Can Psychologists Use AI in Practice? Ethics, HIPAA, and Legal Risks

Artificial intelligence is already becoming part of psychological practice. The American Psychological Association's 2025 Practitioner Pulse Survey found that 56% of psychologists had used AI for work at least once in the previous 12 months, while 29% reported using it at least monthly.

But "using AI" can mean very different things.

Using AI to brainstorm a public workshop title is not the same as recording a psychotherapy session with an AI scribe. Asking AI to edit a general office policy is different from asking software to suggest a diagnosis or treatment plan.

So when I think about psychologists using AI, I would not start by asking whether AI is good or bad.

I would ask three questions:

What is the tool doing? What information does it receive? How much influence does it have over client care?

Those questions make it much easier to separate lower-risk business uses from tools that require deeper ethical, privacy, and legal review.

Can Psychologists Use AI in Practice?

Yes. Psychologists can use AI in professional practice, but there is no blanket rule making every AI tool or every use appropriate.

The American Psychological Association's AI guidance applies familiar professional responsibilities to AI, including competence, informed consent, privacy, bias, and professional judgment. APA also states that psychologists remain responsible for final decisions and should not blindly rely on AI recommendations.

That means the starting point should be the use case, not the product name.

Before bringing an AI tool into your practice, ask what task it performs, whether client information enters the system, whether the output could influence care, and whether you can independently review what it produces.

AI Guidance Is Not Permission for Every Tool

A polished website or a promise that a product was "built for therapists" does not tell you whether it fits your practice.

You still need to understand its intended use, privacy terms, data handling, limits, evidence, and your own professional obligations.

Your state licensing board, professional standards, contracts, insurer requirements, or state laws may also add rules beyond general APA guidance.

A therapist crossing her arms - The Passive Practice

Not Every AI Use Has the Same Level of Risk

One of the easiest ways to make AI decisions clearer is to sort tools by what they actually do.

AI Use Main Questions to Ask
General admin Does the tool receive client or health information?
Marketing Are client details or confidential material being entered?
Note drafting Is the session recorded, stored, or transcribed?
Intake support What information is analyzed and where does it go?
Assessment support Has the tool been tested for this purpose and population?
Clinical decision support Can the psychologist independently review the recommendation?
Client chatbot What does it claim to provide and what happens during a crisis?

Risk tends to increase when AI gets closer to confidential information, assessment, treatment decisions, or direct client interaction.

For example, using AI to suggest headline ideas for a public article raises a different set of concerns than uploading a client record and asking for a treatment recommendation.

If your main interest is public marketing rather than clinical AI, my guide to AI content creation for therapists covers that side separately.

What APA's AI Guidance Means for Psychologists

APA released specific guidance for AI in health service psychology in 2025. It does not replace the existing Ethics Code. Instead, it helps psychologists apply professional responsibilities to newer AI tools.

Maintain Enough Competence to Judge the Tool

You do not need to become a software engineer before using AI.

You do need enough understanding to recognize when a tool might be wrong, incomplete, biased, or being used outside the purpose for which it was designed or tested.

If an AI system produces a clinical suggestion, the psychologist should be able to evaluate that suggestion rather than treating the software as an authority.

Keep Human Judgment in the Loop

APA says psychologists remain responsible for final decisions when AI is involved.

That matters for documentation, assessment support, treatment planning, risk flags, and other outputs that can look convincing simply because a computer generated them.

A confident answer is not necessarily an accurate answer.

Human review should be part of the workflow before AI output reaches the clinical record or influences care.

Address Informed Consent When AI Becomes Part of Care

APA's current guidance says psychologists have an ethical obligation to obtain informed consent by communicating the purpose, application, and potential benefits and risks of AI when it is incorporated into professional practice.

That does not mean every spelling tool or internal administrative feature needs a separate AI consent form.

The better question is whether AI has become part of the professional service, what client information it receives, and what applicable ethics rules or laws require.

AI Therapy Notes and Scribes Need More Than an Accuracy Check

AI documentation is one of the most attractive uses for busy clinicians, but "AI note taking" can describe very different workflows.

One psychologist might dictate a summary after a session. Another might upload an existing draft. An ambient AI scribe may record an entire appointment, create a transcript, and then turn that transcript into a note.

Those workflows should not automatically receive the same review.

Find Out What Is Actually Recorded and Stored

Before using an AI scribe, find out whether it captures audio, creates a full transcript, retains either file, or passes the information to additional vendors.

Then ask how long information is retained, who can access it, whether subcontractors are involved, whether client information can be used for model training or product development, and what happens to stored information after you cancel.

Review Every Final Note

AI documentation can introduce incorrect details, unsupported symptoms, missing context, or wording you would not independently place in the record.

The psychologist should review the note before it becomes part of the chart.

The question is not simply whether AI saves time. It is whether the workflow protects client information and leaves the clinician in control of the final record.

"HIPAA Compliant" Is Not Enough Information

HIPAA does not apply to every psychologist in every situation.

HHS identifies psychologists as health care providers, but a provider is a HIPAA covered entity only when the applicable covered entity requirements are met, including certain electronic health care transactions.

Where HIPAA applies, the relationship with the AI vendor becomes especially important.

HHS now specifically lists a third-party AI chatbot handling PHI for a provider as an example of a business associate. It also lists app vendors providing transcription services. Covered business associate relationships require written agreements containing specific protections and limits on the use and disclosure of PHI.

So instead of asking only, "Is this AI HIPAA compliant?" ask what information the vendor creates, receives, maintains, or transmits on your behalf.

You should also know whether the vendor will sign a business associate agreement when one is required, what the agreement permits the vendor to do, what other companies receive access, how electronic PHI is protected, and how data is returned or deleted.

A badge on a sales page cannot answer those questions for you.

AI Bias Is More Than a Training Data Problem

Bias can enter an AI system through data, model design, testing methods, deployment decisions, and the way people interpret the output.

The NIST AI Risk Management Framework identifies validity, reliability, safety, security, transparency, explainability, privacy, and management of harmful bias as connected parts of trustworthy AI.

That matters in psychology because performance in one population or setting does not guarantee the same performance elsewhere.

Before relying on AI for assessment or clinical recommendations, ask what population was used for testing, what outcomes were measured, what the known error rates are, and whether the tool has been tested outside its original setting.

The closer the software gets to diagnosis or treatment decisions, the stronger that evidence should be.

Clinical Decision Support May Raise FDA Questions

Some health software may also fall within FDA oversight depending on what the software does.

FDA issued final Clinical Decision Support Software guidance in January 2026. It explains when certain clinician-facing decision support functions may fall outside the federal medical device definition and when other software functions remain subject to FDA digital health policies.

You do not need to become an FDA expert to run a psychology practice.

You should look more closely, however, when software analyzes client-specific clinical information, recommends diagnoses or treatment, predicts risk, or produces recommendations you cannot independently evaluate.

Do not assume labels such as "wellness app," "assistant," or "clinical AI" tell you how the product is regulated.

Ask the vendor what regulatory category applies and what evidence supports the claims being made.

A therapist thinking about whether she should use AI for her work - The Passive Practice

A chatbot communicating directly with clients needs different scrutiny from a tool organizing nonclinical office tasks.

APA has issued separate guidance around generative AI chatbots used for mental and behavioral health, including concerns around safety, privacy, and consumers treating general-purpose AI as mental health support.

State regulation is changing too.

For example, Illinois Public Act 104-0054 restricts licensed professionals from allowing AI to make independent therapeutic decisions and places limits on direct AI involvement in therapeutic communication.

Utah's 2026 law also defines and regulates certain mental health chatbots that use generative AI to communicate in ways similar to confidential conversations with a licensed mental health therapist.

Those are examples, not a complete list of state rules.

If you practice across state lines, check the requirements that apply to your services rather than assuming one AI policy works everywhere.

For business uses, my article on marketing with AI covers ways therapists can use AI for public content without placing client material into prompts.

Separate Clinical AI From Business and Marketing AI

I would not review every AI product as if it carries the same risk.

Lower clinical exposure may include brainstorming general content ideas, editing public website copy, organizing nonclinical procedures, or drafting an agenda from information unrelated to clients.

Higher sensitivity may include uploading records, recording sessions, summarizing symptoms, interpreting tests, assessing risk, or recommending diagnoses and treatment.

The category can also change based on the information you enter.

A general writing tool becomes a privacy concern very quickly if someone pastes identifiable client information into it.

That distinction is similar to deciding what can be handled through outsourcing and what still requires your professional judgment.

Use This 10 Question AI Review Before You Buy

Before adding an AI tool to your psychology practice, ask:

  1. What exact task will this tool perform?

  2. Does it receive identifiable client information?

  3. Is PHI involved, and does HIPAA apply to this workflow?

  4. Is a BAA required, and will the vendor sign one?

  5. Does the tool record audio or create transcripts?

  6. How long does the vendor retain information?

  7. Can client information be used to train or improve models?

  8. What evidence supports the intended clinical use?

  9. Can I independently review the output before it affects care?

  10. Do state law, licensing rules, contracts, professional standards, or insurance requirements add anything else?

A vendor being unable to explain its retention policy, data use, or clinical evidence is useful information when you are deciding whether to buy.

A Practical Way to Introduce AI Into Your Practice

You do not need to begin by automating the most sensitive part of your work.

Start with a clearly defined task that does not require client information where possible.

For a solo practice, keep a short record of the product, its intended use, privacy terms, BAA if applicable, and the date you reviewed it.

For a group practice, create an approved tool list so staff knows which AI products may be used and what information may be entered. Train staff on the actual workflow, including what should never be copied into an unapproved AI system.

Review the product again when its features, privacy terms, data practices, or third-party vendors change.

You do not need a giant AI policy binder. You do need enough structure that people in the practice know what is allowed.

If you want help sorting out systems, delegation, and technology from the business side of private practice, business coaching can help you decide what needs your judgment and what can be streamlined.

Should Psychologists Use AI?

The better question is not whether psychologists should use AI at all.

It is whether a particular tool makes sense for a particular task, with the right privacy controls, evidence, consent process, professional oversight, and legal review.

AI may support documentation, administration, research, marketing, and some clinical tasks.

It does not remove the psychologist's responsibility for the professional service, the record, or the decision.

If AI is part of a larger effort to simplify your practice or improve how your business runs, explore private practice marketing, SEO and Content Strategy, or contact The Passive Practice to talk through your next steps.

FAQs About Psychologists Using AI

Can psychologists use AI in private practice?

Yes. Psychologists can use AI, but the appropriate safeguards depend on what the tool does, what information it receives, and which professional and legal rules apply. A writing assistant, AI scribe, decision support tool, and mental health chatbot should not be treated as the same use case.

Can psychologists use AI to write therapy notes?

AI can support documentation, but the clinician should understand whether the tool records sessions, where information is stored, how the vendor uses that information, whether a BAA is required, and how the final record is reviewed. HHS specifically identifies transcription app vendors handling PHI on behalf of providers as potential business associates.

Does an AI tool need to be HIPAA compliant?

If HIPAA applies and the vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity, business associate requirements may apply. Review the actual data flow and agreement rather than relying only on a vendor's marketing claim.

Do psychologists need client consent before using AI?

It depends on how AI is being used and what rules apply to that professional service. APA's AI guidance addresses informed consent and says psychologists should communicate the purpose, application, and potential benefits and risks when AI is incorporated into professional practice.

Can psychologists use AI for diagnosis or treatment planning?

AI may be used as clinical decision support in some settings, but these uses call for stronger evidence, independent professional review, and attention to regulatory requirements. Psychologists remain responsible for final decisions, and some clinical software functions may fall within FDA oversight. 

Previous
Previous

ChatGPT Ads for Private Practice: What This Means for Therapist Marketing

Next
Next

Content Marketing for Therapists: How to Build Trust and Attract the Right Clients