16 CCR § 1815.5, amended · effective 1 January 2026 · read 16 August 2026
The telehealth rule changed in January. Almost nothing you think changed, changed.
In short
What are the telehealth rules for California therapists in 2026?
The two subdivisions that actually changed, the decade-old duty most people think is new, and what the named Security Rule asks of a solo practice
2 subdivisions changed; the rest dates to 2016Two subdivisions of the telehealth standard of practice were amended effective 1 January 2026, and one of them is a single added word. The duty people describe as the new one — verbally taking the client’s full name and present location at the start of every session — has been in force since 1 July 2016. Here is the amendment, and then the section as it actually reads.
What changedWhat did notEvery sessionAt intakeClients elsewhereThe security standardSources
The amendment, in full
One added word, and one added duty.
The Board’s rulemaking was approved by the Office of Administrative Law on 19 August 2025 and took effect on 1 January 2026. The adopted text attached to the Notice of Approval changes the section in exactly these places.
The licensure requirement for treating a client physically located in California now reads “a valid and current and active license or registration issued by the Board”. A registration that has lapsed or gone inactive was never a basis for practice; the word closes the gap on paper.
The industry-best-practices duty is kept, not replaced — a point worth being exact about, because the amendment is often described as a swap. What follows it is new: a duty to comply with the privacy, confidentiality and security laws governing a client’s medical information and protected health information, with two of them named. Those two are the Confidentiality of Medical Information Act and HIPAA’s security standards at 45 C.F.R. §§ 164.302 through 164.318.
“He or she” becomes “they” in subdivisions (c)(3) and (d). Nothing about the duties themselves moves with it.
That is the entire amendment. The Board’s own Final Statement of Reasons, which answers the comments the rulemaking drew, discusses nothing but the privacy and security language — no session documentation, no consent, no jurisdiction. If a duty is not in the three items above, it did not arrive in January.
The correction
The duty you think is new is a decade old.
The requirement being circulated as the January change is subdivision (d)(1): verbally obtain from the client, and document, the client’s full name and address of present location, at the beginning of each telehealth session. It is not new. It is in the text the Board adopted in 2016, word for word, and that section took effect on 1 July 2016. The 2025 rulemaking did not amend it, and the Final Statement of Reasons does not mention it.
Subdivision (d)(1), unchanged since 2016
“Verbally obtain from the client and document the client’s full name and address of present location, at the beginning of each telehealth session.”
The same is true of subdivision (e), the one about clients located in another jurisdiction. It is sometimes described as a 2026 clarification. It is in the 2016 adopted text as well.
Which is a more uncomfortable finding than a new rule would be. A new rule is something to start doing. A ten-year-old rule that a lot of practices have not been following is something to reconcile — and unprofessional conduct under subdivision (f) does not distinguish between the two.
Subdivision (d) · every single session
Three things, every time, not once at the start of the work.
Subdivision (d) is written as a per-session duty — “each time a licensee or registrant provides services via telehealth” — which is what separates it from the intake list below.
Both halves matter and both are commonly half-done. It is not enough to know where the client lives; the duty is the address of the location they are in right now, taken out loud, and written down. From 2016, not 2026.
Explicitly including, in the regulation’s own words, consideration of the client’s psychosocial situation. It is a per-session judgment, not an intake screen that carries forward untouched.
The confidentiality and security of the communication medium, plus the compliance duty described in the security section below.
Subdivision (c) · on initiation
Four things when the telehealth work begins.
The regulation borrows the statute’s consent standard rather than writing its own, so the statute is the thing to read for what consent has to cover and how it is documented.
Separate from consent in the text, and separate in practice: a signature on a consent form is not by itself a record that the risks were described.
The number and the type. For an associate that means the registration number and the fact that it is a registration — the same distinction the advertising rule turns on.
The regulation asks for the documented effort, in the client’s geographic area — which is the reason the per-session location duty in (d)(1) exists at all. If the client moves between sessions, the resources you documented may no longer be theirs.
Subdivision (e) · not new
A client outside California is the other state’s question.
Subdivision (e): a California licensee or registrant may provide telehealth services to a client located in another jurisdiction only if they meet that jurisdiction’s requirements to provide services lawfully there, and telehealth delivery is allowed there. California’s permission is not the operative one. The other state’s is, and California enforces the answer through subdivision (f).
Two different questions, and people run them together
Where the client is decides which state’s practice act applies. That is this page, and subdivision (a) and (e) answer it.
Where you are sitting decides something else entirely, and for an associate it decides whether the hours count. No California statute addresses it. That question is worked in full on the out-of-state hours page.
The one real change
What naming the Security Rule actually asks of a solo practice.
Before January, (d)(3) asked for “industry best practices” — a standard with no citation behind it, which is exactly the objection the Board answered. It now also points at two named bodies of law. Neither is new law; what is new is that failing them is now unprofessional conduct in front of the Board, not only a matter for the agencies that enforce them.
Civil Code part 2.6, beginning at § 56, with respect to a client’s medical information as § 56.05 defines it. California’s own confidentiality statute, which applies to a great many practices that are not HIPAA covered entities.
45 C.F.R. §§ 164.302 through 164.318 — the Security Rule, and only the Security Rule. The Privacy Rule is not what the regulation names here.
Subpart C is short, and it is organized into four groups plus a documentation duty. In the order the regulations run: the general rules and the flexibility-of-approach standard at § 164.306; administrative safeguards at § 164.308, which is where the required risk analysis and risk management live, along with workforce training, incident procedures and contingency planning, and at (b) the requirement that a business associate give satisfactory written assurances; physical safeguards at § 164.310; technical safeguards at § 164.312, whose five standards are access control, audit controls, integrity, authentication and transmission security; organizational requirements including the contract terms themselves at § 164.314; and policies, procedures and documentation at § 164.316.
The questions this makes concrete
- Is there a written risk analysis for the practice, or only an assumption that the platform handles it? § 164.308(a)(1) asks for the analysis by name.
- Is there a signed business associate agreement with the video platform, the electronic record, the billing service and the transcription tool — each of them, not the one that was easiest to get?
- Do the written policies and procedures exist as documents, and are they retained? § 164.316 is a documentation standard, and documentation is the part a one-person practice most often skips.
- If a client is in another state, does that state’s law reach further than California’s — and have you checked, given that subdivision (e) makes their rules the ones that decide?
A note on what this page will not tell you: whether a particular platform satisfies any of this. Vendors describe themselves as HIPAA compliant, and that phrase has no regulatory meaning on its own — the duties above attach to the practice, and the agreement with the vendor is one of them, not a substitute for the rest.
Where every figure came from
Sources.
The 2025 rulemaking - approved 19 August 2025, effective 1 January 2026, read 16 August 2026
The 2016 baseline, which is where most of the section actually comes from
- The adopted text of § 1815.5 as filed in 2016 - carries the per-session name and location duty and the out-of-state subdivision
- The 2016 Notice of Approval, effective 1 July 2016
- 16 CCR § 1815.5 at Cornell - accurate as the 2016 baseline; it had not been updated for the 2026 amendment when this page was written
The law the section points at
- Business and Professions Code § 2290.5 - the telehealth definition and the consent standard subdivision (c)(1) borrows
- Civil Code § 56.05 - the definition of medical information under the Confidentiality of Medical Information Act
- 45 C.F.R. § 164.306 - general rules and flexibility of approach
- 45 C.F.R. § 164.308 - administrative safeguards, including the risk analysis and the business associate requirement
- 45 C.F.R. § 164.310 - physical safeguards
- 45 C.F.R. § 164.312 - technical safeguards
- 45 C.F.R. § 164.314 - organizational requirements and business associate contract terms
- 45 C.F.R. § 164.316 - policies, procedures and documentation
This page restates a regulation and the Board's own rulemaking record; it adds no requirements of its own and it is not legal advice. Where a source disagrees with a summary you have read elsewhere, the Board's adopted text is the authority. Anything turning on your specific platform, your specific records, or a client in a specific other state is a question for a lawyer who practices in this area, not for a web page.