In twenty-three years of hospice cybersecurity work, I have never had a hospice administrator proactively raise the security of chaplaincy documentation as a priority. It is always my observation, not theirs. And yet when I read what hospice chaplains actually document — and I have read thousands of these notes in the context of compliance assessments and training — I am consistently reminded that chaplaincy documentation is among the most intimate and most sensitive information that any healthcare organisation maintains.
A chaplain who has spent four visits with a dying man over two weeks documents not what medications he is receiving, but what he fears; not his vital signs, but the estrangement from his daughter that he is hoping to repair; not his diagnosis, but his questions about what happens after death; not his care plan compliance, but the regrets he has carried for forty years and is now trying to release. This is information that the patient shared in the absolute trust that it would be held with the same discretion that religious confession is held. HIPAA calls it PHI. The chaplain's training calls it sacred. Both are correct. The compliance infrastructure must honour both.
What follows is not just an argument for why spiritual care documentation deserves heightened protection — most hospice leaders accept that argument when it is made clearly. It is a practical guide for implementing that protection in the specific EHR platforms that hospice chaplains document in, in the specific operational workflows where the protection must function, and in the specific training conversations that help chaplains understand HIPAA as an extension of their existing pastoral confidentiality obligations rather than a bureaucratic overlay on them.
Why Spiritual Care Documentation Is Currently Underprotected in Most Hospice EHRs
The default EHR access configuration at most hospice organisations treats chaplaincy notes the same as nursing visit notes — accessible to every clinical user with access to the patient record. This configuration reflects the EHR vendor's default settings, which are designed for clinical workflow convenience rather than minimum necessary compliance. It also reflects the operational culture of interdisciplinary care, where information sharing among team members is valued as a care quality asset. Both of these influences are legitimate. Neither justifies the current state.
Consider who currently has default access to chaplaincy notes in a typical hospice EHR with standard configuration. The clinical supervisor who oversees quality — appropriate. The primary nurse — appropriate in certain circumstances. The social worker — appropriate when the social work and spiritual care teams coordinate. The billing coordinator who accesses the clinical record for billing purposes — not appropriate. The aide who documents personal care visits and can see the full clinical record — not appropriate. The scheduling coordinator who has clinical record access for care coordination purposes — not appropriate. The volunteer coordinator whose access was configured the same as other clinical users for simplicity — not appropriate.
Each of these users has access to the dying man's fears, regrets, and final confidences because no one specifically configured the EHR to restrict chaplaincy note access. That configuration takes less than an hour in most hospice EHR platforms. The gap between the sensitivity of the content and the simplicity of the fix is one of the most actionable compliance improvements available to hospice administrators.
The Ethical and Legal Foundations of Heightened Spiritual Care Protection
The HIPAA Minimum Necessary Standard Applied to Pastoral Documentation
HIPAA's minimum necessary standard requires that access to PHI be limited to what each user needs for their specific role. The question is not whether spiritual care documentation is PHI — it is. The question is which roles have a legitimate clinical need for access to the full spiritual care narrative. The answer is narrower than the default EHR configuration reflects: the chaplain who documented the encounter, the director of chaplaincy services with supervisory oversight, and the physician or nurse practitioner who integrates spiritual care assessment into the overall care plan. Everyone else — including other IDG members who participate in the same patient's care — has access to the chaplain's IDG meeting summary contribution rather than the full pastoral encounter narrative.
State Law Protections for Pastoral Communications
Several states have enacted statutory protections for pastoral communications that go beyond HIPAA's PHI protections. These protections — sometimes called clergy-penitent privilege or pastoral communications privilege — typically protect communications made to a clergy member or spiritual advisor in their professional capacity for the purpose of spiritual counsel. The specific scope, the parties protected, and the conditions under which the privilege applies vary significantly by state.
New York's CPLR § 4505 recognises a privilege for communications between a person and a clergyman acting in his professional character as a spiritual advisor. California's Evidence Code § 1033 recognises a penitent's privilege for penitential communications made in confidence to a member of the clergy. Texas Rule of Evidence 505 recognises communications between clergy and a person seeking spiritual counsel.
The application of these privileges to hospice chaplaincy documentation requires consultation with legal counsel in each state where the hospice operates — the intersection of state privilege law with HIPAA's regulatory framework is not settled uniformly, and the privilege's applicability in the healthcare context varies. What is clear is that hospice compliance officers should be aware that state law may impose confidentiality obligations on spiritual care documentation that are at least as protective as HIPAA's minimum necessary standard — and that those obligations inform the access control configuration that the hospice implements.
For hospice organisations operating in states with pastoral communication privilege, the practical implication is that the access control configuration for chaplaincy notes should reflect the most protective standard applicable — which is at least as restrictive as the HIPAA minimum necessary standard and may be more restrictive depending on the state law analysis. Consult legal counsel in each state where you operate to confirm the applicable standard before finalising the access control configuration.
EHR Configuration: Implementing Chaplaincy Note Restriction in Major Hospice Platforms
The configuration that restricts chaplaincy note access to appropriate roles is achievable in every major hospice EHR platform. The specific steps vary by platform but the underlying capability is consistent: note-type-level access restriction that assigns a restricted access profile to spiritual care documentation separately from the general clinical record access profile.
Axxess Hospice: Configuring Spiritual Care Note Restriction
In Axxess Hospice, chaplaincy note restriction is configured through the role-based access settings in the Administration module:
• Navigate to Administration > Security > User Roles and identify the existing clinical user roles that currently have access to all clinical documentation.
• Create a new restricted document type category for spiritual care documentation. In Axxess, navigate to Administration > Clinical > Document Types and create a "Spiritual Care" or "Pastoral Care" document type that is distinct from the general clinical visit note type.
• Configure the access profile for the Spiritual Care document type to restrict visibility to the Chaplain role, the Clinical Supervisor role (for oversight), and the Physician/NP role (for care plan integration). Remove access from the general clinical user role that applies to nurses, aides, social workers, billing coordinators, and scheduling staff.
• Test the configuration by logging in as a user in each role category and confirming that Spiritual Care notes are visible to appropriate roles and not visible to non-appropriate roles before the configuration goes live.
• Contact Axxess support to confirm the current version's capability for document-type-level access restriction and to verify that the configuration approach described above matches the current administrative interface. Axxess updates its administrative framework periodically.
Brightree Hospice: Configuring Spiritual Care Note Restriction
Brightree's security administration module supports role-based access at the document type and module level:
• In Brightree's Security Administration, navigate to Role Management and create a Chaplaincy role with a restricted permission set that differs from the standard clinical user role.
• In the Chaplaincy role permissions, configure document type access to include Spiritual Care Notes and Care Plan access. Explicitly exclude access to the full clinical record for other documentation categories that the Chaplaincy role does not need.
• For non-chaplaincy clinical roles (Nurse, Aide, Social Worker), navigate to their respective role permissions and confirm that Spiritual Care Notes access is not included in their document type permissions. In default Brightree configurations, all clinical document types may be accessible to all clinical roles — the restriction must be explicitly applied.
• Brightree's SSO integration with external identity providers allows access lifecycle management — including Chaplaincy role assignment and revocation — to be handled through the identity provider, ensuring that access is managed consistently with the hospice's overall identity management programme.
MatrixCare Hospice: Configuring Spiritual Care Note Restriction
MatrixCare offers the most granular permission architecture of the major hospice EHR platforms, supporting access restriction at the note category and field level:
• In MatrixCare's User Management module, navigate to Permission Sets and create a Chaplaincy permission set that explicitly includes access to the Pastoral Care / Spiritual Care note category and explicitly excludes access to all other clinical documentation categories not needed for the chaplaincy role.
• Apply the Chaplaincy permission set to all chaplain user accounts. Confirm that the standard clinical permission set applied to nurses, aides, and social workers does not include the Pastoral Care / Spiritual Care note category.
• MatrixCare supports field-level audit logging for specific document categories. Enable field-level audit logging for the Pastoral Care / Spiritual Care note category to capture not just that a document was accessed but which specific fields were viewed. This enhanced audit capability is particularly valuable for chaplaincy documentation given its sensitivity.
• For MatrixCare multi-setting deployments that also serve SNF or assisted living, confirm that the hospice Chaplaincy permission set does not inherit permissions from other care setting permission sets within the same MatrixCare deployment. Cross-setting permission inheritance is a consistent gap in multi-setting implementations.
Chaplain HIPAA Training: Connecting Regulatory Requirements to Pastoral Values
Hospice chaplains receive extensive training in pastoral confidentiality through their professional formation — clinical pastoral education programmes, denominational training, and board certification processes all emphasise the confidential nature of pastoral relationships. This existing value framework is an asset in HIPAA training for chaplains: rather than presenting HIPAA as an external regulatory imposition, effective chaplain HIPAA training connects the regulatory requirements to the pastoral values that chaplains already hold.
The Framing That Works
The most effective framing I have seen in hospice chaplain HIPAA training: "The confidentiality obligations that HIPAA imposes on how we manage patient information are a legal expression of the pastoral confidentiality that your professional formation already requires of you. HIPAA says that patient information must be shared only with those who have a legitimate need to know it. Your pastoral formation says that what patients share with you in spiritual counsel is held in confidence. These are the same obligation expressed in two different languages. HIPAA adds documentation requirements, access control requirements, and breach notification requirements — but the core value is one you already hold."
This framing produces a different training response from chaplains than a compliance-focused presentation of HIPAA requirements. Chaplains who understand HIPAA as a regulatory extension of their existing pastoral confidentiality obligations are more likely to engage thoughtfully with the specific compliance requirements and less likely to experience HIPAA training as a bureaucratic imposition on their ministry.
The Chaplain-Specific HIPAA Training Content
Beyond the general HIPAA privacy and security training that all hospice workforce members receive, chaplains benefit from training content that addresses their specific documentation context:
• The minimum necessary standard applied to chaplaincy: what this means for how chaplains share information from pastoral encounters with other IDG members — the distinction between sharing clinically relevant information through the clinical communication protocol and sharing pastoral encounter content through the restricted chaplaincy note system
• The cross-discipline information sharing protocol: the specific steps for communicating clinically significant information from a pastoral encounter to the clinical team without disclosing the full spiritual care record — the protocol described in our IDG documentation security article
• The state law pastoral communication privilege: an accessible explanation of whether and how state law extends additional confidentiality protections to pastoral communications in the state where the hospice operates, and what that means for chaplaincy documentation access
• Documentation best practices for spiritual care notes: what level of detail is appropriate to document, what should remain undocumented because it is not relevant to care coordination, and how to describe a pastoral encounter in terms that serve the care plan without exposing the full intimacy of the pastoral conversation
• The access control configuration: a brief explanation of why chaplaincy notes have a restricted access profile in the EHR — so that chaplains understand that the restriction is deliberate and protective, not a technical limitation — and how to request access override when a legitimate clinical need requires it
When Other Care Team Members Request Access to Chaplaincy Notes
The restricted access configuration for chaplaincy notes will occasionally generate requests from other IDG members who want access to spiritual care documentation for what they believe are legitimate clinical reasons. The access request protocol should be documented and understood by all relevant staff before the configuration goes live — a chaplain who is asked by a nurse for access to the spiritual care notes should have a clear, confident response.
The response framework: "Chaplaincy notes have a restricted access profile to protect the confidentiality of what patients share in pastoral encounters. If there is clinically relevant information from a pastoral visit that affects the care plan, the chaplain communicates that information through our clinical communication protocol. If you need specific information from a pastoral encounter that affects your clinical decision-making, please contact the chaplain directly or through the clinical supervisor who can facilitate the appropriate information sharing."
Access override requests — requests for access to chaplaincy notes for a documented clinical reason beyond the standard access profile — should be processed through the HIPAA Security Officer, documented with the clinical rationale, and granted for the specific purpose and time period required rather than as a standing access expansion. Each override request and its disposition should be documented in the access control review log.
ShieldForce implements spiritual care documentation access controls as a standard component of every hospice managed service engagement — EHR-specific configuration for chaplaincy note restriction, cross-discipline information sharing protocol documentation, chaplain HIPAA training with the pastoral values framing, and quarterly audit log review of chaplaincy note access events. The configuration respects both the regulatory obligation and the pastoral trust that makes hospice spiritual care possible. Start with a free assessment.
→ Schedule Your Free HIPAA Risk Assessment — shieldforce.io/hipaa-assessment
→ Explore Hospice Cybersecurity — shieldforce.io/hospice-cybersecurity
→ View Transparent Pricing from $35/user/month — shieldforce.io/pricing-comparison

