Policy development · Clinical care providers
Privacy & Security Policy Development for Mental Health & Counselling Practices
This service drafts the actual policies a counselling practice needs on file: the PHIPA information-practices statement clients receive, a retention schedule for process notes and test protocols, and, increasingly, a social-media and advertising policy that closes the pixel-tracking gap the BetterHelp case exposed. Most practices reach out once a college inspection, an insurer questionnaire, or a new telepractice offering shows the current policy, if one exists, was never written for what the practice actually does now.
Reviewed by the Privacy Horizon team · Last reviewed
What you're protecting
What the policy set has to actually govern
Generic templates fail this niche because they never address the specific decisions a therapy practice makes every week.
Consent to electronic and telepractice services
Language explaining what virtual sessions involve, how records are stored electronically, and what a client is agreeing to before their first video appointment.
Retention and destruction of clinical records
Clear rules for what happens to a chart once treatment ends: the retention period for process notes and psychological test material, and the destruction method applied when that period expires.
Advertising and marketing data practices
A clear statement of whether the website uses tracking pixels, what a directory listing shares, and how any email newsletter tool handles client or prospect contact information.
Supervision, students and associates
Policy language covering what a clinical supervisor or student can access, and how that differs from a colleague's general practice access.
Regulatory map
What the policies need to demonstrate compliance with
Each document maps to a specific requirement, which is why a template built for a different industry rarely holds up under review.
The PHIPA information-practices statement
Section 12(2) requires custodians to have a written statement describing information practices, available to clients on request, that actually reflects how the practice handles records rather than a boilerplate summary of the law.
CRPO's Electronic Practice standard
Standard 3.4 conditions electronic service delivery on informed consent obtained up front, and separately requires that treatment-related emails and texts get filed into the clinical record itself, a detail most generic templates omit entirely.
The College's clinical record expectations
Record retention and destruction practices need to align with what the College expects for clinical, appointment and financial records, which the policy translates into a workable schedule.
PIPEDA's purpose and consent limits
Using intake or contact data collected for care in a marketing tool without appropriate consent runs against PIPEDA's purpose limitation, which is exactly the mechanism the FTC used against BetterHelp under its own law.
What goes wrong
What a missing or generic policy set exposes
Policy gaps in this niche surface at the worst possible moment: in front of a client, a college reviewer, or a regulator.
Ad-tech sharing without a policy catching it
BetterHelp was fined for sending intake answers and identifiers to advertising platforms, a practice that a documented advertising and marketing policy would have flagged and prevented before it started.
A telepractice consent that never existed
Practices that expanded to video sessions quickly, without updating consent language, cannot show clients agreed to electronic delivery specifically, a gap a college inspection or complaint will surface.
No retention schedule for test protocols
Licensed psychological testing materials and scored results kept indefinitely, or destroyed inconsistently, create both a records liability and a possible licensing issue with the test publisher.
Email and text sitting outside the record
Treatment-related messages that never get filed into the clinical chart, contrary to CRPO's Electronic Practice standard, leave an incomplete record if it is ever requested or reviewed.
Our policy development for mental health & counselling practices
What the policy development engagement delivers
Every document is written to reflect how your specific practice actually operates, not a set of blanks filled in on a purchased template.

A PHIPA information-practices statement
The written statement clients can request, describing what records are collected, how they are used, who can access them, and how a client can make an access or correction request.
A clinical record retention and destruction policy
Specific timelines for process notes, test protocols, appointment records and financial data, with a secure destruction method appropriate to each format.
A telepractice and electronic-consent policy
Consent language and internal procedures satisfying CRPO 3.4, including how treatment-related email and text get filed into the clinical record.
An advertising and social-media policy
Rules for what the website, directory listing and any marketing tools may collect and share, written specifically to close the gap the BetterHelp case exposed.
Associate, supervisor and student access policy
Documented boundaries for who can view what in a supervisee's or associate's charts, tied to the practice's actual reporting structure.
How the engagement runs
How we develop the policy set with your practice
Step 1
Review current practices
We look at how records are actually created, stored and shared today, including any consent language already in use, before drafting anything.
Step 2
Draft against the specific requirements
Each policy is written to satisfy PHIPA and CRPO's standards for your practice's structure, whether solo, group or virtual-first.
Step 3
Review with your team
Draft policies are reviewed with the practice owner and, where relevant, associates and administrative staff, so the language matches how the practice actually runs.
Step 4
Finalize and plan for updates
Completed policies are finalized with a plan for periodic review as CRPO standards, PHIPA and the practice's own services evolve.
What it costs
What affects policy development pricing here
Cost is driven mainly by how many policies are needed, whether the practice serves clients in Quebec alongside Ontario, and how much existing documentation can be built on versus started from nothing. A solo practitioner updating a consent form is a smaller project than a multi-province group building a full policy set from scratch.
For a practice that wants its documents kept current without re-engaging each time something changes, policy development sits inside the Virtual Privacy Officer retainer as a standing service. Tell us which policies you need and we will quote the work.
Mental Health & Counselling Practices: Policy development questions, answered
It needs to describe, in plain language, that services may be delivered electronically, how session data and recordings are stored, which platform is used, and how a client can ask questions or raise concerns about that arrangement. This sits alongside, but does not replace, the specific electronic-practice consent CRPO's Standard 3.4 requires before an individual client's first virtual session.
A defensible policy sets a specific retention period tied to professional and legal requirements, generally longer for minors and for records with duty-to-warn or risk documentation, states the format records are kept in, and describes a secure destruction method once the period ends. Test protocols may carry additional publisher licensing restrictions on retention and reproduction that need to be reflected alongside the clinical record rules.
It is worth addressing directly rather than assuming your general consent form covers it, because a joint file raises access questions a single-client policy does not anticipate. The policy should explain how information from one partner is or is not shared with the other, and how an access request from one party to a shared file will be handled.
Review them at least annually, and immediately after any change to telepractice offerings, marketing tools, or the platforms holding client records, since a policy describing last year's practices will not protect the practice if reviewed against what it actually does today. CRPO's standards and provincial statutes also evolve, which is a second reason to revisit the documents on a set schedule rather than only when a problem forces it.
More for mental health & counselling practices
Other services for this niche
About this service
What's Protecting Your Business from the Next Threat?
Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.