Data Security & Protection
Your privacy and the security of your protected health information (PHI) are our highest priorities. We employ industry-leading measures to safeguard your data.
Our Commitment to Privacy
At In Therapy, we understand that trust is the foundation of the therapeutic relationship. Just as we maintain strict confidentiality in our clinical practice, we extend that same level of care to your digital information.
We are committed to protecting your personal and health information through a comprehensive security framework that includes physical, administrative, and technical safeguards. This policy outlines how we collect, use, store, and protect your data in accordance with applicable laws and ethical standards.
Key Principle
Your data is never sold to third parties. We share information only when necessary for your care or as required by law, and always with your explicit consent where applicable.
Regulatory Compliance
In Therapy adheres to all relevant federal, state, and international regulations governing healthcare data privacy. Our compliance program is regularly audited and updated to reflect evolving legal requirements.
HIPAA (Health Insurance Portability and Accountability Act)
We maintain strict adherence to HIPAA Privacy and Security Rules. All covered entities and business associates are bound by Business Associate Agreements (BAAs) to ensure PHI protection throughout the data lifecycle.
GDPR (General Data Protection Regulation)
For clients in the European Economic Area, we comply with GDPR requirements including lawful basis for processing, data minimization, and honoring data subject rights.
Technical Safeguards
We implement state-of-the-art technical measures to protect electronic protected health information (ePHI) from unauthorized access, disclosure, or alteration.
Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Databases, backups, and endpoints are fully encrypted.
Access Control
Role-based access control (RBAC) ensures staff can only access data necessary for their duties. Multi-factor authentication (MFA) is mandatory.
Auditing
Comprehensive audit logs track all access and modifications to PHI. Logs are monitored 24/7 for suspicious activity.
Backups
Automated, encrypted backups are performed daily and stored in geographically distributed, secure data centers.
Infrastructure Security
- Firewalls & IDS/IPS: Advanced threat protection and intrusion detection systems monitor network traffic.
- Vulnerability Management: Regular penetration testing and vulnerability scans conducted by third-party experts.
- Endpoint Protection: All devices accessing client data run enterprise-grade antivirus and endpoint detection solutions.
Organizational Safeguards
Technical measures are complemented by rigorous administrative policies and employee training programs.
| Policy Area | Description |
|---|---|
| Employee Training | Mandatory annual privacy and security training for all staff, including phishing simulations and HIPAA refreshers. |
| Access Reviews | Quarterly access reviews to ensure permissions align with current job responsibilities. Immediate revocation upon role change or termination. |
| Incident Response | Dedicated security incident response team with defined playbooks for breach detection, containment, and remediation. |
| Vendor Management | Third-party vendors are assessed for security compliance before engagement and monitored regularly. |
| Physical Security | Secure office facilities with controlled access, locked filing cabinets, and secure disposal of physical records. |
Telehealth & Video Session Security
Our virtual therapy platform is built on security-by-design principles to ensure your online sessions remain private and protected.
- End-to-End Encryption: Video and audio streams are encrypted end-to-end, ensuring only you and your therapist can access the session.
- Secure Waiting Rooms: Sessions are accessed through unique, time-limited links with virtual waiting rooms to prevent unauthorized entry.
- Session Recording Policy: Sessions are never recorded or stored unless explicitly required for clinical supervision with your written consent.
- Device Recommendations: We provide guidelines for clients to secure their own devices and environments during telehealth sessions.
Client Responsibility
To maintain session privacy, please ensure you are in a private location, use headphones, and avoid recording sessions on unauthorized devices.
Patient Rights
You have specific rights regarding your health information under HIPAA and other privacy laws. In Therapy respects and facilitates the exercise of these rights.
Right to Access
You may request copies of your medical records. We will provide them in the format requested within 30 days.
Right to Amendment
If you believe information is incorrect or incomplete, you may request an amendment to your records.
Right to Accounting
You can request a list of disclosures made for purposes other than treatment, payment, or healthcare operations.
Right to Complaint
You may file a complaint with us or directly with the Office for Civil Rights if you believe your rights have been violated.
Data Retention & Deletion
We retain your health information for the minimum period necessary to fulfill the purpose for which it was collected, or as required by law.
- Clinical Records: Retained for a minimum of 7 years after the last service date, or longer if required by state law.
- Administrative Data: Retained for 5 years following account closure.
- Deletion Requests: Subject to legal retention obligations, we will delete or anonymize your data upon request where feasible.
Breach Notification Protocol
In the unlikely event of a security breach affecting your protected health information, In Therapy is committed to prompt notification and remediation.
We will notify affected individuals within the timeframes required by applicable law, typically within 60 days of discovery. Notifications will include:
- Description of the breach and types of information involved
- Steps taken to investigate and mitigate the incident
- Measures being taken to protect affected individuals
- Contact information for inquiries and credit monitoring services if applicable
Contact Us
If you have questions about this policy, wish to exercise your rights, or need to report a security concern, please contact us:
🚨 Security Incident Reporting
Email: security@intherapy.com
For urgent security concerns, call our 24/7 incident line: (555) 123-4599
📬 Mailing Address
In Therapy
Attn: Data Protection Officer
123 Wellness Blvd, Suite 200
New York, NY 10001