← Back to Home

Information Sharing & Disclosure Policy

Last Updated: January 15, 2025 Effective Date: February 1, 2025 Policy Version: 3.2

Quick Navigation

1. Overview & Commitment to Confidentiality

At In Therapy, we recognize that trust is the foundation of effective mental health care. We are deeply committed to protecting the privacy and confidentiality of all personal and medical information shared with us. This policy outlines how we collect, use, share, and safeguard your information in compliance with applicable laws, including the Health Insurance Portability and Accountability Act (HIPAA), state privacy regulations, and ethical guidelines set by professional licensing boards.

Important Notice

Information shared during therapy sessions is strictly confidential. Exceptions to confidentiality are limited to specific legal and safety circumstances outlined in this policy. You have the right to understand exactly how your data is handled before beginning treatment.

2. Information We Collect & Maintain

To provide safe, effective, and personalized care, we may collect and maintain the following types of information:

  • Personal Identifiers: Name, date of birth, contact information, emergency contacts, and insurance details.
  • Clinical Records: Intake forms, progress notes, treatment plans, assessment results, and session summaries.
  • Financial & Billing Data: Payment history, insurance claims, and self-pay transaction records.
  • Technical & Platform Data: Secure login credentials, session participation logs, and encrypted communication records (for online therapy clients).

All records are maintained in secure, HIPAA-compliant electronic health record (EHR) systems and are accessible only to authorized clinical and administrative staff directly involved in your care.

3. How & When We Share Information

We will only share your protected health information (PHI) when legally permitted or required, or when you provide explicit written consent. Disclosure generally falls into the following categories:

3.1 With Your Explicit Consent

You may authorize us to share specific information with other healthcare providers, family members, employers, or educational institutions. Consent can be granted or revoked at any time in writing.

3.2 For Treatment, Payment & Healthcare Operations

We may share information with other treating professionals to coordinate your care, submit insurance claims, conduct internal quality reviews, or provide continuing education (with identifiers removed).

3.3 Legal & Safety Exceptions

Confidentiality may be legally overridden in the following circumstances:

  • Suspected abuse, neglect, or exploitation of children, elders, or vulnerable adults.
  • Imminent risk of serious harm to yourself or others (duty to warn/protect).
  • Court orders, subpoenas, or lawful governmental requests.
  • Reporting of certain communicable diseases or weapons-related threats as mandated by state law.

Whenever legally permissible, we will notify you before making a mandatory disclosure.

4. Your Rights & Controls

Under federal and state law, you have the right to:

  • Access & Copies: Request to view or obtain copies of your protected health information within 15 business days.
  • Amendment: Request corrections to inaccurate or incomplete records.
  • Restrictions: Ask us to limit how we use or share your information (we will accommodate reasonable requests unless legally required otherwise).
  • Accounting of Disclosures: Receive a list of certain disclosures made without your authorization, excluding those for treatment, payment, or operations.
  • Revoke Consent: Withdraw prior authorization for disclosures at any time by submitting a written request, except for information already shared or legally required.
  • Alternative Communication: Request that we contact you at a specific address, phone number, or method to protect confidentiality.

5. Security & Confidentiality Measures

We implement industry-leading technical, physical, and administrative safeguards to protect your data:

  • End-to-end encryption for all online sessions, messaging, and data storage.
  • Role-based access controls ensuring staff can only view information necessary for their duties.
  • Mandatory annual privacy & security training for all employees, contractors, and volunteers.
  • Regular third-party security audits, vulnerability assessments, and HIPAA compliance reviews.
  • Secure, climate-controlled physical storage for any paper records, with strict shredding protocols for disposal.
Data Breach Protocol

In the unlikely event of a security breach, we are legally required to notify you, relevant authorities, and your insurance provider within mandated timeframes. We will provide clear guidance on protective steps and offer complimentary credit monitoring services when applicable.

6. Third-Party Vendors & Business Associates

We occasionally engage third-party service providers to support our operations, including billing processors, IT infrastructure hosts, and telehealth platform vendors. All vendors are required to sign Business Associate Agreements (BAAs) that legally bind them to the same privacy and security standards we maintain. We conduct due diligence on all partners and monitor compliance regularly.

7. Contact Our Privacy Officer

If you have questions about this policy, wish to exercise your rights, or need to report a privacy concern, please contact our designated Privacy & Compliance Officer:

Privacy Office:
Email: privacy@intherapy.com
Phone: (555) 123-4567 ext. 802
Mail: In Therapy Privacy Office, 123 Wellness Blvd, Suite 200, New York, NY 10001

You may also file a complaint with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights if you believe your privacy rights have been violated. We will not retaliate against you for filing a complaint.

Disclaimer

This document is provided for informational purposes and outlines In Therapy’s general privacy practices. It does not constitute legal advice. For specific legal questions regarding your rights, please consult a qualified attorney or refer to official HHS guidance on HIPAA patient rights.