Data Security & Protection

Your privacy and the security of your protected health information (PHI) are our highest priorities. We employ industry-leading measures to safeguard your data.

📅 Last Updated: June 2025 👤 Version 4.2 🏷️ Policy ID: SEC-2025-006

Our Commitment to Privacy

At In Therapy, we understand that trust is the foundation of the therapeutic relationship. Just as we maintain strict confidentiality in our clinical practice, we extend that same level of care to your digital information.

We are committed to protecting your personal and health information through a comprehensive security framework that includes physical, administrative, and technical safeguards. This policy outlines how we collect, use, store, and protect your data in accordance with applicable laws and ethical standards.

Key Principle

Your data is never sold to third parties. We share information only when necessary for your care or as required by law, and always with your explicit consent where applicable.

Regulatory Compliance

In Therapy adheres to all relevant federal, state, and international regulations governing healthcare data privacy. Our compliance program is regularly audited and updated to reflect evolving legal requirements.

HIPAA Compliant
GDPR Compliant
SOC 2 Type II
HITECH Act

HIPAA (Health Insurance Portability and Accountability Act)

We maintain strict adherence to HIPAA Privacy and Security Rules. All covered entities and business associates are bound by Business Associate Agreements (BAAs) to ensure PHI protection throughout the data lifecycle.

GDPR (General Data Protection Regulation)

For clients in the European Economic Area, we comply with GDPR requirements including lawful basis for processing, data minimization, and honoring data subject rights.

Technical Safeguards

We implement state-of-the-art technical measures to protect electronic protected health information (ePHI) from unauthorized access, disclosure, or alteration.

🔐

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Databases, backups, and endpoints are fully encrypted.

🛡️

Access Control

Role-based access control (RBAC) ensures staff can only access data necessary for their duties. Multi-factor authentication (MFA) is mandatory.

📊

Auditing

Comprehensive audit logs track all access and modifications to PHI. Logs are monitored 24/7 for suspicious activity.

💾

Backups

Automated, encrypted backups are performed daily and stored in geographically distributed, secure data centers.

Infrastructure Security

  • Firewalls & IDS/IPS: Advanced threat protection and intrusion detection systems monitor network traffic.
  • Vulnerability Management: Regular penetration testing and vulnerability scans conducted by third-party experts.
  • Endpoint Protection: All devices accessing client data run enterprise-grade antivirus and endpoint detection solutions.

Organizational Safeguards

Technical measures are complemented by rigorous administrative policies and employee training programs.

Policy Area Description
Employee Training Mandatory annual privacy and security training for all staff, including phishing simulations and HIPAA refreshers.
Access Reviews Quarterly access reviews to ensure permissions align with current job responsibilities. Immediate revocation upon role change or termination.
Incident Response Dedicated security incident response team with defined playbooks for breach detection, containment, and remediation.
Vendor Management Third-party vendors are assessed for security compliance before engagement and monitored regularly.
Physical Security Secure office facilities with controlled access, locked filing cabinets, and secure disposal of physical records.

Telehealth & Video Session Security

Our virtual therapy platform is built on security-by-design principles to ensure your online sessions remain private and protected.

  • End-to-End Encryption: Video and audio streams are encrypted end-to-end, ensuring only you and your therapist can access the session.
  • Secure Waiting Rooms: Sessions are accessed through unique, time-limited links with virtual waiting rooms to prevent unauthorized entry.
  • Session Recording Policy: Sessions are never recorded or stored unless explicitly required for clinical supervision with your written consent.
  • Device Recommendations: We provide guidelines for clients to secure their own devices and environments during telehealth sessions.

Client Responsibility

To maintain session privacy, please ensure you are in a private location, use headphones, and avoid recording sessions on unauthorized devices.

Patient Rights

You have specific rights regarding your health information under HIPAA and other privacy laws. In Therapy respects and facilitates the exercise of these rights.

📄

Right to Access

You may request copies of your medical records. We will provide them in the format requested within 30 days.

✏️

Right to Amendment

If you believe information is incorrect or incomplete, you may request an amendment to your records.

📋

Right to Accounting

You can request a list of disclosures made for purposes other than treatment, payment, or healthcare operations.

⚠️

Right to Complaint

You may file a complaint with us or directly with the Office for Civil Rights if you believe your rights have been violated.

Data Retention & Deletion

We retain your health information for the minimum period necessary to fulfill the purpose for which it was collected, or as required by law.

  • Clinical Records: Retained for a minimum of 7 years after the last service date, or longer if required by state law.
  • Administrative Data: Retained for 5 years following account closure.
  • Deletion Requests: Subject to legal retention obligations, we will delete or anonymize your data upon request where feasible.

Breach Notification Protocol

In the unlikely event of a security breach affecting your protected health information, In Therapy is committed to prompt notification and remediation.

We will notify affected individuals within the timeframes required by applicable law, typically within 60 days of discovery. Notifications will include:

  • Description of the breach and types of information involved
  • Steps taken to investigate and mitigate the incident
  • Measures being taken to protect affected individuals
  • Contact information for inquiries and credit monitoring services if applicable

Contact Us

If you have questions about this policy, wish to exercise your rights, or need to report a security concern, please contact us:

📧 Privacy Officer

Email: privacy@intherapy.com

Phone: (555) 123-4567 ext. 800

🚨 Security Incident Reporting

Email: security@intherapy.com

For urgent security concerns, call our 24/7 incident line: (555) 123-4599

📬 Mailing Address

In Therapy
Attn: Data Protection Officer
123 Wellness Blvd, Suite 200
New York, NY 10001