Drafting Between-Session Communication Inside HIPAA Boundaries
It is 7:40 on a Wednesday morning and Maria has eleven unread messages in her SimplePractice portal. One client wants to move Thursday's appointment. One asks whether she should stop her sertraline because of headaches. One sends three paragraphs about a fight with her sister, ending "what do you think I should do?" Maria has eighteen minutes before her first session, and every message sits on a line most clinicians have never drawn explicitly: the line between administrative and clinical messaging, which is also the line between a free courtesy and an undocumented, unpaid clinical encounter. By the end of this lesson you will classify any between-session message in seconds, use AI to draft replies that stay inside the therapeutic frame and inside HIPAA, rewrite a boundary-blurring response into a frame-safe one, and produce a Messaging Boundary Policy that protects your time, your license, and your clients.
The Line That Decides Everything: Administrative vs Clinical Messaging
Start with the distinction every other rule hangs from. An administrative message handles the logistics of care: scheduling, billing, paperwork, a reminder about the intake form. A clinical message engages the content of care: symptoms, medications, the fight with the sister, "what do you think I should do?" The distinction is not academic. A clinical exchange over the portal is, functionally, a clinical service, and in some jurisdictions and under some payer rules it can create a billable encounter, dragging behind it a documentation requirement, a medical-necessity question, and a chart entry an auditor can ask for later. An unbilled, undocumented clinical encounter is the worst of both worlds: clinical work, no payment, and the only record of the judgment you exercised lives in a thread you may not have charted.
Here is the controlling analogy: your messaging portal is a doorway, not a room. Clients can knock between sessions, and you can answer at the doorway, hand things through it, confirm details through it. But the moment therapy starts happening in the doorway, three things go wrong at once. The session that belongs in the room leaks into the hallway, unpaid and undocumented. The client learns the doorway is where care happens, training an access pattern you cannot sustain. And the frame, the predictable structure that makes therapy safe, dissolves, because neither of you can say anymore where the session begins and ends.
The classification test has three questions. Does answering require clinical judgment about this client's condition or treatment? Clinical. Does answering change or interpret the treatment? Clinical. Could the front desk answer it correctly without opening the chart? Administrative. Maria's messages sort instantly: the reschedule is administrative; the sertraline question is clinical and outside her LCSW scope, making it a handoff; and the three paragraphs about the sister are clinical content knocking on the doorway, asking to be let into the hallway.
HIPAA and the Channel Itself: Where the Message Travels
Before drafting a single reply, settle the channel question, because the most carefully framed message is still a HIPAA problem if it travels through the wrong pipe. The HIPAA Security Rule requires reasonable safeguards for electronic PHI in transit and at rest. A secure client portal inside your EHR (SimplePractice, TherapyNotes, and the major platforms all offer one) is the default safe channel: encrypted, access-controlled, logged. Ordinary email and standard SMS are not. HIPAA does permit unencrypted email with a client who has been warned of the risks and still prefers it, but the preference must be documented, and the prudent practice keeps clinical content off unsecured channels regardless: the client can waive their own privacy comfort, not your judgment about what belongs in writing where.
Now add the AI layer. The data rules from progress notes apply with full force. Paste a client's portal message into a consumer AI tool with no business associate agreement and you have disclosed PHI to a third party without authorization: the client's own words are PHI. So the rule is structural: AI drafting of client communication happens either inside a BAA-covered tool, or with fully de-identified content where you describe the situation generically ("a client asks whether to stop an antidepressant because of side effects; draft a reply that redirects to the prescriber without giving medical advice") and never paste the client's actual text. The second pattern is the workhorse, because for boundary-drafting purposes the model never needs the client's words; it needs the category of the message and the frame rules for the reply.
One more channel rule that saves practices from their worst weeks: nothing about crisis travels through the portal. Asynchronous messaging is structurally wrong for risk: you do not control when it is read, you cannot assess in real time, and a thread is a terrible place to discover, eleven hours later, that a client disclosed suicidal ideation at midnight. Your informed consent and auto-reply both state plainly that the portal is not monitored continuously and never for emergencies, naming what to do instead (988, 911, your crisis coverage). And the hard guardrail applies: if a message contains risk content, AI drafts nothing. The clinician makes the risk determination, takes the indicated action (usually a phone call, not a reply), and documents it. AI never assesses risk, never triages a message as safe, never composes the response to a disclosure of suicidal ideation, abuse, or violence. AI gets the message only after you have decided it is non-crisis.
The Frame: What It Is and How Messages Erode It
The therapeutic frame is the set of agreements that make the work predictable: when sessions happen, how long they last, what they cost, what happens between them. Clients test the frame because testing the container is part of how attachment works, and between-session messaging is the modern frame test. The client sending three paragraphs about the sister fight is not gaming you; she is in pain on a Wednesday and the portal is right there. Your job is to honor the pain and hold the frame, and the difference between those outcomes is usually about four sentences of wording.
Watch frame erosion in slow motion. Week one, the client messages a question and you answer thoughtfully because you care and it took ten minutes. Week three, two messages, each longer. Week six, the client opens Thursday's session with "like I said in my message," and the session content is now being pre-processed in writing, where you cannot use silence, pacing, or anything else that makes the room work. Week nine, you resent opening the portal, the surest sign the frame failed, because resentment is what clinicians feel doing unpaid sessions in a doorway. None of these weeks contained a bad decision. The frame eroded through accumulated kindness, which is exactly why you need a policy and templates rather than fresh judgment at 7:40 AM.
The portal is a doorway, not a room. The moment therapy starts happening in the doorway, it is unpaid, undocumented, and eroding the frame that makes the room work.
The Worked Rewrite: From Boundary-Blurring to Frame-Safe
Here is the promised artifact, worked line by line. The client's message: "I had a huge fight with my sister tonight. She said I always play the victim and I have been spiraling ever since. I tried the breathing thing but I keep replaying what she said. Do you think she is right about me? What should I do?" A caring clinician at 10 PM, typing fast, produces this boundary-blurring reply: "I am so sorry that happened. I do not think you play the victim at all; from everything you have told me, your sister has a pattern of putting you down when she feels criticized. Try to remember what we said about her projections. Maybe journal about what the comment brought up and we can look at it Thursday. You are doing great."
Read it as an auditor or board investigator would. It makes a clinical interpretation in writing ("your sister has a pattern of putting you down"), about a third party never assessed, in a permanent record the client can screenshot into the next family fight. It answers the therapy question ("do you think she is right about me?") asynchronously: therapy in the doorway. It assigns an intervention (journaling) outside any session. It reassures ("you are doing great") in a way that trains the client to seek regulation through the portal. And it documents none of this, despite containing interpretation, intervention, and clinical judgment, the three ingredients of an encounter. This message is the encounter; it is just unpaid, unconsented, and uncharted.
Now the frame-safe rewrite: "Thank you for letting me know what happened tonight; that sounds painful, and I am glad you tried the breathing exercise. The questions you are asking deserve real time rather than a quick message, so let us take them up in Thursday's session. If things feel like more than you can manage before then, you can call the practice line, and if you are ever in crisis, please use 988 or 911 rather than the portal, which is not monitored continuously. See you Thursday." Count what it does: acknowledges (one sentence of warmth, no interpretation), holds (the clinical content is routed to the room), bridges (an interim option that is not a portal conversation), restates the crisis channel without alarm, and commits to the session. Nothing in it could be quoted against the client, the sister, or you. Four sentences, reproducible at 10 PM precisely because it follows a structure rather than fresh clinical composition.
The no-PHI prompt that generates replies in this shape: "Draft a brief, warm, professional reply from a therapist to a non-crisis client message containing emotional content and a request for advice. Structure: one sentence acknowledging the feeling without interpreting it or commenting on any third party; one sentence routing the topic to the next scheduled session; one sentence naming the interim option of calling the practice line; one sentence restating that the portal is not for emergencies, with 988 and 911 named. Tone: calm, caring, boundaried. No advice, no interpretation, no character reassurance, no reference to specific events. Under 90 words." You personalize only the salutation and the session day, by hand. The model never sees the client's message; it produces the frame, you supply the two safe specifics.
The Handoff Messages: Medication Questions and Scope
Medication questions are the most common clinical message a non-prescribing therapist receives and the easiest to fumble. The temptation runs both directions: over-answer ("headaches usually fade in the first two weeks") and you have practiced outside your scope in writing; under-answer ("I cannot discuss medication") and you have abandoned a client mid-concern. The frame-safe handoff validates, routes, and preserves your role: "Thank you for telling me about the headaches; that is exactly the kind of thing your prescriber needs to know, and please do not stop or change the dose on your own before speaking with them. Dr. Okafor's office number is in your portal contacts, and we can also talk Thursday about how the medication conversation is going. If the headaches become severe or you feel unwell in a way that worries you, urgent care or your primary care office is the right same-day step."
Notice the load-bearing line: "do not stop or change the dose on your own before speaking with them." Not medical advice; the standard safety redirection that bridges the gap between your message and the prescriber's callback, and the sentence AI drafts most often omit unless you specify it. The handoff prompt names the structure explicitly: validate, route with a concrete contact step, hold the no-unilateral-changes line, offer in-session follow-up, name the same-day escalation path. Psychiatrists and PMHNPs face the mirror image: for a prescriber, a substantive medication exchange over the portal sits even closer to the billable-encounter line, and several payers now recognize digital E/M codes for this work, one more reason a substantively answered clinical message should become a documented, billed encounter or an appointment.
Care-coordination messages get one rule of their own: anything sent about a client to a third party (prescriber, school counselor, case manager) follows the release-of-information and minimum-necessary disciplines from the ROI lesson. AI may draft the coordination note inside your covered tool, but the scope of disclosure is your decision, made against the signed release, before drafting begins.
When the Message Should Become an Encounter, and How to Say So
Some messages are not frame tests; they are legitimate requests for care that does not fit the weekly slot: the client whose panic attacks returned mid-week, the parent whose child's school just called, the client in acute grief. The frame-safe move is not deflection to Thursday; it is converting the doorway knock into a real encounter: a scheduled call or telehealth session, consented, documented, and where appropriate billed. The language is simple: "This sounds like it deserves more than messages can hold. I have a 20-minute telehealth slot tomorrow at 1:15; would you like it? My usual fee structure applies." That dignifies the need, preserves the economics of your practice, and moves the clinical content into a container where it can be documented and conducted properly.
Your consent paperwork has to support this move, which is why the policy artifact includes a consent paragraph. Clients should learn at intake, not mid-crisis, how messaging works: what the portal is for, the response window (one to two business days is common and defensible), what happens when a message needs more than a message, how between-session clinical time is billed if it is, and that emergencies never wait for the portal. A messaging policy disclosed at intake is a frame everyone agreed to; a boundary improvised at week six reads as rejection. The same paragraph belongs in your AI-use disclosure if a BAA-covered assistant drafts administrative replies.
Document the conversions and the holds. When a thread contains anything clinical, the chart gets a contact note: date, channel, the gist of the message, your response category (held to session, converted to encounter, handed off to prescriber), and any risk screening the content warranted. One template sentence: "Client portal message received [date] re: interpersonal conflict; non-crisis; acknowledged and routed to next scheduled session per messaging policy; no risk indicators in content." Let AI template that freely; it contains no judgment AI is making, only the record of judgment you made.
Building the Template Library: AI as Your Messaging Infrastructure
Here is where AI earns its keep. The sustainable solution to 7:40 AM is not better improvisation; it is a template library covering the recurring message categories, drafted once with AI, edited into your voice, approved cold, reused warm. The categories covering most outpatient traffic: scheduling and rescheduling (administrative, automate freely); billing and superbill requests; paperwork and records requests (administrative, but route actual records release through your ROI process); psychoeducation follow-ups, where the reply attaches the handout rather than re-teaching it in prose; emotional-content non-crisis messages (the acknowledge-hold-bridge-crisis-channel structure); medication questions (the validate-route-hold-offer-escalate handoff); requests for advice or decisions (route to session, never decide in writing); and the convert-to-encounter offer for legitimate mid-week needs.
Draft each template with a no-PHI prompt specifying structure, tone, and prohibitions, as the worked examples did. Then make the library yours: read each template against your actual voice, tighten anything that sounds like a corporate auto-reply, and verify the crisis language names the resources you actually want named. Store it where you message: most EHR portals support saved replies. The result: the 7:40 AM portal review becomes classification work, not composition work. Administrative messages get administrative templates, clinical messages get the hold, the handoff, or the conversion, and crisis content gets you, immediately, with no AI in the loop. Eleven messages, eighteen minutes, frame intact.
The Applied Problem: Your Messaging Boundary Policy
Your artifact is a one-page Messaging Boundary Policy with two faces: a client-facing paragraph for your intake packet and an internal page that operationalizes it. Build the client-facing paragraph first, drafted with AI at the 6th-grade level from the previous lesson, because a messaging policy nobody can read protects nobody. It states plainly: what the portal is for (scheduling, billing, brief questions); the response window (one to two business days); that the portal is never for emergencies, with 988 and 911 named; that messages raising things needing real discussion will be taken up in session or by scheduled call; and how between-session clinical contact is handled and billed. Run it through the Flesch-Kincaid loop until it scores at target.
Then build the internal page in four blocks. Block one: the classification test, the three questions plus the standing rule that risk content bypasses every template and goes straight to clinician action with no AI involvement. Block two: the template library index, eight categories, each with its approved template and a note of which fields you personalize by hand (name, day, prescriber contact). Block three: the documentation rule, every clinical-content message gets a contact note, every converted encounter gets normal encounter documentation. Block four: the conversion criteria, what turns a message into a same-week scheduled contact, the offer language, and how it is billed or not in your setting, checked against your payer contracts and jurisdiction rather than assumed.
Now test it against Maria's inbox. The reschedule hits the scheduling template in thirty seconds. The sertraline message gets the medication handoff with the prescriber contact personalized and the no-unilateral-changes line intact, plus a contact note. The sister-fight message gets the acknowledge-hold-bridge reply, a contact note, and a flag to open Thursday's session with it. Done: a client-facing paragraph scoring at 6th grade in your intake packet and portal auto-reply; an internal page with the test, the library, the documentation rule, and the conversion criteria; and an annual calendar reminder to review against payer contracts and state rules, because the billable-encounter line for digital messaging is moving, and the practice that drew its line in writing is the one that can defend it.
Key Takeaways
- The load-bearing distinction is administrative versus clinical messaging. Administrative messages handle logistics the front desk could answer without the chart; clinical messages engage symptoms, medications, or treatment, and a substantive clinical exchange can create a billable encounter in some jurisdictions, with documentation duties attached. An unbilled, undocumented clinical exchange is clinical work with no payment and no record.
- The portal is a doorway, not a room. Acknowledge at the doorway, hand things through it, but route therapy content into the session: doorway therapy is unpaid, undocumented, and erosive to the frame, and the erosion happens through accumulated kindness rather than bad decisions.
- Channel rules come before wording. Clinical content travels through the secure portal, not ordinary email or SMS, and pasting a client's message into a non-BAA AI tool is an unauthorized PHI disclosure. Draft with AI using generic category descriptions, never the client's actual text.
- Crisis content has an absolute rule: no AI, no templates, no asynchronous reply as the primary response. The clinician makes the risk determination and takes direct action; the auto-reply and consent paperwork state plainly that the portal is never for emergencies, naming 988 and 911.
- The frame-safe reply structure: acknowledge, hold, bridge, restate the crisis channel, commit to the session. One sentence of warmth without interpretation, explicit routing of content to the room, an interim option, and no advice, no third-party commentary, no character reassurance in writing.
- Medication questions get the handoff: validate the concern, route to the prescriber with a concrete contact step, hold the "do not stop or change the dose on your own" line, offer in-session follow-up, name the same-day escalation path. Over-answering practices outside your scope in writing; under-answering abandons the client.
- The artifact is the Messaging Boundary Policy: a 6th-grade client-facing intake paragraph (portal purpose, response window, emergency routing, conversion rule, billing treatment) plus an internal page with the three-question classification test, the eight-category template library, the contact-note rule, and conversion criteria, reviewed annually against payer contracts and state rules.
Skill.re