Privacy policy

HIPAA Compliance

  • Confidentiality of Protected Health Information (PHI): The practice enforces strict administrative, physical, and technical safeguards to secure client records, intake forms, and clinical notes.
  • EHR and Telehealth Security: All electronic health record (EHR) systems (e.g., SimplePractice) and telehealth platforms must utilize end-to-end encryption and have signed Business Associate Agreements (BAAs) on file.
  • Access Controls: Access to PHI is restricted based on the principle of “minimum necessary”—employees only access the records required to fulfill their specific administrative or clinical duties.

Breach Notification

Response Protocol: In the event of an unauthorized disclosure or data breach involving PHI, the practice will immediately follow federal and state breach notification rules, notifying affected clients and regulatory bodies within the legally mandated timeframes.