Privacy Policy

Effective Date: September 9, 2026

ThriveMindHealth.com (“Thrive Mind Health,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information you provide to us.

This Privacy Policy explains how we collect, use, disclose, store, and protect information when you visit ThriveMindHealth.com, contact us, request or receive services, schedule appointments, communicate with our practice, use patient-facing features, or otherwise interact with us.

This Privacy Policy applies to information collected through our website and related communications and services. Certain health information may also be subject to additional protections under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), applicable state privacy laws, and our separate Notice of Privacy Practices.

1. Information We Collect

Depending on how you interact with us, we may collect the following categories of information.

Personal Information

We may collect information that identifies or relates to you, including:

  • Name

  • Date of birth

  • Mailing address

  • Email address

  • Telephone number

  • Emergency contact information

  • Account or login information

  • Demographic information

  • Communication preferences

Health and Medical Information

If you seek or receive healthcare services from us, we may collect information such as:

  • Medical and mental health history

  • Symptoms, diagnoses, and treatment information

  • Medications

  • Treatment plans

  • Appointment and scheduling information

  • Provider notes and clinical documentation

  • Intake forms and questionnaires

  • Referrals

  • Prescription-related information

  • Information you provide during communications with our clinical or administrative staff

Some of this information may constitute Protected Health Information (“PHI”) under HIPAA.

Insurance and Billing Information

We may collect:

  • Health insurance carrier information

  • Member or subscriber identification numbers

  • Group numbers

  • Policy information

  • Claims information

  • Billing records

  • Payment history

  • Financial responsibility information

Payment Information

If you make a payment, we or our payment processors may collect information necessary to process the transaction, such as:

  • Credit or debit card information

  • Billing address

  • Transaction details

Payment information may be processed by third-party payment processors. We generally do not directly store complete payment-card information when it is processed through a third-party payment provider.

Communications

We may collect information you provide through:

  • Website forms

  • Email

  • Telephone calls

  • Text messages

  • Appointment requests

  • Patient portal communications

  • Customer support or administrative inquiries

  • Feedback, surveys, or other communications

Website and Device Information

When you use our website, certain information may be collected automatically, including:

  • IP address

  • Browser type

  • Device type

  • Operating system

  • Pages visited

  • Referring website

  • Date and time of access

  • Website activity

  • Cookie identifiers and similar technical information

We may use cookies and similar technologies for website functionality, security, user preferences, session management, and related operational purposes.

2. How We Use Information

We may use information we collect to:

  • Provide healthcare and mental health services

  • Evaluate requests for services

  • Schedule, confirm, change, and manage appointments

  • Communicate with patients and prospective patients

  • Provide appointment reminders

  • Respond to questions and inquiries

  • Maintain patient records

  • Coordinate treatment and care

  • Verify insurance coverage and benefits

  • Submit and process insurance claims

  • Collect payments and manage billing

  • Process prescriptions and referrals where applicable

  • Provide administrative and customer support

  • Operate and maintain our website

  • Maintain website and account security

  • Detect, prevent, and investigate fraud or misuse

  • Improve our services and website

  • Comply with legal, regulatory, licensing, and professional obligations

  • Protect our rights, patients, staff, and others

  • Send informational, operational, or promotional communications where permitted by law

3. Protected Health Information and HIPAA

If Thrive Mind Health is a HIPAA-covered entity or business associate, information that qualifies as PHI will be handled in accordance with HIPAA and other applicable healthcare privacy laws.

Our use and disclosure of PHI may also be governed by a separate Notice of Privacy Practices, which describes how medical information about you may be used and disclosed and how you can access that information.

If there is a conflict between this Privacy Policy and our Notice of Privacy Practices with respect to PHI, the Notice of Privacy Practices will control.

4. Text Messages and SMS Communications

If you provide your mobile phone number, we may use it to send communications related to our services, including:

  • Appointment confirmations

  • Appointment reminders

  • Scheduling messages

  • Administrative notices

  • Billing-related communications

  • Patient support communications

  • Practice updates

  • Other healthcare-related communications

Where permitted and with any consent required by law, we may also send promotional or informational messages.

Message frequency may vary. Message and data rates may apply.

You may opt out of non-essential text messages by following the instructions included in the message, such as replying STOP, where applicable.

Opting out of promotional text messages does not necessarily prevent us from sending messages that are necessary for treatment, healthcare operations, billing, safety, or other legally permitted purposes.

We do not sell mobile phone numbers or SMS consent information to third parties for their own marketing purposes.

5. Email Communications

We may communicate with you by email regarding appointments, services, billing, administrative matters, educational information, practice updates, and other matters related to our services.

You may unsubscribe from promotional email communications using the unsubscribe mechanism provided in the communication.

Certain operational, healthcare, billing, legal, or administrative emails may still be sent when necessary.

6. Cookies and Similar Technologies

Our website may use cookies and similar technologies.

Cookies may be used to:

  • Keep the website functioning properly

  • Remember user preferences

  • Maintain secure sessions

  • Improve website performance

  • Detect fraud or misuse

  • Understand general website usage

  • Support website features and functionality

You may be able to control cookies through your browser settings. Disabling certain cookies may affect the functionality of the website.

We do not currently use Google Analytics or Meta Pixel.

If our use of tracking or analytics technologies changes materially, we may update this Privacy Policy accordingly.

7. How We Share Information

We may disclose information as reasonably necessary for the purposes described in this Privacy Policy.

Healthcare Providers and Organizations

We may share information with healthcare professionals, pharmacies, laboratories, hospitals, specialists, referral providers, or other organizations involved in your care when permitted by law.

Insurance Companies and Payment Organizations

We may share information with:

  • Health insurance plans

  • Claims processors

  • Billing companies

  • Payment processors

  • Financial institutions

as necessary to verify benefits, process claims, collect payments, or administer billing.

Service Providers

We may use third-party vendors to support our operations, including providers of:

  • Website hosting

  • Electronic health record systems

  • Patient portals

  • Appointment scheduling

  • Communications

  • Email services

  • SMS services

  • Payment processing

  • Cloud storage

  • Cybersecurity

  • Information technology

  • Administrative support

  • Billing and claims processing

These service providers may receive information only as necessary to perform services for us and may be subject to contractual, confidentiality, privacy, and security obligations.

Where required by HIPAA, vendors handling PHI may be required to enter into Business Associate Agreements with us.

Legal and Regulatory Disclosures

We may disclose information when required or permitted by law, including:

  • In response to subpoenas, court orders, or lawful legal process

  • To comply with healthcare regulations

  • To comply with licensing or professional requirements

  • To respond to governmental or regulatory authorities

  • To prevent fraud or unlawful activity

  • To protect the health or safety of an individual or the public

  • To protect our legal rights, property, or operations

Business Transactions

Information may be disclosed or transferred in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, subject to applicable law.

8. Sale and Sharing of Personal Information

We do not sell personal information for money.

We also do not knowingly sell or share PHI for advertising purposes in violation of HIPAA or applicable healthcare privacy laws.

Depending on applicable state privacy laws, certain transfers of personal information may legally qualify as a “sale,” “sharing,” or “targeted advertising” even where no money is exchanged. Where required, we will provide applicable rights and opt-out mechanisms.

9. Sensitive Personal Information

We may collect information that is considered sensitive personal information under applicable laws, including health information, insurance information, government identifiers, account credentials, and financial information.

We use sensitive personal information only as reasonably necessary to provide services, operate our business, comply with legal obligations, protect security, and for other purposes permitted by applicable law.

10. Data Security

We use reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, disclosure, alteration, or destruction.

These safeguards may include:

  • Access controls

  • Authentication measures

  • Encryption where appropriate

  • Secure data storage

  • Vendor security requirements

  • Staff privacy and security training

  • System monitoring

  • Policies governing access to sensitive information

No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Data Retention

We retain information for as long as reasonably necessary to:

  • Provide healthcare services

  • Maintain medical records

  • Comply with professional recordkeeping requirements

  • Process billing and insurance matters

  • Resolve disputes

  • Enforce agreements

  • Meet legal, regulatory, tax, and accounting requirements

Medical records may be retained for periods required by federal and state healthcare laws.

12. Your Privacy Rights

Depending on your state of residence and the laws applicable to your information, you may have the right to:

  • Request access to personal information we maintain about you

  • Request correction of inaccurate information

  • Request deletion of certain information

  • Request information about how we use or disclose your information

  • Obtain a copy of certain information

  • Restrict or object to certain uses of personal information

  • Opt out of certain marketing communications

  • Opt out of certain sales or sharing of personal information

  • Limit certain uses of sensitive personal information

  • Withdraw consent where processing is based on consent

These rights may be subject to exceptions, including healthcare-record retention obligations, HIPAA requirements, legal claims, security requirements, and other applicable laws.

We will not unlawfully discriminate against you for exercising applicable privacy rights.

13. HIPAA Patient Rights

Where HIPAA applies, you may have additional rights regarding your PHI, including rights to:

  • Inspect or obtain copies of your health records

  • Request corrections to your records

  • Request restrictions on certain uses and disclosures

  • Request confidential communications

  • Receive an accounting of certain disclosures

  • Obtain a copy of our Notice of Privacy Practices

  • File a privacy complaint

Please refer to our Notice of Privacy Practices for additional information.

14. California Privacy Rights

If California privacy laws apply to your information, you may have rights under laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”).

These rights may include the right to:

  • Know what categories of personal information we collect

  • Request access to specific personal information

  • Request correction

  • Request deletion

  • Know the categories of third parties to whom information is disclosed

  • Opt out of the sale or sharing of personal information

  • Limit certain uses of sensitive personal information

Information governed by HIPAA and certain other healthcare privacy laws may be exempt from some CCPA/CPRA requirements.

To exercise applicable rights, contact us using the information provided below.

15. Children’s Privacy

Our website and services are not intended for children to use independently where parental or guardian consent is required by law.

We may provide healthcare services to minors when legally permitted and with appropriate consent from a parent, guardian, or other authorized individual.

Information regarding minors will be handled according to applicable healthcare, consent, confidentiality, and privacy laws.

16. Third-Party Websites and Services

Our website may link to websites, patient portals, scheduling systems, payment platforms, pharmacies, insurance websites, or other third-party services.

We are not responsible for the privacy practices of third-party websites or services that we do not control.

You should review the privacy policies of those third parties before providing information to them.

17. Telehealth

If we provide telehealth services, information may be transmitted through electronic communications or telehealth platforms.

We use reasonable safeguards and appropriate service providers intended to protect the privacy and security of telehealth communications.

Telehealth services may also be subject to additional consent forms, privacy disclosures, and state-specific requirements.

18. Do Not Track Signals

Some browsers provide “Do Not Track” or similar privacy signals.

Because there is not a single universally accepted standard for all such signals, our website may not respond to every browser-based Do Not Track signal.

Where legally required, we may recognize supported browser-based opt-out preference signals.

19. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our services, technology, legal obligations, or privacy practices.

When we make changes, we will update the “Effective Date” shown at the top of this Privacy Policy.

Material changes may also be communicated through our website or through other appropriate means.

20. Contact Us

If you have questions about this Privacy Policy, our privacy practices, or your personal information, or if you wish to exercise applicable privacy rights, contact:

Thrive Mind Health
Website: ThriveMindHealth.com
Email: [Privacy or Contact Email]
Phone: [Phone Number]
Mailing Address: [Business Address]

For questions specifically concerning medical records, HIPAA rights, or our Notice of Privacy Practices, please contact our Privacy Officer or designated privacy contact at the information above.