A newer version of the platform is available. Please refresh the page.
By: John M. Grohol, Psy.D
Posted by permission. Copyright by Psychcentral.com. Originally posted at https://psychcentral.com/best/best2.htm
With the advent of a growing number of therapists turning to the online world to conduct some form of counseling or therapy online, legitimate concerns are raised about limitations of this modality. This article seeks to clarify some of the most relevant issues related to confidentiality when offering mental health services online.
Technical Limits to Confidentiality in the Real World
Confidentiality is not an absolute. It never has been in the real world, nor should it be held up to an impossible or ideal standard in the online world. Every area below is an area which I am personally familiar with; other areas may exist but are not included here. Confidentiality is broken under specific circumstances, both legitimately and illegitimately:
Legitimate
Illegitimate
Obtaining unauthorized access to a client’s chart may be as simple as going into an unlocked or loosely-monitored filing room and browsing through the files. In larger organizations, this activity can go unquestioned and unnoticed by other staff. In some hospitals, access to confidential chart material can be gained by wearing a doctor’s white coat and by simply looking like you know what you’re doing. Never underestimate the power of attitude.
The problem with authorized access by staff or clinic personnel examining parts of a client’s record in which they have no valid purpose doing so may present a more commonplace and troublesome breech of confidentiality.
Technical Limits to Confidentiality in the Online World
Legitimate
Best practice dictates that real-world contact information is imperative, however, to ensure an emergency situation can be properly handled. (Putting off obtaining or verifying such information is not recommended; the nature of an emergency is that it is unexpected and traumatic, so you cannot count on gaining that information at that later moment.)
One solution to this problem is to emphasize the importance of double-checking one’s recipient list in the email before pressing the Send button.
One solution to this problem is for the client to use a Web-based email system, such as Hotmail or Freemail. While this may solve this kind of unauthorized access to your email by the users sharing your computer, it may open you up to additional illegitmate risks in confidentiality (noted below). Such systems are also not usually capable of using encryption.
Illegitimate
Others make the claim that your Internet service provider (ISP) regularly snoops through your personal email (e.g., America Online, or your local provider). This is a pretty outrageous claim. It assumes many things, such as that your ISP is inherently dishonest and untrustworthy (they are a business; dishonesty and untrustworthiness do not appear to be good business attributes to have). The claim also assumes that technically it can be done (it can), but that a person would bother doing it. Most ISP have thousands, if not tens-of-thousands of customers. To sit there and sort through the thousands of emails which pass through one’s ISP is to imagine someone with a lot more time on their hands than anyone I know. While a filtering program could be setup to look for keywords (who’s going to look for “depression”?!), again, it speaks to the business’s lack of honesty and untrustworthiness. If such a business practice ever got out (and it would, since most ISPs are run by a staff of people), they would quickly go out of business.
The other possibility is the interception of email as it makes its way through the vast network of the Internet. Again, this is possible, but only remotely so. Millions of emails pass through the Internet daily. While you could imagine someone who wants to monitor them (some claim the FBI, CIA, and NSA all do!), it would be a tremendous task. People who are on networks like America Online, with 14 million other members, would have even greater security (because of the size of their internal network).
According to figures quoted in the Feb. 8, 1999 issue of InternetWeek, 3.4 trillion email messages were delivered in the U.S. in 1998. 2.1 billion email messages are sent daily by U.S. users. Unless you are doing so from your place of employment, interception of your email by an unauthorized user appears to be an incredibly small risk. It would be impossible to ensure absolutely no risk in such a transaction (just as a real-world therapist cannot ensure absolutely no risk in a real-world transaction, e.g., because they do not know their therapy office has been bugged or a patient’s record has been tampered with).
All email based risks can be virtually eliminated through the use of readily available technology. Encryption is available for most newer email clients. If clients are informed of the benefits of encryption (which protects against legitimate and illegitimate access to their email communications), it may be worth it to them to acquire such technology and install it on their computer or cause to have it installed.
As a test, a psychiatrist colleague of mine and myself wanted to see whether we could easily use encryption in an email to one another. We both had encryption technology installed in our email programs already, so it was just a matter of registering our public keys and sending the message. This was a virtually painless process we worked out in just a message or two. While we were both computer-literate individuals, we were in fact using different types of computers and programs to send and receive this email. If you cannot figure out how to do this yourself, or your email software doesn’t support encryption, I strongly urge you to consult with someone who can install it for you, or switch to an email program which supports encryption.
Encryption is a recommended technology which should be utilized when conducting online therapeutic interventions. At this time, however, it may not be considered a best practice because of the limitations in encryption technology (e.g., difficulty installing and registering, limits on U.S. encryption standards, usability questions, etc.). For instance, if you are emotionally distraught, the additional steps needed to read and send encrypted messages may simply be too much hassle. I still don’t know of anyone who uses encrypted email on a regular basis for any type of business.
This article outlined some of the common risk factors associated with confidentiality and privacy, comparing the real-world risks to the online world. While the online world does indeed offer its fair share of risks to a client’s confidentiality and privacy, it is not readily apparent that these risks are significantly or inherently greater than similar risks already taken in real-world therapy sessions.
There may be a tendency amongst professionals used to operating in the real world to overlook or virtually ignore the real, everyday risks associated with their practice, or to dismiss them as irrelevant or minimal. Yet these same professionals will loudly point out the risks of email based interventions without placing such risks into any type of useful context. Context is everything. Understanding the potential dangers is the first step toward giving a client truly informed consent, and taking measures to reduce these risks.
This is the first in a series of articles I hope to write in the upcoming months about various aspects of cybertherapy (often called “online therapy”). I hope they will act as a guide and starting point for anyone interested in practicing in this medium.