Your privacy is crucial to us.

Here’s how we protect it.

Please wait while the policy is loaded. If it does not load, please click here to view the policy.

Privacy Policy

Effective Date: July 1, 2025

Last Updated: July 1, 2025

This privacy policy describes how Fides Catholic Counseling, a Catholic counseling practice in Minnesota, collects, uses, discloses and safeguards personal information, including protected health information (PHI), obtained through our website and counseling services. We are committed to respecting your privacy and complying with all applicable laws, including the HIPAA Privacy Rule and Minnesota health privacy laws. Please read this policy carefully to understand your rights and how we handle your information.

Information we collect

Personal and health information: We collect personal information that you voluntarily provide when you contact us or schedule an appointment. This may include your name, email address, postal address, phone number, date of birth and any health or counseling-related information you provide (e.g., symptoms, medical history, counseling concerns). Such information, when it is health-related and identifiable, is considered PHI under HIPAA and is protected accordingly.

Website usage data: When you visit our website, we may automatically collect certain technical information about your visit (such as IP address, browser type, device type, pages viewed, and visit duration) through cookies and similar technologies. This data is used for web analytics purposes and does not identify you individually.

All information collected is used only to the extent necessary to communicate with you, provide and manage counseling services, process appointments, and improve our website and services.

How we use and disclose information

We use your personal information and PHI only as permitted by HIPAA and Minnesota law:

Treatment: To provide counseling and therapy services. We may use or disclose your PHI to coordinate your care with other healthcare providers or as part of treatment (e.g., consultation or referral), in accordance with HIPAA.

Payment: To process billing and payment for services (including insurance claims) and to fulfill our financial responsibilities related to your care.

Health care operations: For activities that support our practice operations, such as quality assurance, practice management, legal and accounting services, training and compliance with legal requirements.

Appointment scheduling and communications: To contact you about appointments, reminders, updates and any other information related to your counseling (by phone, email, or text) as authorized by you. We may also use contact information to send occasional practice updates or newsletters, from which you may unsubscribe at any time.

Required by law: We may disclose PHI if required by law (e.g., mandatory reporting of abuse, court orders, health oversight or other legal proceedings) or if needed to prevent a serious and imminent threat to health or safety.

With your authorization: Any other uses or disclosures of your information not described above will only occur with your written authorization, which you may revoke at any time.

We do not use your information for marketing or fundraising purposes without your explicit written consent.

Third party tools and services

Our website and practice use certain third-party tools to provide services and analyze website traffic. These include:

Google Analytics: We use Google Analytics to collect anonymous usage data (e.g., page views, session duration) for website improvement. Google Analytics employs first-party cookies to record general visitor information and does not collect any personal identifiers or PHI. We ensure that no health information or identifiers are sent to Google Analytics. Google Analytics is not HIPAA-compliant for PHI, and we do not transmit any PHI through it. The analytics cookies used (_ga, etc.) do not contain personal data and help us understand site usage patterns. You may opt out of Google Analytics tracking by disabling cookies in your browser or by installing the Google Analytics Opt-out Browser Add-on. Blocking these cookies will not affect your ability to use our website.

SimplePractice (scheduling and clinical records): We use SimplePractice as our practice management system for appointment scheduling, secure intake forms, documentation and billing. SimplePractice is HIPAA-compliant and HITRUST-certified. We have a BAA with SimplePractice, and all PHI entered into SimplePractice is stored on their encrypted servers. SimplePractice provides secure client portals, telehealth video, and encrypted messaging for communication. By using SimplePractice for PHI, we ensure compliance with HIPAA security standards.

Cookies and tracking

We use cookies and similar technologies on our website:

Essential cookies: These are necessary for the website to function (e.g., enabling you to submit forms).

Analytics cookies: We use Google Analytics (as noted above) and cookies to understand how visitors use the site and to improve our services. These cookies may record when you visited and which pages you viewed, but do not identify you personally.

Consent: We display a cookie consent banner on our website to inform you about cookie usage and to obtain your consent before placing non-essential cookies. You can withdraw consent or adjust cookie preferences at any time through your browser settings or our cookie settings page.

Opt-out: You can opt out of analytics cookies by clearing your browser cookies or using opt-out tools as noted above. Disabling cookies will not prevent you from accessing any part of our website, but some features may not work as smoothly.

HIPAA Privacy Rule compliance

We adhere strictly to the HIPAA Privacy Rule. This notice describes how we may use and disclose your PHI and your rights under HIPAA.

Privacy practices notice: We provide a written Notice of Privacy Practices explaining our uses and disclosures of PHI and your rights. You may request a copy of this notice at any time.

Permitted uses and disclosures: As a covered entity, we may use or disclose PHI without your authorization for treatment, payment, and health care operations. All other uses (e.g., marketing, research, psychotherapy notes) require your written permission. We also follow the “minimum necessary” rule, meaning we limit PHI use and disclosure to the minimum needed for the purpose.

Business associates: When we use vendors (business associates) to perform services involving PHI, we have BAAs in place to ensure they protect your information as required by HIPAA. For example, SimplePractice features operate under BAAs to safeguard PHI.

Special privacy protections: Our counselors abide by professional ethical standards that impose additional confidentiality obligations. In accordance with Catholic ethical principles and professional ethics, we regard client confidentiality as a bedrock imperative. Any religious or spiritual matters you share are kept strictly confidential. (Please note that, while HIPAA governs health information, clergy-penitent confidentiality (the “seal of confession”) is absolute under canon law; although we operate as health providers, we honor these religious ethics to the fullest extent.)

Your privacy rights

You have several rights regarding your PHI under HIPAA and Minnesota law:

Right to notice: You have the right to receive our Notice of Privacy Practices explaining how we handle PHI.

Right of access: You may inspect and obtain a copy of your health records (PHI) in our custody. Generally, we must comply within 30 days of your request. If we deny access (which is rare), we will provide a written reason and appeal process.

Right to amendment: If you believe information in your record is incorrect or incomplete, you may request an amendment. We will review your request and notify you of our decision.

Right to restrictions: You may request restrictions on certain uses or disclosures of your PHI. For example, you can ask that we not share information with your health plan for services you paid for privately. We will consider all reasonable requests.

Right to confidential communications: You may request that we communicate with you in a confidential way (for example, sending mail to a work address instead of home). We will accommodate reasonable requests.

Right to accounting of disclosures: You can request an accounting of certain disclosures we have made of your PHI (except for disclosures made for treatment, payment, or certain other permitted purposes) during the past six years.

Right to file complaints: If you believe your privacy rights have been violated, you may file a complaint with us (see Contact Information below) or with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR). We will not retaliate against you for filing a complaint.

Additionally, under Minnesota law, you may have rights to access and control your health records similar to those under HIPAA, and special provisions apply to disclosures of mental health records. For instance, Minnesota’s Health Records Act generally requires your consent before a provider may release your health records to others. Minnesota counseling rules also require counselors to safeguard private client information and only disclose it with consent or under limited exceptions (such as preventing serious harm).

Finally, Minnesota’s Consumer Data Privacy Act (effective July 31, 2025) grants Minnesota residents rights concerning personal data (e.g., confirmation, access, correction, deletion, and opt-out of targeted advertising or profiling). Note, however, that this law explicitly exempts health records and PHI regulated by HIPAA. Nonetheless, we strive to uphold transparency and may allow you to exercise any applicable rights regarding data we collect.

Data security measures

We employ comprehensive safeguards to protect your information:

Administrative safeguards: Our practice has implemented policies and procedures to ensure the confidentiality and security of your PHI. Staff receive HIPAA privacy and security training, and we limit access to PHI only to authorized personnel (e.g., the counselor, administrative staff) who need it to perform their duties. All staff sign confidentiality agreements.

Physical safeguards: We maintain physical protections (locked cabinets, secure offices) for paper records, and secure facilities for our electronic systems. Our servers and computers are protected by firewalls, antivirus software and automatic locking mechanisms when idle. Client charts (electronic or paper) are stored in secure locations.

Technical safeguards: Electronic PHI is secured with technical measures. We use unique user IDs and strong passwords for all systems. Access controls ensure only authorized users can access PHI. We use encryption for PHI both in transit and at rest: for example, our website uses HTTPS/SSL encryption, and our practice management system encrypts stored data. (As HHS notes, the goal of encryption is to prevent unauthorized access to electronic PHI.) We also implement audit controls (logging) to track access to PHI and monitor for unauthorized activity. Backups are performed regularly and stored securely.

Business associate agreements: We require all vendors who handle PHI on our behalf (e.g., SimplePractice) to enter into HIPAA-compliant BAAs. These agreements oblige the vendor to protect PHI and report any breaches.

In summary, we follow industry best practices (and the HIPAA Security Rule) to guard your data. As HHS explains, covered entities must ensure the confidentiality, integrity and availability of electronic PHI and protect it against threats and unauthorized disclosures. We conduct periodic risk assessments and update our security measures as needed.

Cookies and online tracking

We use cookies and similar tracking technologies to enhance your experience and analyze our site traffic:

Cookie consent: When you first visit our website, a banner will inform you about cookie usage and allow you to consent to non-essential cookies. You may change cookie settings at any time via the banner or your browser.

Types of cookies: We use only non-invasive cookies (such as Google Analytics) for statistics. These cookies do not collect personal information beyond an anonymous identifier. They help us see which pages are most visited and how users navigate the site.

Opt-out: You can control cookies through your browser settings (e.g., to delete cookies or block new ones). In addition, Google provides a browser add-on to disable Google Analytics. Opting out will not impair your ability to use the site, but may affect certain personalized features.

Minnesota state privacy provisions

We comply with Minnesota-specific privacy laws as follows:

Consent for health records: Minnesota law (Minn. Stat. §144.293) prohibits disclosing a patient’s health records without written consent or a court order. We will obtain your authorization before releasing records, except where law specifically allows disclosure (such as emergencies or as required by law).

Counseling confidentiality rules: Under Minnesota counseling rules, we are required to safeguard all private client information and disclose it only when legally permitted. We will generally not disclose your information without your consent. The only exceptions include preventing serious and imminent harm, complying with mandatory reporting laws (e.g. abuse of a minor or elder), or other legal obligations.

Minnesota notice requirements: Minnesota’s Health Records Act provides patients with rights to access, copy, and request amendments to their records (similar to HIPAA) and generally requires providers to notify patients of their rights. We will meet or exceed these requirements as part of our practice (for example, by providing this privacy notice and honoring record requests).

Religious ethics and confidentiality

As a Catholic counseling practice, we honor and respect the spiritual and ethical aspects of confidentiality. Our professional code of ethics, in line with Catholic values, considers client confidentiality a bedrock ethical imperative. Any spiritual, religious or personal matters you discuss in counseling are held in strict confidence. We do not disclose such information outside of counseling except as required by law (and then only the minimum necessary). For Catholic clients, we also recognize that sacramental confessions are bound by an absolute seal under canon law, and we fully respect this principle by not serving in an official confessor role. In any case, our approach is to maintain the highest standards of trust and privacy in all matters you share.

Changes to this policy

We may update this privacy policy as needed to reflect changes in our practices, legal requirements or technological developments. When we update the policy, we will post the revised version on our website with a new “last updated” date. We encourage you to review this policy periodically. If the changes are significant, we may provide more prominent notice (such as an email notification, if we have your email address on file).

Contact information

If you have any questions, concerns or complaints about our privacy practices or this policy, please contact:

Privacy officer: Fides Catholic Counseling

Address: 1595 Selby Ave., Suite 105, St. Paul, Minnesota 55104

Phone: 651-321-1030

Email: [email protected]

We will respond to all reasonable requests and work to address any issue you raise. You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights (by mail, email or online) or with the Minnesota Department of Health if you believe your privacy rights have been violated. No retaliatory action will be taken against you for filing a complaint.

Thank you for entrusting us with your care. We are dedicated to protecting your privacy and maintaining your trust.

Sources: We have drafted this policy based on HIPAA regulations and guidance, Minnesota health privacy laws, and the practices of HIPAA-compliant service providers. You may refer to these sources for further information.