
Privacy Policy
Privacy Policy for Heard Counseling
1. Introduction
At Heard Counseling LLC, we are committed to protecting the privacy and security of our clients' personal health information (PHI). This policy outlines how we collect, use, store, and safeguard your data in compliance with the Health Insurance Portability and Accountability Act (HIPAA). This includes communication through platforms like Telzio and other online therapy technologies.
2. Definitions
-
Protected Health Information (PHI): Any information that relates to your physical or mental health, treatment, or payment for healthcare services that can identify you.
-
Telehealth Services: Virtual therapy sessions delivered via phone, video call, or other remote communication methods.
-
Business Associate: A third-party service provider, such as Telzio, who may handle PHI on behalf of Heard Counseling LLC.
3. Information We Collect
We may collect the following types of information for the purpose of providing therapy services:
-
Personal Identifiable Information (PII): Name, address, phone number, email, date of birth.
-
Health Information: Medical history, treatment plans, diagnoses, therapy session notes.
-
Communication Data: Data associated with virtual therapy sessions, including video, audio, or chat records.
4. Use and Disclosure of Information
We will use and disclose your PHI only for the following purposes:
-
Treatment: To provide therapy services and support, including communication via Telzio or other telehealth platforms.
-
Payment: For billing and payment purposes (e.g., insurance claims or payment processing).
-
Healthcare Operations: For practice management, quality improvement, and legal compliance.
We will obtain your consent prior to using your data for any other purpose.
5. Data Management and Security Measures
A. Data Encryption and Transmission Security
We use secure methods to ensure your data is transmitted and stored safely. Telzio, our chosen communications provider, complies with HIPAA standards for securing communication and data in transit. Video and phone calls are encrypted to prevent unauthorized access during virtual sessions. Any and all opt-in data will not be shared with third parties.
B. Access Controls
We restrict access to your PHI to authorized personnel only, such as licensed therapists and administrative staff. All authorized personnel undergo HIPAA training.
C. Data Retention
We retain your health records for a minimum of six years, as required by HIPAA regulations. After this period, records are securely destroyed or anonymized.
D. Business Associate Agreement (BAA) with Telzio
We have entered into a Business Associate Agreement (BAA) with Telzio, which outlines their obligations to protect your PHI. Telzio is required to comply with HIPAA guidelines, ensuring that your information is protected during virtual therapy sessions.
6. Communication via Telzio
Telzio provides telephony services for virtual therapy appointments. This platform is HIPAA-compliant and ensures that your calls and video sessions are encrypted and secure. We do not use Telzio or any third-party service to record therapy sessions without your explicit consent, unless required by law.
A. Confidentiality During Communication
-
All virtual sessions will be conducted in private and secure environments.
-
We will not share or disclose your session details with anyone without your consent, except as required by law (e.g., for mandatory reporting of abuse, court orders, etc.).
-
Mobile information will not be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
B. Secure Appointment Scheduling
Appointments can be scheduled via encrypted communication methods, such as secure email or a HIPAA-compliant platform. Confirmation or reminders may be sent via secure channels.
7. Client Rights and Control Over Information
You have the right to:
-
Access and Review Your Information: You may request access to your records or a copy of your health information.
-
Request Amendments: You may request corrections or updates to your health information if it is inaccurate or incomplete.
-
Revocation of Consent: You may revoke consent to share information with specific individuals or entities at any time, except where required by law.
-
Request Restrictions: You may request restrictions on how your health information is used or shared, though we are not obligated to agree to such restrictions.
To exercise these rights, please contact hello@heardcounseling.com.
If you wish to be removed from receiving future communications from Heard Counsleing, you can opt out by texting STOP.
8. Reporting Security Breaches
In the unlikely event of a data breach, we will promptly notify you in accordance with HIPAA's Breach Notification Rule. You will be informed of what happened, the information affected, and what steps you can take to protect yourself.
9. Changes to This Privacy Policy
We reserve the right to update this privacy policy periodically to comply with legal requirements and industry best practices. Any changes will be communicated to you, and the updated policy will be made available on our website.
10. Contact Us
If you have any questions or concerns about this privacy policy or our practices, please contact our Executive Director at kait@heardcounseling.com