Health data is a separate legal category
For a therapy, counselling or dental practice, almost everything you record about a client is special-category data under GDPR Article 9 or 'sensitive personal information' under the CPRA. That changes the paperwork: you need a lawful basis for processing under Article 6 and a separate condition under Article 9 (usually explicit consent, or the provision of health care), and in California sensitive information carries a right to limit its use.
A website privacy policy is not a substitute for a HIPAA Notice of Privacy Practices if you are a US covered entity, and it is not your clinical records policy either. Its job is narrower and specific: to explain what your public-facing website, booking system and enquiry forms do with the information a prospective or existing client types in before they ever become a patient record.
- Enquiry and intake forms, including free-text 'reason for contact' fields
- Screening questionnaires such as PHQ-9 or GAD-7 collected online
- Appointment scheduling, reminders and no-show records
- Telehealth platform metadata (join times, IP address, device)
- Insurance, superbill and billing details handled by your payment processor
- Session notes storage — named systems only, not clinical content