Notice of Privacy Practices
Effective: July 31, 2026
In short: if you are a parent, guardian, or client of a therapy practice that uses Theralyn, your practice is your direct care provider and is responsible for its own Notice of Privacy Practices. This document explains how Theralyn, as their software vendor, handles protected health information on their behalf.
1. Who This Notice Is For
Theralyn provides software to ABA, OT, and Speech therapy practices. Those practices — not Theralyn — are the HIPAA Covered Entities with a direct treatment relationship to the children and families they serve, and each practice is responsible for providing its own official Notice of Privacy Practices governing that relationship. This document instead describes how Theralyn, as the practice's technology vendor and HIPAA Business Associate, handles protected health information (PHI) on their behalf.
2. What Information This Covers
On behalf of invited early-access therapy practices, Theralyn stores a child's name, guardian contact details, therapy session notes and observations, therapy goals, and assessment results — collectively, protected health information (PHI).
3. How We Use and Disclose PHI
We use PHI only to provide the contracted service back to the therapy practice that entered it: hosting the platform, recording session documentation, scheduling, and generating reports. We do not use PHI for our own marketing or analytics, and do not sell PHI. We disclose PHI only to infrastructure subprocessors necessary to run the service (under appropriate agreements), as directed by the practice itself, or as required by law.
4. Parent & Guardian Report Access
Practices may share a session report with a parent or guardian via a time-limited link: it expires after 7 days, allows a maximum of 10 views, and can be revoked by the practice at any time. Report content shared this way is limited to the child's first name.
5. Security Safeguards
Our safeguards include encryption in transit and at rest, role-based access control, organization-level data isolation, and audit logging of account activity. We are actively building out the fuller set of technical, administrative, and physical safeguards required by HIPAA's Security Rule as our compliance program matures — see our Security & Compliance FAQ for current status. We do not claim any third-party security certification at this time.
6. Data Retention & Deletion
When a therapy practice deletes a child's record or offboards from Theralyn, the associated data is permanently removed — there is currently no separate retention period held after deletion. We are developing a more formal data retention policy; until it is published, treat deletion as immediate and permanent.
7. Your Rights Regarding PHI
If PHI about you or your child is stored in Theralyn on behalf of a therapy practice, that practice controls the record. To request access to, correction of, or deletion of that PHI, please contact your therapy practice directly — they are the Covered Entity responsible for fulfilling those rights, and Theralyn supports such requests when instructed by the practice.
8. Our Business Associate Status
Theralyn acts as a Business Associate under HIPAA to each therapy practice or organization using the platform to store PHI, governed by a Business Associate Agreement (BAA) with that organization. If your organization uses Theralyn to store PHI and does not yet have a signed BAA with us, contact hello@theralyn.co to request one.
9. Breach Notification
If we become aware of a breach involving PHI, we will notify the affected therapy practice(s) without unreasonable delay, consistent with HIPAA's Breach Notification Rule, so each practice can meet its own notification obligations to the individuals it serves.
10. Changes to This Notice
We will update this notice as Theralyn's product and compliance program continue to mature. Material changes will be communicated to organizations using the platform via their account administrators.
11. Questions or Complaints
Questions about this notice, or about how Theralyn handles PHI: hello@theralyn.co. If you believe your privacy rights have been violated, you also have the right to file a complaint with your therapy practice directly, or with the U.S. Department of Health and Human Services Office for Civil Rights.
See also our Privacy Policy and Terms of Service.
Questions? hello@theralyn.co