Compliance, Privacy & Ethical Standards

In Therapy is committed to maintaining the highest standards of data security, patient privacy, and clinical ethics. This page outlines our regulatory adherence, security protocols, and commitment to transparent, lawful practice.

Effective: January 1, 2025 Last Updated: October 15, 2025 Version 4.2

HIPAA & Patient Privacy

In Therapy operates in full compliance with the Health Insurance Portability and Accountability Act (HIPAA) and applicable state privacy laws. All Protected Health Information (PHI) is handled strictly for treatment, payment, and healthcare operations purposes.

🔒 Privacy Safeguards Compliant

  • Business Associate Agreements (BAAs) executed with all vendors handling PHI
  • Role-based access controls with principle of least privilege
  • Annual HIPAA training mandated for all clinical and administrative staff
  • Automatic session timeouts and multi-factor authentication (MFA) enforcement
Notice of Privacy Practices Clients receive our full Notice of Privacy Practices at intake. A printed or digital copy is available upon request at any time during treatment. By engaging our services, clients acknowledge they have been informed of their rights regarding their health information.

Data Security & Encryption

We employ enterprise-grade security measures to protect client data across all platforms, devices, and storage environments.

Security ControlImplementationStandard
Transit EncryptionTLS 1.3 across all web, API, and email channelsNIST SP 800-52 Rev 2
At-Rest EncryptionAES-256 for databases, backups, and file storageFIPS 140-2 Level 2
InfrastructureSOC 2 Type II certified cloud providersAICPA SOC 2
Access ControlSSO, RBAC, MFA, biometric auth on mobileZero Trust Architecture
Monitoring24/7 SIEM, automated anomaly detection, audit logsISO 27001

Client Rights & Access

Under HIPAA and ethical guidelines, clients maintain specific rights regarding their health information:

📄 Information Access & Portability

Clients may request copies of their records, therapy notes, and assessment results within 30 days. Electronic health records (EHR) can be exported in FHIR-compliant or standard PDF formats upon verified request.

✏️ Amendment & Correction

If a client believes information in their record is inaccurate or incomplete, they may submit a written amendment request. Our Compliance Officer will review and respond within 15 business days.

Breach Notification In the event of a confirmed data breach affecting PHI, we will notify affected clients, the Department of Health and Human Services (HHS), and applicable state authorities within legally mandated timeframes (typically 60 days or less).

Clinical Ethics & Licensing

All therapists at In Therapy are fully licensed, insured, and bound by professional ethical codes including APA, NASW, ACA, or state-equivalent standards.

  • Mandatory continuing education (CE) hours tracked annually
  • Supervised clinical practice for associate-level providers
  • Strict boundaries regarding dual relationships, gifts, and social media interactions
  • Mandatory reporting protocols for abuse, elder maltreatment, and imminent harm
  • Independent Ethics Review Board conducts quarterly audits of clinical documentation

Data Retention & Deletion

Clinical records are retained in accordance with federal and state regulations governing mental health documentation. Minimum retention periods vary by jurisdiction but typically range from 7 to 10 years post-termination of services.

Upon lawful request and expiration of mandatory retention periods, personal data may be permanently purged from active systems. Backups follow a 30-day staggered deletion cycle to ensure compliance without service disruption.

Third-Party & Vendor Oversight

We maintain strict vendor risk management protocols. All third-party service providers undergo:

  • Security questionnaires and SOC 2 / ISO 27001 validation
  • Penetration testing verification or equivalent security certifications
  • Contractual liability and indemnification clauses
  • Quarterly compliance reviews and right-to-audit provisions

Reporting & Contact

If you suspect a privacy violation, security incident, or ethical concern, please report it immediately through our secure channels. All reports are treated confidentially and investigated promptly.

Compliance Officer

Name: Dr. Elena Rostova, JD, MHA
Title: Director of Compliance & Patient Privacy
Email: compliance@intherapy.com (PGP key available)
Secure Portal: Submit Encrypted Report

🔐 End-to-end encrypted submission • Anonymous reporting supported