LEGAL
Privacy Policy
Last Updated: September 3, 2026
Baiden & Associates PLLC (“Baiden & Associates,” “we,” “us,” or “our”) provides fully virtual behavioral health services through licensed clinicians in Maryland, Virginia, the District of Columbia, North Carolina, and Ohio, and, through our LeafyNotes Consulting division (“powered by Baiden & Associates PLLC”), business process, documentation, and audit-preparation services to behavioral health provider organizations. This Privacy Policy explains how we collect, use, disclose, and protect information about visitors to our website, prospective and current clients, and business clients of LeafyNotes Consulting (collectively, “you”) in connection with our website, client portal, scheduling tools, telehealth platform, and related services (collectively, the “Services”).
This Policy is written in plain language so it is easy to use as the public-facing companion to the HIPAA Notice of Privacy Practices in Section 8, which governs our treatment of Protected Health Information (“PHI”).
1. Information We Collect
1.1 Information You Provide Directly
- Contact and intake information: name, email address, phone number, mailing address, date of birth, gender, state of residence, and emergency contact details submitted through our website forms, scheduling wizard, or client portal.
- Clinical and health information: information you share during intake, assessments, and sessions, including mental health history, diagnoses, treatment goals, and progress notes (this is Protected Health Information — see Section 8).
- Insurance and billing information: insurance carrier and member ID (for clients using Aetna, Cigna, Optum/UHC, or Carelon), payment card details, and billing address, processed through our billing platforms and payment processor.
- Communications: messages you send us by email, phone, text, or through the client portal, including appointment-related messages and any recorded voicemail.
- Supervised visitation records: for clients of our supervised visitation service, information about the parties, minor children, and any court orders or attorney contacts relevant to scheduling and conducting supervised visits.
- LeafyNotes Consulting client information: for behavioral health provider organizations engaging LeafyNotes Consulting, business and operational information, and, where applicable, de-identified or client-authorized clinical documentation accessed while performing documentation, EHR-population, audit-preparation, or workflow-consulting services.
1.2 Information Collected Automatically
- Device and usage data: IP address, browser type, device type, pages viewed, referring URL, and approximate location, collected through our website and scheduling tools.
- Cookies and similar technologies: see Section 3 below.
- Telehealth session metadata: date, time, and duration of virtual sessions conducted through our telehealth platform (Sessions Health). Sessions are not recorded by default; a session is recorded only if Baiden & Associates specifically requests to do so and you agree at that time.
2. How We Use Information
We use the information described above to:
- Schedule, provide, and coordinate clinical and consulting services;
- Process insurance claims and payments and communicate with insurers and billing partners;
- Maintain accurate clinical and business records in our EHR (Sessions Health) and related systems;
- Communicate with you about appointments, billing, and administrative matters;
- Improve our website, scheduling flow, and service offerings;
- Meet our legal, regulatory, licensing, and accreditation obligations (including CARF/BHA audit readiness for LeafyNotes clients); and
- Protect the security, integrity, and proper use of our Services.
We do not sell personal information, and we do not use PHI for marketing without your written authorization.
3. Cookies and Website Analytics
Our website uses cookies and similar technologies, such as Google Analytics, to understand how visitors use our site and to improve its content and performance. These tools may collect your IP address, browser type, pages viewed, and referring/exit pages. We do not use cookies to collect PHI, and we do not permit third-party advertising trackers on pages that collect clinical or scheduling information.
You can control cookies through your browser settings, though disabling cookies may affect some website functionality (such as remembering your progress through the scheduling wizard). Instructions for managing Google Analytics specifically are available at https://tools.google.com/dlpage/gaoptout.
4. Telehealth-Specific Disclosures
- Services are delivered virtually by clinicians licensed in the state where you are physically located at the time of service (Maryland, Virginia, D.C., North Carolina, or Ohio).
- Electronic transmission of video, audio, and text carries inherent security risks; while our telehealth platform and EHR use industry-standard encryption, no method of transmission over the internet is completely secure.
- You are responsible for ensuring a private, confidential physical space and a secure internet connection when participating in telehealth sessions.
- In the event of a technology failure during a session, your clinician will attempt to reach you by phone using the contact information on file.
5. Third-Party Service Providers
We work with third-party vendors who process information on our behalf, under confidentiality and, where required, Business Associate Agreement (“BAA”) obligations. These currently include:
- Electronic health record, documentation, and telehealth platform: Sessions Health (system of record for clinical documentation, forms, assessments, and virtual sessions), Tebra, and Credible.
- Insurance billing platforms: Headway (Aetna and Cigna), Alma (Optum/UHC), and other affiliated billing partners engaged for Maryland Medicaid, Medicare, or other Behavioral Health Administration (BHA)-regulated billing arrangements.
- Scheduling and referral services: Zocdoc.
- Payment processing: for self-pay clients, payments are processed through Sessions Health using Stripe as the underlying payment processor; insurance copayments and claims are handled directly by the applicable billing partner listed above.
- Email and communications: we are transitioning to a HIPAA-compliant email provider; no clinical information is sent by email until this transition is complete.
- Website hosting and content: BrighterVision (or successor host) and, for informational/marketing pages only, Hostinger.
These vendors are contractually restricted to using your information only to provide services to us and are prohibited from using it for their own independent purposes.
6. Supervised Visitation Services
Our supervised visitation program is a legacy service with its own booking process, separate from clinical mental health services. Because this service often involves minor children and court-ordered arrangements, we may collect and disclose information (including about minors who are not our clients) as necessary to schedule and conduct visits, to comply with court orders, and to communicate with the parties’ attorneys or the court, where legally required or authorized. This service is not directed to children as an audience and does not involve marketing to children; information about minors is used solely to carry out the ordered visitation.
7. LeafyNotes Consulting (Business Clients)
When LeafyNotes Consulting provides virtual assistant, documentation, EHR-population, business process/AI consulting, or CARF/BHA audit-preparation services to another behavioral health provider organization, we act as a service provider and, where the engagement involves access to that organization’s clients’ PHI, as a Business Associate under HIPAA, governed by a separate Business Associate Agreement with that organization rather than by this Policy. This Policy governs information we collect about the business client itself (such as contact and billing information) in connection with the consulting engagement.
8. HIPAA Notice of Privacy Practices
This Section describes how medical information (“PHI”) about you may be used and disclosed, and your rights regarding that information. It applies to Baiden & Associates PLLC clinicians and staff who provide or support your care.
8.1 How We May Use and Disclose PHI
- Treatment: to provide, coordinate, or manage your care, including with other providers involved in your treatment.
- Payment: to bill and collect payment for services, including sharing information with your health plan (Aetna, Cigna, Optum/UHC, Carelon) or Maryland Medicaid as applicable.
- Health care operations: for quality assurance, supervision, audits, and administrative activities, including case review with our clinical auditor.
- Individuals involved in your care: to a family member or other person involved in your care or payment for care, where permitted.
- As required by law: including mandatory reporting of abuse or neglect, responses to court orders or subpoenas, health oversight activities, and public health reporting.
- Mental health and substance use records: additional state and federal protections (including 42 CFR Part 2 for substance use treatment records, where applicable) may require your specific written authorization before we disclose these records; we will obtain that authorization when required.
- Psychotherapy notes and marketing: we will not disclose psychotherapy notes or use your PHI for marketing or fundraising without your written authorization, except as permitted by law.
8.2 Your Rights Regarding PHI
- Right to inspect and receive a copy of your record, including an electronic copy from our EHR where feasible.
- Right to request an amendment to your record.
- Right to an accounting of certain disclosures made in the six years prior to your request.
- Right to request restrictions on certain uses and disclosures, including a request that we not disclose information to your health plan for services you paid for in full, out of pocket.
- Right to request confidential communications by an alternative method or at an alternative location.
- Right to a paper copy of this Notice, even if you agreed to receive it electronically.
- Right to be notified in the event of a breach of your unsecured PHI.
To exercise any of these rights, contact us using the information in Section 13. We will respond in accordance with HIPAA’s timeframes.
8.3 Complaints
If you believe your privacy rights have been violated, you may file a complaint with us using the contact information below, or with the U.S. Department of Health and Human Services, Office for Civil Rights, at https://www.hhs.gov/ocr/privacy/hipaa/complaints/index.html. You will not be penalized for filing a complaint.
9. State Privacy Law Rights
Some states, including Maryland (Maryland Online Data Privacy Act) and Virginia (Consumer Data Protection Act), have enacted comprehensive consumer privacy laws. These laws generally apply to businesses that process personal data at a scale well beyond our current operations, and PHI governed by HIPAA is generally exempt from their requirements. As a matter of practice, and regardless of whether a specific law applies to us, we will honor reasonable requests from you to:
- confirm what personal information we hold about you;
- correct inaccurate information; and
- request deletion of information we are not otherwise required to retain (clinical records subject to HIPAA and state recordkeeping requirements cannot be deleted on request).
We do not sell personal information and do not use it for cross-context behavioral advertising. To make a request, contact us using the information in Section 13. We will re-evaluate and update this section as our operations grow or as new state laws take effect in the states where we operate.
10. Data Retention
We retain clinical records for the period required by the licensing and recordkeeping rules of the state in which services were provided. Based on a review of the record-retention requirements of Maryland, Virginia, the District of Columbia, North Carolina, and Ohio, we apply the longest standard across those states as our uniform policy: we retain adult client records for a minimum of seven (7) years from the date of last service, and records created while a client was a minor until the later of the client’s 25th birthday or ten (10) years after the termination of services. Business and billing records are retained as needed to meet tax, insurance, and audit obligations. When information is no longer needed, we securely delete or destroy it in accordance with our data retention procedures.
11. Children’s Privacy
Our clinical Services are intended for adults. We do not knowingly collect personal information from children under 13 through our website in a manner inconsistent with the Children’s Online Privacy Protection Act (COPPA). If you believe a child has provided us with personal information without appropriate parental or guardian consent, please contact us so we can address it. This section does not apply to information about minors collected in the course of supervised visitation services described in Section 6, which is collected for the purpose of carrying out court-ordered visitation rather than as a service directed to children.
12. Security
We use administrative, technical, and physical safeguards designed to protect your information, including encrypted data transmission and access controls within our EHR and billing systems. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your unsecured PHI, we will notify you as required by HIPAA and applicable state law.
13. Contact Information
If you have questions about this Privacy Policy or wish to exercise any of the rights described above, please contact us at:
Baiden & Associates PLLC
8609 Second Ave, Suite 404B
Silver Spring, MD 20910
Phone: 301-244-9126
Email: info@baidenassociates.org
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The “Last Updated” date at the top of this page reflects the most recent revision. Material changes will be posted on this page, and where appropriate, we will notify you by email.