AI for Mental & Behavioral Health Clinicians
Proficient · M29 · lesson 29 of 30 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
The Tarasoff Duty-to-Protect Letter and Documentation
📖
now learning

The Tarasoff Duty-to-Protect Letter and Documentation

15 min

A client in his third month of treatment, escalating through a custody dispute, says: "If he gets the kids, I will put him in the ground. I know where he parks." There is a name, a pattern, a serious threat of physical violence against a reasonably identifiable victim, and the session has forty minutes left. What the clinician does next, and how she documents it, sits at the intersection of the strongest confidentiality protections in health care and the narrow, state-specific duty that pierces them. This is Tarasoff territory, and almost everything clinicians believe about it is half right: the duty is not "warn the victim" in most modern formulations, the statutes vary enormously by state, and the determination itself belongs to the clinician alone, with AI permitted to scaffold the letter only after the clinician has decided that disclosure is required. By the end of this lesson you will have a Tarasoff Letter Structure paired with a Clinical-Determination Record: the documentation set that shows a reviewer, a board, or a court that the duty was analyzed, the decision was the clinician's, and the protective action was proportionate.

What Tarasoff Actually Established, and What It Did Not

Tarasoff v. Regents of the University of California (the 1976 California Supreme Court decision) established that when a therapist determines, or under professional standards should determine, that a patient presents a serious danger of violence to another, the therapist incurs an obligation to use reasonable care to protect the intended victim. The court's famous line, that the protective privilege ends where the public peril begins, is the part everyone remembers. What the half-remembered version gets wrong is the content of the duty. Tarasoff itself spoke of a duty to protect, dischargeable through various steps, warning the victim, notifying police, or taking whatever other steps are reasonably necessary under the circumstances. Fifty years of statutes, amendments, and case law later, the duty in most states is a structured, codified thing, and its shape depends entirely on where you are licensed.

The controlling analogy for this lesson: the Tarasoff duty is a controlled demolition of confidentiality, not a fire alarm. A fire alarm is pulled reflexively, by anyone, at the first smell of smoke. A controlled demolition is engineered: a qualified professional determines that the structure must come down, calculates exactly how much charge to use, documents the engineering analysis, and takes down only what must come down, leaving everything around it standing. Confidentiality is the structure. The threat determination is the engineering analysis. The disclosure, if one is made, is the precisely placed charge: the minimum necessary, to the specified recipients, for the protective purpose, with the analysis on file. A clinician who discloses reflexively at the first frightening sentence has pulled a fire alarm inside a building that needed engineering, and the law in most states does not protect that.

This matters because the failure modes run in both directions. Under-response, a credible threat against an identifiable victim met with silence, is the classic Tarasoff liability. Over-response is the quieter one: breaching confidentiality on a threat that did not meet the statutory threshold, in a state where disclosure is permissive rather than mandatory, or to recipients beyond what the statute specifies, can itself generate board complaints and civil exposure, and in some states the statutory immunity only attaches when the duty was actually triggered and discharged as specified. The clinician's protection in both directions is the same thing: a documented determination.

California: Duty to Protect, Not Duty to Warn

Start with California because it is the origin state and because its current law is the one clinicians most often misstate. Since the 2013 statutory revision, California Civil Code §43.92 frames the psychotherapist's obligation as a duty to protect. Get the terminology exact, because the difference is operational, not cosmetic. Under §43.92, a psychotherapist's duty arises when a patient communicates to the psychotherapist a serious threat of physical violence against a reasonably identifiable victim or victims. The statute provides that the duty is discharged by making reasonable efforts to communicate the threat to the victim or victims and to a law enforcement agency, and the statute supplies immunity when the duty is discharged that way. But the post-2013 framing as a duty to protect means that protective actions are the point, and warning is one instrument among several. Alternative protective actions, initiating hospitalization, intensifying treatment with increased session frequency, coordinating lethal-means restriction with the family, can be part of satisfying the duty, and in some clinical situations warning the identified victim could exacerbate risk rather than reduce it: provoking the client toward immediacy, triggering a confrontation, or collapsing the treatment relationship that is itself the best protective instrument available.

The reasoning that California's revision codified runs in the same direction the Washington Supreme Court later traced in Volk v. DeMeerleer (2016), a decision that startled clinicians nationally by extending a mental health professional's duty to victims who were foreseeable rather than specifically identified, based on the broader common-law duty owed by professionals with special relationships to dangerous patients. Volk is Washington law, not California law, and its scope remains controversial, but it teaches the continuity lesson: courts keep returning to protection as the underlying obligation, with warning as one tactic. A clinician who thinks of the duty as "make the phone call, get the immunity" is thinking one move deep in a game the courts play several moves deep.

For California clinicians, the practical synthesis: when the §43.92 trigger is met, a serious threat of physical violence communicated by the patient against a reasonably identifiable victim, the discharge pathway the statute names (reasonable efforts to communicate the threat to the victim and to law enforcement) is the immunity-bearing route, and the clinician should follow it unless there is a documented clinical reason that warning would increase danger, in which case the protective-action analysis, what was done instead and why, must be documented with exceptional care. Either way, the chart must show the analysis, not just the action.

The State Map: Why You Cannot Generalize

Now widen the lens, because the single most dangerous habit in Tarasoff practice is importing another state's rule. The statutes vary substantially in trigger, in what they require or merely permit, and in immunity. Texas Health and Safety Code §611.004 is the famous outlier: Texas has no mandatory Tarasoff duty, and the statute permits, but does not require, disclosure to medical or law enforcement personnel when there is a probability of imminent physical injury to the patient or others; the Texas Supreme Court declined to adopt a Tarasoff duty in Thapar v. Zezulka. A Texas clinician who "warns the victim" directly is acting outside the permissive disclosure channels §611.004 names, which run to law enforcement and medical personnel, not to the threatened individual. Florida's §456.059 addresses psychiatrists specifically, making disclosure permissive when a patient communicates a specific threat against a clearly identified victim, with a separate framework that ties immunity to disclosure made in specified ways. Illinois, through the Mental Health and Developmental Disabilities Confidentiality Act, 740 ILCS 110/11, permits disclosure when, in the therapist's sole discretion, it is necessary to warn or protect against a clear, imminent risk of serious injury or death, language that vests the judgment explicitly in the clinician. New York's Mental Hygiene Law §33.13 governs the confidentiality of clinical records and the narrow conditions under which they may be released, the gate any New York disclosure analysis must pass through alongside the state's separate reporting frameworks.

Read those side by side and the variation is not decorative. Mandatory versus permissive changes whether silence is itself a breach. The trigger language, "serious threat of physical violence" versus "probability of imminent physical injury" versus "clear, imminent risk of serious injury or death", changes which client statements start the clock. The discharge specification, victim and law enforcement in California, law enforcement and medical personnel in Texas, changes who you may lawfully call. The immunity provisions change what protects you when you act. A practice with clinicians licensed in multiple states, or a telehealth caseload crossing state lines, cannot run one Tarasoff protocol; it needs a per-state annex, and the annex must cite the statute, not a webinar slide.

One discipline follows from all of this, and it belongs in your protocol in bold: before any disclosure, the clinician identifies the controlling statute by the client's location and the clinician's licensure, reads the actual trigger and discharge language, and documents which statute was applied. That sentence in the record, "analysis conducted under Cal. Civ. Code §43.92," is the difference between a determination and a guess.

AI never makes the Tarasoff determination. The clinician decides whether the duty is triggered, decides what protective action discharges it, documents the reasoning, and signs. Only after that decision is made may AI scaffold the letter that records it.

The Clinical Determination and Its Record

The determination itself is a clinical-legal judgment with several components, and the Clinical-Determination Record is the artifact that captures each one. Component one: the threat, documented verbatim. "If he gets the kids, I will put him in the ground. I know where he parks," in quotation marks, with context: when in the session, in response to what, with what affect. Paraphrase is the enemy here more than anywhere else in the chart, because the statutory trigger turns on what was communicated. Component two: identifiability. Is the victim reasonably identifiable, named, or determinable from the client's statements? Document the basis: "victim is client's former spouse, named in session, address known to client." Component three: seriousness and capability, the clinical assessment of whether this is a serious threat of physical violence: the client's history of violence, access to means, specificity and planning in the threat, current destabilizers (the custody ruling due Friday, the escalating alcohol use), and protective factors. This is a violence-risk analysis, the homicidal sibling of the suicide-risk formulation from earlier in this chapter, and it deserves the same five-domain rigor. Component four: the statutory analysis: which state's law controls, what the trigger language requires, whether this situation meets it, and whether disclosure is mandatory, permissive, or unavailable. Component five: consultation. A Tarasoff determination made alone is legally permissible and professionally unwise; the call to the supervisor, the attorney, or the malpractice carrier's risk line, documented with time and substance, is some of the cheapest liability protection that exists. Component six: the decision, stated plainly: duty triggered or not triggered; protective actions selected, with the reasoning for each action taken and each considered and rejected; and the limits-of-confidentiality disclosure made to the client, because in most situations the client should hear from the clinician what is about to happen and why, a clinical act that preserves what can be preserved of the alliance.

Notice what is nowhere in those six components: any AI role. The determination phase is a no-AI zone in the strictest sense in this program. Do not ask a model whether the threat "meets the Tarasoff standard." Do not paste the client's statement into a chatbot for a risk read. Do not let a scribe's transcript summary stand in for your verbatim documentation of the threat. The determination is the controlled-demolition engineering analysis, and it is performed by the licensed engineer. There are two reasons beyond the by-now-familiar statutory ones. First, the determination requires weighing the client's history, affect, and context against specific statutory language, a synthesis the model will perform fluently and unaccountably, and fluent unaccountable answers are anchors. Second, the inputs themselves are radioactive: a communicated threat naming a third party is among the most sensitive content a chart can hold, and it does not belong in any tool outside your documented, BAA-covered stack even for formatting, until the practice's policy says exactly which tool and under what configuration.

The Clinical-Determination Record is therefore written by the clinician, in the clinician's words, contemporaneously. It is the longest fully handmade document this chapter asks of you, and it should be. When the decision is "duty not triggered," the record matters just as much: the verbatim statement, the analysis of why it did not meet the statutory threshold (conditional venting without identifiable victim, no capability, retracted with credible processing), the intensified monitoring plan, and the consultation. The chart that shows a considered non-disclosure is protected; the chart that shows the threat and then silence is the Tarasoff case in chief.

The Tarasoff Letter: Structure, and Where AI May Finally Enter

Once, and only once, the clinician has determined that disclosure is required and selected the protective actions, the documentation machinery may include AI, in the scaffolding seat. The Tarasoff letter, the written communication to the victim, to law enforcement, or both, depending on what your statute specifies, has a structure that must do precise work, and a blank page at a moment of high stress produces bad letters. The structure has six parts. Part one: identification: who the writer is (name, license, practice), and the capacity in which the letter is sent ("pursuant to my obligations under California Civil Code §43.92"). Part two: the communication of threat: that on a stated date, a patient of the practice communicated a serious threat of physical violence against the recipient (or the named individual, in the law enforcement copy), conveying the substance of the threat sufficient for protection. Part three: the statutory basis, stated plainly, so the recipient and any later reader understands this is a legally compelled or authorized disclosure, not gossip. Part four: minimum-necessary discipline: the letter conveys the threat, the identity needed for protection, and the urgency; it does not convey the diagnosis, the treatment history, the substance use disclosures, or anything else the chart holds. The demolition charge is placed at the load point, not the whole building. Part five: the protective recommendations, factual and restrained: that the recipient may wish to contact law enforcement (in the victim letter), and the practical information that aids protection. Part six: the record trail: date, time, method of delivery, and the parallel notifications made (the call to law enforcement logged with agency, badge or report number, time).

The AI prompt that scaffolds this safely is structural, not substantive: "I am a licensed clinician. I have determined, under [statute], that a duty-to-protect disclosure is required, and I have completed the clinical determination record. Draft the structure of a notification letter with the following six sections [list them], using formal, factual, restrained language, with bracketed placeholders for every fact: [DATE OF COMMUNICATION], [SUBSTANCE OF THREAT], [STATUTE], [RECIPIENT]. Do not invent any factual content. Do not include clinical information beyond the placeholders. Flag any section where you are tempted to add detail, and leave it to me." The clinician fills every placeholder by hand from the determination record, verifies the statute citation against the actual statute, strips anything the model added beyond structure, and reads the finished letter against one test: does this letter disclose the minimum necessary for protection and nothing else? Then the phone calls, because in a genuine emergency the letter follows the call: a serious imminent threat is communicated to law enforcement and the victim by the fastest reasonable means, with the letter and the chart documenting what was communicated, to whom, and when.

A note on the limits-of-confidentiality conversation with the client, because it has a documentation life of its own. Most clients heard at intake that threats of harm to others are an exception to confidentiality; the moment that exception activates, the clinician revisits it: what will be disclosed, to whom, why, and what it means for treatment. That conversation, documented, is evidence of clinical integrity, sometimes de-escalates the threat itself, and frames whether treatment can continue. There are narrow situations where informing the client first would itself elevate danger; if you make that judgment, document it as a judgment, with reasoning.

After the Disclosure: The Week Two Documentation

The Tarasoff file does not close when the letter is sent. The week that follows has its own documentation duties, and they are the ones practices most often drop. First, the disposition of the treatment relationship: did the client remain in treatment, escalate, terminate, require hospitalization? The post-disclosure session note carries the same verbatim discipline as the determination record, because the client's response to the disclosure is itself risk data. Second, the protective-action follow-through: if hospitalization was initiated, the 5150 or state-equivalent paperwork and its outcome; if means restriction was coordinated, the verification loop from the previous lesson; if session frequency was intensified, the attendance record. Third, the coordination trail: the law enforcement report number, any callback from the agency, any contact from the victim, each logged with date and substance. Fourth, the internal reporting: the practice's incident process, the malpractice carrier notification if the policy requires it, and for pre-licensed clinicians, the supervisor's documented review, because an associate never carries a Tarasoff determination alone; the supervisor is in the consultation component by policy, in real time, and the record shows it.

Then there is the non-event documentation, the harder discipline: when the clinician determines the duty was not triggered, the monitoring that follows must appear in the chart with the same rigor as a suicide-risk re-assessment trail. The threat that did not meet the threshold on Tuesday can meet it after Friday's custody ruling, and a chart that shows the clinician re-evaluating, session by session, against the named statutory standard, is a chart that proves ongoing professional attention. AI's role here mirrors the previous lessons exactly: it may flag, against the open monitoring plan, that the new session note lacks a threat-status update; it may format the clinician's dictated re-evaluation into the established structure. It may not characterize the client's new statements, may not compare them to the statutory trigger, and may not suggest that the threshold has or has not been met. The clinician reads the statute; the clinician hears the client; the clinician decides, every time.

One organizational point closes this section. Jordan's 25-clinician practice should not have twenty-five private Tarasoff protocols; it should have one written protocol with the per-state annex, the consultation pathway with names and after-hours numbers, the letter scaffold pre-approved by counsel, the no-AI-zone definition for the determination phase, and the post-disclosure checklist. The middle of a credible threat is the worst possible time to design a workflow, and the best possible time to execute one that already exists.

The Applied Problem: The Tarasoff Letter Structure and Clinical-Determination Record

Your artifact is a two-part documentation set: the Clinical-Determination Record template and the Tarasoff Letter Structure, built as a pair, because the letter is only as defensible as the determination behind it. Build them in three steps.

Step one: draft the Clinical-Determination Record template by hand, no AI, as a fixed six-component form: (1) Threat as communicated, verbatim, with session context; (2) Victim identifiability and basis; (3) Violence-risk analysis: history, means, specificity, destabilizers, protective factors; (4) Statutory analysis: controlling statute identified by client location and clinician licensure, trigger language quoted, threshold met or not met, disclosure mandatory or permissive; (5) Consultation: who, when, substance; (6) Determination and protective actions: each action taken with reasoning, each considered and rejected with reasoning, and the limits-of-confidentiality conversation with the client documented or the documented judgment for deferring it. Add the header line: "This record is completed solely by the licensed clinician. No AI tool may be used in the determination phase." Then complete the template once against the custody-dispute scenario from this lesson's opening, in a California frame under Civil Code §43.92, writing the analysis as if the chart will be read aloud in a hearing, because the good ones are written that way every time.

Step two: build the letter scaffold. Run the structural prompt from this lesson and verify its output against the six parts: identification and capacity, communication of threat, statutory basis, minimum-necessary content, protective recommendations, record trail. Confirm every factual position is a bracketed placeholder, strip any substantive language the model volunteered, and check the minimum-necessary test: nothing about diagnosis, treatment history, or any clinical content beyond the threat and the protection-relevant facts. Produce two variants: the victim letter and the law enforcement letter, because their content differs at the margins (the law enforcement copy carries the report-coordination details; the victim copy carries the practical protective information).

Step three: the verification pass that defines "done." Read the completed determination record and ask: could a reviewer reconstruct the decision, including the statute applied and the roads not taken, from this document alone? Read the filled letter and ask: is every fact traceable to the determination record, is the statute citation verified against the statute itself rather than the model's memory, and would the letter survive the minimum-necessary test in front of a privacy officer? File the pair with your state annex and your consultation phone tree. Done looks like this: the next time a client says the unsayable at minute 12, you are executing a protocol, not inventing one.

Key Takeaways

  • Tarasoff established a duty to protect, dischargeable by warning, notifying police, or other reasonably necessary steps, and fifty years of state statutes have made the duty's trigger, discharge, and immunity entirely jurisdiction-specific. The duty is a controlled demolition of confidentiality: engineered, documented, and minimal, never a reflexive alarm.
  • California, since the 2013 revision of Civil Code §43.92, is unambiguously a duty-to-protect jurisdiction, not duty-to-warn. The statutory discharge route is reasonable efforts to communicate the threat to the victim and to law enforcement, but protective actions beyond warning, hospitalization, intensified treatment, means-restriction coordination, can be part of satisfying the duty, and warning can sometimes exacerbate risk; the reasoning continuity runs through Volk v. DeMeerleer (Washington, 2016), which extended duty to foreseeable victims.
  • State statutes vary substantially and cannot be generalized: Texas Health and Safety Code §611.004 is permissive only, with disclosure channels to law enforcement and medical personnel, not the victim; Florida §456.059 addresses psychiatrists with permissive disclosure tied to specified procedures; Illinois 740 ILCS 110/11 vests disclosure in the therapist's sole discretion against a clear, imminent risk standard; New York Mental Hygiene Law §33.13 gates record disclosure. Every protocol needs a per-state annex citing the actual statute.
  • The determination phase is a strict no-AI zone: AI never decides whether the duty is triggered, never compares a client's statement to a statutory standard, never characterizes threat seriousness. The clinician documents the threat verbatim, analyzes identifiability, capability, and the controlling statute, consults, decides, and signs. Under-response and over-response are both liabilities, and the documented determination is the protection against each.
  • AI may scaffold the Tarasoff letter only after the clinician has decided disclosure is required: a structural prompt producing the six-part letter with bracketed placeholders, no invented facts, no clinical content beyond the minimum necessary for protection. The clinician fills every placeholder from the determination record and verifies the statute citation against the statute itself.
  • The file stays open after the letter: post-disclosure session documentation, protective-action follow-through, the law enforcement coordination trail, supervisor review for any pre-licensed clinician, and, when the duty was not triggered, a monitoring trail that re-evaluates the threat against the named statutory standard session by session.
  • Your artifact is the paired set: a six-component Clinical-Determination Record completed solely by the clinician, and a two-variant Tarasoff Letter Structure (victim and law enforcement) that passes the minimum-necessary test, filed with the state annex and the consultation phone tree, so the protocol exists before the threat does.