At In Therapy, protecting your health information is our highest priority. We maintain strict adherence to the Health Insurance Portability and Accountability Act (HIPAA) and employ industry-leading security measures to safeguard your privacy.
We understand that seeking therapy requires trust and vulnerability. That's why we've built our practices, systems, and culture around uncompromising confidentiality and regulatory compliance.
All electronic protected health information (ePHI) is stored, processed, and transmitted through HIPAA-certified platforms with strict administrative, physical, and technical safeguards.
Your data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Only authorized personnel with role-based access can view your records.
Multi-factor authentication, session timeouts, and detailed audit logs ensure that only your assigned care team can access your information, and every access is monitored.
We conduct quarterly vulnerability assessments, annual third-party penetration testing, and continuous compliance monitoring to stay ahead of emerging threats.
We partner exclusively with vendors who meet or exceed HIPAA security standards. Every third-party service provider that handles your data signs a comprehensive Business Associate Agreement outlining their legal obligations to protect your information.
Our current BAA partners include our secure video conferencing platform, electronic health record (EHR) system, payment processor, and data backup providers. All agreements are reviewed annually and updated to reflect current regulations.
Federal law grants you specific rights regarding your protected health information. We are committed to honoring these rights transparently and promptly.
You have the right to request and receive a copy of your protected health information, including therapy notes, within 30 days of your request.
If you believe your records contain inaccurate or incomplete information, you may request amendments. We will review and respond to your request within 60 days.
You may request a list of certain disclosures of your health information made for purposes other than treatment, payment, or healthcare operations.
You may request limits on how we use or disclose your information for treatment, payment, or healthcare operations. We will honor reasonable restrictions where legally required.
In the event of a data breach affecting your unsecured protected health information, we are legally required to notify you, the Department of Health and Human Services, and potentially the media, within mandated timeframes.
If you have concerns about your health information, wish to exercise your HIPAA rights, or suspect a privacy violation, please contact our Privacy Officer directly.