Effective Date: March 28, 2026
Last Updated: March 28, 2026

Haley Lewis, CSW (“we,” “us,” “our,” or “the Practice”) operates the website haleylewistherapy.com (the “Site”). This Privacy Policy describes how we collect, use, and protect information you provide when using our Site. It also explains your rights regarding that information.

Because we provide mental health services, we are committed to safeguarding the privacy and confidentiality of all client information in accordance with the Health Insurance Portability and Accountability Act (HIPAA), Utah state law, and professional ethical standards.

1. Information We Collect

We collect information in two main ways:

a. Information You Voluntarily Provide

  • Contact Form: When you complete the contact form, we collect your name, email address, phone number, and any message you include.
  • Schedule an Appointment: If you use our online scheduling tool, you will provide personal information such as your name, contact details, and insurance information. That information is processed directly by our scheduling platform (see Section 4).
  • Blog Comments or Inquiries: If you comment on a blog post or contact us via email, we receive the information you choose to share.
  • Client Portal / TherapyNotes: Links to our secure client portal and TherapyNotes are provided for existing clients. Any information you submit through those platforms is governed by HIPAA and the terms of those services.

b. Automatically Collected Information

  • Cloudflare Analytics: We use Cloudflare Analytics to understand how visitors interact with our Site. This service collects anonymous, aggregated data such as pages visited, referral sources, and general location (city/region). It does not use cookies to track individual users across the web, and it does not collect personally identifiable information (PII) like your name or IP address in a way that identifies you.

2. How We Use Your Information

  • To respond to inquiries submitted via the contact form or email.
  • To facilitate appointment scheduling and related communications.
  • To improve the content and functionality of our Site.
  • To comply with legal and ethical obligations (e.g., reporting requirements, court orders).
  • No PHI on the Site: The Site itself is not a secure method of communication. You should not include protected health information (PHI) in contact forms, emails, or blog comments. PHI should be shared only through our secure client portal or during a therapy session.

3. Third‑Party Services & Links

Our Site uses or links to third‑party services that have their own privacy policies:

  • Scheduling Platform: [Name of scheduling tool, e.g., Acuity, SimplePractice Scheduling] – used to manage appointment requests. Their privacy policy can be found at [link].
  • TherapyNotes: Our electronic health record (EHR) and client portal. Existing clients access TherapyNotes to complete forms, communicate securely, and view appointment information. TherapyNotes’ privacy practices are available at [link].
  • Blog Platform: Our blog is hosted on [platform, e.g., WordPress]. Please review their privacy policy for how they handle data.

We are not responsible for the privacy practices of these third‑party websites. We encourage you to read their policies before providing any personal information.

4. Confidentiality & HIPAA

As a mental health provider, I am bound by HIPAA and Utah state law to protect the privacy of client health information.

  • Secure Messaging: Clients are provided access to a secure messaging system through TherapyNotes. All clinical communications should occur via that system or during scheduled appointments.
  • No Warranty of Security: While we take reasonable steps to protect the information you send through our Site (e.g., contact forms), email and website forms are not inherently secure. By using these features, you acknowledge the risk and agree not to transmit PHI through them.
  • Exceptions: Confidentiality may be breached in certain legally mandated situations (e.g., imminent harm, abuse reporting). Those exceptions will be discussed with you during the initial intake process.

5. Cookies & Tracking Technologies

Our Site does not use cookies for marketing, advertising, or cross‑site tracking. Cloudflare Analytics uses a privacy‑focused approach that does not set cookies or track individual users. We do not use Google Analytics, Facebook Pixel, or similar tools.

You may disable cookies in your browser settings, but doing so may affect the functionality of some third‑party services (such as the scheduling tool).

6. Children’s Privacy

Our Site is not intended for children under 13. We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided us with personal information, we will delete it immediately.

7. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information. Under Utah law, residents have the right to:

  • Know what personal information we collect about you.
  • Request deletion of your personal information.
  • Opt out of the “sale” of your personal information (we do not sell any personal information).

To exercise these rights, please contact us using the information in Section 9. We will respond within the timeframe required by law.

8. Data Security

We take reasonable administrative, technical, and physical measures to protect the information you provide. However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.

9. Contact Information

If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact:

Haley Lewis, CSW
Email: [email protected]
Phone: (801) 555-1234
Mailing Address: 123 Main Street, Suite 200, Salt Lake City, UT 84101

For matters related to your protected health information (PHI), please refer to our Notice of Privacy Practices (provided separately during intake) or contact us using the secure client portal.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last Updated” date. We encourage you to review this page periodically.