Duty to Warn and Duty to Protect: A Guide for US Mental Health Clinicians
What the Tarasoff duty to warn and duty to protect means for US healthcare staff, how HIPAA permits disclosure for serious threats and what to document.
Confidentiality is the foundation of mental health care, but it is not absolute. When a patient makes a credible threat to harm someone else, clinicians in the United States may have a legal duty to act, which can mean breaking confidentiality. The concept is often called the Tarasoff duty. How it works depends on the state, and on federal privacy law. This guide explains the basics for US mental health and healthcare staff.
It is general information, not legal advice. State laws vary significantly, so check your state's statute and case law, your licensing board's guidance and your organisation's policy. When a real situation arises, seek advice from your risk management or legal team.
What is the Tarasoff duty?
The duty takes its name from a landmark California case, Tarasoff v. Regents of the University of California, decided in the 1970s. It established that a mental health professional may have an obligation to take reasonable steps to protect an identifiable person who is threatened by a patient. Since then, states have developed their own approaches through statutes and court decisions. In general terms, the duty is triggered when a patient communicates a credible threat of serious violence toward an identifiable victim.
Duty to warn versus duty to protect
States tend to take one of two approaches:
- Duty to warn. The clinician must notify the potential victim or others who can intervene, such as law enforcement.
- Duty to protect. The clinician has a broader range of options for protecting the person, such as safety planning, arranging hospitalisation or contacting authorities, without necessarily being required to notify the victim.
Some states make action mandatory, some make it permissive, and some have no clear rule. Find out which applies in the state or states where you practise. Our guide to involuntary psychiatric holds guide covers involuntary holds, which can form part of a protective response.
How HIPAA fits in
The federal privacy rule, HIPAA, allows covered entities to disclose protected health information without the patient's authorisation when necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public. This is set out in 45 CFR 164.512(j). In a Tarasoff situation, it can allow disclosure to the person threatened, to law enforcement or to others who are in a position to reduce the risk. The minimum necessary standard still applies, so share only what is needed for the safety purpose. Our HIPAA training requirements guide explains the wider privacy framework.
What to do when a threat is made
- Assess the threat. Is it specific, credible and directed at an identifiable person? Consider access to means, history of violence and the patient's mental state.
- Consult. Talk to a supervisor, colleague or risk management team, and where appropriate your professional liability insurer or legal adviser.
- Consider less intrusive options first. Safety planning, increased contact, medication review and voluntary admission may reduce risk.
- Act if the threshold is met. Where your state law or your clinical judgment requires it, take protective steps, such as warning the person or alerting law enforcement.
- Limit disclosure. Share only what is necessary.
- Follow up. Keep working with the patient where possible, and review the plan.
Documentation
Good records matter, because they show that you acted in good faith and with sound professional judgment. Document:
- the nature and credibility of the threat, in the patient's own words where possible
- your risk assessment and the factors you considered
- who you consulted and what they advised
- who you disclosed information to, what you disclosed and why
- the outcome and any follow-up
Duty to warn and self-harm
Tarasoff concerns threats against other people. Different rules and clinical approaches apply where the risk is to the patient themselves. See our suicide risk reduction guide for suicide risk practice.
Common mistakes
- Assuming one national rule. State laws differ, and a clinician licensed in more than one state needs to check each.
- Breaching confidentiality too early. Not every angry statement is a credible threat.
- Failing to act when the threshold is met. Delay can put someone in danger.
- Over-disclosure. Sharing more than is necessary can breach privacy rules.
- Poor documentation. Decisions that are not recorded are hard to defend.
Frequently asked questions
Does HIPAA stop me from warning someone?
No. HIPAA permits disclosure to prevent or lessen a serious and imminent threat, subject to the minimum necessary standard and applicable state law.
Is the duty the same in every state?
No. States vary between mandatory and permissive approaches, and some do not have a clear rule.
Should I tell the patient first?
Discuss your obligations at the start of treatment through informed consent, and consider whether telling the patient is safe and clinically appropriate when a threat arises.
Where can teams find training?
See the CPD hub for professional development options for healthcare teams.
Learnsignal will update this guide as state laws and guidance change.
This page was last updated:
Learnsignal Healthcare Education Team
The Learnsignal Healthcare Education Team creates CPD and compliance training content for nurses, allied health professionals, and care providers, drawing on current regulatory guidance from bodies including NMBI and equivalent professional regulators.
View all posts by Learnsignal Healthcare Education Team


