Privacy Policy

Your privacy is our foundation

Last updated: November 11, 2025

Psync Health ("we," "our," or "us") is committed to protecting the privacy and security of your health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mental health practice management platform.

As a healthcare technology platform, we comply with the Health Insurance Portability and Accountability Act (HIPAA) and implement industry-leading security practices to protect your Protected Health Information (PHI).

HIPAA Compliance

Psync Health complies with the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules. We maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of your PHI.

Business Associate Agreements

We have signed Business Associate Agreements (BAAs) with all third-party service providers who may access or process PHI, including:

  • Cloud hosting and infrastructure providers
  • AI and machine learning service providers
  • Email and communication services
  • Database and backup services

These agreements ensure that all vendors handling PHI maintain HIPAA-compliant security standards and protect your information with the same level of care that we do.

Information We Collect

Protected Health Information (PHI)

  • Patient demographic information (name, date of birth, contact information)
  • Clinical data (diagnoses, treatment plans, therapy session notes)
  • Session recordings and transcripts (with explicit consent)
  • Progress notes and clinical assessments
  • Appointment scheduling and attendance records

Account and Billing Information

  • User account credentials (email, encrypted password)
  • Payment and billing information
  • Insurance information (when applicable)

Technical Information

  • Device information and browser type
  • IP addresses and access logs
  • Usage analytics (anonymized and aggregated)

AI Technology Transparency

How We Use AI

Psync Health uses advanced AI technology to assist therapists with clinical documentation, session analysis, and therapeutic insights. Our AI features are designed to augment—not replace— the clinical judgment of licensed mental health professionals.

AI Capabilities

  • Audio transcription with speaker identification and timestamps
  • Session summary generation and clinical note assistance
  • Therapeutic insight analysis and pattern recognition
  • Treatment progress tracking and recommendations

AI Data Protection

  • No AI Training: Your patient data is never used to train AI models or improve third-party services
  • HIPAA-Compliant Processing: All AI processing occurs in HIPAA-compliant environments with signed BAAs
  • Human Oversight: All AI-generated content must be reviewed and approved by licensed clinicians before being finalized
  • Encrypted Processing: PHI is encrypted both in transit to and from AI services, and at rest during processing
  • Audit Trails: All AI interactions are logged for security and compliance monitoring

Accuracy and Limitations

While our AI technology provides valuable assistance, it is not a substitute for professional clinical judgment. Therapists maintain full responsibility for all clinical decisions, diagnoses, and treatment plans. AI-generated insights are provided as tools to support—not replace— licensed mental health professionals.

Data Security Measures

We implement comprehensive security measures to protect your health information from unauthorized access, disclosure, alteration, or destruction.

Technical Safeguards

  • AES-256-GCM Encryption: All PHI is encrypted at rest using industry-standard 256-bit encryption
  • TLS 1.3 Encryption: All data transmissions are encrypted in transit
  • Multi-Tenant Isolation: Complete data segregation between users and organizations
  • Role-Based Access Controls: Granular permissions ensuring users only access authorized data
  • Multi-Factor Authentication: Optional additional security layer for account access
  • Session Management: Secure session handling with automatic timeout after 8 hours
  • Audit Logging: Comprehensive tracking of all PHI access and modifications

Administrative Safeguards

  • Regular security risk assessments and vulnerability testing
  • Staff training on HIPAA compliance and security best practices
  • Incident response procedures and breach notification protocols
  • Background checks for personnel with PHI access

Physical Safeguards

  • HIPAA-compliant cloud infrastructure with restricted physical access
  • Redundant backup systems and disaster recovery procedures
  • Secure data center facilities with 24/7 monitoring

Audio Recording Policy

Consent Requirements

We never record therapy sessions without explicit, informed consent from all participants. Before any recording begins, patients must:

  • Receive clear information about what will be recorded
  • Understand how the recording will be used and stored
  • Know who will have access to the recording
  • Provide written or electronically documented consent
  • Retain the right to decline recording at any time

Storage and Retention

Audio recordings containing PHI are:

  • Encrypted with AES-256-GCM encryption immediately upon upload or creation
  • Stored in HIPAA-compliant cloud infrastructure with signed BAAs
  • Retained according to applicable state and federal regulations (typically 6-10 years)
  • Accessible only to authorized users with proper authentication
  • Protected by comprehensive audit trails tracking all access

Deletion and Disposal

When audio recordings are deleted (either by user request or at the end of the retention period), we ensure secure destruction using certified data deletion methods that prevent recovery of the data.

Your Rights Under HIPAA

Under HIPAA, you have the following rights regarding your Protected Health Information:

Right to Access

You have the right to view, download, or request copies of your health records. We will provide access within 30 days of your request.

Right to Amendment

You have the right to request corrections to inaccurate or incomplete health information. We will respond to amendment requests within 60 days.

Right to Accounting of Disclosures

You have the right to receive a list of certain disclosures of your PHI that we have made.

Right to Request Restrictions

You have the right to request restrictions on certain uses and disclosures of your PHI. While we are not required to agree to all restrictions, we will accommodate reasonable requests.

Right to Confidential Communications

You have the right to request that we communicate with you about your health information through alternative means or at alternative locations.

Right to Request Deletion

Subject to legal retention requirements, you may request deletion of your account and associated data. We will securely delete your information in accordance with our data retention policies and applicable laws.

Right to File a Complaint

If you believe your privacy rights have been violated, you have the right to file a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights. You will not be retaliated against for filing a complaint.

Data Sharing & Disclosures

We share PHI only as permitted or required by HIPAA regulations:

Permitted Disclosures

  • Treatment: Coordinating care with other healthcare providers (with your authorization)
  • Payment: Processing billing and insurance claims
  • Healthcare Operations: Quality improvement, training, and administrative functions

Required Disclosures

  • When required by law (court orders, subpoenas)
  • To prevent serious threat to health or safety (duty to warn)
  • Suspected child, elder, or dependent adult abuse
  • Public health activities and disease reporting

We Do NOT Share PHI With

  • Marketing or advertising platforms
  • Social media networks
  • Unapproved third parties without your explicit authorization
  • AI training datasets or model improvement programs

Breach Notification

In the unlikely event of a data breach affecting your PHI, we will:

  • Notify you within 60 days of discovering the breach
  • Provide a description of what information was affected
  • Explain the steps we are taking to mitigate harm
  • Offer guidance on steps you can take to protect yourself
  • Provide contact information for questions and assistance
  • Report the breach to the U.S. Department of Health and Human Services Office for Civil Rights

We maintain comprehensive incident response procedures and conduct regular security drills to ensure rapid, effective response to any potential security incidents.

Data Retention & Deletion

We retain PHI in accordance with applicable federal and state regulations:

  • Clinical Records: Minimum 6 years (HIPAA baseline); up to 10 years depending on state requirements
  • Audio Recordings: Retained per state-specific regulations and organizational policies
  • Billing Records: Minimum 6 years from date of service
  • Audit Logs: Minimum 6 years for compliance monitoring

After the retention period expires, or upon valid deletion request (subject to legal requirements), we securely destroy all PHI using certified deletion methods that prevent data recovery.

Contact Information

For questions about this Privacy Policy, to exercise your privacy rights, or to report privacy concerns, please contact:

Psync Health Privacy Officer

Email: privacy@psynchealth.com

File a Complaint with HHS

If you believe your privacy rights have been violated, you may file a complaint with:

U.S. Department of Health and Human Services

Office for Civil Rights

Phone: 1-800-368-1019

Website: hhs.gov/ocr/privacy

Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on our website and updating the "Last Updated" date. Your continued use of our services after such changes constitutes acceptance of the updated policy.