Privacy Policy
Last updated September 3, 2026
Privacy Policy — Mountain Psychotherapy & EMDR (Clinical Social Work Practice)
This Privacy Policy describes how Mountain Psychotherapy & EMDR (“we,” “our,” or “us”) collects, uses, stores, and protects personal and health information for our clinical social work practice in Minnesota and Iowa. We are committed to protecting your privacy and maintaining the confidentiality of your mental health and clinical records in accordance with applicable laws, including federal and state privacy laws and professional ethics.
Scope and Purpose
This policy applies to all personal and protected health information (PHI) we collect from clients, prospective clients, third-party payers, and referral sources in the course of providing trauma-focused therapy, EMDR, and support for life transitions.
The purpose of this policy is to inform you about our privacy practices, your rights regarding your information, and how to contact us with questions or complaints.
Types of Information Collected
Identifying information: name, date of birth, address, phone number, email, emergency contact, and other demographic data.
Clinical information: presenting concerns, mental health history, diagnoses, treatment plans, progress notes, session summaries, risk assessments, and clinical correspondence.
Administrative and billing information: insurance details, billing records, claims information, payment history, and authorization documents.
Communication records: messages and emails exchanged with our staff, appointment scheduling information, and consent forms.
Electronic information: IP addresses and usage logs collected from our website or telehealth platforms as needed for service delivery, security, and troubleshooting.
Legal Bases for Use (where applicable)
Treatment: We use PHI to provide, coordinate, and manage clinical care, including assessments, therapy, referrals, and follow-up.
Payment: We use and disclose necessary information to obtain payment, process claims, and manage billing and collection.
Healthcare operations: We use information for quality assurance, clinical supervision, practice management, licensing compliance, training, and recordkeeping.
Legal compliance and safety: We may use or disclose PHI when required by law (e.g., mandatory reporting of child or vulnerable adult abuse, court orders) or to prevent imminent harm to you or others.
Consent and Authorization
We obtain appropriate written consent for treatment and for use of telehealth services.
We will obtain your written authorization before using or disclosing PHI for purposes other than treatment, payment, or healthcare operations, except where otherwise permitted or required by law.
You may revoke authorizations in writing at any time, except to the extent we have already acted in reliance on the authorization.
Confidentiality and Limits
Your therapy records are confidential and will not be released without your written consent, except for the following legally permitted or required disclosures:
Suspected child abuse or dependent adult/elder abuse reporting.
Threats of serious bodily harm to self or others (duty to warn/protect).
Court orders, subpoenas, or as required by law.
When you sign a release of information for specified third parties (e.g., other providers, insurance companies).
Situations involving certain public health reporting obligations.
We will limit disclosures to the minimum necessary information to achieve the purpose.
Telehealth and Electronic Communication
We offer telehealth services using secure, HIPAA-compliant platforms. We will discuss telehealth risks, benefits, and alternatives and obtain informed consent prior to starting.
Electronic communications (email, text messaging) may be used for appointment scheduling and limited clinical communication when you provide consent. Such communications carry inherent risks (e.g., interception). We will discuss secure options and you may request restrictions on electronic communication.
We retain records of telehealth sessions and electronic communications as part of the clinical record.
Data Security and Retention
We maintain administrative, technical, and physical safeguards to protect PHI from unauthorized access, alteration, disclosure, or destruction consistent with legal and ethical obligations.
Access to client records is limited to authorized personnel as needed for treatment, payment, or practice operations.
We retain clinical records in accordance with state licensing and record-retention laws. After the retention period, records are securely destroyed.
Use of Third Parties and Business Associates
We may disclose PHI to business associates who perform services on our behalf (e.g., billing services, telehealth vendors, EHR providers). We require business associates to safeguard PHI and comply with applicable privacy standards.
When required, we enter into written agreements to protect PHI shared with third parties.
Clients’ Rights
Right to access: You have the right to inspect and obtain a copy of your protected health information (PHI) and other personal information we maintain about you, except where restricted by law. Requests may be made in writing; we will respond within the timeframes required by applicable law.
Right to request corrections: If you believe information in your record is incorrect or incomplete, you may request an amendment. We will review and, if appropriate, amend the information or note your disagreement as required by law.
Right to restrict disclosures: You may request restrictions on certain uses and disclosures of your PHI for treatment, payment, or healthcare operations. We are not required to agree to all requests but will comply when required by law or when we agree in writing.
Right to an accounting of disclosures: You have the right to receive an accounting of certain disclosures of your PHI made by us for purposes other than treatment, payment, and healthcare operations, and other permitted disclosures as required by law.
Right to confidential communications: You may request that we communicate with you by alternative means or at alternative locations (for example, a different phone number or mailing address). We will accommodate reasonable requests when feasible.
Right to withdraw consent: You have the right to revoke any authorization or consent you previously provided for uses and disclosures of PHI, except to the extent that we have already taken action in reliance on it.
Right to receive a paper copy of this notice: You may request and obtain a paper copy of our privacy practices and this privacy notice even if you have previously agreed to receive notices electronically.