Agency Information Collection Activities: Proposed Collection; Public Comment Request: Information Collection Request Title: SAMHSA Data Security Requirements for Accessing Confidential Data (OMB No. 0930-0396)
Impact on your practice
Therapists and agencies receiving SAMHSA grants should monitor this data security requirement, as it may impose new compliance obligations for handling client records and program data. The final rule could affect documentation practices and IT infrastructure requirements.
Key facts
SAMHSA proposing new data security requirements for accessing confidential data
Information collection request under Paperwork Reduction Act review
Affects organizations receiving SAMHSA funding and handling sensitive behavioral health data
First notice for public comment; will advance to OMB for clearance
Therapy Companion analysis
If your practice or agency receives SAMHSA funding—whether through grants for substance use disorder treatment, mental health services, or research—you will face new data security compliance requirements. SAMHSA is currently seeking OMB approval (OMB No. 0930-0396) for an information collection that will formalize data security standards for accessing confidential client records and program data. This is not optional: organizations receiving SAMHSA funds must comply with federal data security requirements as a condition of funding. The practical impact centers on three areas: (1) IT infrastructure and access controls—you'll need to document and potentially upgrade systems that control who accesses client data, including encryption, authentication protocols, and audit logging; (2) staff training and credentialing—your team will need documented training on data security protocols, with records maintained for compliance verification; (3) documentation burden—you'll be required to maintain detailed records of data access, security incidents, and remediation efforts. The compliance timeline matters: SAMHSA is in the public comment phase (ending October 13, 2026), followed by OMB clearance. Once approved, implementation deadlines will follow. Smaller solo practices and community mental health centers receiving SAMHSA grants face the highest operational burden, as they typically lack dedicated IT and compliance staff. Larger agencies with existing security infrastructure will absorb costs more easily, but all organizations will incur documentation and training expenses.
Background
SAMHSA has long required grantees to protect client confidentiality under 42 CFR Part 2 (the federal substance use disorder confidentiality rule) and HIPAA. However, enforcement has been inconsistent, and data breaches involving behavioral health records have increased significantly over the past five years. This information collection request represents SAMHSA's effort to standardize and strengthen data security requirements across all funded programs. The Paperwork Reduction Act requires federal agencies to seek public comment and OMB approval before imposing new information collection burdens on the public. By framing this as an 'information collection,' SAMHSA is signaling that organizations will need to collect, maintain, and report data security compliance information—a shift from voluntary best practices to mandatory documentation. This aligns with broader federal trends toward stricter behavioral health data protection, driven by increased telehealth adoption, remote work, and high-profile breaches in the mental health sector.
What you should do
Determine your SAMHSA funding status immediately: Review all current grants, contracts, and cooperative agreements with SAMHSA or SAMHSA-funded intermediaries. If you receive any SAMHSA funding, you will be subject to these requirements once finalized. Document your funding sources and amounts for compliance tracking.
Submit public comments by October 13, 2026: If you operate a SAMHSA-funded program, submit comments to Regulations.gov (document 2026-16531) describing the operational and financial burden of the proposed requirements. Include specific costs for IT upgrades, staff training, and documentation systems. Collective feedback from practitioners shapes the final rule.
Audit your current data security practices now: Conduct an inventory of systems that store or access client data (EHRs, billing systems, file servers, cloud storage). Document current access controls, encryption status, user authentication methods, and audit logging capabilities. Identify gaps before compliance deadlines are announced.
Develop a data security compliance plan: Create a written policy addressing access controls, staff training, incident reporting, and audit procedures. Assign responsibility for data security oversight (even if outsourced to IT vendors). This demonstrates good-faith compliance preparation and reduces liability.
Budget for IT and training costs: Estimate expenses for encryption upgrades, multi-factor authentication implementation, staff training programs, and documentation systems. Include these in your 2027 budget planning. Seek technical assistance from SAMHSA or your state mental health authority if available.
Notable excerpts
"Agency Information Collection Activities: Proposed Collection; Public Comment Request: Information Collection Request Title: SAMHSA Data Security Requirements for Accessing Confidential Data (OMB No. 0930-0396)" — Federal Register Notice 2026-16531, indicating SAMHSA is formalizing data security requirements for organizations accessing confidential behavioral health data.
"Written comments should be received by October 13, 2026" — Federal Register Notice 2026-16531, establishing the deadline for public comment on the proposed data security information collection.
View full source text
Policy changes drive denial patterns
Therapy Companion tracks both: the policy shifts on this page and the denial patterns hitting your claims.
Related policy changes
STAT+: Trump administration quietly picks Timothy Westlake to lead mental health agency
SAMHSA leadership directly impacts federal funding streams, clinical guidance, and regulatory priorities that affect therapists nationwide. Westlake's background in addiction policy signals potential shifts in how SAMHSA allocates resources and develops clinical standards.
[OK] HB1911: Mental health; definitions; 988 Suicide and Crisis Lifeline System; administrative structure; evaluation; workforce retention; trust fund; telecommunication fee; maximization of federal funding; effective date.
This bill addresses the operational backbone of Oklahoma's 988 system with emphasis on workforce stability and federal funding leverage. For therapists, stable 988 infrastructure and workforce retention means more reliable crisis response for clients and potential partnership opportunities. The federal funding maximization language suggests the state is actively pursuing SAMHSA grants and other federal resources.
[OK] HB4092: 988 Mental Health Lifeline; terms; Department of Mental Health and Substance Abuse Services; suicide prevention and crisis service activities; performance and clinical standards; promulgation of rules; 988 Lifeline Revolving Fund; purpose; funding; enforcement; effective date.
While this bill primarily affects crisis centers and 988 infrastructure rather than direct therapy practice, it signals state investment in crisis services that may create referral pathways and reduce emergency department burden for therapists' clients. The funding mechanism and performance standards could influence how crisis services coordinate with outpatient mental health providers.
HHS clears 2 peer support programs for federal foster care funding
This expands federal funding pathways for peer support-based interventions in child welfare and family services. Therapists working in family-based treatment, substance use, or child welfare may see increased referrals or partnership opportunities as states adopt these programs, though direct reimbursement impact is limited.