When a Client Threatens You: What HIPAA Actually Allows You to Report
A supervisor's or clinician's guide to reporting crimes, threats, or stalking by a client — grounded in the federal Privacy Rule.
The scenario clinicians don't talk about enough
Most HIPAA training focuses on protecting the client. Almost none of it addresses what happens when the client is the one causing harm — to you, your practice, or your home. A client threatens you during a session. A former client shows up outside your office. Someone starts following you home, sending unwanted messages, or making veiled threats against your family.
In that moment, a lot of clinicians freeze on the wrong question: "Can I even talk to the police about this? Isn't that a HIPAA violation?"
The short answer: HIPAA was never designed to protect a client's right to threaten, stalk, or assault their provider. The Privacy Rule builds in specific, narrow exceptions for exactly this kind of situation. Below is what the regulation actually says, sourced directly from the U.S. Department of Health & Human Services (HHS) Office for Civil Rights (OCR) — the federal agency that enforces HIPAA — along with the related legal doctrine (Tarasoff) that supervisors should be teaching alongside it.
This is educational information, not legal advice. State law varies and can be more protective of clients than HIPAA's federal floor. Consult your malpractice carrier, licensing board, or an attorney licensed in your state before acting on any of this.
1. HIPAA already has a "provider as crime victim" exception
This is the one most clinicians have never heard of, and it's the most directly relevant.
Under 45 CFR § 164.502(j)(2), a covered entity may report a suspected perpetrator of a crime to law enforcement when the report is made by a victim who is a member of the covered entity's workforce. HHS's own guidance confirms that this "same limited information" reporting pathway applies specifically to situations where a workforce member — which includes the treating clinician — is the victim of a crime committed by a patient.
In plain terms: if a client commits a crime against you personally (assault, threats, harassment, stalking, property damage, breaking and entering, etc.), HIPAA does not require you to stay silent to protect that client's confidentiality. You are permitted to report what you experienced to law enforcement as a victim, using limited identifying information about the perpetrator (name, description, and similar identifiers), without a signed authorization from the client.
2. Reporting a serious, imminent threat to health or safety
45 CFR § 164.512(j)(1)(i) permits disclosure — including to law enforcement or to the target of the threat — when a provider believes in good faith that disclosure is:
necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public;
made to someone reasonably able to prevent or lessen that threat, which can include the intended target; and
consistent with applicable law and professional ethical standards.
A provider is presumed to be acting in good faith if the belief is based on their own direct knowledge or a credible representation from someone else with apparent knowledge. This provision covers threats a client makes against you, but it also covers threats made against a third party — a coworker, a family member, or anyone else who becomes a named target during treatment.
This is the HIPAA-side counterpart to the duty to warn / duty to protect doctrine that originated in the 1976 California Supreme Court case Tarasoff v. Regents of the University of California. That case established that when a patient discloses a credible, specific threat against an identifiable person, a treating clinician's obligation to protect public safety can override confidentiality. Most states have since adopted some version of a Tarasoff-style statute defining exactly when and how a clinician must warn a victim, notify police, or take other protective steps — but the details (who must be warned, what threshold triggers it, whether it's mandatory or permissive) vary significantly by state. Supervisors should have supervisees check their specific state statute rather than assume California's rule applies everywhere.
3. Crimes committed on your premises
45 CFR § 164.512(f)(5) allows a covered entity to report protected health information that it believes in good faith is evidence of a crime that occurred on the covered entity's premises. If a client commits an act on-site — vandalizes your office, assaults staff, threatens someone in your waiting room — this provision lets you report what happened to law enforcement without needing the client's authorization first.
4. Off-site emergencies
45 CFR § 164.512(f)(6) covers a narrower scenario: when a provider is responding to a medical emergency that occurs off their premises, they may alert law enforcement about the nature of a crime, its location, and the identity or description of the perpetrator. (This provision has a carve-out: it does not apply if the provider believes the person needing emergency care is themselves a victim of abuse, neglect, or domestic violence — that scenario is governed by a separate provision, 45 CFR § 164.512(c).)
5. When state or federal law simply requires it
45 CFR § 164.512(f)(1)(i) permits — and where applicable requires — disclosure to comply with other laws. Many states have mandatory reporting statutes covering things like gunshot or stab wounds, workplace violence incidents, or threats against public employees. If your state has a statute requiring or authorizing a report in your situation (e.g., an anti-stalking law, a workplace violence reporting requirement), HIPAA explicitly steps aside to let you comply with it.
6. Escaped/fugitive and identification provisions
Two narrower law-enforcement provisions round out the picture:
45 CFR § 164.512(j)(1)(ii)(B) — disclosure to identify or apprehend someone who appears to have escaped from lawful custody.
45 CFR § 164.512(f)(2) — limited identifying information (name, address, date of birth, distinguishing physical characteristics, etc. — not full clinical records) can be disclosed in response to a law enforcement request to locate or identify a suspect, fugitive, witness, or missing person.
These matter less often for a stalking-by-client scenario but are useful if a client who has threatened you is also wanted or being sought by police.
What HIPAA does not give you
It's worth being precise about the limits, since overreach creates its own liability:
These are permissive exceptions, not blanket authorizations. Except where state law makes a report mandatory, HIPAA generally allows disclosure — it doesn't obligate you to disclose your client's full clinical record. You still owe a minimum necessary standard: share only what's needed for the law enforcement purpose (45 CFR §§ 164.502(b), 164.514(d)).
Full treatment notes are not automatically fair game. The provisions above are built around limited identifying or safety-relevant information, not an open door to your entire chart. Psychotherapy notes carry even stronger protection under HIPAA and generally require separate authorization.
You should still verify who you're talking to. If a law enforcement request comes from someone the practice doesn't already know, HIPAA requires verifying their identity and authority before disclosing (45 CFR § 164.514(h)).
State law can be stricter than HIPAA. HIPAA sets a federal floor, not a ceiling. Some states impose additional confidentiality protections on mental health records specifically, which can narrow what you're allowed to share even where HIPAA would permit it.
A practical checklist for supervisors and supervisees
When a client commits, threatens, or appears to be committing a crime against you, your practice, or your home:
Prioritize immediate safety first. Call 911 if there's an active or imminent threat — safety decisions don't wait on a HIPAA analysis.
Identify which exception applies to what you're about to disclose: are you reporting as a crime victim (164.502(j)(2)), warning of an imminent threat (164.512(j)), reporting an on-premises crime (164.512(f)(5)), or complying with a state mandatory-reporting law (164.512(f)(1)(i))?
Disclose the minimum necessary. Stick to identifying details and the facts relevant to the threat or crime — not the client's full clinical history.
Document your rationale in writing, contemporaneously: what you disclosed, to whom, under which provision, and why you believed disclosure was necessary.
Check your state's specific statute on duty to warn/protect and any mandatory reporting laws — HIPAA is the federal floor, and your state's rule may add requirements HIPAA doesn't mention.
Loop in your supervisor, licensing board consult line, or attorney before broader disclosures beyond what's needed for an immediate safety report, especially where the situation is ambiguous.
The bottom line
Confidentiality exists to protect the therapeutic relationship — not to leave clinicians unprotected when a client crosses the line into criminal conduct against them. HIPAA's drafters anticipated this exact conflict and built in exceptions for it. Supervisors should be walking supervisees through these provisions before a crisis happens, not during one.
SourcesU.S. Department of Health & Human Services, Office for Civil Rights, "When does the Privacy Rule allow covered entities to disclose protected health information to law enforcement officials?" — HHS.gov45 CFR § 164.502(j)(2); § 164.512(f); § 164.512(j); § 164.514(d) and (h) — Code of Federal Regulations, ecfr.govTarasoff v. Regents of the University of California, 17 Cal. 3d 425 (1976); overview via NCBI Bookshelf, National Library of Medicine, StatPearls, "Duty to Warn"University of Minnesota Open Textbook Library, Ethical Practice in a Culturally Diverse Society, Ch. 7.10, "Duty to Warn/Duty to Protect"
This post is for general educational purposes for licensed clinicians and supervisors. It is not legal advice. Consult your state licensing board, malpractice carrier, or a healthcare attorney in your jurisdiction for guidance on a specific situation.