Legal Information
Privacy Policy
Effective Date: July 6, 2026 • Last Updated: July 10, 2026
Your Privacy & Confidentiality Matter
At Strength Behavioral Services, we are deeply committed to protecting the privacy and confidentiality of your health information. This Privacy Policy explains how we collect, use, disclose, and safeguard your Protected Health Information (PHI) in strict compliance with the Health Insurance Portability and Accountability Act (HIPAA) and applicable New Jersey and federal laws.
1. HIPAA Notice of Privacy Practices
This Notice describes how medical and mental health information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
Strength Behavioral Services is required by law to:
- Maintain the privacy and security of your Protected Health Information (PHI)
- Provide you with this Notice of our legal duties and privacy practices
- Follow the terms of the Notice currently in effect
- Notify you promptly if a breach occurs that may have compromised the privacy or security of your information
- Accommodate reasonable requests you may have to communicate health information by alternative means or at alternative locations
2. Information We Collect
We collect and maintain the following types of clinical and personal information to provide safe, comprehensive psychiatric care:
Protected Health Information (PHI)
- Personal identifying information (full name, address, phone number, date of birth, email)
- Comprehensive medical and psychiatric evaluation histories
- Mental health diagnoses, treatment goals, and progress notes
- Medication management histories, pharmacy details, and prescription records
- Psychotherapy notes (maintained separately with strict, elevated protections)
- Insurance coverage verification and billing records
- Digital and written communication logs (phone calls, emails, patient portal exchanges)
Website & Telehealth Digital Information
- IP addresses and browser metadata (for encrypted system security logs)
- Contact inquiries and scheduling requests submitted via secure online forms
- HIPAA-compliant telehealth session technical data (connection timestamps and duration without audio/video recording)
3. How We Use and Disclose Your Information
Uses and Disclosures Without Your Written Authorization
Under HIPAA regulations, we are permitted to use and disclose your PHI without your written consent for the following core healthcare purposes:
Treatment
To provide, coordinate, or manage your psychiatric evaluations and medication therapy. This includes collaborating with covering providers or your pharmacy.
Payment
To bill and collect payment for services rendered, verify health insurance coverage, and process claims. Only the minimum necessary details are shared.
Operations
For internal practice management, clinical quality assessment, licensing reviews, staff compliance training, and secure software maintenance.
Other Permitted Exceptions Required by Law
- As Required by Federal/State Law: When legally mandated by judicial orders or public health statutes
- Abuse, Neglect, or Domestic Violence: When legally required to report suspected child, elder, or vulnerable adult abuse
- Judicial & Administrative Proceedings: In response to valid court orders or formal legal subpoenas (with strict verification)
- Serious Threat to Health or Safety: To prevent or lessen an imminent, severe threat to your life or the safety of another individual
- Health Oversight & Audits: For state licensing board reviews or federal compliance inspections
4. Disclosures Requiring Your Written Authorization
Any use or disclosure of your health information not explicitly covered in Section 3 requires your explicit, signed written authorization before release. This specifically includes:
- Psychotherapy Notes: Separately recorded clinical process notes taken during therapy require separate, specific authorization before any disclosure.
- Release to Family/Friends: We will not discuss your treatment with family members, employers, or spouses without your explicit verbal or written permission unless a life-threatening emergency exists.
- No Sale of Information: We do not and will never sell, rent, or trade your personal health information to third-party advertisers or data brokers.
Right to Revoke: You have the absolute right to revoke a written authorization at any time by submitting a signed written request to our office. Revocation applies to all future disclosures but cannot undo releases already made while your consent was active.
5. Your Rights Regarding Your Health Information
Under HIPAA and New Jersey health regulations, you retain the following fundamental rights over your psychiatric and medical records:
Right to Inspect and Copy
You may inspect and request electronic or paper copies of your clinical and billing records. Requests must be submitted in writing. We will respond within statutory deadlines and may charge a reasonable, cost-based administrative fee for copying or mailing.
Right to Request Amendments
If you believe information in your record is incorrect or incomplete, you may submit a written request for amendment explaining your reasoning. If denied due to clinical accuracy, you have the right to file a statement of disagreement.
Right to Request Confidential Communications
You have the right to request that we communicate with you only through specific, designated channels (e.g., calling your cell phone rather than a home number, or mailing documents to a P.O. Box). We accommodate all reasonable confidential requests.
Right to Restrict Out-of-Pocket Disclosures
If you pay for a psychiatric evaluation or treatment session out-of-pocket in full at the time of service, you have the legal right to request that we do not disclose diagnostic or treatment details for that specific visit to your health insurance plan.
Right to an Accounting of Disclosures
You may request a formal log of all instances where your PHI was disclosed to outside entities for reasons other than routine treatment, billing, or operations over the past six years.
6. How We Protect Your Information
We employ rigorous administrative, physical, and technical security measures designed to safeguard your data from unauthorized access or breaches:
Technical Security
256-bit encryption for electronic health records, multi-factor authentication, enterprise firewalls, and automatic system logouts.
Physical Security
Restricted, key-card access to office suites, locked file cabinets for paper documents, and certified cross-cut shredding.
Administrative Protocols
Mandatory annual HIPAA staff training, strict privacy policies, and executed Business Associate Agreements with all software vendors.
7. Telehealth Privacy & Security Standards
When participating in virtual telepsychiatry visits, we guarantee the highest standards of digital confidentiality:
- All video appointments are conducted using encrypted, HIPAA-compliant telehealth software
- Video/audio streams are never recorded or stored by our practice or our software partners
- Secure patient waiting rooms prevent unauthorized third parties from joining your private consultation
Patient Security Recommendation: To ensure maximum privacy on your end, we advise attending your virtual appointment from a quiet, private room using a password-protected personal Wi-Fi network rather than public or shared internet connections.
8. Privacy of Adolescents & Minors
For patients under 18 years of age, parents/guardians generally hold the legal right to inspect clinical records. However, under specific New Jersey mental health statutes, adolescents may hold distinct confidentiality rights regarding sensitive reproductive or psychiatric disclosures. We balance parental transparency with adolescents' right to a safe, therapeutic bond in accordance with state law.
9. Website Contact Form Privacy
Our public website contact form is designed strictly for general administrative inquiries and initial scheduling requests. Please do not transmit detailed medical histories, clinical symptoms, or urgent psychiatric concerns through public contact forms. Once established as a patient, all clinical messaging must occur through your secure, encrypted Patient Portal.
10. Record Retention & Policy Updates
In compliance with New Jersey Board of Nursing regulations and clinical standards, adult patient medical records are retained securely for a minimum of seven (7) years from the date of last professional contact. Records of minors are preserved for seven (7) years beyond their 18th birthday.
We reserve the right to amend or update this Privacy Policy as federal or state laws evolve. The revised notice will apply to all historical and future health data we maintain. Updated versions are immediately posted on our website and available upon request in our office.
11. Questions, Requests, or Filing a Complaint
If you have any questions about your privacy rights, wish to request copies of your records, or feel your confidentiality rights have been compromised, please contact our Practice Privacy Officer immediately. You will never be penalized, discriminated against, or retaliated against for asking questions or filing a formal complaint.
Practice Privacy Officer
Strength Behavioral Services
Attn: HIPAA Privacy Officer
28-32 Prince Street
Elizabeth, NJ 07308
Phone: (908) 895-8089
Email: admin@strengthbehavioralservices.com
U.S. Department of Health & Human Services
Office for Civil Rights (OCR)
200 Independence Avenue, S.W.
Room 509F, HHH Building
Washington, D.C. 20201
Phone: 1-800-368-1019
Online: OCR Complaint Portal