1. HIPAA Notice of Privacy Practices
Mayflower Behavioral Health LLC ("Practice", "we", "us", or "our"), led by Azeezat A. Samuel, PMHNP-BC, is a healthcare covered entity subject to the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and relevant state mental health privacy statutes in Georgia, Washington, Iowa, and Arizona.
We are legally required to maintain the privacy of your Protected Health Information (PHI), provide you with this detailed notice of our legal duties and privacy practices, notify you following a breach of unsecured PHI, and abide by the terms of this notice currently in effect.
2. Protected Health Information (PHI) We Collect
In the course of providing psychiatric evaluations, psychotherapy, and medication management, we collect information that identifies you and relates to your past, present, or future physical or mental health:
- Contact & Demographic Data: Legal name, date of birth, biological sex, gender identity, home address, phone number, email address, emergency contact details, and state of physical residence.
- Clinical & Medical History: Psychiatric symptoms, medical history, family psychiatric history, allergies, substance use history, past treatment records, and clinical consultation notes.
- Prescription & Pharmacy Records: Medications prescribed, dosages, pharmacy preferences, and Prescription Drug Monitoring Program (PDMP) verification data.
- Billing & Payment Data: Health insurance subscriber details, claims records, credit card or payment card tokens (processed securely via PCI-DSS compliant gateways; full card numbers are never stored on our web server).
- Telehealth Session Telemetry: Connection logs and session timestamps (telehealth video sessions are real-time, encrypted, and never recorded without express prior written consent).
3. How We Use and Disclose Protected Health Information
Under HIPAA, we may use and disclose your PHI for the following core purposes without requiring separate authorization:
- For Treatment: We use your clinical information to evaluate, diagnose, and manage your psychiatric care. We may coordinate care with your primary care physician, therapist, or preferred pharmacy for prescription dispensation.
- For Payment: We submit claims to your health insurance provider, process copayments, and verify insurance eligibility through encrypted billing clearinghouses.
- For Healthcare Operations: We use aggregated health data for clinic quality improvement, internal clinical review, compliance audits, and accreditation purposes.
Disclosures Permitted or Required by Law
We may be required or permitted to disclose your PHI without your authorization under specific legal circumstances:
- Averting Serious Threats to Health or Safety: To prevent or lessen an imminent threat to your health or safety or the safety of another individual (e.g., emergency crisis intervention).
- Mandated Reporting of Abuse: Required reporting of suspected child abuse, elder abuse, or vulnerable adult neglect.
- Legal & Judicial Proceedings: In response to a valid court order, subpoena, or administrative warrant, subject to strict state psychiatric confidentiality safeguards.
- Public Health Oversight: Disclosures to public health authorities for disease tracking, adverse medication reactions, or regulatory compliance.
Psychotherapy Notes Protection
Psychotherapy notes maintained separately from your medical record receive heightened protection under HIPAA. They will never be disclosed without your specific, signed, written authorization, except where mandated by law.
4. Your Health Information Rights Under HIPAA
As a patient of Mayflower Behavioral Health, you have the following legal rights:
- Right to Inspect and Copy: You have the right to inspect and obtain an electronic or paper copy of your clinical medical and billing records.
- Right to Amend: If you believe your health records contain inaccurate or incomplete information, you may request a written amendment.
- Right to an Accounting of Disclosures: You may request a list of certain disclosures of your PHI made outside of treatment, payment, or operations during the past 6 years.
- Right to Request Confidential Communications: You have the right to request that we contact you at a specific phone number, email address, or mailing address.
- Right to Request Restrictions: You may request restrictions on how your PHI is used or disclosed for treatment, payment, or healthcare operations. If you pay out-of-pocket in full for a service, you have the right to restrict disclosure to your insurer.
- Right to a Paper Copy: You may request a printed paper copy of this privacy notice at any time.
5. GDPR, UK-GDPR & Consumer Privacy Rights
To provide transparency to all website visitors, Mayflower Behavioral Health implements data protection principles aligned with the General Data Protection Regulation (GDPR), the UK-GDPR, and applicable US state privacy laws (including California CCPA/CPRA):
- Lawful Basis for Processing: We process non-PHI digital telemetry based on legitimate clinical and operational interests, and explicit consent for optional analytics or functional cookies.
- Right of Access & Portability: You may request a summary of personal digital data collected about you in a structured, machine-readable format.
- Right to Rectification & Erasure ("Right to be Forgotten"): You may request the correction or erasure of non-clinical personal data. (Note: Medical records must be retained in accordance with state medical record retention statutes).
- Right to Withdraw Consent: You have the absolute right to modify or withdraw your cookie and data preferences at any time using our persistent cookie preferences modal.
- No Sale of Data: Mayflower Behavioral Health does not sell, rent, or trade your personal data, web activity, or health information to third-party data brokers or marketing networks.
7. Telehealth Security & Digital Communications
Telehealth visits are conducted via secure, end-to-end encrypted video technology that complies with HIPAA Security Rule requirements (45 CFR Part 160 and Part 164).
- EHR & Patient Portal: Patient scheduling and clinical documentation are managed via CharmHealth EHR, an established cloud health system with SOC 2 Type II and HIPAA certification.
- No Public Wi-Fi Recommendation: Patients are advised to join telehealth visits from private, confidential spaces utilizing password-protected internet connections.
- Unencrypted Communications Disclaimer: Standard email and SMS text messaging are not guaranteed to be secure channels for transmission of sensitive clinical information. Patients are encouraged to communicate via the encrypted patient portal.
8. Data Retention & Record Disposal
In compliance with professional nursing board regulations and statutory healthcare record retention requirements in Georgia, Washington, Iowa, and Arizona, adult psychiatric records are retained for a minimum of 7 to 10 years following the last date of professional clinical service.
Upon expiration of the mandatory retention timeframe, medical and demographic records are destroyed in a secure manner designed to render all electronic and physical media permanently unrecoverable.
9. Privacy Officer Contact & Complaints
If you have questions about this Notice of Privacy Practices, wish to exercise any of your HIPAA or GDPR rights, or believe your privacy rights have been violated, please contact our designated Privacy Officer:
Mayflower Behavioral Health LLC
Telephone: (470) 655-6029
Email: care@mayflowerbehavioralhealth.com
Serving Adults across Georgia, Washington, Iowa & Arizona
You may also file a formal written complaint with the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) by visiting hhs.gov/ocr. We will never retaliate against you in any way for filing a complaint.