Privacy Policy

1. Introduction

PM NOW Telehealth Platform ("Platform") enables mental health providers to deliver virtual care and allows clients (patients) to access mental health services, schedule appointments, complete forms, and communicate securely.

This Privacy Policy applies to all users, including:

  • Clients (patients) receiving mental health services
  • Providers delivering services through PM NOW
  • Administrative staff with authorized access

We comply with:

  • HIPAA Privacy & Security Rules
  • HITECH Act
  • Federal and state mental health privacy laws
  • Industry standards for telehealth platforms

2. Who This Policy Covers

A. Clients (Patients)

Individuals receiving mental health services through PM NOW.

B. Providers

Licensed clinicians, therapists, psychiatrists, counselors, and other authorized professionals using PM NOW to deliver care.

C. Administrative Users

Authorized staff performing scheduling, billing, or operational functions.

Each group may have different rights and responsibilities, which are outlined throughout this policy.

3. Information We Collect

We collect information from both Clients and Providers, but the type and purpose differ.

A. Information Collected From Clients (Patients)

1. Personal & Demographic Information

  • Name, address, phone, email
  • Date of birth
  • Emergency contact
  • Insurance information (if applicable)

2. Health & Clinical Information (PHI)

  • Intake forms and screening questionnaires
  • Mental health assessments
  • Diagnoses, treatment plans, progress notes
  • Telehealth session details
  • Medication or care-related information
  • Appointment history
  • Uploaded documents or forms

3. Communication Data

  • Secure messages with providers
  • SMS/email notifications
  • OTP verification logs

4. Technical Information

  • IP address
  • Device type
  • Browser information
  • Usage logs

B. Information Collected From Providers

1. Professional Information

  • Name, credentials, license numbers
  • NPI (if applicable)
  • Specialties
  • Clinic affiliation
  • Availability and scheduling preferences

2. Operational Information

  • Appointment notes
  • Documentation and clinical entries
  • Billing and claims information
  • Communication with clients

3. Technical Information

  • Login credentials
  • Device and usage logs
  • Access timestamps (audit logs)

4. Compliance Information

  • Identity verification
  • Background or credentialing documents (if required)

4. How We Use Information

We use information differently for Clients and Providers, but always within HIPAA-permitted purposes.

A. Use of Client (Patient) Information

1. Treatment

  • Telehealth sessions
  • Provider–patient communication
  • Care coordination
  • Clinical documentation

2. Payment

  • Billing and invoicing
  • Insurance claims
  • Payment processing

3. Healthcare Operations

  • Quality improvement
  • Appointment management
  • Audit logs
  • Customer support

4. Platform Functionality

  • Authentication
  • OTP verification
  • Notifications and reminders

B. Use of Provider Information

1. Credentialing & Verification

  • Confirming identity and licensure
  • Ensuring compliance with state and federal regulations

2. Service Delivery

  • Scheduling
  • Documentation
  • Communication with clients

3. Operational & Administrative

  • Performance analytics
  • Audit logs
  • Security monitoring

4. Payment & Compensation

  • Provider payouts
  • Tax documentation (if applicable)

5. How We Share Information

We share information only as permitted by HIPAA and applicable laws.

A. Sharing Client (Patient) Information

1. With Your Providers

  • Therapists
  • Psychiatrists
  • Case managers
  • Care coordinators

2. With Authorized Business Associates

Vendors supporting PM NOW operations, such as:

  • Telehealth video provider
  • SMS/OTP provider
  • Hosting and cloud infrastructure
  • Analytics and performance tools
  • Form and document management tools

All vendors must sign a Business Associate Agreement (BAA).

3. With Your Consent

  • Release of information to family, schools, or other providers
  • Sharing records with third parties at your request

4. As Required by Law

  • Court orders
  • Mandatory reporting (abuse, threats, emergencies)

B. Sharing Provider Information

1. With Clients

  • Provider name, credentials, and availability
  • Clinic affiliation
  • Professional profile

2. With Business Associates

For operational purposes such as:

  • Credentialing
  • Scheduling
  • Payment processing
  • Telehealth technology

3. With Regulatory Bodies

If required for:

  • License verification
  • Audits
  • Compliance investigations

6. Your Rights Under HIPAA

A. Rights for Clients (Patients)

  • Access your records
  • Request corrections
  • Request restrictions
  • Request confidential communications
  • Receive an accounting of disclosures
  • Obtain a copy of this policy

B. Rights for Providers

  • Access your own profile and documentation
  • Request corrections to your professional information
  • Review audit logs related to your account
  • Request information about how your data is used

7. How We Protect Your Information

We apply the same high-level security controls to both Client and Provider data.

Technical Safeguards

  • Encrypted data at rest and in transit
  • End-to-end encrypted telehealth sessions
  • Multi-factor authentication
  • Role-based access control
  • Secure audit logs

Administrative Safeguards

  • HIPAA training for all staff
  • Access control policies
  • Vendor risk assessments
  • Incident response procedures

Physical Safeguards

  • Secure data centers
  • Restricted server access
  • Device security protocols

8. Cookies & Tracking

Used only for:

  • Session security
  • Platform performance
  • User experience

Never used for advertising.

9. Data Retention

Clients

PHI is retained according to:

  • HIPAA
  • State mental health record laws
  • Clinical requirements

Providers

Professional and operational data is retained for:

  • Compliance
  • Audit logs
  • Legal obligations

10. Minors' Privacy

PM NOW serves minors receiving mental health services.

We comply with:

  • HIPAA
  • State minor consent laws
  • Parental/guardian authorization requirements

11. Third-Party Links

External links are not governed by this policy.

12. Changes to This Policy

Updates will be posted with a revised "Effective Date."