- Home
- Privacy Policy
Privacy Policy & HIPAA Notice of Privacy Practices
Last updated: 05.01.2026
This document serves as both our Website Privacy Policy and our HIPAA Notice of Privacy Practices. It describes how we collect, use, and protect your information when you use our website and when you receive clinical services from us.
Please read this document carefully. By using our website or services, you acknowledge that you have read and understood this policy.
Interpretation and Definitions
Interpretation
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Company (referred to as either “the Company”, “We”, “Us” or “Our” in this Agreement) refers to MadeMind Wellness & Performance PLLC, 7234 W North Ave Ste 208 Chicago, IL 30039.
Affiliate means an entity that controls, is controlled by or is under common control with a party, where “control” means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
Account means a unique account created for You to access our Service or parts of our Service.
Website refers to MadeMind Wellness website, accessible from www.mademindwellness.com. It may also refer to the My Best Practice website, accessible from www.mbpractice.com.
Service refers to both our Website and clinical therapy services.
Protected Health Information (PHI) means individually identifiable health information that we create, receive, maintain, or transmit in connection with providing healthcare services to you. This is protected under the Health Insurance Portability and Accountability Act (HIPAA).
Business Associate means a third-party service provider that creates, receives, maintains, or transmits PHI on our behalf and has signed a Business Associate Agreement ensuring HIPAA compliance.
Personal Data refers to information collected through our website that may identify you but is not health-related.
HIPAA Notice of Privacy Practices
This section applies to Protected Health Information (PHI) collected, used, or disclosed in connection with treatment, payment, and healthcare operations.
Our Legal Duty
We are required by law to:
- Maintain the privacy of your Protected Health Information
- Provide you with this notice of our legal duties and privacy practices
- Follow the terms of the notice currently in effect
- Notify you if we are unable to agree to a requested restriction
- Accommodate reasonable requests you may have to communicate health information by alternative means or at alternative locations
How We May Use and Disclose Health Information About You
For Treatment: We may use and disclose your PHI to provide, coordinate, or manage your healthcare and related services. This may include coordination with other healthcare providers involved in your care.
For Payment: We may use and disclose your PHI to bill and collect payment for services provided. This may include disclosure to your insurance company or other third-party payers.
For Healthcare Operations: We may use and disclose your PHI for our healthcare operations, such as quality assessment, training, and administrative functions.
Uses and Disclosures That Require Your Authorization
Other uses and disclosures of your PHI will be made only with your written authorization. You may revoke such authorization at any time by providing written notice to our Privacy Officer.
Uses and Disclosures That Do NOT Require Your Authorization
Federal and state law allows us to use or disclose your PHI without your authorization in specific circumstances:
Required by Law: When required by federal, state, or local law.
Public Health and Safety: To report disease, injury, or public health concerns to appropriate authorities.
Abuse, Neglect, or Domestic Violence: When we are legally required to report suspected abuse, neglect, or domestic violence to protective services or law enforcement.
Health Oversight Activities: To health oversight agencies authorized by law to conduct audits, investigations, or inspections.
Judicial and Administrative Proceedings: In response to a valid court order or subpoena.
Law Enforcement: When required by law enforcement for specific purposes such as identifying suspects, locating missing persons, or reporting crimes that occur on our premises.
To Prevent Serious Harm: When we believe in good faith that disclosure is necessary to prevent or lessen a serious and imminent threat to your health or safety, or to the health or safety of another person or the public.
Coroners and Medical Examiners: For identification of a deceased person or to determine cause of death.
Workers’ Compensation: As required by workers’ compensation or similar programs.
Your Rights Regarding Your Health Information
You have the following rights regarding your health information:
Right to Inspect and Copy: You have the right to inspect and obtain a copy of your health information. We may charge a reasonable fee for copying and mailing records.
Right to Amend: If you believe your health information is incorrect or incomplete, you may request that we amend it.
Right to an Accounting of Disclosures: You have the right to request a list of disclosures we have made of your health information.
Right to Request Restrictions: You have the right to request restrictions on certain uses and disclosures of your health information.
Right to Request Confidential Communications: You have the right to request that we communicate with you about health matters in a certain way or at a certain location.
Right to a Paper Copy of This Notice: You have the right to receive a paper copy of this notice upon request.
Limits of Confidentiality in Therapy
While we maintain strict confidentiality of your therapeutic information, there are legal and ethical limits to confidentiality. We are required to break confidentiality in the following situations:
Imminent Risk of Harm: If we have reason to believe you pose a serious and imminent risk of harm to yourself or another identifiable person, we must take steps to protect safety. This may include notifying potential victims, contacting emergency services, or initiating hospitalization procedures.
Child Abuse or Neglect: We are mandated reporters under Georgia, Illinois, and Washington state law. If we have reasonable cause to suspect that a child is being abused or neglected, we must report this to Georgia, Illinois and/or Washington state Child Protective Services or law enforcement.
Elder or Dependent Adult Abuse: If we have reasonable cause to believe that an elder (age 65+) or dependent adult is being abused, neglected, or exploited, we must report this to Georgia, Illinois, and/or Washington state Adult Protective Services.
Court Orders and Subpoenas: If a valid court order is issued, we may be required to disclose your records or testify about your treatment. We will make every effort to notify you if this occurs and will only disclose the minimum necessary information.
Legal Proceedings Involving You: If you are involved in a court proceeding and raise your mental or emotional state as an issue, the court may order us to release your records.
We will make every effort to discuss these situations with you before breaking confidentiality, except in emergency situations where doing so could increase risk of harm.
Collecting and Using Your Personal Data
Types of Data Collected
Personal Data
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
- Email address
- First name and last name
- Phone number
- Address, State, Province, ZIP/Postal code, City
- Insurance information
- Emergency contact information
- Usage Data
Clinical Information
When you become a client, we collect additional information necessary for treatment and to comply with legal and insurance requirements:
- Mental health history and current symptoms
- Treatment goals and preferences
- Session notes and clinical assessments
- Treatment plans and progress records
- Medication information (if applicable)
- Emergency contact information
- Insurance information and billing records
- Signed consent forms and agreements
How Clinical Information is Stored: All clinical records are stored in our HIPAA-compliant Electronic Health Records (EHR) system, My Best Practice. Access is restricted to authorized staff only and protected by encryption and secure login credentials.
Usage Data
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
We may also collect information that Your browser sends whenever You visit our Service or when You access the Service by or through a mobile device.
Tracking Technologies and Cookies
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze Our Service.
You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.
Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on your personal computer or mobile device when You go offline, while Session Cookies are deleted as soon as You close your web browser.
We use both session and persistent Cookies for the purposes set out below:
Necessary / Essential Cookies
- Type: Session Cookies
- Administered by: Us
- Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these Cookies, the services that You have asked for cannot be provided, and We only use these Cookies to provide You with those services.
Cookies Policy / Notice Acceptance Cookies
- Type: Persistent Cookies
- Administered by: Us
- Purpose: These Cookies identify if users have accepted the use of cookies on the Website.
Functionality Cookies
- Type: Persistent Cookies
- Administered by: Us
- Purpose: These Cookies allow us to remember choices You make when You use the Website, such as remembering your login details or language preference. The purpose of these Cookies is to provide You with a more personal experience and to avoid You having to re-enter your preferences every time You use the Website.
Tracking and Performance Cookies
- Type: Persistent Cookies
- Administered by: Third-Parties
- Purpose: These Cookies help us understand how visitors use our website, which pages are most visited, and how we can improve the user experience. We do not use this information for advertising purposes.
For more information about the cookies we use and your choices regarding cookies, please visit our Cookies Policy.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain our Service, including to monitor the usage of our Service.
- To manage Your Account: to manage Your registration as a user of the Service. The Personal Data You provide can give You access to different functionalities of the Service that are available to You as a registered user.
- To contact You: To contact You by email, telephone calls, SMS, or other equivalent forms of electronic communication, such as a mobile application’s push notifications regarding updates or informative communications related to the functionalities, products or contracted services, including the security updates, when necessary or reasonable for their implementation.
- To provide You with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless You have opted not to receive such information.
- To manage Your requests: To attend and manage Your requests to Us.
- For Treatment, Payment, and Healthcare Operations: As described in the HIPAA Notice section above.
We may share your personal information in the following situations:
- With HIPAA-Compliant Service Providers: We may share your information with service providers who help us operate our website and provide clinical services. All providers who handle PHI sign Business Associate Agreements ensuring HIPAA compliance. These may include:
- Electronic Health Record (EHR) system providers
- Telehealth platform providers
- Billing and insurance verification services
- Secure email and communication providers
- IT support and security providers
- With Healthcare Providers: With your written authorization, we may share your PHI with other healthcare providers involved in your care (such as your physician, psychiatrist, or other therapists).
- With Insurance Companies: For payment purposes and coordination of benefits, we may share the minimum necessary PHI with your insurance company.
- For Legal Compliance: As required by law, as described in the “Limits of Confidentiality” section above.
We do NOT:
- Sell your personal information or PHI to third parties
- Use your information for targeted advertising
- Share your clinical information for marketing purposes
- Disclose your PHI without authorization except as required or permitted by law
Telehealth Privacy and Security
If you participate in telehealth (video) sessions, the following privacy and security measures apply:
Platform Security: All video sessions are conducted through Zoom Workplace, a HIPAA-compliant, encrypted telehealth platform. Video sessions are conducted in real-time and are not recorded unless you provide specific written consent for recording.
Session Links: For security purposes, telehealth session links are sent 15 minutes before your scheduled appointment. If you do not receive a link, please contact us through your client portal.
Your Responsibilities for Privacy: To protect your privacy during telehealth sessions:
- Join sessions from a private location where you cannot be overheard
- Use a secure, password-protected internet connection (avoid public Wi-Fi)
- Ensure your device has updated security software and operating system
- Use headphones if others are nearby
- Close unnecessary applications during the session
- Do not record sessions without explicit written consent
Limitations and Risks: While we use secure, encrypted platforms, please understand:
- No electronic transmission is 100% secure
- There is always a small risk of unauthorized access or technical difficulties
- Emergency services may be harder to deploy in a telehealth setting
- Technology failures may interrupt sessions
In Case of Emergency: If you are experiencing a mental health emergency during a telehealth session, we will work with you to contact emergency services in your location. Please ensure we have your current physical location on file.
Records Retention
Clinical Records: We retain clinical records for a minimum of 7 years from the date of last service, or longer as required by state law. In the case of minors, records are retained until the client reaches the age of majority plus 7 years.
Billing Records: Billing records are retained for 7 years in accordance with federal tax requirements.
Website Usage Data: Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.
How We Protect Your Information
The security of your personal data and PHI is critically important to us. We implement multiple layers of security:
Physical Safeguards:
- Secure, locked office space with restricted access
- Secure storage for any paper records
- Controlled building access
- Secure disposal of records (shredding)
Technical Safeguards:
- Encrypted, HIPAA-compliant electronic health records system
- Secure, encrypted telehealth platform
- Password-protected devices and systems
- Automatic session timeouts
- Regular software updates and security patches
- Firewall and antivirus protection
- Encrypted data transmission
- Secure, encrypted backup systems
Administrative Safeguards:
- Access to PHI limited to essential staff on a need-to-know basis
- Regular staff training on HIPAA privacy and security
- Business Associate Agreements with all vendors who handle PHI
- Written privacy and security policies and procedures
- Regular risk assessments
- Incident response plan
Important Note: No method of electronic storage or transmission is 100% secure. While we implement industry-standard security measures, we cannot guarantee absolute security. We will notify you promptly in the unlikely event of a data breach affecting your information.
Breach Notification
In the event of a breach of your unsecured PHI, we will:
- Investigate the breach immediately upon discovery
- Contain the breach and mitigate harm
- Notify you without unreasonable delay and no later than 60 days after discovery
What We Will Tell You:
- What happened and when we discovered it
- The types of information involved in the breach
- Steps you should take to protect yourself from potential harm
- What we are doing in response to the breach
- Contact information for questions and further assistance
Additional Notifications: Depending on the nature and scope of the breach, we may also be required to notify:
- The U.S. Department of Health and Human Services
- Local media (in cases of large breaches affecting 500+ individuals)
- Law enforcement (if criminal activity is suspected)
If you believe your privacy rights have been violated or a breach has occurred, please contact our Privacy Officer immediately using the contact information at the end of this notice.
Business Associates
We may share your PHI with third-party service providers who assist us in providing services to you. These “Business Associates” include:
- Electronic Health Record (EHR) system providers
- Billing and insurance verification services
- Telehealth platform providers
- Credit card processing companies
- IT support and security providers
All Business Associates are required to sign Business Associate Agreements (BAAs) ensuring they will safeguard your PHI in accordance with HIPAA regulations.
Website Analytics
We use Google Analytics to understand how visitors use our website and to improve your experience. Google Analytics collects information such as how often users visit the site, what pages they visit, and what other sites they used prior to coming to our site.
What Google Analytics Collects:
- Pages visited and time spent on each page
- How you arrived at our site (search engine, direct link, etc.)
- General location information (city/region, not specific address)
- Device and browser information
- We use this information only to improve our website, not for advertising
Opting Out: You can opt-out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.
For more information on Google’s privacy practices, visit: https://policies.google.com/privacy
Email Communications
We may use your email address to:
- Send appointment reminders and confirmations
- Share important updates about your treatment or our practice
- Send newsletters or educational content (you can opt-out anytime)
- Respond to your inquiries
Opting Out: You may opt-out of receiving promotional emails by clicking the “unsubscribe” link in any email or by contacting us directly. Please note that even if you opt-out of promotional emails, we will still send you essential communications related to your appointments and treatment.
Email Security: While we use secure email systems, please be aware that regular email is not a completely secure form of communication. We recommend not including sensitive health information in regular emails. For secure communication, please use our client portal messaging system.
Children's Privacy
Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent, We take steps to remove that information from Our servers.
For clients under 18 years of age, a parent or legal guardian must provide consent for treatment and has the right to access the minor’s health information, subject to certain exceptions under state law.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party’s site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Changes to this Privacy Policy
We may update our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the “Last updated” date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Complaints
If you believe your privacy rights have been violated, you have the right to file a complaint with:
Our Privacy Officer: Janita Wiley Director of Marketing & Outreach, MadeMind Wellness & Performance LLC 7234 W North Ave Ste 208 Chicago, IL 30039 janita@mademdinwellness.com [773] 301-1329.
U.S. Department of Health and Human Services: Office for Civil Rights U.S. Department of Health & Human Services 200 Independence Avenue, S.W. Washington, D.C. 20201 Toll Free: 1-877-696-6775 Website: www.hhs.gov/ocr/privacy/hipaa/complaints/
We will not retaliate against you for filing a complaint.
Contact Us
If you have any questions about this Privacy Policy, You can contact us:
Privacy Officer: Janita Wiley Director of Marketing & Outreach
By email: admin@mademindwellness.com
By phone: (773) 301-1329
By mail: MadeMind Wellness & Performance PLLC, 7234 W North Ave Ste 208, Chicago, IL 30039
Effective Date:This Notice is effective as of 05.01.2026 and will remain in effect until replaced or amended.