At In Therapy, safeguarding your privacy and maintaining the confidentiality of your clinical records is fundamental to our practice. This Data Retention Policy outlines how we collect, store, secure, and eventually dispose of your personal and health information in strict compliance with HIPAA, state medical board regulations, and applicable data protection laws.
Last Updated: January 15, 2025 | Effective Date: February 1, 2025
What Information We Collect & Retain
To provide safe, effective therapeutic care and maintain operational compliance, we collect and retain the following categories of information:
- Clinical Records: Session notes, treatment plans, diagnosis codes, progress reports, and psychotherapy documentation.
- Personal Identifiers: Full name, date of birth, contact information, emergency contacts, and government-issued IDs (for verification).
- Health & Insurance Data: Insurance provider details, group numbers, referral information, and medical history relevant to treatment.
- Financial Records: Invoices, payment receipts, superbills, and billing correspondence.
- Digital Communications: Secure email exchanges, platform messages, and signed consent forms.
Data Retention Periods
We retain your information for legally required minimum periods, and sometimes longer to ensure continuity of care, protect against legal claims, and maintain clinical integrity. Once the retention period expires, data is securely and permanently destroyed.
| Data Category | Retention Period | Legal / Operational Basis |
|---|---|---|
| Clinical & Psychotherapy Records | 7 years after last treatment | State medical board & HIPAA requirements |
| Minor Patient Records | td>7 years after age of majorityState juvenile health regulations | |
| Billing & Insurance Records | 6–10 years | Tax code & payer compliance audits |
| Platform Account Data | Duration + 2 years | Service continuity & security monitoring |
| Communications & Correspondence | 5 years | Operational integrity & dispute resolution |
How We Secure Your Data
Your information is protected through industry-leading security protocols, including:
- End-to-End Encryption: All clinical data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Access Controls: Role-based permissions ensure only authorized clinicians and administrative staff access your records.
- Secure Infrastructure: Hosted on HIPAA-compliant, SOC 2 Type II certified cloud servers with regular third-party security audits.
- Employee Training: All staff undergo mandatory privacy, security, and ethical handling training annually.
- Physical Security: Any physical records (if applicable) are stored in locked, climate-controlled facilities with limited key access.
Your Rights & Data Management
Under applicable privacy laws, you have the right to:
- Access & Copy: Request a complete copy of your clinical and administrative records.
- Correction: Request amendments to inaccurate or incomplete information.
- Data Portability: Receive your data in a structured, machine-readable format.
- Deletion Requests: Submit requests for data removal, subject to legal retention obligations.
- Revocation of Consent: Withdraw consent for data processing at any time (excluding legally mandated records).
To exercise these rights, please contact our Privacy Officer or submit a signed Authorization for Release of Information form. We respond to valid requests within 30 business days.
Updates to This Policy
We review and update this Data Retention Policy periodically to reflect changes in healthcare regulations, technology standards, or our operational practices. Material changes will be communicated via secure email or platform notification. Your continued use of our services constitutes acknowledgment of updated policies.
Questions About Your Data?
Our Privacy & Compliance team is available to assist with records requests, access permissions, or policy clarifications.
Contact Privacy Officer →