AI Insights Healthcare & Medical

Crisis Duty, 42 CFR Part 2, and Your Practice’s Intake: A 2026 Playbook

June 15, 2026 7 min read

Talk to Fred

Ask Fred about Healthcare & Medical

This is the same Fred you would put on your own site. Ask about Healthcare & Medical, compliance, or how the guardrails work. Fred listens.

Behavioral health is the setting with the least margin for a wrong answer, which is exactly why the standard for an assistant on a practice’s site is the most demanding in this series. The job is not to be a better receptionist. It is to schedule and answer logistics without ever standing between a person in distress and a clinician, to protect the most sensitive data a practice holds, and to recognize the one moment that cannot be automated and get a human into it fast. In 2026, with intake increasingly handled online, a practice needs a clear standard for what its site is allowed to do when someone reaches out at 2 a.m.

This guide is the companion to the threat piece. The threat side covers the intake bot that answered a crisis with a booking link. This one covers the standard: what a compliant intake assistant does, what it must hand to a person immediately, and how it protects confidentiality built for this field.

The Crisis Handoff Is the Whole Standard

People disclose things to a screen at night they would never say to a front desk. A compliant assistant is built for that reality. It does not attempt to assess risk, counsel, or reassure, because none of those belong to a website. What it does is recognize that a conversation has turned urgent and move immediately to a human pathway and appropriate crisis resources, without burying the person in a scheduling flow.

This matters because clinicians operate under duty-to-protect obligations that, depending on the state, can require action when a client signals danger to themselves or others. Those duties are state law and vary, and they assume a professional is present. An intake tool cannot carry that duty, so the standard is that it never tries to. It hands off. The quality of an intake assistant in this field is measured almost entirely by how cleanly and quickly it routes a crisis to a person, and that routing is the design, not a feature bolted on after launch.

Clinical Questions Belong to a Licensed Clinician

Outside a crisis, the gentle questions are still traps. "Do you think I have anxiety, or something worse?" "Is it normal to feel like this?" Answering is diagnosing and counseling, the practice of a licensed profession, and a website performing it is giving clinical guidance with no license, no assessment, and no one accountable. A fragile person may take that answer to heart.

The compliant standard draws the line at information versus advice. The assistant can describe services, explain how intake works, and convey that a clinician is the right person to answer a clinical question. It does not offer an opinion on symptoms or a label for what someone is feeling. Those route to a licensed clinician, every time.

What AI Compliance for Mental Health Practices Requires for Confidentiality

Mental health information sits among the most protected data there is. The practice is a covered entity under HIPAA’s rules, and if it touches substance use disorder treatment, an even tighter federal layer applies under 42 CFR Part 2’s confidentiality protections. Those protections are stricter than HIPAA in important ways, which is precisely why a generic widget is a poor fit: it was not built to honor them.

A compliant deployment treats every disclosure, symptoms, history, substance use, as data that has to stay inside the practice’s controls. That means a business associate agreement with the vendor, encryption and access controls that meet the Security Rule, and an honest answer to whether Part 2 reaches the practice’s services before any tool collects a word. Pull it together and the standard is a short, strict list: recognize a crisis and route it to a person instantly, refuse clinical opinion and route it to a clinician, and protect confidentiality by design under both HIPAA and, where it applies, Part 2. A disclaimer satisfies none of these.

Why a Prompt Cannot Meet the Standard

The reflex is to write the rules into the assistant’s instructions: never counsel, never diagnose, escalate a crisis. Treat the boundary as set.

It is not set, because of how the technology works. A language model follows an instruction when the request matches the wording it was warned about, and a person in distress does not phrase things cleanly or stop at the first deflection. You tell it to escalate a crisis. The person does not announce a crisis. They write something quieter and harder to read, and a model built to respond keeps the conversation going rather than handing it off, because responding is its default and a prompt is only a request to hold that default back. In this field, that gap is not theoretical. It is the difference between a handoff and a harm.

That is why an instruction cannot carry this. An instruction asks the model to behave. It does not stop the model from speaking, and it cannot guarantee the handoff happens at the moment it matters most. A real boundary is enforced in the system: it decides what the assistant may say before it answers, holds the clinical and crisis lines no matter how the conversation is worded, and triggers the human handoff as the designed response rather than a hoped-for one. "Will not" is a suggestion. "Cannot" is an architecture.

What a Compliant Deployment Looks Like

Meeting the standard does not mean a practice gives up the assistant that schedules and answers logistics after hours. It means running one built for the obligations this field is organized around.

Fred is built that way. It answers from your own practice content, schedules and handles logistics, protects confidentiality, and is built to hand a person to a human the instant a conversation turns clinical or urgent. It runs more than 50 industry guardrail packs, and the behavioral-health pack is built around the crisis handoff, the line against diagnosis and counseling, and the confidentiality rules under HIPAA and 42 CFR Part 2. Fred does not counsel, does not diagnose, and does not try to manage a crisis on its own. It cannot. It handles the intake logistics, protects the most sensitive data a practice holds, and gets a person to a clinician when that is what the moment requires.

The goal is not a more capable intake bot. It is one that can be shown to route a person to care at the moment it matters and to protect what they disclosed getting there.

Frequently asked questions

What is the most important thing a mental health intake assistant must do?

Recognize when a conversation has turned urgent and route the person to a human pathway and appropriate crisis resources immediately, without trapping them in a scheduling flow. Clinicians carry duty-to-protect obligations that assume a professional is present, and an intake tool cannot carry that duty, so the standard is that it hands off rather than tries to assess or reassure. The crisis handoff is the core of a compliant deployment, not an add-on.

Can a mental health assistant answer questions about symptoms?

No. Offering an opinion on whether someone has anxiety, depression, or "something worse" is diagnosing and counseling, the practice of a licensed profession. A compliant assistant describes services and explains how intake works, then routes any clinical question to a licensed clinician. It does not label what a person is feeling, because a fragile client may act on that answer and no one accountable formed it.

What confidentiality rules apply to a mental health practice's assistant?

The practice is a HIPAA covered entity, and if it provides substance use disorder treatment, the stricter protections of 42 CFR Part 2 also apply. A compliant deployment runs under a business associate agreement with encryption and access controls that meet the Security Rule, keeps every disclosure inside the practice’s systems, and confirms whether Part 2 reaches its services before any tool collects information. These rules are built into the design, not added after a complaint.

Put your own Fred to work.

You just talked to Fred above. The same agent answers your visitors from your content, captures the lead, and books the job, 24/7.