HIPAA & Patient Privacy
In Therapy operates in full compliance with the Health Insurance Portability and Accountability Act (HIPAA) and applicable state privacy laws. All Protected Health Information (PHI) is handled strictly for treatment, payment, and healthcare operations purposes.
🔒 Privacy Safeguards Compliant
- Business Associate Agreements (BAAs) executed with all vendors handling PHI
- Role-based access controls with principle of least privilege
- Annual HIPAA training mandated for all clinical and administrative staff
- Automatic session timeouts and multi-factor authentication (MFA) enforcement
Data Security & Encryption
We employ enterprise-grade security measures to protect client data across all platforms, devices, and storage environments.
| Security Control | Implementation | Standard |
|---|---|---|
| Transit Encryption | TLS 1.3 across all web, API, and email channels | NIST SP 800-52 Rev 2 |
| At-Rest Encryption | AES-256 for databases, backups, and file storage | FIPS 140-2 Level 2 |
| Infrastructure | SOC 2 Type II certified cloud providers | AICPA SOC 2 |
| Access Control | SSO, RBAC, MFA, biometric auth on mobile | Zero Trust Architecture |
| Monitoring | 24/7 SIEM, automated anomaly detection, audit logs | ISO 27001 |
Client Rights & Access
Under HIPAA and ethical guidelines, clients maintain specific rights regarding their health information:
📄 Information Access & Portability
Clients may request copies of their records, therapy notes, and assessment results within 30 days. Electronic health records (EHR) can be exported in FHIR-compliant or standard PDF formats upon verified request.
✏️ Amendment & Correction
If a client believes information in their record is inaccurate or incomplete, they may submit a written amendment request. Our Compliance Officer will review and respond within 15 business days.
Clinical Ethics & Licensing
All therapists at In Therapy are fully licensed, insured, and bound by professional ethical codes including APA, NASW, ACA, or state-equivalent standards.
- Mandatory continuing education (CE) hours tracked annually
- Supervised clinical practice for associate-level providers
- Strict boundaries regarding dual relationships, gifts, and social media interactions
- Mandatory reporting protocols for abuse, elder maltreatment, and imminent harm
- Independent Ethics Review Board conducts quarterly audits of clinical documentation
Data Retention & Deletion
Clinical records are retained in accordance with federal and state regulations governing mental health documentation. Minimum retention periods vary by jurisdiction but typically range from 7 to 10 years post-termination of services.
Upon lawful request and expiration of mandatory retention periods, personal data may be permanently purged from active systems. Backups follow a 30-day staggered deletion cycle to ensure compliance without service disruption.
Third-Party & Vendor Oversight
We maintain strict vendor risk management protocols. All third-party service providers undergo:
- Security questionnaires and SOC 2 / ISO 27001 validation
- Penetration testing verification or equivalent security certifications
- Contractual liability and indemnification clauses
- Quarterly compliance reviews and right-to-audit provisions
Reporting & Contact
If you suspect a privacy violation, security incident, or ethical concern, please report it immediately through our secure channels. All reports are treated confidentially and investigated promptly.
Compliance Officer
Name: Dr. Elena Rostova, JD, MHA
Title: Director of Compliance & Patient Privacy
Email: compliance@intherapy.com (PGP key available)
Secure Portal: Submit Encrypted Report