Overview
At In Therapy, we recognize that trust is the foundation of the therapeutic relationship. We understand that you share deeply personal information with us, and we take our responsibility to protect that information seriously.
This policy outlines how we collect, use, store, and share your health information, our compliance with the Health Insurance Portability and Accountability Act (HIPAA), and the rights you have regarding your protected health information (PHI).
🔒 Our Commitment
Your privacy is non-negotiable. All staff members undergo rigorous training on data privacy and ethical standards to ensure your information remains secure at all times.
HIPAA Compliance
In Therapy strictly adheres to the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. We have implemented comprehensive policies and procedures to safeguard your protected health information.
Minimum Necessary Standard
We follow the "minimum necessary" standard, meaning we only access, use, or disclose the minimum amount of PHI needed to accomplish the intended purpose. For example, billing staff only see information relevant to insurance claims.
Business Associate Agreements
We require all third-party vendors and service providers who handle PHI (such as cloud storage, telehealth platforms, and billing companies) to sign Business Associate Agreements (BAAs) ensuring they also comply with HIPAA regulations.
Data Security Measures
We employ multi-layered security measures to protect your data across digital and physical environments:
- Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256). This includes emails, portal communications, and stored records.
- Secure Electronic Health Records (EHR): We use a HIPAA-compliant EHR system with role-based access controls, audit logs, and automatic session timeouts.
- Multi-Factor Authentication (MFA): All staff and therapist accounts require MFA to prevent unauthorized access.
- Regular Audits: We conduct quarterly security audits and annual risk assessments to identify and mitigate vulnerabilities.
- Physical Security: Our offices utilize keycard access, locked filing cabinets for any paper records, and secure shredding services for disposal.
| Security Measure | Description |
|---|---|
| Firewall Protection | Enterprise-grade firewalls monitor and control network traffic. |
| Anti-Virus/Malware | Real-time threat detection and automated updates on all devices. |
| Device Management | Remote wipe capabilities for lost or stolen company devices. |
Telehealth Privacy
For clients engaging in online therapy, we prioritize privacy in your home environment as well as our digital platform.
Platform Security
We use a dedicated, encrypted video conferencing platform designed for healthcare. Features include:
- End-to-end encryption for all video and audio streams.
- No recording of sessions unless explicitly authorized by the client in writing.
- Virtual waiting rooms to ensure privacy before the session begins.
⚠️ Your Responsibility
To ensure maximum privacy during online sessions, we recommend using headphones, finding a private space where you cannot be overheard, and ensuring your device is secure with a password.
Your Rights Under HIPAA
As our client, you have specific rights regarding your protected health information:
- Right to Access: You may request copies of your medical records within 30 days of your request.
- Right to Amendment: You may request corrections to your records if you believe they are inaccurate.
- Right to an Accounting of Disclosures: You can request a list of certain disclosures we made of your PHI.
- Right to Request Restrictions: You may ask us to limit how we use or share your information, though we are not always required to agree.
- Right to Confidential Communications: You may request that we contact you in a specific way or at a certain location (e.g., only via text or at work).
Limitations of Confidentiality
While we strive to maintain strict confidentiality, there are legal and ethical exceptions where we may be required or permitted to disclose information without your consent:
- Mandatory Reporting: Suspected abuse or neglect of children, elders, or dependent adults.
- Duty to Warn: If you pose a serious and imminent threat to yourself or an identifiable third party (Tarasoff duty).
- Court Orders: If a valid court order or subpoena is issued for your records.
- Medical Emergencies: Information may be shared with medical professionals in an emergency to treat you.
Breach Notification Policy
In the unlikely event of a data breach involving unsecured PHI, we are required to notify affected individuals without unreasonable delay and in no case later than 60 days following the discovery of the breach.
Our breach response plan includes immediate containment, investigation, notification to affected parties and the Department of Health and Human Services (HHS), and remediation steps to prevent future incidents.
Contact Our Privacy Officer
If you have questions about this policy, wish to exercise your rights, or suspect a privacy violation, please contact our designated Privacy Officer:
In Therapy Privacy Team
Email: privacy@intherapy.com
Phone: (555) 123-4567 ext. 2
Mail: 123 Wellness Blvd, Suite 200, NY 10001