Privacy Policy & Notice of Privacy Practices
Effective Date: January 1, 2026 | Last Updated: August 2026
INN Behavioral Centers Inc. ("Company," "we," "us," or "our") is committed to protecting your privacy and safeguarding the personal and health information of the children and families we serve. This Privacy Policy describes how we collect, use, disclose, and protect information gathered through our website, intake portals, telehealth platforms, and in-home Applied Behavior Analysis (ABA) therapy services across North Carolina, Texas, Colorado, and other authorized operating jurisdictions.
1. Scope & Relationship to HIPAA Notice of Privacy Practices
This policy applies to website visitors, intake applicants, and active clients.
- Protected Health Information (PHI): When you receive healthcare services from us or submit health details for intake, evaluation, or billing, that data is considered Protected Health Information (PHI) governed by the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and applicable state privacy laws.
- Non-PHI Website Data: Non-health information collected through general website browsing (such as IP addresses, standard cookies, and general inquiries) is governed by the website-specific provisions of this policy.
2. Information We Collect
We collect information directly from parents, legal guardians, and authorized representatives to deliver individualized behavioral therapy and administrative services.
- Parent / Guardian Identifying Information: Full name, phone number, email address, physical home address, billing address, and emergency contact details.
- Child Clinical & Developmental Information: Full name, date of birth, age, gender, diagnostic history (including ICD-10 F84 Autism Spectrum Disorder, ADHD, OCD, Anxiety), developmental assessments (VB-MAPP, ABLLS-R), behavioral data, Individualized Education Programs (IEP), physician referrals, and medical history.
- Billing & Payment Records: Credit card details, bank information (processed via secure, PCI-DSS compliant third-party payment gateways), and out-of-network superbill records containing CPT and diagnostic codes.
- Telehealth & Technical Data: Video/audio communication metadata during virtual BCBA sessions, device identifiers, browser type, and log files.
3. How We Use and Disclose Your Information
We only use and disclose personal data and PHI for permitted operational, clinical, and legal purposes:
- Treatment: To conduct functional behavior assessments, formulate behavior intervention plans (BIP), provide in-home and telehealth ABA therapy, and conduct parent coaching sessions.
- Payment & Invoicing: To collect service deposits, process session fees, and generate itemized superbills upon request for submission to private health insurers.
- Healthcare Operations: For quality assurance, clinical supervision, internal auditing, staff training, and platform maintenance.
- With Your Explicit Consent: To coordinate multidisciplinary care with external providers (such as your child's pediatrician, speech-language pathologist, occupational therapist, or school district) via a signed Authorization to Release Information.
- Required by Law: In cases of mandatory reporting for suspected child abuse or neglect, judicial subpoenas, or valid public health directives.
4. Children’s Online Privacy Protection Act (COPPA)
Our services are directed to children ages 2–12 through their parents or legal guardians. We never knowingly collect personal data directly from children under 13 online. All intake submissions, health history disclosures, and consent forms must be completed by a verified parent or legal guardian.
5. State-Specific Compliance Disclosures
North Carolina
We comply with North Carolina General Statutes regarding the confidentiality of medical records and the North Carolina Identity Theft Protection Act (N.C. Gen. Stat. § 75-60 et seq.). All client records and identifying numbers are retained securely, restricted from unauthorized viewing, and destroyed in compliance with statutory medical record retention schedules.
Texas
In compliance with the Texas Medical Records Privacy Act (Texas Health & Safety Code Ch. 181) and the Texas Data Privacy and Security Act (TDPSA):
- Texas law provides privacy protections that exceed federal HIPAA standards in certain areas of marketing and data sharing. We do not sell, rent, or trade your or your child's personal or health information under any circumstances.
- All clinical personnel and administrative contractors in Texas receive required privacy training concerning Texas-specific medical confidentiality.
- Texas clients have the right to request electronic copies of their health records within statutory delivery timelines.
Colorado
In compliance with the Colorado Privacy Act (CPA) (Colo. Rev. Stat. § 6-1-1301 et seq.) and Colorado medical record confidentiality rules:
- We collect only the minimum necessary data required to deliver ABA therapy and comply with clinical oversight standards.
- Colorado residents retain the right to confirm whether we process their personal data, access their data, correct inaccuracies, or request data deletion (subject to mandatory clinical record retention mandates under state healthcare licensing laws).
6. Telehealth Security & Technical Safeguards
For virtual BCBA consultations and parent coaching across North Carolina, Texas, and Colorado:
- All telehealth sessions are conducted through HIPAA-compliant, end-to-end encrypted video platforms backed by executed Business Associate Agreements (BAAs).
- Sessions are live and are never recorded without prior, separate written consent from the parent or guardian.
- Families are advised to participate in telehealth sessions from a private room to protect their own household privacy.
7. Data Security & Storage
We implement administrative, physical, and technical safeguards to secure your personal data and PHI:
- Data encryption in transit (SSL/TLS) and at rest (AES-256).
- Strict role-based access control restricted solely to authorized clinical analysts (BCBA/QBA) and direct care technicians (RBT/ABAT).
- Firewalls, intrusion detection, and multi-factor authentication across all clinical electronic health record (EHR) systems.
8. Your Rights Under HIPAA & State Law
As a parent or legal guardian, you have the right to:
- Inspect and Copy: Review and obtain copies of your child’s behavioral records and billing history.
- Request Amendments: Request a correction if you believe clinical or demographic records are incomplete or inaccurate.
- Request Restrictions: Request limits on how we share information for treatment or operations (subject to clinical and legal constraints).
- Accounting of Disclosures: Receive an itemized list of specific non-routine disclosures made with respect to your child's PHI.
- Confidential Communications: Request to receive updates, emails, or bills through specific communication channels (phone, email, or secure portal).
9. Informal Dispute & Privacy Concern Resolution
We care deeply about your family’s privacy, care experience, and trust. If you have a question, concern, or dispute regarding how your personal information or your child’s health records are handled, we respectfully encourage and request that you contact our Privacy Official directly before initiating any formal external complaints or legal proceedings.
Many concerns arise from simple administrative misunderstandings and can be resolved promptly, amicably, and effectively through direct communication.
When you contact us, our leadership team will review your concern immediately, investigate the matter in good faith, and work closely with you to reach a fair and satisfactory resolution.
(Please note: This informal resolution process is designed to facilitate swift, collaborative problem-solving and does not restrict or eliminate your statutory right to file a formal complaint with relevant state licensing boards or the U.S. Department of Health and Human Services).
Direct Privacy Contact: Irmelle Norvil
Phone: 863-430-2868
10. Contact Us & Official Privacy Officer
To exercise any of your statutory privacy rights, request an accounting of disclosures, or submit a formal inquiry regarding our compliance practices across North Carolina, Texas, or Colorado, please reach out to our office:
INN Behavioral Centers Inc.
Attn: Privacy Officer / Irmelle Norvil
Phone: 863-430-2868
General Inquiries: info@innbehavioral.com
Service Region: North Carolina | Texas | Colorado
If you believe your privacy rights have been violated, you have the right to file a formal complaint with INN Behavioral Centers Inc. or with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights. We will not retaliate against you or your child for filing a complaint.