Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Policy development · Clinical care providers

Privacy & Security Policy Development for Mental Health & Counselling Practices

This service drafts the actual policies a counselling practice needs on file: the PHIPA information-practices statement clients receive, a retention schedule for process notes and test protocols, and, increasingly, a social-media and advertising policy that closes the pixel-tracking gap the BetterHelp case exposed. Most practices reach out once a college inspection, an insurer questionnaire, or a new telepractice offering shows the current policy, if one exists, was never written for what the practice actually does now.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What the policy set has to actually govern

Generic templates fail this niche because they never address the specific decisions a therapy practice makes every week.

Consent to electronic and telepractice services

Language explaining what virtual sessions involve, how records are stored electronically, and what a client is agreeing to before their first video appointment.

Retention and destruction of clinical records

Clear rules for what happens to a chart once treatment ends: the retention period for process notes and psychological test material, and the destruction method applied when that period expires.

Advertising and marketing data practices

A clear statement of whether the website uses tracking pixels, what a directory listing shares, and how any email newsletter tool handles client or prospect contact information.

Supervision, students and associates

Policy language covering what a clinical supervisor or student can access, and how that differs from a colleague's general practice access.

Regulatory map

What the policies need to demonstrate compliance with

Each document maps to a specific requirement, which is why a template built for a different industry rarely holds up under review.

The PHIPA information-practices statement

Section 12(2) requires custodians to have a written statement describing information practices, available to clients on request, that actually reflects how the practice handles records rather than a boilerplate summary of the law.

Primary source →

CRPO's Electronic Practice standard

Standard 3.4 conditions electronic service delivery on informed consent obtained up front, and separately requires that treatment-related emails and texts get filed into the clinical record itself, a detail most generic templates omit entirely.

Primary source →

The College's clinical record expectations

Record retention and destruction practices need to align with what the College expects for clinical, appointment and financial records, which the policy translates into a workable schedule.

Primary source →

PIPEDA's purpose and consent limits

Using intake or contact data collected for care in a marketing tool without appropriate consent runs against PIPEDA's purpose limitation, which is exactly the mechanism the FTC used against BetterHelp under its own law.

Read our guide →

What goes wrong

What a missing or generic policy set exposes

Policy gaps in this niche surface at the worst possible moment: in front of a client, a college reviewer, or a regulator.

  • Ad-tech sharing without a policy catching it

    BetterHelp was fined for sending intake answers and identifiers to advertising platforms, a practice that a documented advertising and marketing policy would have flagged and prevented before it started.

    Source →

  • A telepractice consent that never existed

    Practices that expanded to video sessions quickly, without updating consent language, cannot show clients agreed to electronic delivery specifically, a gap a college inspection or complaint will surface.

  • No retention schedule for test protocols

    Licensed psychological testing materials and scored results kept indefinitely, or destroyed inconsistently, create both a records liability and a possible licensing issue with the test publisher.

  • Email and text sitting outside the record

    Treatment-related messages that never get filed into the clinical chart, contrary to CRPO's Electronic Practice standard, leave an incomplete record if it is ever requested or reviewed.

Our policy development for mental health & counselling practices

What the policy development engagement delivers

Every document is written to reflect how your specific practice actually operates, not a set of blanks filled in on a purchased template.

Modern and luxury office
  1. A PHIPA information-practices statement

    The written statement clients can request, describing what records are collected, how they are used, who can access them, and how a client can make an access or correction request.

  2. A clinical record retention and destruction policy

    Specific timelines for process notes, test protocols, appointment records and financial data, with a secure destruction method appropriate to each format.

  3. A telepractice and electronic-consent policy

    Consent language and internal procedures satisfying CRPO 3.4, including how treatment-related email and text get filed into the clinical record.

  4. An advertising and social-media policy

    Rules for what the website, directory listing and any marketing tools may collect and share, written specifically to close the gap the BetterHelp case exposed.

  5. Associate, supervisor and student access policy

    Documented boundaries for who can view what in a supervisee's or associate's charts, tied to the practice's actual reporting structure.

How the engagement runs

How we develop the policy set with your practice

  1. Step 1

    Review current practices

    We look at how records are actually created, stored and shared today, including any consent language already in use, before drafting anything.

  2. Step 2

    Draft against the specific requirements

    Each policy is written to satisfy PHIPA and CRPO's standards for your practice's structure, whether solo, group or virtual-first.

  3. Step 3

    Review with your team

    Draft policies are reviewed with the practice owner and, where relevant, associates and administrative staff, so the language matches how the practice actually runs.

  4. Step 4

    Finalize and plan for updates

    Completed policies are finalized with a plan for periodic review as CRPO standards, PHIPA and the practice's own services evolve.

What it costs

What affects policy development pricing here

Cost is driven mainly by how many policies are needed, whether the practice serves clients in Quebec alongside Ontario, and how much existing documentation can be built on versus started from nothing. A solo practitioner updating a consent form is a smaller project than a multi-province group building a full policy set from scratch.

For a practice that wants its documents kept current without re-engaging each time something changes, policy development sits inside the Virtual Privacy Officer retainer as a standing service. Tell us which policies you need and we will quote the work.

Mental Health & Counselling Practices: Policy development questions, answered

It needs to describe, in plain language, that services may be delivered electronically, how session data and recordings are stored, which platform is used, and how a client can ask questions or raise concerns about that arrangement. This sits alongside, but does not replace, the specific electronic-practice consent CRPO's Standard 3.4 requires before an individual client's first virtual session.

A defensible policy sets a specific retention period tied to professional and legal requirements, generally longer for minors and for records with duty-to-warn or risk documentation, states the format records are kept in, and describes a secure destruction method once the period ends. Test protocols may carry additional publisher licensing restrictions on retention and reproduction that need to be reflected alongside the clinical record rules.

It should state plainly whether the practice website uses tracking pixels or similar technology, what data any such tool can capture, and commit to not sharing intake, appointment or contact information with advertising platforms. If a directory listing or email marketing tool is used, the policy should name it and describe what information it receives, since the BetterHelp case turned specifically on data recipients clients never expected.

It is worth addressing directly rather than assuming your general consent form covers it, because a joint file raises access questions a single-client policy does not anticipate. The policy should explain how information from one partner is or is not shared with the other, and how an access request from one party to a shared file will be handled.

Review them at least annually, and immediately after any change to telepractice offerings, marketing tools, or the platforms holding client records, since a policy describing last year's practices will not protect the practice if reviewed against what it actually does today. CRPO's standards and provincial statutes also evolve, which is a second reason to revisit the documents on a set schedule rather than only when a problem forces it.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.