Therapy

Privacy Policy for Therapists & Counselors

Privacy policy template for therapists, counselors, and telehealth practices.

Free · No signup · PDF & DOCX export · GDPR / CCPA / UK / CA / AU / LGPD / DPDP

No account or signup required
GDPR & CCPA clauses included
Clauses for AI tools & SaaS
Free PDF & DOCX export
Page last updated · May 2026

Therapists handle highly sensitive personal data. This template explains how a privacy policy complements (not replaces) HIPAA and covers telehealth, intake, and notes.

What's included

  • Telehealth platform disclosures
  • Intake forms and assessments
  • Session notes & retention
  • HIPAA-aware language
  • Insurance & billing data
  • GDPR special categories

Why you need this

  • Required for any web-facing practice
  • Builds trust with new clients
  • Complements HIPAA Notice of Privacy Practices
  • Reduces regulatory risk

Health data is a separate legal category

For a therapy, counselling or dental practice, almost everything you record about a client is special-category data under GDPR Article 9 or 'sensitive personal information' under the CPRA. That changes the paperwork: you need a lawful basis for processing under Article 6 and a separate condition under Article 9 (usually explicit consent, or the provision of health care), and in California sensitive information carries a right to limit its use.

A website privacy policy is not a substitute for a HIPAA Notice of Privacy Practices if you are a US covered entity, and it is not your clinical records policy either. Its job is narrower and specific: to explain what your public-facing website, booking system and enquiry forms do with the information a prospective or existing client types in before they ever become a patient record.

  • Enquiry and intake forms, including free-text 'reason for contact' fields
  • Screening questionnaires such as PHQ-9 or GAD-7 collected online
  • Appointment scheduling, reminders and no-show records
  • Telehealth platform metadata (join times, IP address, device)
  • Insurance, superbill and billing details handled by your payment processor
  • Session notes storage — named systems only, not clinical content

Concrete scenarios most practices get wrong

A contact form that asks 'what would you like help with?' collects health data the moment somebody types 'anxiety'. If that form emails you through a third-party form provider, that provider is a processor handling special-category data and belongs in your policy with a data processing agreement in place.

Booking tools are the second common gap. Calendly, SimplePractice, Cliniko, Halaxy and Jane all store client identifiers and appointment history on their own infrastructure, frequently outside your country. Name the tool, say what it stores, and say where.

The third is marketing pixels. A Meta or Google Ads pixel on a page titled 'trauma therapy' can transmit an inference about a visitor's health. Regulators in the US and EU have taken action over exactly this. If you run ads, either keep tracking off clinical pages or gate it behind consent and disclose it plainly.

Retention, and why it differs from other businesses

Most small businesses can promise to delete data when it is no longer needed. Health practitioners usually cannot: professional bodies and state or national law often set minimum retention for clinical records — commonly seven years for adults, and until a set age for minors. Your policy should distinguish clearly between website enquiry data (which you can delete quickly, and should) and clinical records subject to a statutory retention period, and should say that a deletion request cannot override that period.

Where to publish it, and what to do next

Link the policy in your site footer so it appears on every page, and again directly next to any intake or contact form — a short line above the submit button saying what happens to the information carries more weight with a regulator than a buried link. If you use a client portal, include the link on the sign-up screen. If you take payments online, your processor will also expect a reachable URL.

Common mistakes worth checking before you publish: relying on your HIPAA notice alone for the website; copying a generic template that promises deletion 'on request' while your records law says otherwise; failing to name your telehealth and booking vendors; and never revisiting the document after switching practice-management software.

  • Generate the base document in the privacy policy wizard, then add your retention periods
  • Read the GDPR guide if you see clients in the EU or UK
  • Pair it with a cookie policy if your site runs analytics or ads

Not legal advice. PolicyGenie is a self-help document tool, not a law firm. The templates and articles here are general information only and may not fit your circumstances or reflect the most recent changes in the law. Review anything you publish, and get advice from a qualified lawyer in your jurisdiction if your business handles sensitive data or operates in a regulated industry. See our full disclaimer.

Advertisement

Generate your policy now

Free • PDF & DOCX • No signup

Start the generator

Frequently asked questions

Everything you need to know before publishing your policy.