Patient Confidentiality in Psychotherapy in an Age of Autonomous AI Agent Attacks
Disclaimer: This article is 100% old fashioned human thought. No generative AI was used in its creation, including writing, editing and fact checking.
The views expressed here are mine and mine alone.
TLDR; The assumption of confidentiality in psychotherapy is changing. Clinical information may be becoming less secure where it is internet adjacent. The problem is not new, your information has always been valuable and sacred. The threat balance may be shifting from Social Engineering to Autonomous AI Agents.
For patients, asking your therapist and considering how your information is stored and handled may be increasingly prudent.
For therapists, considering record keeping practices that balance the security of sensitive information with the convenience of internet facing handling and storage are increasingly important. This consideration might include if information is to leave your hands through auditing or legal processes.
Finally, there may be some cool things which come about when we go back to some of the older ways of doing things, too.
This article is organised around a central question:
How might we best approach patient confidentiality in psychotherapy regarding record keeping and correspondence when we can no longer assume that internet adjacent information is confidential?
To place this article in time, I am writing at the end of September 2026. A few days ago, the Australian Federal Government announced that data thought to be secured by Medicare was breached by OpenAI’s AI Agents. At this time, the Australian Federal Government is saying no patient data was accessed, however, there are conflicting reports and the scope of the attack remains unclear. What does appear clear is that this breach was benign and was not aimed at harming anyone. Beyond the embarrassment this event has caused, so what?
The data breach here illustrates that patient information we had thought to be stored on secured systems may in fact be vulnerable to external access as Autonomous AI Agents become more capable and lower in cost. This event prompted me to consider my existing information security measures and share publicly my thoughts and practices with patients and other therapists alike.
What is confidentiality and why does it matter?
Confidentiality is the assumption between therapist and patient that ensures information shared in therapy will not be repeated BY THE THERAPIST without the express permission of the patient. A patient should be free to share any information the therapist shares, and therapists should keep this in mind when considering therapeutic self-disclosure. Group therapy extends these assumptions and requires that all patients privilege each other’s confidentiality and weigh that other group participants do not have the same ethical and professional consequences for failing to maintain confidentiality as the therapist does. There are special legal and ethical limits to confidentiality, and good therapists will always advise you of these at the outset of therapy, and, when entering into a discussion which approaches the limits of confidentiality.
This next claim is broad, and not strictly true, but it serves our purposes and brevity requirements here. Depth-oriented psychotherapies are not possible without a level of confidentiality which is satisfactory to the patient. Here, depth-oriented means psychotherapies which are concerned with matters greater than symptomatic relief and seek to address underlying processes. As an aside and though not exhaustive, a good rule of thumb for assessing whether a therapist has a depth orientation is their level of comfort with questions which revolve around “Why”. These disciplines require a therapeutic relationship where the patient can trust that things which they would not ordinarily speak are honored and safe. Those more developed in the symptomatic orientations may hold other views about requirement for confidentiality and their practice.
What can patients ask their therapists with regard to confidentiality and information security?
For some readers, this will be news. You are allowed to ask your therapist questions. If you want to discuss aspects of a problem with your therapist, and, you would be concerned with those aspects becoming public through a data breach – here are a half a dozen questions which may open a productive conversation:
- What kind of records do you keep?
- Could we please discuss exactly what is recorded and how it is recorded, when considering recording particularly sensitive information?
- What options are available to me in how you store my information?
- How does your correspondence with my GP or Psychiatrist work?
- How would you become aware of a data breach, and, how would you let me know?
- In the event my information is released without my permission, what steps should we take to address my safety and protect my personal information?
What did a decade of practice in Specialist Public Mental Health teach me about this problem and general approaches to note keeping?
I probably have to be careful about what I say here, so I’ll keep to the public facing facts and generalities. I have historically viewed the risk of breaches to patient information as mostly from two angles. The most likely being mishandling during a bureaucratic process. The second being a Social Engineering attack, where criminal elements produce or gain compromising information on someone else with access to a secure system be it in Services Australia, Medicare, State Health Departments, Police, etc., and coerce that employee into accessing and releasing information. A distant third was an organised Cyber Attack, and if that were the case, it seemed more likely that those elements would hold system access to ransom than they would access and distribute patient information.
This data breach changed my mind.
As AI models become more capable, more autonomous and more accessible, the risk of information through benign and nefarious AI Agent hacks increases. This trend has a disturbing consequence, namely, that information therapists had previous and in good faith thought to be stored in secure systems becomes more likely to one day result in a breach of confidentiality.
Early in my career, I received a piece of advice that has stuck with me. Once you enter information into a database, be it a clinical note, assessment or correspondence, you have no control over who will access it or how it will be used in the future. If you pay the observation its warranted attention, you may quickly realise that good clinical record keeping and more clinical record keeping are not the same thing. To qualify, I am not saying that information stored in various EHRs will be misused, only that it is out of the hands of the author once it is there. This led me to develop two axioms for record keeping:
- Write nothing which you would not sit and read together with the people which it concerns.
- Patient information belongs to the patient; therapists are merely responsible for the stewardship of it.
What are my current practices on confidentiality and information security?
Frankly, I don’t like this section. It feels like a list, however, here I will share some of my current practices in balancing convenience and security. I hope they act as food for thought for other therapists considering where information is stored and where it travels. All of our practices are different, having different expectations and orientations. Every method of information storage has its own inherent strengths and vulnerabilities. My answers so far are unlikely to be your answers, but broadly, I think our questions are similar.
My default position is to keep as much information as physical and handwritten as is practical, given billing and correspondence requirements. So how does this work in practice?
In private practice:
Referrals usually arrive via:
- Phone Call
- Email from a prospective patient
- Email from another clinician, GP or Psychiatrist with password protected PDF
- Secure Electronic Messaging System (SEMS) from another clinician, GP or Psychiatrist.
From here I direct contact through phone calls or face-to-face discussions. Emailing is generally for administrative matters.
On my Electronic Health Record (EHR), I keep only contact, billing and attendance information.
Session Notes are strictly handwritten and filed.
Professional Correspondence is typed and sent via post, emailed via password protected PDF or through SEMS
Closing Thought
Our older practices can both manage for cyber security risks and make for beautiful possibilities. Some of my most cherished possessions as a therapist are patients’ handwritten letters to me which came about as replies to my therapeutic letters to them.
Maybe scoping out a little we can see that defensive practice here risks turning therapeutic information into data. It isn’t. It is one of the residuals left by two or more human beings working together on a problem. Sometimes I think we forget that. Maybe that matters more, and events like this inadvertently reveal to us that which has been misplaced.
So, I’ll close here with a question oriented toward what is possible, which we may do well to discuss:
“Given the state of things, what might we once again find if we return to practices that we have since discarded in the interest of expedience?”
