HIPAA Notice
Notice of Privacy Practices for Website Inquiries · Effective Date: April 2026
1 Our Commitment to Your Privacy
Bedrock ABA is committed to protecting the privacy of your health information. This notice describes how health-related information collected through our website may be used and disclosed, and how you can access this information.
2 Health Information We Collect
Through our website inquiry forms, we may collect:
- Your child's first name and age
- Autism Spectrum Disorder (ASD) diagnosis status
- Behavioral and developmental concerns
- Insurance provider information
- Service preferences and location
This information is collected for the sole purpose of evaluating your child's potential eligibility for ABA therapy services and preparing our intake team to assist you effectively.
3 How We Use Health Information
We use the health-related information you provide to:
- Assess preliminary eligibility for ABA services
- Verify insurance coverage with your authorization
- Match your child with an appropriate therapist
- Prepare our team for your initial consultation
- Contact you to discuss next steps and answer questions
4 How We Protect Your Information
We safeguard your health information through:
- Encrypted data transmission (HTTPS/SSL) on all forms and pages
- Secure, access-controlled client management systems
- Limited staff access on a strict need-to-know basis
- Regular review and updating of our security practices
5 Disclosure of Health Information
We will NOT disclose your health information without your consent except in the following limited circumstances:
- To insurance companies, with your authorization, for coverage verification
- To our clinical team (BCBAs, RBTs) directly involved in your child's care
- As required by law, regulation, or valid court order
We do NOT share health information with advertising platforms, marketing partners, or any third parties for commercial purposes.
6 Your Rights
You have the following rights regarding your health-related information:
To exercise any of these rights, contact us at [email protected] or (385) 563-1930.
7 Data Retention
We retain health-related inquiry information for as long as necessary to provide services or as required by applicable law. If you do not become an active client, we will retain your inquiry information for no more than 24 months, after which it will be securely deleted upon request.
8 Website Forms vs. Clinical Records
Once you become an active client, your child's full clinical records — including treatment plans, session notes, progress reports, and assessments — are governed by a separate, comprehensive Notice of Privacy Practices provided during the formal intake process, in full compliance with HIPAA regulations. That notice will describe your rights and our obligations in greater detail as they apply to clinical care.
9 Changes to This Notice
We may update this notice from time to time to reflect changes in our practices or applicable law. The current version will always be available at this URL. We encourage you to review this notice periodically.
10 Contact Us
If you have questions about this HIPAA Notice or wish to exercise your rights, please contact our Privacy Office:
If you believe your privacy rights have been violated, you may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at www.hhs.gov/ocr. We will not retaliate against you for filing a complaint.
This notice is provided as a general framework. Bedrock ABA recommends consulting with a qualified attorney to ensure full compliance with applicable federal and state regulations, including HIPAA and Utah health privacy laws.