Home > Is a Prospective Client’s Inquiry Protected Health Information?

Is a Prospective Client’s Inquiry Protected Health Information?

Close-up of a person completing an intake form on a clipboard, the point where inquiry information becomes protected health information

In most cases, yes. Once a covered entity receives an inquiry attached to identifying information, that inquiry generally qualifies as protected health information under HIPAA. The person does not have to become a client first.

What makes information PHI?

HIPAA defines protected health information as individually identifiable information, held or transmitted by a covered entity or business associate, that relates to a person’s past, present, or future physical or mental health condition, the provision of health care to that person, or payment for that care.

Two parts of that definition do the work here. The information has to identify someone, and it has to relate to health or the provision of health care.

Does it count if the person never becomes a client?

Yes. The definition covers the future provision of health care, which is exactly what a prospective client is asking about. Someone who calls a behavioral health practice to ask about availability has not received care. They are inquiring about receiving it, and that falls inside the definition.

This surprises a lot of practice owners, because operationally the person feels like a stranger until they schedule. Legally, the clock started when the inquiry arrived.

What if they only left a name and a phone number?

That is usually enough. The name is the identifier. The context supplies the rest, because the person contacted a behavioral health provider seeking care, and that fact by itself suggests something about their health.

This is why behavioral health sits in a tighter position than most other specialties. In a general medical context, the fact that someone contacted a provider reveals relatively little. In behavioral health, the specialty is the diagnosis-adjacent detail.

What about website analytics and ad tracking?

This is the genuinely contested area and it deserves a careful answer.

The Office for Civil Rights issued guidance on online tracking technologies in December 2022 and revised it in March 2024. In June 2024, a federal court vacated part of that guidance as it applied to unauthenticated public web pages. The legal picture has continued to move since.

Anything a practice builds in this area should be checked against the current standing of that guidance rather than against an article summarizing where things stood a year ago.

What about substance use disorder programs?

42 CFR Part 2 applies on top of HIPAA and is stricter. It carries its own consent requirements, and the differences are meaningful enough that a Part 2 program should not assume HIPAA-compliant practices are sufficient.

What does this mean practically?

Three things. Inquiries need to be stored somewhere with appropriate safeguards, which for most practices means something other than a shared inbox or a spreadsheet on a desktop. Any vendor that touches that data needs a business associate agreement. And what can be sent back to an advertising platform is constrained by all of the above.

This is general information and not legal advice. A practice making decisions about how it stores or transmits inquiry data should have those decisions reviewed by counsel familiar with health privacy law.

Prefer to Listen? Tune into The Beacon Way Podcast

On The Beacon Way, Adrienne Wilkerson, CEO and co-founder of Beacon, connects with entrepreneurs and business leaders who share what it really takes to build and lead.