coaches are all navigating this terrain with very little standardized guidance. Existing ethics codes were written before AI session tools existed, which means practitioners are largely left to construct their own frameworks.

That is exactly the kind of problem the team at mePro built around. mePro's AI session notes and practice management tools were designed with the understanding that ethical use requires more than good intentions. It requires structure, documentation, and clear process. This article walks through the core components every therapist should include in an AI use policy, with practical language you can adapt for your own practice.

Defining the Scope: What AI Tools Does Your Practice Actually Use?

The first step in writing any effective policy is inventory. Practitioners often underestimate how many AI-powered tools they are already using. Scheduling assistants that predict no-shows, billing platforms that flag claim errors, transcription services that convert session audio to text, EHR systems with auto-generated documentation prompts, and client portal chatbots all qualify. If you are not sure whether a tool uses AI, read the vendor's data processing agreement. The answer is almost always yes.

Your AI use policy should begin with a clear and specific list of every tool your practice uses that involves AI processing of any kind. This list should include the name of the tool, the vendor, the type of data it handles (scheduling data, clinical content, billing information), and whether it processes protected health information (PHI). This is not a one-time exercise. It requires a review process, typically at least annually, to account for updates vendors make to their own systems and for any new tools you add to your workflow.

Scope also includes how you use AI within sessions versus outside of them. An AI transcription tool that runs during a therapy session raises different consent considerations than a billing automation tool that processes claims after the fact. Your policy should distinguish between these uses and address each one separately. Clients have a right to understand what happens to their information at every stage of their care, and that clarity starts with you knowing your own systems well enough to explain them.

A well-defined scope section of your AI use policy should address:

  • A complete inventory of AI-enabled tools currently in use, updated at least annually
  • Classification of each tool by the type of data it processes (PHI, administrative, financial)
  • Distinction between in-session AI use (transcription, note generation) and back-office AI use (billing, scheduling)
  • Identification of which tools are covered under your Business Associate Agreements (BAAs) and which are not

Defining scope early does more than clarify your own practices. It gives you the foundation for every other section of the policy. Informed consent language, data handling procedures, and staff training all depend on knowing exactly what tools are in play. Practitioners who skip this step often find themselves backtracking when a client raises a specific question they cannot answer with confidence.

Scope is also where you surface gaps. If you discover that a tool you have been using for months does not have a signed BAA, that is a compliance issue you need to address immediately. A thorough scope section forces that kind of audit and creates a paper trail showing that your practice takes AI governance seriously.

Clients who understand how their information is handled tend to feel more secure in the therapeutic relationship, not less. Transparency around AI does not undermine trust. Handled well, it reinforces it. Practitioners who avoid this conversation often find themselves managing larger ruptures later when clients discover AI involvement through other means.

Documentation of consent matters as much as the consent itself. Your policy should specify where and how AI consent is recorded in the client file so that you have a clear record if questions ever arise. This is the kind of workflow detail that mePro's practice management tools are designed to support, keeping consent documentation organized and accessible within the same system where clinical records live.

Data Security, Vendor Accountability, and What Happens When Things Go Wrong

Even the most ethically designed AI workflow carries risk if the underlying data handling is not secure. Therapists have a professional and legal obligation to protect client information, and that obligation extends to every vendor they authorize to process PHI on their behalf. AI tools that handle session content are particularly high-stakes because the data involved is among the most sensitive that exists. A breach involving therapy notes is not the same as a breach involving appointment times.

Your AI use policy should include a data security section that addresses vendor vetting, BAA requirements, and breach response. Every vendor whose AI tool touches PHI must have a signed BAA in place before use begins. That agreement transfers specific HIPAA obligations to the vendor and creates legal accountability if a breach occurs. Vendor vetting should go beyond the BAA itself to include a review of the vendor's security certifications (SOC 2 Type II is a standard benchmark), data retention policies, and whether data is used to train the vendor's AI models. That last point is critical. Some AI tools use client data to improve their algorithms unless you explicitly opt out.

Breach response is an area many solo and small-group practices overlook in their AI governance planning. Your policy should specify what steps you will take if an AI vendor reports a data breach, including how quickly you will notify affected clients, what your state reporting obligations are, and who in your practice is responsible for coordinating the response. HIPAA's Breach Notification Rule has specific timelines that do not pause because you are a one-person practice or because the breach originated with a vendor rather than with you directly.

A complete data security section of your AI use policy should cover:

  • BAA requirements for every AI vendor that handles PHI, confirmed before use begins
  • A vendor vetting checklist that includes security certifications, data retention terms, and AI training data policies
  • A clearly defined breach response protocol with assigned responsibilities and HIPAA-compliant notification timelines
  • A policy on staff access to AI-generated clinical content, including who can view, edit, and finalize AI-drafted notes

Accountability does not end at the vendor level. Your policy should also address how AI-generated content is reviewed and approved before it becomes part of the clinical record. AI session notes, for example, should always be reviewed and edited by the treating clinician before they are finalized. No AI output should enter a client's permanent record without human clinical oversight. This is both an ethical standard and a quality of care issue.

The reality is that AI tools are only as trustworthy as the governance structures around them. Writing and maintaining a clear AI use policy is how therapists demonstrate that they are using these tools intentionally and responsibly. It is also how they protect themselves when questions arise, whether from clients, licensing boards, or insurers. The experts at mePro consistently emphasize that ethical AI use in clinical settings is not about avoiding the technology. It is about building the right structures around it so that the technology serves clients and practitioners well.

Frequently asked questions

Do I need a separate AI use policy, or can I just update my existing privacy notice?

+

Updating your privacy notice is a good starting point, but it is not sufficient on its own. A standalone AI use policy covers ground that a standard privacy notice does not, including vendor accountability, in-session versus back-office AI use distinctions, breach response protocols, and clinician review requirements for AI-generated content. The team at mePro designed mePro's practice management tools to support structured documentation workflows, making it easier to maintain separate, organized policy documents and link them to client intake records without duplicating administrative work across your system.

How do I explain AI session notes to clients without alarming them?

+

Plain language and context go a long way. Most clients understand that technology handles parts of their healthcare experience. What matters is being specific: explain what the tool does, confirm that their information is handled securely, and let them know they can ask questions at any time. The team at mePro built mePro's AI session notes with therapist transparency in mind, generating draft notes that the clinician reviews and edits before finalizing. That human review step is something you can communicate directly to clients as a clear reassurance that no AI output enters their record unchecked.

What should I look for in a vendor's Business Associate Agreement before using their AI tool?

+

A BAA should explicitly name the type of PHI the vendor will access, describe the safeguards they use to protect it, define their breach notification obligations and timelines, and state whether your data is used to train AI models. That last point is frequently buried in supplemental terms. mePro's AI session notes operate under a BAA framework built for mental health practice specifically, with data handling policies designed around clinical privacy requirements. Before signing any BAA, review it with your practice attorney if possible, and confirm that AI training data exclusions are explicitly documented.

How often should I update my AI use policy?

+

At minimum, review your AI use policy annually. In practice, any of the following should trigger an earlier review: adding a new AI-powered tool to your workflow, receiving notice that a vendor has changed its data processing terms, a change in applicable state or federal privacy regulations, or a reported breach by any vendor you use. mePro's practice management tools include workflow features that help practitioners track administrative tasks like policy reviews, so these scheduled obligations do not fall through the cracks during busy clinical periods. Building the review into your annual compliance calendar is the most reliable approach.

If I use AI to help draft treatment plans or progress notes, am I still clinically responsible for the content?

+

Yes, fully and without exception. AI-generated clinical content is a draft, not a final document. The treating clinician is responsible for reviewing, editing, and approving everything that enters the client record, and that clinical judgment cannot be delegated to an algorithm. This is one reason the team at mePro built an edit-before-finalize step directly into the AI session notes workflow. Practitioners review the AI-generated draft, make clinical adjustments, and sign off before the note is saved. That structure reinforces the standard that clinician oversight is always the final step in any AI-assisted documentation process.

What should my AI use policy say about staff and supervisees who use AI tools in my practice?

+

Your policy should define exactly which AI tools staff and supervisees are authorized to use, under what conditions, and what review process applies to any AI-generated clinical content they produce. Supervisors carry accountability for work produced under their license, which means AI-assisted documentation by a supervisee still requires the same clinical review as anything else. mePro's EHR capabilities include user-level access controls and note review workflows that make it practical for supervisors to oversee AI-assisted documentation across a team without creating significant additional administrative burden. Clear role-based expectations in your written policy are the foundation for that oversight structure.

See why therapists are switching to mePro

Start free in minutes, or take a guided tour with our team.

Not sure about how it works?

Book a demo to see mePro in action, ask questions, and explore how the platform can support your practice at every stage.

©2026 mePro. All rights reserved.