Privacy Policy
Effective Date: May 12, 2025
Applies to: All U.S.-based clients, users, contractors, and visitors of Empowered Harmony Counseling, Psychiatry & Wellness Center
​​
Empowered Harmony Counseling, Psychiatry & Wellness Center (“Empowered Harmony,” “we,” “our,” “us”) is committed to safeguarding your privacy and ensuring the security of your personal, medical, and health-related information. This policy explains how we collect, use, protect, and disclose your data and complies with HIPAA, the HITECH Act, 42 CFR Part 2, CCPA, and all applicable federal and state privacy laws.
By engaging with our services or visiting our platforms, you agree to the terms outlined in this Privacy Policy.
1. Who We Are
Empowered Harmony is growing to a nationwide corporation, virtual behavioral health and wellness practice headquartered in Wyoming. We provide therapy, psychiatry, coaching, integrative wellness, and culturally responsive services. Our team includes licensed and pre-licensed providers, psychiatric professionals, administrative support, coaches, and contractors. All professionals adhere to HIPAA and their respective ethical codes and licensing requirements.
2. Scope of This Policy
This policy covers all data collected through our:
• Website, portals, and forms
• Client communications via text, call, email, or video
• Interactions with referral sources, contractors, and third-party platforms
It does not cover external websites linked through our site. Please review those sites’ privacy policies separately.
3. Types of Data We Collect
A. Personal and Demographic Information:
Name, contact details, ID verification, emergency contacts, payment and insurance data.
B. Health and Clinical Information (PHI):
Diagnosis, treatment notes, provider communications, prescriptions, care coordination details.
C. Technical and Usage Data:
Device identifiers, browser data, IP address, referral source, geolocation (approximate).
D. Third-Party Sources:
Insurance payers, referring professionals, EAPs, schools, or courts, only with consent or as legally required.
4. Legal Grounds for Collection
We collect your data:
• With your consent
• To deliver health services
• To comply with legal obligations
• For safety and emergency purposes
• In support of legitimate operational needs
5. How We Use Your Data
We use your data to:
• Provide, coordinate, and document care
• Communicate updates, reminders, and billing
• Improve services and maintain secure systems
• Fulfill legal and ethical obligations
• Conduct de-identified research or supervision (if applicable)
We never use or sell PHI for marketing or advertising without explicit consent.
​
6. Data Sharing
A. With Authorization:
To coordinate care or provide reports to approved parties.
B. Without Authorization (Legally Permitted):
For court orders, abuse reporting, safety risks, or audits.
C. With Business Associates:
Under strict Business Associate Agreements (BAAs) with vendors such as TherapyNotes, SimplePractice, cloud platforms, billing processors, or credentialing partners.​
7. Data Storage and Retention
• Adult records: Retained at least 7 years from last service date
• Minor records: Retained at least 7 years past age 18
• Financial and communication records: Retained per legal and tax requirements
• Data is stored securely with access logs and encryption
8. Your Privacy Rights
You have the right to:
• Access or request copies of your records
• Request amendments or restrictions
• Opt for confidential communication
• Revoke consents
• File privacy complaints without retaliation
Contact: support@empoweredharmony.com
9. Children and Adolescent Privacy
• Clients under 14 require parental consent
• Adolescents may have partial privacy rights depending on state law
• Record access may be limited to parents unless legally mandated
10. Cookie and Web Tracking Policy
We use cookies and analytics tools (e.g., Google Analytics) to improve site functionality and user experience. These tools do not collect PHI. You may disable cookies in your browser settings.
​
11. Marketing and Communications
We do not send promotional messages without consent. You may opt out at any time via email or the “unsubscribe” link in messages.​
12. Security Measures
Our safeguards include:
• Encryption of PHI
• Two-factor authentication (2FA)
• Role-based access controls
• Regular audits and training
• Confidentiality agreements
If a breach occurs, you will be notified within 60 days per HIPAA and the HITECH Act.
13. Client Portals and Third-Party Disclaimers
We use HIPAA-compliant platforms (e.g., SimplePractice, TherapyNotes). Although vendors are carefully selected and contractually bound to confidentiality, we are not liable for vendor-side failures beyond our control.
​
14. Special Handling of Sensitive Data
Sensitive information such as trauma history, sexual orientation, substance use, and disability status is treated with extra care. Only authorized personnel have access to this data.
15. Use of AI Tools
We may use AI tools (e.g., grammar support, documentation aids) to improve quality and efficiency. These tools never replace clinical decision-making and are used under HIPAA-compliant settings.
16. Minor Rights and Parental Access
Minors may have rights to confidentiality under certain state laws. We follow the most protective law available and only release minor records with proper authorization.
​
17. Cross-State Compliance
We operate in multiple states and comply with each state’s privacy, telehealth, and minor consent laws. The highest standard is always applied.
18. Business Associate Agreements
We maintain signed BAAs with all vendors and contractors who handle PHI. All third parties must comply with our privacy and security protocols.​
19. Subprocessors and Transparency
A list of vendors who process data on our behalf is available upon written request. All subprocessors undergo regular risk and compliance assessments.
20. Termination of Services
Upon ending services, you may request a copy of your records (fees may apply). Records are retained as required by law unless otherwise requested and permitted.
21. Complaints and Violations
If you believe your privacy rights have been violated, contact:
• Empowered Harmony: support@empoweredharmony.com
• HHS Office for Civil Rights: https://www.hhs.gov/hipaa/filing-a-complaint
You will not face retaliation.
Contact Information
Empowered Harmony Counseling, Psychiatry & Wellness Center
​Email: support@empoweredharmony.com
​
