Blue Lotus Telepsychiatry Services, Inc.
PRIVACY NOTICE AND NOTICE OF PRIVACY PRACTICES
Effective Date: August 26, 2026
PRIVACY NOTICE AND NOTICE OF PRIVACY PRACTICES
Last Updated: August 26, 2026
This Privacy Notice and Notice of Privacy Practices ("Notice") describes how Blue Lotus Telepsychiatry Services Inc. ("Blue Lotus," "we," "us," or "our") collects, uses, maintains, protects, and discloses information about individuals who use our telepsychiatry and related healthcare services ("Services"), visit our website at https://bluelotustelepsych.com, communicate with us electronically or by telephone, or otherwise interact with our practice.
Blue Lotus is based in Ohio and provides telepsychiatry services to patients in states in which our healthcare professionals are appropriately licensed or otherwise authorized to practice, including Ohio, New York, Florida, and Washington.
Because we provide healthcare services, much of the information we maintain is protected health information ("PHI") under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and may also be protected by additional federal or state laws. This Notice is intended to describe our privacy practices and your rights regarding your information.
This Notice applies to information collected through our Services, including information provided during appointments, through our patient portal, by telephone, text message, email, our website, and other communications with our practice.
Important: This Notice is not a substitute for any authorization that may be required by law for a particular use or disclosure of your health information.
-
Depending on how you interact with us, we may collect the following categories of information.
Information You Provide
We may collect information you provide directly to us, including:
Name and preferred name
Date of birth
Contact information, including mailing address, telephone number, and email address
Emergency contact information
Insurance and billing information
Payment information
Identification and demographic information
Information about your healthcare providers
Medical, psychiatric, psychological, and behavioral health information
Medication history and treatment history
Diagnoses, symptoms, treatment plans, and clinical notes
Information regarding allergies, medical conditions, and medications
Information regarding mental health, substance use, and other health conditions when relevant to your care
Information you provide through questionnaires, assessments, forms, or patient portals
Information provided by a parent, guardian, caregiver, or authorized representative when legally permitted
Communications between you and our practice
Other information necessary to provide, coordinate, document, or administer healthcare services
Information Collected Through Our Website
When you visit our website, we may collect information such as:
IP address
Browser and device information
Date and time of website visits
Pages viewed
General website usage information
Information submitted through website forms
Information collected through cookies or similar technologies
We seek to limit the collection of health information through our public website. Please do not submit sensitive medical or psychiatric information through a public website contact form unless specifically instructed to do so.
Information From Other Sources
When permitted by law, we may receive information from third parties, including:
Other healthcare providers
Pharmacies
Health insurance companies and health plans
Healthcare clearinghouses
Laboratories
Hospitals and healthcare facilities
Caregivers, parents, guardians, or authorized representatives
Other individuals or organizations involved in your care
Government agencies
Services that assist us with scheduling, billing, identity verification, or healthcare administration
-
As a healthcare provider, we maintain PHI as defined by HIPAA and other applicable laws.
PHI may include information that identifies you and relates to your past, present, or future physical or mental health, healthcare services, or payment for healthcare services.
Examples include psychiatric evaluations, diagnoses, medication information, treatment plans, progress notes, appointment information, and communications concerning your care.
We protect PHI in accordance with applicable federal and state privacy and security requirements.
Where state law provides greater privacy protection than federal law, we will comply with the more protective requirement when applicable.
-
We may use and disclose your information as permitted or required by applicable law.
Treatment
We may use or disclose your information to provide, coordinate, or manage your healthcare.
For example, we may communicate with another healthcare professional involved in your treatment when permitted by law.
Payment
We may use or disclose information to obtain payment for healthcare services, process claims, verify insurance coverage, or otherwise administer payment for services.
Healthcare Operations
We may use or disclose information as necessary for healthcare operations, including:
Quality improvement
Care coordination
Credentialing
Compliance activities
Auditing
Administrative functions
Patient safety
Training and supervision, when permitted by law
Business management
Fraud and abuse prevention
Appointment and Administrative Communications
We may contact you regarding:
Appointments
Appointment reminders
Scheduling
Prescription-related communications
Billing
Patient portal notifications
Follow-up instructions
Changes to services or policies
Other administrative matters related to your care
Text Messaging
If you provide your telephone number and consent to receive text messages, we may use text messaging for appointment reminders, scheduling, billing, follow-up instructions, and other administrative or care-related communications.
You may opt out of non-emergency text messages by replying STOP when available or by contacting our office.
Text messaging may not be completely secure. We therefore encourage you to avoid sending highly sensitive medical information by text message unless specifically instructed to do so.
Opting out of text messages will not prevent you from receiving necessary healthcare services.
As Required by Law
We may use or disclose information when required to do so by federal, state, or local law.
Public Health and Safety
We may disclose information when permitted or required by law for public health activities, to prevent or control disease, to report certain conditions, or to address serious threats to health or safety.
Abuse, Neglect, or Domestic Violence
We may disclose information when required or permitted by law concerning suspected abuse, neglect, or domestic violence.
Judicial and Administrative Proceedings
We may disclose information in response to a court order, subpoena, discovery request, or other lawful process when the disclosure is permitted or required by applicable law.
Law Enforcement
We may disclose information to law enforcement when permitted or required by applicable law.
Serious and Imminent Threats
We may disclose information when necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public, consistent with applicable law.
Healthcare Providers and Other Persons Involved in Your Care
When permitted by law, we may disclose appropriate information to individuals involved in your care or payment for your care.
Business Associates and Service Providers
We may use third-party vendors and service providers to assist with our operations, including electronic health records, telehealth platforms, scheduling, billing, payment processing, communications, information technology, and secure data storage.
When required by HIPAA, these entities will be treated as business associates and will be subject to appropriate contractual privacy and security obligations.
We do not authorize our service providers to use PHI for purposes that are prohibited by applicable law.
Business Transfers
If Blue Lotus is involved in a merger, acquisition, sale, restructuring, financing, or other business transactions, information may be transferred as permitted by law and subject to applicable privacy protections.
-
Certain uses and disclosures of PHI require your written authorization.
Except as otherwise permitted or required by law, we will obtain your written authorization before:
Using or disclosing your PHI for purposes requiring authorization under HIPAA;
Using or disclosing psychotherapy notes when authorization is required;
Selling PHI; or
Using PHI for marketing when authorization is required.
You may revoke an authorization in writing at any time to the extent permitted by law. Revocation will not affect actions already taken in reliance on the authorization.
A privacy notice itself does not authorize a use or disclosure for which the law requires a separate authorization.
-
If we maintain records that are subject to the federal confidentiality requirements applicable to substance use disorder records under 42 C.F.R. Part 2, those records will be handled in accordance with Part 2, HIPAA, and other applicable federal and state laws.
Where applicable, Part 2 protections may provide additional confidentiality protections beyond HIPAA.
We will obtain the consent or authorization required by applicable law before making disclosures that require patient consent.
-
Psychiatric and mental health information may receive additional protection under federal or state law.
We will disclose mental health information only as permitted or required by applicable law and will limit disclosures to the information reasonably necessary for the applicable purpose when required.
For patients receiving services in New York, additional protections may apply to clinical information and mental health records under New York law.
For patients receiving services in Florida, psychiatric and clinical records may be subject to additional confidentiality requirements under Florida law.
For patients receiving services in Washington, health information may be subject to Washington's health information confidentiality requirements in addition to federal law.
-
Telepsychiatry requires the electronic transmission of healthcare information.
We use reasonable administrative, technical, and physical safeguards designed to protect information transmitted and stored through our telehealth and electronic systems.
Depending on the platform used, electronic communications may include:
Video and audio communications
Patient portal messages
Email
Text messages
Electronic forms
Appointment information
Prescription-related communications
Clinical information
We use telehealth and electronic communication platforms that we determine are appropriate for the services we provide and that are configured to provide appropriate privacy and security protections.
Patients should use a private location and a secure internet connection whenever possible when participating in telepsychiatry appointments.
Patients should also take reasonable steps to prevent unauthorized individuals from hearing or viewing their appointments or accessing their patient portal.
-
Our website may use cookies, analytics tools, pixels, or similar technologies to operate the website, understand website usage, improve website functionality, and maintain website security.
We will take reasonable steps to avoid transmitting protected health information through website analytics or advertising technologies unless such transmission is permitted by applicable law and appropriate safeguards are in place.
We do not sell patient medical records.
If our website uses third-party analytics, advertising, scheduling, chat, or other technologies that may collect information from visitors, those technologies may have their own privacy practices.
-
We maintain administrative, technical, and physical safeguards designed to protect personal information and PHI from unauthorized access, use, disclosure, alteration, or destruction.
Security measures may include, as appropriate:
Access controls
Authentication procedures
Encryption
Secure electronic systems
Workforce training
Vendor security requirements
Risk assessments
Monitoring and security procedures
Secure disposal of information
Policies governing workforce access to patient information
No electronic system or transmission over the internet can be guaranteed to be completely secure.
If a breach of unsecured PHI or other protected information occurs, we will provide notifications as required by applicable federal and state law.
-
We retain medical records and other information for the periods required or permitted by applicable federal and state law.
Medical record retention requirements may differ depending on the patient's state of residence, age, type of record, and other circumstances.
When information is no longer required to be retained, we will securely destroy, delete, or de-identify it in accordance with applicable law and our policies.
-
We may provide telepsychiatry services to individuals under the age of 18 when legally permitted.
When treating a minor, we will handle the minor's information in accordance with HIPAA, applicable state law, and the laws governing parental, guardian, or other authorized access to healthcare information.
Parents and guardians do not necessarily have unrestricted access to all information concerning a minor's healthcare. The rights of a parent or guardian to access a minor's records may depend on the minor's age, the type of service provided, applicable consent laws, and other circumstances.
Where a minor is legally authorized to consent to particular healthcare services, applicable law may limit parental or guardian access to information relating to those services.
-
If you have PHI protected by HIPAA, you may have the following rights, subject to applicable legal limitations:
Right to Inspect and Copy
You generally have the right to inspect and obtain a copy of your PHI maintained by us.
Right to Request an Amendment
You may request that we amend PHI that you believe is inaccurate or incomplete.
Right to an Accounting of Disclosures
You may request an accounting of certain disclosures of your PHI.
Right to Request Restrictions
You may request restrictions on certain uses or disclosures of your PHI. We are not required to agree to every requested restriction, except where required by law.
Right to Confidential Communications
You may request that we communicate with you by a particular method or at a particular location.
Right to Receive a Copy of This Notice
You may request a paper or electronic copy of this Notice at any time.
Right to File a Complaint
You may complain to us or to the U.S. Department of Health and Human Services if you believe your privacy rights have been violated.
You will not be retaliated against for filing a privacy complaint.
-
In addition to federal protections, certain states may provide additional privacy rights or protections.
Ohio
Ohio patients' healthcare information is subject to federal HIPAA requirements and applicable Ohio laws and regulations.
For telehealth services, we maintain safeguards designed to protect the privacy and security of patient information transmitted electronically.
Ohio law also requires certain providers to maintain written policies governing staff access to and disclosure of patient records and protected health information.
New York
New York patients may have additional protections concerning medical and mental health information.
Where applicable, New York law provides heightened confidentiality protections for certain clinical and mental health records, and disclosures may be restricted to circumstances authorized by law.
We will comply with applicable New York requirements concerning access to, confidentiality of, and disclosure of patient records.
Florida
Florida patients may have additional protections concerning medical, psychiatric, and clinical records.
Florida law generally requires patient records to remain confidential and restricts disclosure except where authorized or required by law.
We will comply with applicable Florida requirements concerning the confidentiality, maintenance, access, and disclosure of patient records.
Washington
Washington patients may have additional protections under Washington's health information privacy laws.
Washington law generally restricts disclosure of health care information without patient authorization except where disclosure is otherwise authorized by law.
Washington patients may also have rights concerning access to and amendment of their health information.
-
Washington's My Health My Data Act may apply to certain consumer health data that is not otherwise exempt from the Act.
To the extent the Act applies to information collected through our website or other non-HIPAA activities, we will maintain and publish a separate Washington Consumer Health Data Privacy Policy addressing:
Categories of consumer health data collected;
Purposes for collecting consumer health data;
Sources of consumer health data;
Categories of consumer health data shared;
Categories of third parties with whom consumer health data is shared;
Consumer rights;
How consumers may exercise those rights; and
Other disclosures required by Washington law.
The Washington Consumer Health Data Privacy Policy will be made available through a prominent link on our website as required by applicable law.
We will not sell consumer health data except as expressly permitted by applicable law and with any authorization required by law.
-
We do not sell patients' medical records or PHI.
We do not sell personal information for money.
If any activity involving the disclosure, licensing, transfer, or other monetization of personal information could constitute a "sale" under an applicable state privacy law, we will comply with the applicable law, including any required consent, authorization, opt-out, or other rights.
-
We do not use patients' PHI for targeted advertising except as permitted by applicable law and, where required, with the patient's authorization.
We seek to avoid using sensitive health information for advertising or marketing purposes without the permissions required by law.
-
Depending on your state of residence and the information involved, you may have rights to:
Access your personal information;
Obtain a copy of your personal information;
Request correction of inaccurate information;
Request deletion of personal information;
Obtain information about how personal information is collected and used;
Request information about disclosures or sharing;
Withdraw consent where processing is based on consent;
Opt out of certain forms of data processing where applicable; and
Exercise other rights provided by applicable state law.
These rights are subject to exceptions and limitations established by law, including exceptions relating to medical records, PHI, legal obligations, security, and other protected information.
A request to delete information does not necessarily require us to delete medical records that we are legally required to maintain.
-
To submit a privacy request or ask questions regarding this Notice, contact:
Blue Lotus Telepsychiatry Services Inc.
300 Weatherstone Dr.
Wadsworth, OH 44281
United StatesEmail:maryhva@onlinepsych.org
We may need to verify your identity before fulfilling certain requests.
If you submit a request through an authorized representative, we may require documentation establishing the representative's authority as permitted by law.
We will respond to privacy requests within the time required by applicable law.
-
If you believe your privacy rights have been violated, you may contact us using the information above.
You may also submit a complaint to the U.S. Department of Health and Human Services, Office for Civil Rights.
We will not retaliate against you for filing a privacy complaint.
-
We may update this Notice from time to time to reflect changes in our practices, technology, applicable laws, or regulatory requirements.
When we make material changes, we will update the "Last Updated" date and provide additional notice when required by law.
The current version of this Notice will be posted on our website.
-
Blue Lotus Telepsychiatry Services Inc.
300 Weatherstone Dr. #187 UPS Box
Wadsworth, OH 44281
United StatesEmail: contact@bluelotustelepsych.org
Website: https://bluelotustelepsych.com
If you have questions about this Notice, our privacy practices, your rights, or the handling of your health information, please contact us using the information above.
NOTICE OF PRIVACY PRACTICES ACKNOWLEDGMENT
Patients may be asked to acknowledge receipt of our Notice of Privacy Practices.
Acknowledgment of receipt does not constitute authorization for uses or disclosures of PHI that require a separate authorization under applicable law.
If a patient declines to sign an acknowledgment, we will document the refusal as required by applicable law.
