Legal

TheraTax Privacy Policy

Platform: TheraTax  |  Domains: TheraTax.ai, JoinTheraTax.com, TheraTaxPro.com and all redirecting domains

Notice: This Privacy Policy is effective as of October 1, 2026, and was last updated in October 2026. Please read this document carefully. By accessing or using the TheraTax platform, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy.

1. Introduction & Scope

TheraTax LLC ("TheraTax," "we," "us," or "our") is committed to protecting the privacy, security, and confidentiality of all information entrusted to us by the individuals and professionals who use our platform. This Privacy Policy describes how TheraTax collects, uses, stores, discloses, and protects personal information, Protected Health Information (PHI), and financial data in connection with the operation of our services.

1.1 Covered Domains

This Privacy Policy applies to TheraTax and all websites, platforms, applications, and services owned or operated by TheraTax, including but not limited to TheraTax.ai, JoinTheraTax.com and TheraTaxPro.com, as well as any other domains that redirect to or are operated in connection with those primary domains (collectively, the "Platform"). All references to the "Platform" in this document encompass the full scope of TheraTax's digital presence described herein.

1.2 Nature of Services

TheraTax is a specialized professional services platform designed to serve licensed mental health professionals, including licensed therapists, counselors, psychologists, licensed clinical social workers, and other licensed behavioral health practitioners (collectively, "Professional Users"). TheraTax provides such professionals with access to tax preparation, tax planning, financial analysis, advisory services, and related financial management tools tailored to the unique needs of healthcare professionals in private and group practice settings.

1.3 HIPAA Status

Depending on the nature of the services provided and the data processed in a given context, TheraTax may function as a Covered Entity and/or as a Business Associate as those terms are defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations at 45 CFR Parts 160 and 164. TheraTax is committed to fulfilling all applicable obligations under HIPAA and the Health Information Technology for Economic and Clinical Health (HITECH) Act, Pub. L. 111-5, in whatever capacity it operates relative to a given covered entity or business associate relationship.

1.4 Who Is Covered

This Privacy Policy governs all individuals who interact with the Platform in any capacity, including: (a) visitors who browse the Platform without registering; (b) registered Professional Users who hold active accounts on the Platform; (c) administrative personnel or authorized representatives of Professional Users; and (d) any individuals whose information may be transmitted to TheraTax by a covered entity or business associate in connection with the delivery of services. All such individuals are referred to herein as "users" unless otherwise specified.

1.5 Acceptance

Your use of the Platform constitutes your agreement to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, you must discontinue use of the Platform immediately. Professional Users who enter into a Business Associate Agreement (BAA) with TheraTax are additionally bound by the terms of that agreement, which shall govern in the event of any conflict with this Privacy Policy with respect to the handling of PHI.

2. Information We Collect

TheraTax collects information necessary to provide its services, maintain platform security, comply with applicable law, and continually improve the user experience. The categories of information we collect are described below.

(a) Information You Provide Directly

TheraTax collects information that users actively and voluntarily provide when registering for, accessing, or using the Platform. This includes:

  • Account Registration Data: Full legal name, business name, professional email address, phone number, mailing address, and professional license number(s), including the issuing state and license type.
  • Payment and Billing Information: Credit card or bank account information, billing address, and transaction history necessary to process payments for TheraTax services. Payment data is processed in a manner consistent with applicable security standards.
  • Communications: Records of any correspondence, inquiries, support requests, or other communications you submit to TheraTax through the Platform, by email, or through other channels.
  • Uploaded Documents: Any documents, files, records, or other materials you upload to the Platform in connection with your use of TheraTax's services, including but not limited to financial statements, tax records, practice records, and related materials.

(b) Protected Health Information (PHI)

In the course of providing services to licensed healthcare professionals who operate as covered entities under HIPAA, TheraTax may receive, access, transmit, or otherwise process Protected Health Information (PHI). Under HIPAA (45 CFR § 160.103), PHI is defined as individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate in any form or medium, including electronic, paper, or oral, and that relates to: (i) the past, present, or future physical or mental health or condition of an individual; (ii) the provision of healthcare to an individual; or (iii) the past, present, or future payment for the provision of healthcare to an individual, where such information identifies or reasonably could be used to identify the individual.

TheraTax receives PHI only when a covered entity or another business associate transmits such information to TheraTax for the specific, limited purposes necessary to deliver the contracted services. TheraTax does not collect PHI independently or for its own business purposes beyond those expressly authorized under HIPAA and the applicable Business Associate Agreement. All PHI received by TheraTax is handled in strict accordance with Section 4 of this Privacy Policy and TheraTax's HIPAA compliance program.

(c) Tax and Financial Information

TheraTax collects and processes sensitive tax and financial data as necessary to provide its core tax preparation, planning, and advisory services. This includes, without limitation:

  • Federal and state income information, including wages, self-employment income, practice revenue, and investment income;
  • Business and personal expense data, deductions, credits, and depreciation schedules;
  • Employer Identification Numbers (EINs), Social Security Numbers (SSNs), and Individual Taxpayer Identification Numbers (ITINs);
  • Prior-year federal and state tax returns, tax transcripts, and notices from taxing authorities;
  • IRS Forms W-2, 1099 (all variants), Schedule C, Schedule E, Schedule F, K-1, and related supporting schedules and attachments;
  • Bank and financial account information provided for purposes of direct deposit, estimated tax payments, or financial analysis;
  • Retirement account contributions, health savings account (HSA) data, and other tax-advantaged account information.

(d) Automatically Collected Data

When you visit or interact with the Platform, TheraTax and its infrastructure providers may automatically collect certain technical and usage data through standard web server and application logging technologies. This information includes:

  • Internet Protocol (IP) address and approximate geographic location derived from IP address;
  • Browser type and version, operating system, and device type;
  • Unique device identifiers and hardware model information;
  • Session duration, pages visited, features accessed, and interaction patterns within the Platform;
  • Referring URLs and exit pages;
  • Platform performance and error logs.

(e) Cookies and Tracking Technologies

TheraTax uses cookies and similar technologies to operate and improve the Platform. Cookies are small text files stored on your device by your web browser at the direction of the Platform. TheraTax uses the following categories of cookies:

  • Session Cookies: Temporary cookies that expire when your browser session ends. These are used for authentication and to maintain your active session state on the Platform.
  • Persistent Cookies: Cookies that remain on your device for a defined period beyond the browser session. These are used to remember user preferences and facilitate a more efficient user experience upon return visits.
  • Functional Cookies: Cookies that enable specific Platform features and functionality, such as language preferences, display settings, and form auto-fill features necessary for service delivery.
  • Analytics Cookies: Cookies that collect aggregate, non-identifying usage data about how users interact with the Platform. This data is used solely for the purpose of understanding Platform usage trends and improving service quality. Analytics cookies do not track individual user behavior across third-party websites.

3. How We Use Your Information

TheraTax uses the information it collects only for lawful and specified purposes consistent with this Privacy Policy, applicable law, and, where applicable, the terms of a Business Associate Agreement. The specific purposes for which TheraTax uses collected information are as follows:

  • Service Delivery and Account Management: To create and maintain user accounts, authenticate users, process transactions, provide access to Platform features, respond to support requests, and fulfill the contracted services for which users have enrolled.
  • Tax Preparation, Financial Analysis, and Reporting: To prepare, review, analyze, file, or advise on federal and state tax returns, financial statements, estimated tax schedules, and related deliverables on behalf of Professional Users and their practices.
  • HIPAA-Compliant Processing of PHI: To receive, use, and disclose PHI to the minimum extent necessary when acting as a Business Associate in support of a covered entity's treatment, payment, or healthcare operations, as those terms are defined under HIPAA (45 CFR § 164.501).
  • Platform Security, Fraud Prevention, and Abuse Detection: To monitor for unauthorized access, detect and investigate suspicious activity, enforce Platform terms, and maintain the integrity and security of the Platform and its data.
  • Communications: To send transactional communications (such as account confirmations, receipts, and service notifications), compliance notices required by law or regulation, and platform updates or feature announcements. TheraTax does not use personal information for unsolicited marketing communications unrelated to the services for which a user has enrolled.
  • Legal Compliance: To comply with applicable U.S. federal and state laws and regulations, respond to valid legal process, satisfy regulatory obligations, and enforce TheraTax's legal rights and remedies.
  • Platform Improvement: To analyze aggregate, de-identified usage data for the purpose of improving Platform functionality, performance, user experience, and service offerings. TheraTax does not use individually identifiable information for this purpose without appropriate authorization.
⚠ Important Notice Regarding Data Sales
TheraTax does not sell, rent, trade, or otherwise transfer for valuable consideration any personal information, PHI, or tax and financial data to any third party for such third party's own commercial purposes. This prohibition is absolute and applies regardless of the form of compensation offered.

4. Protected Health Information (PHI) – HIPAA Compliance

4.1 Definition of PHI

As defined at 45 CFR § 160.103, Protected Health Information (PHI) means individually identifiable health information, including demographic information collected from an individual, that is: (a) created or received by a healthcare provider, health plan, employer, or healthcare clearinghouse; (b) relates to the past, present, or future physical or mental health or condition of an individual, the provision of healthcare to an individual, or the past, present, or future payment for the provision of healthcare to an individual; and (c) identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual. PHI includes, but is not limited to, information transmitted or maintained in electronic form (ePHI).

4.2 Governing Regulations

TheraTax handles PHI only as permitted and required under HIPAA and its implementing regulations, including the Privacy Rule (45 CFR Part 164, Subpart E) and the Security Rule (45 CFR Part 164, Subpart C), as amended by the HITECH Act, Pub. L. 111-5, and any applicable rules promulgated by the U.S. Department of Health & Human Services (HHS). TheraTax's policies, procedures, and practices are designed to achieve and maintain full compliance with these requirements.

4.3 Minimum Necessary Standard

In all uses and disclosures of PHI, TheraTax applies the minimum necessary standard as required by 45 CFR § 164.502(b). TheraTax makes reasonable efforts to limit PHI access to those members of its workforce whose roles require such access to fulfill the contracted services, and to limit the amount of PHI used, disclosed, or requested to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request.

4.4 Business Associate Agreements

When TheraTax acts as a Business Associate to a Covered Entity, TheraTax enters into a written Business Associate Agreement (BAA) with that Covered Entity, as required by 45 CFR § 164.308(b) and 45 CFR § 164.502(e). The BAA establishes the permitted and required uses and disclosures of PHI by TheraTax, including TheraTax's obligations with respect to safeguarding PHI, reporting impermissible uses or disclosures, and assisting the Covered Entity in fulfilling individual rights requests. No PHI shall be transmitted to TheraTax by a Covered Entity in the absence of a valid, executed BAA.

4.5 Permitted Uses and Disclosures of PHI

TheraTax uses and discloses PHI only as expressly permitted or required by HIPAA and the applicable BAA. Permitted uses and disclosures include:

  • Treatment: To facilitate or support the provision of healthcare to an individual by a healthcare provider, consistent with the definition at 45 CFR § 164.501.
  • Payment: To support the activities of a covered entity to obtain or provide reimbursement for the provision of healthcare, including billing, claims management, and utilization review.
  • Healthcare Operations: To support the covered entity's legitimate healthcare operations activities as defined at 45 CFR § 164.501, including quality assessment, administrative activities, and legal and compliance functions.
  • As required by law, including in response to valid court orders, subpoenas, or government directives, subject to applicable HIPAA safeguards;
  • As otherwise expressly authorized by the covered entity or the individual to whom the PHI pertains, in accordance with HIPAA authorization requirements at 45 CFR § 164.508.

4.6 De-Identification

TheraTax may de-identify PHI in accordance with the standards set forth at 45 CFR § 164.514(a)–(c). De-identification may be accomplished through either: (a) the Expert Determination Method, whereby a qualified statistical or scientific expert applies generally accepted principles to certify that the risk of identifying the individual is very small; or (b) the Safe Harbor Method, whereby eighteen (18) specific categories of direct and quasi-identifiers are removed and TheraTax has no actual knowledge that the remaining information could be used alone or in combination to identify an individual. Information that has been de-identified in accordance with 45 CFR § 164.514 is no longer PHI and is not subject to the HIPAA Privacy Rule.

4.7 Breach Notification

In the event of a breach of unsecured PHI, TheraTax will fulfill its breach notification obligations in accordance with the HITECH Act and 45 CFR §§ 164.400–164.414. A "breach" is defined as the acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Privacy Rule that compromises the security or privacy of the PHI. TheraTax will:

  • Notify the affected Covered Entity without unreasonable delay and in no case later than sixty (60) calendar days after discovery of the breach;
  • Provide the Covered Entity with all information required under 45 CFR § 164.410 to enable the Covered Entity to fulfill its individual notification obligations;
  • Where TheraTax is acting as a Covered Entity, provide notification to affected individuals, the Secretary of HHS, and, where applicable, prominent media outlets, within the timeframes required under 45 CFR §§ 164.404–164.408;
  • Document all breaches and the risk assessments conducted to determine whether notification was required, in accordance with HIPAA documentation requirements.

5. IRS Tax Data Handling

5.1 Scope of Tax Data

In the course of providing tax preparation, planning, and advisory services, TheraTax handles highly sensitive IRS tax data on behalf of Professional Users. Such data includes, without limitation, federal and state income tax returns (all forms), tax transcripts obtained from the IRS or state tax agencies, IRS Forms W-2, 1099-NEC, 1099-MISC, 1099-K, 1099-INT, 1099-DIV, Schedule C, Schedule E, Schedule F, Schedule SE, Form 1040 and all associated schedules and attachments, Schedule K-1, Social Security Numbers (SSNs), Individual Taxpayer Identification Numbers (ITINs), Employer Identification Numbers (EINs), and any other records related to the federal or state tax obligations of the user or their practice.

5.2 Exclusive Use for Tax Services

Tax data collected or received through the Platform is used exclusively to provide the tax preparation, planning, filing, and advisory services for which the user has contracted with TheraTax. Tax data is never used for advertising, cross-selling unrelated products, or any purpose outside the direct scope of the engaged tax and financial services.

5.3 IRS Security Standards

TheraTax complies with IRS Publication 4600 (Safeguarding Federal Tax Returns — A Guide for Return Preparers) and all other applicable IRS data security standards and Publication 1345 requirements for authorized IRS e-file providers. TheraTax maintains a written data security plan consistent with the IRS's data security requirements for tax return preparers and takes reasonable and appropriate technical, administrative, and physical measures to protect tax data from unauthorized access, use, disclosure, alteration, or destruction.

5.4 Encryption

Tax data stored within the TheraTax Platform is protected using industry-standard encryption at rest. Tax data transmitted to or from the Platform is protected using industry-standard encryption in transit (TLS/SSL or equivalent). These measures are designed to render tax data unreadable to unauthorized parties both during storage and during transmission.

5.5 No Unauthorized Sharing

TheraTax does not share tax data with any individual, entity, or government authority except: (a) as expressly authorized by the user in writing; (b) as required by applicable law or valid legal process; or (c) as necessary to complete the tax filing or advisory services for which the user has enrolled (e.g., electronic submission to the IRS or applicable state tax authority on the user's behalf, pursuant to a signed authorization). Written authorization from the account holder is required before TheraTax may disclose any tax records to any third party not encompassed within (b) or (c) above.

5.6 Retention of Tax Records

TheraTax retains tax records for a minimum of seven (7) years from the date of filing or the date the return was due, whichever is later, consistent with general IRS guidance on the statute of limitations for tax assessments (26 U.S.C. § 6501). Records pertaining to employment taxes, substantial understatements, or fraudulent returns may be retained for longer periods as required by applicable IRS guidance and law. Upon expiration of the applicable retention period, tax records will be securely destroyed or de-identified in accordance with TheraTax's data destruction policies.

6. Cookies and Tracking Technologies

6.1 Overview

Cookies are small data files placed on your device by websites you visit. TheraTax uses cookies and similar client-side storage technologies to provide essential Platform functionality, maintain session security, remember user preferences, and collect aggregate usage data to improve the Platform. TheraTax's use of cookies is limited to the categories described in this Section and does not extend to behavioral advertising, cross-site tracking, or the collection of personally identifiable information for purposes unrelated to Platform operation.

6.2 Types of Cookies Used

  • Session Cookies: These cookies are temporary files created when you log into the Platform and are automatically deleted when you close your browser or log out. Session cookies are strictly necessary for authentication and to maintain the integrity and continuity of your active user session.
  • Persistent Cookies: These cookies remain on your device for a defined period of time following the end of your browser session, unless you delete them manually through your browser settings. TheraTax uses persistent cookies to remember user preferences, facilitate faster login, and streamline the user experience on return visits.
  • Functional Cookies: These cookies enable specific Platform features and are necessary for the proper operation of core Platform functionality. Functional cookies may store user interface preferences such as display settings, language selection, and navigation state.
  • Analytics Cookies: TheraTax uses analytics cookies to collect aggregate, non-identifying information about how users interact with the Platform. This data is used solely to understand overall Platform usage trends and to inform decisions about Platform improvement.

6.3 What TheraTax Does Not Do

TheraTax does not use tracking pixels, web beacons, fingerprinting technologies, behavioral advertising cookies, retargeting cookies, or any technology designed to track individual user behavior across third-party websites or to build individual advertising profiles. No cookie data collected through the Platform is sold, rented, or shared with advertising networks, data brokers, or any third party for commercial advertising purposes.

6.4 User Control of Cookies

Users may control the placement and retention of cookies through their web browser settings. Most modern browsers allow users to view, delete, block, or restrict cookies on a site-by-site or global basis. Instructions for managing cookies are typically available through the "Settings," "Privacy," or "Help" section of your browser. Please note that disabling session or functional cookies may limit your ability to access or use certain features of the Platform, including secure authentication and account management functions. TheraTax is not responsible for any loss of Platform functionality resulting from a user's election to disable necessary cookies.

6.5 No Sale of Cookie Data

Cookie data collected through the Platform is used exclusively for the purposes described in this Section. TheraTax does not sell, share, or otherwise transfer cookie data to any advertising network, data broker, or other third party for commercial purposes under any circumstances.

7. Data Sharing and Disclosures

7.1 No Sale of Personal Information or PHI

TheraTax does not sell, rent, trade, license, or otherwise transfer for monetary or other valuable consideration any personal information, PHI, or tax and financial data to any third party. This prohibition is unconditional and applies to all categories of data collected through the Platform.

7.2 Permitted Disclosures

TheraTax may share user data only under the following limited circumstances:

  • (a) Service Providers Acting Under Contractual Data Protection Obligations: TheraTax engages certain third-party service providers to perform functions necessary to support the operation of the Platform, such as data hosting, infrastructure management, payment processing, and technical support. All such service providers are bound by written contractual agreements that prohibit them from using TheraTax data for any purpose other than performing services on TheraTax's behalf, require them to maintain data security standards at least as protective as those described in this Privacy Policy, and require them to return or securely destroy data upon termination of the service relationship. Where PHI is involved, service providers are required to execute Business Associate Agreements with TheraTax as required by HIPAA.
  • (b) Professional Users (Licensed Providers and Account Holders): TheraTax may share data with the licensed professional who is the registered account holder to the extent necessary to deliver the contracted services. TheraTax does not share one Professional User's data with another Professional User's account without express authorization from the originating account holder.
  • (c) Legal and Regulatory Authorities: TheraTax may disclose personal information, including PHI where legally compelled, to government agencies, law enforcement authorities, courts, or other regulatory bodies when required to do so by valid legal process, including subpoenas, court orders, administrative orders, or other binding legal directives. Where legally permitted to do so, TheraTax will notify the affected user of such a request prior to disclosure. TheraTax may also disclose information when it has a good-faith belief that disclosure is necessary to prevent imminent harm to persons or property or to protect the legal rights of TheraTax.
  • (d) Successors in Interest: In the event of a merger, acquisition, reorganization, sale of substantially all assets, or other corporate transaction involving TheraTax, personal information and data maintained by TheraTax may be transferred to the successor entity. Any such successor will be required to honor the terms of this Privacy Policy and any applicable BAAs with respect to all transferred data. TheraTax will provide notice to registered users of any such transfer and any material changes to data handling practices that result from the transaction.

7.3 Prohibition on Third-Party Data Use

All third-party processors and service providers engaged by TheraTax are expressly prohibited, by contract, from using data received from TheraTax for their own independent business purposes, including but not limited to advertising, product development, or data aggregation for sale to other parties.

7.4 Disclosures Required by Law

TheraTax will comply with valid and binding legal process, including subpoenas, court orders, civil investigative demands, and government requests, when it determines in good faith that compliance is legally required. TheraTax will make reasonable efforts to notify affected users of such requests when notification is legally permissible and when providing notice would not undermine the purpose of the disclosure. TheraTax reserves the right to challenge legal process that it believes to be overly broad, improper, or inconsistent with applicable law.

8. Your Rights Under HIPAA and U.S. Law

Individuals whose PHI is maintained by TheraTax in connection with TheraTax's function as a Covered Entity, or whose rights are passed through from a covered entity for which TheraTax serves as a Business Associate, have the following rights under 45 CFR Part 164, Subpart E (the HIPAA Privacy Rule). To exercise any of the rights described below, individuals should submit a written request to TheraTax's Privacy Officer using the contact information provided in Section 14 of this Privacy Policy.

(a) Right to Access PHI — 45 CFR § 164.524

Individuals have the right to inspect and obtain a copy of their PHI maintained in a designated record set, as defined at 45 CFR § 164.501. TheraTax will respond to written requests for PHI access within thirty (30) days of receipt, or within sixty (60) days if an extension is necessary, in which case TheraTax will provide written notice of the extension and the reason for the delay. TheraTax may charge a reasonable, cost-based fee for producing copies of PHI in the format requested. TheraTax may deny access in limited circumstances as permitted by 45 CFR § 164.524(a)(2) and (a)(3), and will provide a written denial with notice of appeal rights where a denial is issued.

(b) Right to Amend PHI — 45 CFR § 164.526

Individuals have the right to request that TheraTax amend PHI or a record about the individual in a designated record set for as long as TheraTax maintains such information. TheraTax will act on a written amendment request within sixty (60) days of receipt, or within an extension period not to exceed an additional thirty (30) days. TheraTax may deny an amendment request if the PHI was not created by TheraTax, is not part of a designated record set, or is accurate and complete. A written denial will include the basis for denial, a statement of the individual's right to submit a written statement of disagreement, and TheraTax's right to submit a rebuttal.

(c) Right to an Accounting of Disclosures — 45 CFR § 164.528

Individuals have the right to receive an accounting of certain disclosures of their PHI made by TheraTax during the six (6) years prior to the date of the request (or a shorter period if requested). This right does not apply to disclosures for treatment, payment, or healthcare operations; disclosures made to the individual; disclosures authorized by the individual; or disclosures otherwise excluded from the accounting requirement under 45 CFR § 164.528(a)(1). TheraTax will provide the accounting within sixty (60) days of a written request, subject to one permissible extension of thirty (30) days with written notice. The first accounting in any twelve (12)-month period shall be provided at no charge; a reasonable fee may be charged for subsequent requests within the same period.

(d) Right to Request Restrictions — 45 CFR § 164.522(a)

Individuals have the right to request that TheraTax restrict the use or disclosure of their PHI for treatment, payment, or healthcare operations, or disclosures to persons involved in the individual's care. TheraTax is not required to agree to a requested restriction, except as required by 45 CFR § 164.522(a)(1)(vi) (restriction on disclosure to a health plan for a service paid for out of pocket in full). If TheraTax agrees to a restriction, it will comply with the restriction except where the information is needed to provide emergency treatment. Any agreement to a restriction must be in writing to be binding on TheraTax.

(e) Right to Confidential Communications — 45 CFR § 164.522(b)

Individuals have the right to request that TheraTax communicate their PHI by alternative means or to an alternative location. TheraTax will accommodate reasonable requests for confidential communications without requiring a reason for the request, provided that the request specifies the alternative means or location for communication and the request is workable within TheraTax's operational framework. Requests should be submitted in writing to TheraTax's Privacy Officer.

(f) Right to Receive a Notice of Privacy Practices

TheraTax will provide its Notice of Privacy Practices to any individual upon request. The Notice of Privacy Practices describes TheraTax's legal duties and privacy practices with respect to PHI and will be made available in a clear and accessible format. Individuals may request a paper copy of the Notice of Privacy Practices by contacting TheraTax's Privacy Officer using the information in Section 14.

(g) Right to File a Complaint

Individuals who believe their HIPAA privacy rights have been violated have the right to file a complaint with TheraTax's Privacy Officer or directly with the U.S. Department of Health & Human Services, Office for Civil Rights (OCR). Complaints to TheraTax must be submitted in writing to the Privacy Officer at the contact information provided in Section 14. TheraTax will not retaliate against any individual for filing a complaint in good faith. Complaints to HHS OCR may be submitted online at www.hhs.gov/ocr/privacy.

9. Security Safeguards

9.1 HIPAA Security Rule Compliance

TheraTax implements administrative, physical, and technical safeguards in accordance with the HIPAA Security Rule (45 CFR Part 164, Subpart C) to protect the confidentiality, integrity, and availability of electronic PHI (ePHI) that TheraTax creates, receives, maintains, or transmits. TheraTax's security program is documented, regularly reviewed, and updated in response to identified risks.

9.2 Administrative Safeguards

TheraTax's administrative security measures include:

  • Workforce Training: All workforce members with access to PHI or sensitive user data receive HIPAA privacy and security training upon hire and on a regular, ongoing basis thereafter.
  • Access Management: TheraTax implements role-based access controls limiting workforce access to PHI and sensitive data to those whose job functions require such access, consistent with the minimum necessary standard.
  • Risk Analysis and Risk Management: TheraTax conducts documented risk analyses to identify potential vulnerabilities and implements risk management measures to reduce identified risks to reasonable and appropriate levels, in accordance with 45 CFR § 164.308(a)(1).
  • Contingency Planning: TheraTax maintains documented contingency plans, including data backup and disaster recovery procedures, to ensure the continued availability and integrity of ePHI and other critical data in the event of an emergency or system failure.
  • Sanction Policy: TheraTax applies appropriate sanctions against workforce members who fail to comply with TheraTax's privacy and security policies and procedures.

9.3 Physical Safeguards

TheraTax's physical security measures include:

  • Facility access controls limiting physical access to locations where ePHI is processed or stored to authorized personnel only;
  • Workstation use and security policies governing the proper use and positioning of workstations with access to ePHI;
  • Device and media controls governing the receipt, removal, and disposition of hardware and electronic media containing ePHI, including documented media disposal procedures.

9.4 Technical Safeguards

TheraTax's technical security measures include:

  • Access Controls: Unique user identification, automatic logoff, and encryption-based access controls to ensure that only authorized persons access ePHI and Platform systems.
  • Audit Controls: Logging and monitoring of hardware, software, and procedural activity on systems containing ePHI to detect and investigate inappropriate access or usage.
  • Integrity Controls: Mechanisms to authenticate ePHI and detect unauthorized alteration or destruction of data in transit and at rest.
  • Transmission Security: Encryption of ePHI during transmission over electronic communications networks using industry-standard protocols to guard against unauthorized interception.

9.5 Periodic Risk Assessments

TheraTax conducts periodic, comprehensive risk assessments of its information systems and security controls. The results of each assessment are documented and used to update TheraTax's security policies, procedures, and technical controls on an ongoing basis. Risk assessments are conducted at least annually and following any significant change to the Platform, its infrastructure, or TheraTax's operational environment.

9.6 Security Incidents and Breach Response

In the event of an actual or suspected security incident involving PHI, TheraTax will follow its documented incident response procedures and fulfill its breach notification obligations under the HITECH Act and 45 CFR §§ 164.400–164.414, as further described in Section 4.7 of this Privacy Policy.

⚠ User Responsibility
No security system is impenetrable or guaranteed to be free from breach. TheraTax strongly encourages all users to protect their account credentials by using strong, unique passwords, enabling all available authentication protections, and promptly reporting any suspected unauthorized access to their TheraTax account to TheraTax's Privacy Officer. Users bear responsibility for maintaining the confidentiality of their own login credentials.

10. Data Retention

10.1 General Retention Principle

TheraTax retains personal information and other data only for as long as is necessary to fulfill the purposes for which it was collected, to provide the contracted services, and to satisfy applicable legal, regulatory, and compliance obligations. Retention periods are determined by reference to applicable federal and state law, IRS guidance, HIPAA requirements, and the nature and sensitivity of the data in question.

10.2 PHI Retention

PHI is retained in accordance with the requirements of applicable HIPAA regulations, applicable state healthcare record retention laws, and the terms of any BAA in effect between TheraTax and the relevant covered entity. Retention periods for PHI may vary by state based on applicable licensing board regulations and medical records statutes. TheraTax will not retain PHI beyond the period required for the applicable services unless required to do so by law or regulation.

10.3 Tax Record Retention

Tax records and related financial information are retained for a minimum of seven (7) years from the date the applicable tax return was filed or the due date of the return (without regard to extensions), whichever is later, consistent with IRS guidance regarding the general statute of limitations for tax assessments under 26 U.S.C. § 6501. Records subject to longer retention requirements under applicable federal or state law will be retained for such longer period as required.

10.4 Account Termination

Upon termination or deactivation of a user account, TheraTax will retain data for the period necessary to fulfill applicable legal retention obligations. Following the expiration of all applicable retention periods, data will be securely deleted or de-identified using industry-accepted data destruction methods. TheraTax will not retain personal data beyond applicable retention periods solely for business convenience.

10.5 Aggregate Data

TheraTax may retain aggregate, de-identified data derived from user interactions for an indefinite period for purposes of platform analytics and improvement, provided that such data cannot reasonably be used to identify any individual user.

11. Children's Privacy

11.1 Platform Audience

TheraTax is a professional business-to-business (B2B) platform intended exclusively for use by licensed healthcare professionals, licensed financial professionals, and their authorized business representatives. The Platform is not designed for, marketed to, or directed at individuals under the age of eighteen (18), and TheraTax has no reasonable expectation that minors will access or use the Platform.

11.2 No Knowing Collection from Minors

TheraTax does not knowingly collect, maintain, or use personal information from any individual under the age of eighteen (18). By registering for or using the Platform, users represent and warrant that they are at least eighteen (18) years of age and, where applicable, hold a valid professional license authorizing their use of TheraTax's services.

11.3 Discovery and Deletion

If TheraTax becomes aware that it has inadvertently collected personal information from an individual under the age of eighteen (18) without the requisite verifiable parental consent required by applicable law, TheraTax will promptly take steps to delete such information from its records and to discontinue any further collection from such individual.

11.4 COPPA Compliance

To the extent that any portion of the Platform may be accessible to children under the age of thirteen (13), TheraTax complies with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq., and the implementing regulations promulgated by the Federal Trade Commission. Parents or legal guardians who believe that TheraTax may have collected personal information from a child under thirteen (13) are encouraged to contact TheraTax's Privacy Officer immediately using the contact information provided in Section 14 of this Privacy Policy.

12. U.S. Legal Disclosures

12.1 Governing Law

This Privacy Policy is governed exclusively by applicable U.S. federal law and the laws of the applicable U.S. state, as described in Section 12.4 below. TheraTax's privacy practices are designed to comply with, among others, the following applicable U.S. federal laws and regulations:

  • The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations at 45 CFR Parts 160 and 164;
  • The Health Information Technology for Economic and Clinical Health (HITECH) Act, Pub. L. 111-5, and its implementing regulations;
  • The Federal Trade Commission Act, 15 U.S.C. § 45, which prohibits unfair or deceptive acts or practices in or affecting commerce, including misrepresentations about data privacy practices;
  • The Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq., and the FTC's implementing regulations at 16 CFR Part 312;
  • Applicable IRS regulations and published guidance, including Treasury Regulation § 301.7216-1 et seq. governing the confidentiality of tax return information, IRS Publication 4600, and Publication 1345;
  • The Gramm-Leach-Bliley Act (GLBA), 15 U.S.C. § 6801 et seq., to the extent applicable to TheraTax's financial services activities.

12.2 State Law Compliance

TheraTax provides services to Professional Users located across multiple U.S. states. TheraTax is committed to complying with applicable state healthcare privacy laws, professional licensing and medical records statutes, state consumer protection laws, and applicable state data breach notification requirements. Where applicable state law imposes requirements more protective of individual privacy than federal law, TheraTax will apply the more protective standard.

12.3 U.S.-Only Services

TheraTax's services are directed exclusively to licensed professionals and users located within the United States. TheraTax does not direct its services to individuals or entities outside the United States. This Privacy Policy does not apply to non-U.S. residents, and TheraTax makes no representations regarding compliance with the privacy laws of any jurisdiction outside the United States.

12.4 Dispute Resolution and Governing Jurisdiction

Any dispute arising out of or relating to this Privacy Policy or TheraTax's privacy practices shall be governed by the laws of the State of [State – to be inserted], without regard to its conflict of law principles, and shall be subject to the exclusive jurisdiction of the federal and state courts located within that state. Nothing in this Section limits TheraTax's right to seek injunctive or other equitable relief in any court of competent jurisdiction.

13. Changes to This Policy

13.1 Right to Update

TheraTax reserves the right to modify, update, or revise this Privacy Policy at any time to reflect changes in applicable law, regulatory guidance, TheraTax's services, or TheraTax's data handling practices. The most current version of the Privacy Policy will always be available on the Platform, and the "Last Updated" date at the top of this document will reflect the date of the most recent revision.

13.2 Notice of Material Changes

TheraTax will provide advance notice of material changes to this Privacy Policy by one or more of the following means: (a) sending an email notice to the registered email address associated with your TheraTax account; or (b) posting a prominent notice on the Platform for a reasonable period prior to the effective date of the change. A change is "material" if it significantly alters the types of information TheraTax collects, the purposes for which it uses such information, the categories of parties with whom it shares information, or the rights available to users.

13.3 Acceptance of Changes

Continued access to or use of the Platform following the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms. If you do not agree with a revised Privacy Policy, you must discontinue use of the Platform and, if applicable, contact TheraTax to request account closure.

13.4 BAA Holders

For Professional Users who have executed a Business Associate Agreement with TheraTax, updates to this Privacy Policy do not modify the terms of the applicable BAA. Any conflicts between this Privacy Policy and a BAA regarding the handling of PHI shall be resolved in favor of the BAA.

14. Contact Information & Privacy Officer

14.1 Designated Privacy Officer

TheraTax has designated a Privacy Officer who is responsible for overseeing TheraTax's HIPAA compliance program, ensuring adherence to this Privacy Policy, responding to privacy-related inquiries and complaints, and coordinating TheraTax's response to privacy incidents and breach events. The Privacy Officer is the primary point of contact for all privacy-related matters involving the Platform.

14.2 Contact Information

To exercise your rights under this Privacy Policy or applicable law, to submit a privacy-related inquiry or complaint, to request a copy of TheraTax's Notice of Privacy Practices, to request execution of a Business Associate Agreement, or for any other privacy-related matter, please contact TheraTax's Privacy Officer using the information below:

Privacy OfficerTiffany Parker
Emailprivacy@theratax.ai
Mailing AddressTheraTax, 3300 Hamilton Mill Rd, Ste 102#730, Buford, GA 30519
PlatformTheraTax.ai | JoinTheraTax.com | TheraTaxPro.com

14.3 Response Timeframes

TheraTax will acknowledge receipt of written privacy inquiries and complaints within five (5) business days and will endeavor to provide a substantive response within thirty (30) days. For HIPAA-specific rights requests, response timeframes are as specified in Section 8 of this Privacy Policy or as otherwise required by applicable HIPAA regulations.

14.4 HHS Office for Civil Rights

Individuals who believe their HIPAA rights have been violated may also file a complaint directly with the U.S. Department of Health & Human Services, Office for Civil Rights (OCR), without first filing a complaint with TheraTax. OCR contact information is as follows:

U.S. Department of Health & Human Services — Office for Civil Rights (OCR)

Website: www.hhs.gov/ocr/privacy

Toll-Free: 1-800-368-1019

TDD: 1-800-537-7697

Mailing: 200 Independence Avenue, S.W., Washington, D.C. 20201

TheraTax expressly affirms that no individual will be subjected to retaliation, intimidation, coercion, discrimination, or any other adverse action for filing a complaint with TheraTax or with the U.S. Department of Health & Human Services, Office for Civil Rights.

General information on this website is not individualized tax, legal, or financial advice. Outcomes depend on your specific facts and eligibility.