Written forcounting hours → · licensed →

16 CCR § 1815.5, amended · effective 1 January 2026 · read 16 August 2026

The telehealth rule changed in January. Almost nothing you think changed, changed.

In short

What are the telehealth rules for California therapists in 2026?

The two subdivisions that actually changed, the decade-old duty most people think is new, and what the named Security Rule asks of a solo practice

2 subdivisions changed; the rest dates to 2016

Two subdivisions of the telehealth standard of practice were amended effective 1 January 2026, and one of them is a single added word. The duty people describe as the new one — verbally taking the client’s full name and present location at the start of every session — has been in force since 1 July 2016. Here is the amendment, and then the section as it actually reads.

2subdivisions the 2026 amendment touched
1 Jul 2016when the per-session duty began
§§ 164.302–.318the security rule now named in the regulation
0new duties in subdivision (c) or (e)

What changedWhat did notEvery sessionAt intakeClients elsewhereThe security standardSources

The amendment, in full

One added word, and one added duty.

The Board’s rulemaking was approved by the Office of Administrative Law on 19 August 2025 and took effect on 1 January 2026. The adopted text attached to the Notice of Approval changes the section in exactly these places.

1Subdivision (a) gains “and active”.

The licensure requirement for treating a client physically located in California now reads “a valid and current and active license or registration issued by the Board”. A registration that has lapsed or gone inactive was never a basis for practice; the word closes the gap on paper.

2Subdivision (d)(3) gains a second sentence.

The industry-best-practices duty is kept, not replaced — a point worth being exact about, because the amendment is often described as a swap. What follows it is new: a duty to comply with the privacy, confidentiality and security laws governing a client’s medical information and protected health information, with two of them named. Those two are the Confidentiality of Medical Information Act and HIPAA’s security standards at 45 C.F.R. §§ 164.302 through 164.318.

3The pronouns are modernized.

“He or she” becomes “they” in subdivisions (c)(3) and (d). Nothing about the duties themselves moves with it.

That is the entire amendment. The Board’s own Final Statement of Reasons, which answers the comments the rulemaking drew, discusses nothing but the privacy and security language — no session documentation, no consent, no jurisdiction. If a duty is not in the three items above, it did not arrive in January.

The correction

The duty you think is new is a decade old.

The requirement being circulated as the January change is subdivision (d)(1): verbally obtain from the client, and document, the client’s full name and address of present location, at the beginning of each telehealth session. It is not new. It is in the text the Board adopted in 2016, word for word, and that section took effect on 1 July 2016. The 2025 rulemaking did not amend it, and the Final Statement of Reasons does not mention it.

Subdivision (d)(1), unchanged since 2016

“Verbally obtain from the client and document the client’s full name and address of present location, at the beginning of each telehealth session.”

The same is true of subdivision (e), the one about clients located in another jurisdiction. It is sometimes described as a 2026 clarification. It is in the 2016 adopted text as well.

Which is a more uncomfortable finding than a new rule would be. A new rule is something to start doing. A ten-year-old rule that a lot of practices have not been following is something to reconcile — and unprofessional conduct under subdivision (f) does not distinguish between the two.

Subdivision (d) · every single session

Three things, every time, not once at the start of the work.

Subdivision (d) is written as a per-session duty — “each time a licensee or registrant provides services via telehealth” — which is what separates it from the intake list below.

1Name and present location, verbally, and documented.

Both halves matter and both are commonly half-done. It is not enough to know where the client lives; the duty is the address of the location they are in right now, taken out loud, and written down. From 2016, not 2026.

2Assess whether the client is appropriate for telehealth.

Explicitly including, in the regulation’s own words, consideration of the client’s psychosocial situation. It is a per-session judgment, not an intake screen that carries forward untouched.

3Industry best practices for telehealth — and, since January, named privacy law.

The confidentiality and security of the communication medium, plus the compliance duty described in the security section below.

Subdivision (c) · on initiation

Four things when the telehealth work begins.

1Informed consent under Business and Professions Code § 2290.5.

The regulation borrows the statute’s consent standard rather than writing its own, so the statute is the thing to read for what consent has to cover and how it is documented.

2Inform the client of the risks and limitations of treatment by telehealth.

Separate from consent in the text, and separate in practice: a signature on a consent form is not by itself a record that the risks were described.

3Give the client your number and the type of license or registration.

The number and the type. For an associate that means the registration number and the fact that it is a registration — the same distinction the advertising rule turns on.

4Document reasonable efforts to find emergency resources in the client’s area.

The regulation asks for the documented effort, in the client’s geographic area — which is the reason the per-session location duty in (d)(1) exists at all. If the client moves between sessions, the resources you documented may no longer be theirs.

Subdivision (e) · not new

A client outside California is the other state’s question.

Subdivision (e): a California licensee or registrant may provide telehealth services to a client located in another jurisdiction only if they meet that jurisdiction’s requirements to provide services lawfully there, and telehealth delivery is allowed there. California’s permission is not the operative one. The other state’s is, and California enforces the answer through subdivision (f).

Two different questions, and people run them together

Where the client is decides which state’s practice act applies. That is this page, and subdivision (a) and (e) answer it.

Where you are sitting decides something else entirely, and for an associate it decides whether the hours count. No California statute addresses it. That question is worked in full on the out-of-state hours page.

The one real change

What naming the Security Rule actually asks of a solo practice.

Before January, (d)(3) asked for “industry best practices” — a standard with no citation behind it, which is exactly the objection the Board answered. It now also points at two named bodies of law. Neither is new law; what is new is that failing them is now unprofessional conduct in front of the Board, not only a matter for the agencies that enforce them.

1The Confidentiality of Medical Information Act.

Civil Code part 2.6, beginning at § 56, with respect to a client’s medical information as § 56.05 defines it. California’s own confidentiality statute, which applies to a great many practices that are not HIPAA covered entities.

2HIPAA’s security standards, Subpart C.

45 C.F.R. §§ 164.302 through 164.318 — the Security Rule, and only the Security Rule. The Privacy Rule is not what the regulation names here.

Subpart C is short, and it is organized into four groups plus a documentation duty. In the order the regulations run: the general rules and the flexibility-of-approach standard at § 164.306; administrative safeguards at § 164.308, which is where the required risk analysis and risk management live, along with workforce training, incident procedures and contingency planning, and at (b) the requirement that a business associate give satisfactory written assurances; physical safeguards at § 164.310; technical safeguards at § 164.312, whose five standards are access control, audit controls, integrity, authentication and transmission security; organizational requirements including the contract terms themselves at § 164.314; and policies, procedures and documentation at § 164.316.

The questions this makes concrete

  • Is there a written risk analysis for the practice, or only an assumption that the platform handles it? § 164.308(a)(1) asks for the analysis by name.
  • Is there a signed business associate agreement with the video platform, the electronic record, the billing service and the transcription tool — each of them, not the one that was easiest to get?
  • Do the written policies and procedures exist as documents, and are they retained? § 164.316 is a documentation standard, and documentation is the part a one-person practice most often skips.
  • If a client is in another state, does that state’s law reach further than California’s — and have you checked, given that subdivision (e) makes their rules the ones that decide?

A note on what this page will not tell you: whether a particular platform satisfies any of this. Vendors describe themselves as HIPAA compliant, and that phrase has no regulatory meaning on its own — the duties above attach to the practice, and the agreement with the vendor is one of them, not a substitute for the rest.

Where every figure came from

Sources.

This page restates a regulation and the Board's own rulemaking record; it adds no requirements of its own and it is not legal advice. Where a source disagrees with a summary you have read elsewhere, the Board's adopted text is the authority. Anything turning on your specific platform, your specific records, or a client in a specific other state is a question for a lawyer who practices in this area, not for a web page.

Verified to source

Every figure on this page was re-checked against the statute, schedule or filing it cites.

Where you are on the path

This page is written for two stages of the path.

  • counting hoursThe telehealth rule as it actually reads - including the per-session duty that started in 2016, not January. All 26 for this stage →
  • licensedWhat the 1 January 2026 amendment changed (two subdivisions) and what it did not - plus what naming the Security Rule asks of a solo practice. All 13 for this stage →

You should not have to work this part out on your own.

Once a month: free tools and apps worth having, better ways to run the admin side of a practice, what other California therapists are actually doing, and anything new here that might save you an afternoon.

About monthly. One click to leave. Never sold, never shared. The consent box is separate and unticked because California requires it — and because it should be.