Privacy Policy

Effective Date: December 31, 2022 Last Updated: 8/20/2026 Version: 2.0

Respect Behavior Therapy ("Company," "Respect," "we," "us," or "our") is a Georgia-based behavioral health organization engaged in the delivery of Applied Behavior Analysis ("ABA") therapy services and related clinical, diagnostic, and support services. The Company is a "covered entity" as that term is defined at 45 C.F.R. § 160.103, and is subject to the administrative simplification provisions of the Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, as amended by the Health Information Technology for Economic and Clinical Health Act, Pub. L. No. 111-5 (collectively, "HIPAA"), and the regulations promulgated thereunder at 45 C.F.R. Parts 160, 162, and 164 (the "HIPAA Rules").

This Privacy Policy (the "Policy") is a legally binding statement of the Company's practices with respect to the collection, use, disclosure, transmission, retention, and safeguarding of information, including Protected Health Information, personally identifiable information, and non-identifiable technical data, obtained through the Company's websites, client and workforce portals, electronic communications, telephonic and short message service channels, intake processes, and the delivery of services.

PLEASE READ THIS POLICY CAREFULLY. By accessing or using the Sites or Services (each as defined in Section 2 below), by submitting information to the Company through any channel, or by communicating with the Company by electronic mail, telephone, or text message, you acknowledge that you have read, understood, and agree to be bound by the terms of this Policy. If you do not agree with any term of this Policy, you must discontinue use of the Sites and Services and should contact the Privacy Officer identified in Section 24 to discuss alternative means of communication.

1.1 This Policy is not a Notice of Privacy Practices. Nothing in this Policy is intended to substitute for, replace, amend, or limit the Company's Notice of Privacy Practices ("NPP") issued pursuant to 45 C.F.R. § 164.520. The NPP is the controlling instrument governing the Company's uses and disclosures of Protected Health Information and the rights of individuals with respect to such information.

1.2 Order of precedence. In the event of any conflict, ambiguity, or inconsistency between this Policy and (a) the NPP, (b) any executed Authorization, (c) any Business Associate Agreement, (d) any applicable payer or funding-source agreement, or (e) any requirement of federal or state law, the following order of precedence shall govern, in descending order of authority: (i) applicable federal and state law; (ii) the NPP; (iii) any executed Authorization; (iv) applicable contractual instruments; and (v) this Policy.

1.3 Preemption. Where a provision of applicable state law is more stringent than HIPAA within the meaning of 45 C.F.R. § 160.202, the more stringent provision shall control. This Policy shall be construed at all times in a manner consistent with such law.

1.4 No waiver of rights. Nothing in this Policy shall be construed to require any individual to waive any right under the HIPAA Rules, and no such waiver shall be a condition of treatment, payment, enrollment, or eligibility for benefits. See 45 C.F.R. § 164.530(h).

For purposes of this Policy, the following capitalized terms shall have the meanings ascribed to them below. Terms not otherwise defined herein shall have the meanings given to them in the HIPAA Rules.

"Authorization" means a written authorization satisfying the content and form requirements of 45 C.F.R. § 164.508.

"Business Associate" has the meaning set forth at 45 C.F.R. § 160.103, and generally means a person or entity that creates, receives, maintains, or transmits Protected Health Information on behalf of the Company in the performance of a function or activity regulated by the HIPAA Rules.

"Business Associate Agreement" or "BAA" means a written agreement satisfying the requirements of 45 C.F.R. §§ 164.502(e) and 164.504(e).

"Client" means an individual who receives, has received, or has sought Services from the Company, including a minor child receiving Services.

"Designated Record Set" has the meaning set forth at 45 C.F.R. § 164.501.

"Health Care Operations" has the meaning set forth at 45 C.F.R. § 164.501.

"Individual" means the person who is the subject of Protected Health Information, and includes a Personal Representative acting on that person's behalf to the extent permitted under 45 C.F.R. § 164.502(g).

"Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, whether or not such information constitutes Protected Health Information.

"Personal Representative" means a person authorized under applicable law to act on behalf of an Individual in making decisions related to health care, including a parent, legal guardian, custodian, or holder of a valid power of attorney, subject to the limitations of 45 C.F.R. § 164.502(g).

"Protected Health Information" or "PHI" has the meaning set forth at 45 C.F.R. § 160.103, and generally means individually identifiable health information transmitted or maintained in any form or medium by the Company, excluding education records covered by the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and employment records held by the Company in its role as employer.

"Services" means the ABA therapy, assessment, supervision, care coordination, billing, scheduling, and related clinical and administrative services provided by the Company.

"Sites" means, collectively, the Company's public website located at www.respectbt.com, the Company's client and workforce portal(s) (including, without limitation, clients.respectbt.com and any successor or additional platform designated by the Company from time to time), and any other digital property owned, operated, or controlled by the Company that links to this Policy.

"SMS" means short message service, multimedia message service, and any comparable text-based mobile messaging channel used by the Company.

"Treatment" and "Payment" have the meanings set forth at 45 C.F.R. § 164.501.

"Workforce Member" has the meaning set forth at 45 C.F.R. § 160.103, and includes employees, volunteers, trainees, students, independent contractors, and other persons whose conduct, in the performance of work for the Company, is under the direct control of the Company, whether or not paid by the Company.

"You" and "your" mean the individual accessing the Sites, receiving or seeking Services, acting as a Personal Representative, serving as a Workforce Member, or otherwise interacting with the Company.

3.1 Persons covered. This Policy applies to:

(a) visitors to and users of the Sites;

(b) Clients and prospective Clients, and their parents, legal guardians, custodians, and other Personal Representatives;

(c) Workforce Members, applicants for employment or contract engagement, and their designated emergency contacts and references;

(d) vendors, referral sources, payers, and other third parties who transmit information to, or receive information from, the Company's systems; and

(e) any person who sends to, or receives from, the Company an SMS message, electronic mail message, or telephonic communication.

3.2 Matters excluded from this Policy. This Policy does not govern:

(a) information practices of third parties, including payers, schools, diagnosing providers, or other health care providers, even where such parties are referenced on the Sites or receive information from the Company pursuant to a permitted disclosure;

(b) information collected through websites, applications, or platforms not owned or controlled by the Company, including any third-party site accessed via hyperlink from the Sites; or

(c) de-identified information that has been rendered non-identifiable in accordance with 45 C.F.R. § 164.514(b), or a limited data set used or disclosed pursuant to a data use agreement satisfying 45 C.F.R. § 164.514(e), which information is not subject to the restrictions applicable to PHI.

3.3 Geographic scope. The Sites and Services are directed to, and intended solely for, persons located within the United States. See Section 20.

The Company collects information directly from you, automatically through your use of the Sites, and from third parties acting on your behalf or on the Company's behalf. The categories of information collected are enumerated below.

4.1 Information Collected Automatically (Technical and Usage Data)

When you access the Sites, the Company and its service providers may automatically collect:

(a) Internet Protocol (IP) address and approximate geolocation derived therefrom; (b) browser type, version, language settings, and user-agent string; (c) device type, device identifiers, operating system, and screen resolution; (d) date, time, time zone, and duration of access; (e) referring and exit uniform resource locators (URLs); (f) pages and resources requested, clickstream data, and interaction timestamps; and (g) authentication events, session identifiers, and access-attempt logs, including failed authentication attempts.

4.2 Cookies and Similar Technologies

(a) Strictly necessary cookies are employed to maintain session state, enforce authentication, preserve security tokens, and prevent cross-site request forgery. These cookies are essential to the operation of the Sites and cannot be disabled without impairing functionality.

(b) Analytics cookies and web beacons are employed to measure aggregate traffic volume, page performance, and content engagement.

(c) Server log files are maintained for security monitoring, intrusion detection, audit control, and incident investigation, consistent with 45 C.F.R. § 164.312(b).

(d) No PHI in tracking technologies. The Company does not knowingly deploy on any authenticated portal page, or on any page reasonably likely to disclose an Individual's relationship to the Company as a recipient of behavioral health services, any third-party tracking technology that transmits PHI to a third party absent an executed BAA or a valid Authorization. The Company does not use advertising pixels or cross-context behavioral advertising technologies on authenticated pages.

(e) Browser controls. You may configure your browser to refuse or delete cookies. Doing so may render portions of the Sites inoperable.

4.3 Information You Provide That Is Not PHI

Including, without limitation: name, electronic mail address, telephone number, and free-text message content submitted through general contact forms, employment inquiries, or newsletter registrations.

4.4 Protected Health Information

Collected through intake documentation, service delivery, secure portal submissions, payer transactions, and clinical encounters, including, without limitation:

(a) full legal name, date of birth, mailing and residential address, telephone numbers, electronic mail addresses, and emergency contacts; (b) Social Security number, member identification numbers, and other identifiers where required for eligibility verification or payer submission; (c) health plan, Medicaid, or other funding-source information, authorization numbers, benefit determinations, claims data, and remittance information; (d) diagnostic information, referral documentation, prescriptions and orders, medical and developmental history, and prior evaluations; (e) functional behavior assessments, standardized and criterion-referenced assessment protocols and results, direct observation data, and graphed behavioral data; (f) treatment plans, behavior intervention plans, skill acquisition programs, mastery criteria, progress notes, session notes, and supervision documentation; (g) incident reports, restrictive-procedure documentation, and safety-related communications; and (h) audio, video, photographic, or telehealth recordings, only where collected pursuant to a separately executed, revocable written Authorization identifying the purpose and permitted recipients of such recording.

4.5 Workforce Information

Including, without limitation: application materials and résumés; identity and work-authorization documentation, including E-Verify records; background check and fingerprinting results; professional certification, licensure, and registration data (including Behavior Analyst Certification Board credentials); supervision logs and continuing education records; compensation, tax withholding, and payroll data; time and attendance records, including geolocation data captured at clock-in and clock-out where the Company's timekeeping system is so configured; scheduling and assignment data; disciplinary records; and benefits enrollment data.

Statutory note. Employment records held by the Company in its role as employer are excluded from the definition of PHI under 45 C.F.R. § 160.103. Such records are nonetheless treated by the Company as confidential and are safeguarded under the Company's internal information security program and applicable employment law.

4.6 Information Received From Third Parties

Including, without limitation, information received from: health plans and Medicaid contractors; referring physicians, psychologists, and diagnosticians; educational agencies (subject to applicable consent); prior ABA providers; and background check, credentialing, and payroll vendors engaged by the Company.

4.7 Sensitive Categories

The Company acknowledges that substantially all Client information it maintains constitutes sensitive information concerning the diagnosis and treatment of a developmental or behavioral health condition, and applies heightened safeguards accordingly.

5.1 Clients, Parents, Guardians, and Personal Representatives

The Company uses Client information for the following purposes:

(a) Treatment — assessment, treatment planning, direct service delivery, clinical supervision, care coordination with other providers, and continuity of care; (b) Payment — eligibility and benefits verification, prior authorization and reauthorization requests, claims submission and adjudication, appeals, collections activity, and coordination of benefits; (c) Health Care Operations — quality assessment and improvement, outcomes review, clinical protocol development, staff training and competency evaluation, credentialing, licensing and accreditation activities, business planning, audit, and compliance functions; (d) Scheduling and appointment administration — including confirmations, reminders, rescheduling, and notification of session or company cancellations, closures, and service interruptions; (e) Communication — with you and with persons you have designated in writing as authorized recipients of information; and (f) Legal and regulatory compliance — including mandatory reporting obligations, response to lawful process, and cooperation with health oversight agencies.

5.2 Workforce Members

The Company uses Workforce Member information to administer employment and contractor relationships; to verify and monitor credentials, licensure, supervision hours, and continuing education; to assign, schedule, and dispatch personnel to Clients; to administer payroll, benefits, leave, and reimbursement; to conduct performance management and investigate complaints; to enforce information security and acceptable use policies, including monitoring of Company systems and accounts; and to satisfy federal, state, payer, and accreditation reporting obligations.

Notice regarding Company systems. Workforce Members should have no expectation of privacy in any communication transmitted through, or data stored on, Company-owned or Company-administered systems, accounts, or devices, or in any personal device enrolled under the Company's bring-your-own-device policy, except to the extent otherwise required by law.

5.3 Site Visitors

The Company uses technical and usage data to operate, maintain, secure, and improve the Sites; to detect, investigate, and prevent fraud, abuse, and unauthorized access; to measure aggregate content engagement; and to compile de-identified statistical reporting.

6.1 Permitted without Authorization. Consistent with 45 C.F.R. § 164.502 and § 164.506, the Company may use and disclose PHI without an Individual's written Authorization for Treatment, Payment, and Health Care Operations.

6.2 Disclosures permitted or required by law. Consistent with 45 C.F.R. § 164.512, the Company may use or disclose PHI without Authorization where such use or disclosure is: required by law; for public health activities; concerning victims of abuse, neglect, or domestic violence, including mandatory reporting of suspected child abuse or neglect under O.C.G.A. § 19-7-5; for health oversight activities; in the course of judicial or administrative proceedings pursuant to a court order, subpoena, or discovery request satisfying the assurances required by 45 C.F.R. § 164.512(e); for law enforcement purposes; to coroners, medical examiners, and funeral directors; for organ and tissue donation; for research subject to Institutional Review Board or Privacy Board approval; to avert a serious and imminent threat to health or safety; for specialized government functions; and as authorized by and to the extent necessary to comply with workers' compensation laws.

6.3 Uses and disclosures requiring Authorization. The Company will obtain a valid written Authorization prior to any use or disclosure of PHI: (a) constituting marketing, as defined at 45 C.F.R. § 164.501; (b) constituting a sale of PHI, as defined at 45 C.F.R. § 164.502(a)(5)(ii); (c) of psychotherapy notes, except as permitted by 45 C.F.R. § 164.508(a)(2); or (d) for any purpose not otherwise permitted or required by the HIPAA Rules.

6.4 Revocation of Authorization. You may revoke an Authorization at any time by written notice delivered to the Privacy Officer. Revocation shall be effective upon receipt and shall not apply to any action taken by the Company in reliance upon the Authorization prior to receipt of the revocation. See 45 C.F.R. § 164.508(b)(5).

6.5 Opportunity to agree or object. The Company may disclose PHI to family members, other relatives, or close personal friends involved in an Individual's care, and in disaster relief situations, in accordance with 45 C.F.R. § 164.510, subject to your right to agree or object.

6.6 Minimum necessary. Except with respect to disclosures for Treatment purposes, disclosures to the Individual, disclosures made pursuant to an Authorization, and disclosures required by law, the Company limits uses, disclosures, and requests for PHI to the minimum amount reasonably necessary to accomplish the intended purpose, in accordance with 45 C.F.R. § 164.502(b) and § 164.514(d).

6.7 No sale of information. The Company does not sell, rent, lease, trade, or otherwise monetize PHI or Personal Information, and does not disclose PHI or Personal Information to third parties for those parties' independent marketing purposes or for cross-context behavioral advertising.

7.1 Categories of recipients. The Company may disclose information, subject at all times to Sections 6 and 7.2, to the following categories of recipients:

(a) health plans, Medicaid and Medicaid managed care organizations, third-party administrators, and clearinghouses, for eligibility, authorization, claims, and audit purposes; (b) other health care providers, for Treatment and care coordination; (c) Business Associates, including practice management, electronic health record, clinical documentation, scheduling, timekeeping, secure messaging, telecommunications, cloud hosting, data backup, and billing vendors; (d) professional certification and credentialing bodies, including the Behavior Analyst Certification Board, for verification, supervision documentation, and disciplinary reporting; (e) the Company's attorneys, accountants, auditors, and insurers, each of whom is bound by professional or contractual duties of confidentiality; (f) federal, state, and local governmental authorities, courts, and health oversight agencies, pursuant to lawful process or statutory mandate; and (g) a successor entity in connection with a merger, acquisition, consolidation, reorganization, or sale of all or substantially all of the Company's assets, provided that any such successor shall be bound by the terms of this Policy and by all obligations imposed upon the Company under the HIPAA Rules with respect to the information transferred.

7.2 Business Associate Agreements required. The Company shall not permit any vendor, contractor, or subcontractor to create, receive, maintain, or transmit PHI on the Company's behalf except pursuant to a written BAA satisfying 45 C.F.R. §§ 164.502(e) and 164.504(e), which agreement shall obligate the Business Associate to implement appropriate safeguards, restrict use and disclosure, report security incidents and breaches, ensure equivalent obligations flow down to subcontractors, and return or destroy PHI upon termination.

7.3 Current principal vendors. The Company's principal Business Associates and technology vendors as of the Last Updated date include, without limitation: Tebra (revenue cycle and practice management), ABADesk (clinical documentation), and Ezi Practice Manager (operational and practice management, including scheduling, timekeeping, secure messaging, document exchange, and the parent Care Portal). The Company reserves the right to add, substitute, or discontinue vendors at its discretion, and shall execute a BAA with each such vendor prior to any transmission of PHI.

7.4 Analytics vendors. The Company's public marketing website may employ third-party analytics services that collect technical and usage data described in Section 4.1. Where Google Analytics is deployed, you may opt out of measurement by installing the browser add-on available at https://tools.google.com/dlpage/gaoptout.

8.1 Security Rule compliance. The Company maintains a written information security program designed to comply with 45 C.F.R. Part 164, Subpart C, and to ensure the confidentiality, integrity, and availability of all electronic PHI that the Company creates, receives, maintains, or transmits.

8.2 Administrative safeguards (45 C.F.R. § 164.308), including: designation of a Privacy Officer and a Security Officer; periodic risk analysis and risk management; sanction policies for workforce violations; information system activity review; workforce clearance, authorization, and termination procedures; mandatory HIPAA and security awareness training at hire and periodically thereafter; contingency planning, including data backup, disaster recovery, and emergency mode operation plans; and periodic technical and non-technical evaluation.

8.3 Physical safeguards (45 C.F.R. § 164.310), including: facility access controls; workstation use and security policies; visitor management; secure storage of physical records; and documented media reuse and disposal procedures.

8.4 Technical safeguards (45 C.F.R. § 164.312), including: unique user identification and role-based access control enforced at the application and database layers; multi-factor authentication where supported; automatic session termination; audit controls and immutable access logging; integrity controls; encryption of PHI in transit using industry-standard transport layer security and encryption of PHI at rest; and tenant-level data isolation within multi-tenant platforms.

8.5 Limitations. No method of electronic transmission or storage is absolutely secure. While the Company implements safeguards it reasonably believes to be appropriate to the nature and scope of the PHI it maintains, the Company does not and cannot warrant absolute security. You transmit information to the Company at your own risk with respect to the transmission medium you select.

9.1 Permitted uses. The Company's portals are provided for the purposes of intake and enrollment; execution and exchange of consents, authorizations, and clinical documentation; review of treatment goals, progress reporting, and session information; workforce onboarding, credentialing, scheduling, timekeeping, and training; and secure messaging between authorized users.

9.2 Credential obligations. You shall: (a) maintain the confidentiality of your credentials and shall not disclose, share, transfer, or permit the use of your credentials by any other person; (b) select credentials meeting the Company's stated complexity requirements; (c) promptly notify the Privacy Officer upon becoming aware of any actual or suspected unauthorized access to your account; and (d) access only that information which you are authorized to access.

9.3 Prohibited conduct. You shall not attempt to circumvent authentication, authorization, encryption, rate limiting, or audit controls; access or attempt to access data belonging to another user, Client, or organization; scrape, harvest, reverse engineer, decompile, probe, or conduct vulnerability testing against the Sites without prior written authorization; introduce malicious code; or use the Sites in any manner that violates applicable law.

9.4 Enforcement. The Company reserves the right to suspend or terminate access, preserve and review audit logs, and refer conduct to law enforcement, without prior notice, where the Company reasonably believes a violation of this Section has occurred. Unauthorized access to a protected computer may constitute a criminal offense under 18 U.S.C. § 1030 and O.C.G.A. § 16-9-90 et seq.

9.5 Termination of access. Portal access is contingent upon an active treatment or workforce relationship and shall be deactivated upon discharge, resignation, or termination, subject to the Company's obligation to furnish records upon lawful request under Section 12.

This Section constitutes the Company's SMS-specific privacy and consent disclosures and is incorporated into and made a part of this Policy.

10.1 Program Description and Purposes

The Company operates one or more non-marketing, transactional and operational messaging programs. Messages may be sent to Clients, parents, guardians, Personal Representatives, and Workforce Members for the following purposes:

(a) appointment confirmations, reminders, and rescheduling notifications; (b) notification of Company closures and cancellations, including inclement weather closures, facility closures, holiday schedules, and unplanned service interruptions; (c) notification of session cancellations initiated by the Company, the Client, or an assigned Workforce Member; (d) staff scheduling and assignment notifications, including new Client assignments, shift assignments and changes, open-shift and coverage requests, session reassignment, location or address changes, and cancellation of assigned sessions; (e) workforce operational notifications, including timekeeping exceptions, missed clock-in or clock-out alerts, documentation and note-completion deadlines, credential and certification expiration reminders, supervision scheduling, mandatory training deadlines, and payroll cut-off reminders; (f) onboarding, documentation, and authorization-status notifications, including notice that a document requires signature or that an authorization is expiring; (g) portal and account notifications, including account creation, password reset, and multi-factor authentication codes; (h) urgent safety, incident, or emergency communications; and (i) responses to inquiries you initiate by text message.

10.2 Content Limitations

Messages are drafted to convey the minimum information necessary. The Company does not transmit detailed clinical content, assessment results, diagnostic information, or session data by SMS. You acknowledge that SMS is not an encrypted or secure transmission medium, that messages may be retained on your device and by your wireless carrier, and that a message identifying the Company as sender may itself disclose your relationship to a behavioral health provider to any person with access to your device.

10.3 Consent and Opt-In

(a) Enrollment is voluntary and requires affirmative opt-in. You may opt in by providing your mobile telephone number in an intake, onboarding, or portal form containing the required disclosures, or by replying YES to the Company's welcome message.

(b) Consent is not a condition of purchase, treatment, employment, or eligibility for benefits. Declining SMS communication will not affect your care or your employment, and the Company will communicate with you by telephone, electronic mail, portal message, or postal mail instead.

(c) You represent that you are the subscriber to, or the customary user of, the mobile telephone number you provide, and that you are authorized to consent to receive messages at that number. You shall notify the Company immediately upon relinquishing or changing that number.

(d) The Company maintains records of consent, including the date, time, method, and content of the disclosures presented at the time consent was obtained.

10.4 Opt-Out and Help

(a) You may revoke consent at any time and by any reasonable means, including by replying STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any message. The Company will send a single confirmation message and will cease further non-emergency messaging to that number.

(b) Reply HELP for assistance, or contact the Company using the information in Section 24.

(c) Opting out of SMS does not withdraw consent for telephone calls, electronic mail, or postal mail, and does not terminate the treatment or employment relationship.

10.5 Message Frequency and Charges

Message frequency varies according to your appointment schedule, assignment volume, and account activity. Message and data rates may apply. The Company is not responsible for charges imposed by your wireless carrier. Delivery is not guaranteed, and the Company is not liable for delayed or undelivered messages caused by carrier conditions, device settings, number portability, or factors outside the Company's control. Carriers are not liable for delayed or undelivered messages.

10.6 No Sale or Sharing of Mobile Data

The Company does not use SMS for advertising or marketing. Mobile telephone numbers, SMS opt-in consent, and SMS message content are not sold, rented, leased, or shared with any third party for marketing or promotional purposes, and are not shared with any affiliate or non-affiliate for such purposes. Mobile telephone numbers are disclosed only to the Company's telecommunications Business Associates for the sole purpose of transmitting the messages described in Section 10.1.

10.7 Supported Carriers and Age

Messaging is supported on major United States wireless carriers. Enrollment is limited to persons eighteen (18) years of age or older. See Section 19.

10.8 Rights Regarding SMS Data

Subject to Section 12 and to the Company's retention obligations, you may request access to message records associated with your number; request correction of the mobile number of record; and request deletion of SMS history that the Company is not required by law, payer contract, or professional standard to retain.

11.1 The Company's standard practice is to transmit PHI through its secure portal. Standard, unencrypted electronic mail is not a secure medium and may be intercepted, misdirected, or retained by intermediaries.

11.2 An Individual may request in writing that the Company communicate PHI by unencrypted electronic mail or other unsecured channel. The Company will honor such a request after advising the Individual of the associated risks and obtaining confirmation that the Individual wishes to proceed, consistent with the guidance of the United States Department of Health and Human Services. The Company shall bear no liability for interception, disclosure, or loss occurring after transmission where such transmission was made at the Individual's documented request.

11.3 Do not transmit PHI through the Company's public website contact form. That form is not a secure channel. Please use the portal or telephone the Company directly.

11.4 Confidential communications. You may request that the Company communicate with you by alternative means or at alternative locations pursuant to 45 C.F.R. § 164.522(b). The Company will accommodate reasonable requests.

12.1 Rights under the HIPAA Rules. Subject to the limitations and exceptions set forth in the HIPAA Rules and applicable state law, you have the following rights:

(a) Right of access (45 C.F.R. § 164.524) — to inspect and obtain a copy of PHI about you maintained in a Designated Record Set, in the form and format requested if readily producible, including electronic copies, and to direct the Company to transmit such copy to a designated third party. The Company will act on a request no later than thirty (30) days following receipt, with one permitted thirty (30) day extension upon written notice. A reasonable, cost-based fee may be charged as permitted by 45 C.F.R. § 164.524(c)(4) and O.C.G.A. § 31-33-3.

(b) Right to amend (45 C.F.R. § 164.526) — to request amendment of PHI you believe is inaccurate or incomplete. The Company may deny a request on the grounds enumerated in the regulation and will provide written notice of denial, along with your right to submit a statement of disagreement.

(c) Right to an accounting of disclosures (45 C.F.R. § 164.528) — to receive an accounting of certain disclosures made during the six (6) years preceding the request, excluding disclosures for Treatment, Payment, and Health Care Operations and other categories excepted by the regulation.

(d) Right to request restrictions (45 C.F.R. § 164.522(a)) — to request restrictions on uses and disclosures. The Company is not obligated to agree, except that the Company must agree to a request to restrict disclosure to a health plan where the disclosure is for purposes of carrying out Payment or Health Care Operations, is not otherwise required by law, and the item or service has been paid for in full out of pocket.

(e) Right to confidential communications (45 C.F.R. § 164.522(b)) — as described in Section 11.4.

(f) Right to revoke Authorization (45 C.F.R. § 164.508(b)(5)) — as described in Section 6.4.

(g) Right to notification of a breach (45 C.F.R. §§ 164.404–164.410) — as described in Section 13.

(h) Right to a paper copy of the Notice of Privacy Practices (45 C.F.R. § 164.520), upon request, notwithstanding prior electronic delivery.

12.2 Rights under Georgia law. Georgia law affords additional rights, including the right of a patient or authorized representative to obtain a complete and current copy of the patient's record upon written request under O.C.G.A. § 31-33-2, subject to the provider's limited authority under O.C.G.A. § 31-33-2(c) to withhold a record where disclosure would be detrimental to the physical or mental health of the patient, in which event the record shall be furnished to another provider designated by the patient.

12.3 Procedure for exercising rights. Requests must be submitted in writing to the Privacy Officer at the address or electronic mail address set forth in Section 24, and must include the requester's name; the Client's name and date of birth; a description of the right being exercised and the information at issue; the requested delivery format; and a signature. Requests submitted by electronic mail should include "HIPAA Privacy Request" in the subject line.

12.4 Verification. Prior to acting upon any request, the Company shall verify the identity and authority of the requester in accordance with 45 C.F.R. § 164.514(h). The Company may require government-issued photographic identification and, in the case of a Personal Representative, documentation of legal authority, including a birth certificate, custody order, guardianship order, or power of attorney. The Company may decline to act upon a request it cannot verify.

12.5 Denials. Where a request is denied in whole or in part, the Company shall provide a written explanation of the basis for denial and a description of any applicable right of review.

13.1 The Company maintains a documented incident response plan providing for detection, containment, investigation, risk assessment, remediation, and notification.

13.2 In the event of a breach of unsecured PHI as defined at 45 C.F.R. § 164.402, the Company shall conduct the four-factor risk assessment prescribed by that section and, where notification is required, shall notify affected Individuals without unreasonable delay and in no case later than sixty (60) calendar days following discovery, in the manner prescribed by 45 C.F.R. § 164.404. The Company shall further notify the Secretary of the United States Department of Health and Human Services in accordance with 45 C.F.R. § 164.408 and, where a breach affects more than five hundred (500) residents of a State or jurisdiction, prominent media outlets in accordance with 45 C.F.R. § 164.406.

13.3 Where a breach implicates personal information within the meaning of Georgia's Personal Identity Protection Act, O.C.G.A. § 10-1-910 et seq., the Company shall provide notice in accordance with the requirements of that statute.

13.4 Business Associates are contractually obligated to report security incidents and breaches to the Company without unreasonable delay.

14.1 Clinical records. The Company retains PHI for the longer of: (a) the period required under O.C.G.A. § 31-33-2, which requires a provider having custody and control of any evaluation, diagnosis, prognosis, or laboratory report in a patient's record to retain such item for not less than ten (10) years from the date such item was created; (b) with respect to a minor Client, such longer period as is prudent in light of the applicable statute of limitations and the tolling thereof during minority; (c) any period required by an applicable payer, Medicaid, or grant agreement; and (d) any period required by a litigation hold, subpoena, audit, or governmental investigation.

14.2 HIPAA documentation. Policies, procedures, Authorizations, BAAs, risk analyses, training records, sanctions, and other documentation required by the HIPAA Rules are retained for six (6) years from the date of creation or the date last in effect, whichever is later, pursuant to 45 C.F.R. § 164.530(j)(2).

14.3 Employment and payroll records. Retained in accordance with the Fair Labor Standards Act, the Internal Revenue Code, the Immigration Reform and Control Act, Title VII, the Americans with Disabilities Act, the Age Discrimination in Employment Act, applicable Georgia law, and the Company's records retention schedule.

14.4 SMS and communication records. Retained only so long as necessary for care coordination, operational administration, consent verification under Section 10.3(d), and compliance with applicable law.

14.5 Technical logs. Audit logs, access logs, and security telemetry are retained in accordance with the Company's security program and, where such logs relate to electronic PHI, for not less than six (6) years.

14.6 Destruction. Upon expiration of the applicable retention period, records are destroyed by means rendering PHI unreadable, indecipherable, and incapable of reconstruction, consistent with National Institute of Standards and Technology Special Publication 800-88.

14.7 Deletion requests. You may request deletion of information the Company is not required to retain. The Company shall have no obligation to delete, and shall decline to delete, any record subject to a retention obligation described in this Section.

15.1 The Company may employ software features that apply automated logic or machine learning to support scheduling optimization, documentation drafting, progress summarization, clinical decision support, and administrative workflow.

15.2 Where such features process PHI, the Company shall use only vendors that have executed a BAA and that contractually commit not to use Company data to train generalized models for the benefit of the vendor or third parties.

15.3 No automated clinical determination. No automated system substitutes for the professional judgment of a Board Certified Behavior Analyst or other qualified clinician. All clinical determinations, treatment plans, and documentation are reviewed and approved by a qualified human clinician prior to finalization.

15.4 The Company does not engage in automated decision-making producing legal or similarly significant effects concerning any Individual without human review.

16.1 The Company may create de-identified information in accordance with 45 C.F.R. § 164.514(b), and may use and disclose such de-identified information without restriction. The Company shall not attempt, and shall contractually prohibit its vendors from attempting, to re-identify de-identified information except as permitted by 45 C.F.R. § 164.502(d).

16.2 Use or disclosure of PHI for research purposes shall occur only pursuant to a valid Authorization, an Institutional Review Board or Privacy Board waiver satisfying 45 C.F.R. § 164.512(i), a limited data set governed by a data use agreement, or the reviews-preparatory-to-research or decedent-research exceptions.

17.1 Internal complaints. You may file a complaint with the Company by contacting the Privacy Officer at the address set forth in Section 24. Complaints should describe the conduct at issue, the date of occurrence, and the resolution sought.

17.2 Complaints to the federal government. You may file a complaint with the Secretary of the United States Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue SW, Washington, DC 20201; telephone 1-800-368-1019 (TDD 1-800-537-7697); or online at https://www.hhs.gov/ocr/complaints/index.html. A complaint must generally be filed within one hundred eighty (180) days of the date you knew or should have known of the act complained of.

17.3 No retaliation. The Company shall not intimidate, threaten, coerce, discriminate against, or take any other retaliatory action against any person for filing a complaint, participating in an investigation, exercising any right under this Policy or the HIPAA Rules, or opposing any act reasonably believed in good faith to be unlawful. See 45 C.F.R. § 164.530(g).

18.1 All Workforce Members are required to complete HIPAA privacy and security training at hire and periodically thereafter, to execute a confidentiality agreement, to access PHI only on a need-to-know basis, and to report suspected privacy or security incidents immediately.

18.2 Violations are subject to sanctions up to and including termination of employment or engagement, referral to the applicable certifying or licensing board, and referral to law enforcement. Impermissible disclosure of PHI may carry individual criminal liability under 42 U.S.C. § 1320d-6.

19.1 The Company provides Services to children and adolescents. Clinical information concerning a minor Client is collected from, and is accessible to, that minor's parent, legal guardian, or other Personal Representative, subject to the limitations of 45 C.F.R. § 164.502(g) and applicable Georgia law regarding minors' consent to treatment.

19.2 The Sites are not directed to children under the age of thirteen (13) within the meaning of the Children's Online Privacy Protection Act, 15 U.S.C. § 6501 et seq., and its implementing regulation at 16 C.F.R. Part 312. The Company does not knowingly collect Personal Information directly from a child through the Sites. Minors are not permitted to register for portal accounts, submit forms, or enroll in SMS messaging independently.

19.3 If the Company becomes aware that it has inadvertently collected Personal Information directly from a child in a manner inconsistent with this Section, it shall delete such information promptly, except where retention is required as part of the clinical record.

19.4 Custody disputes. Where the Company receives conflicting instructions from persons claiming parental or guardianship authority, the Company may decline to act pending receipt of a controlling court order or other satisfactory documentation of authority. The Company does not adjudicate custody disputes.

20.1 The Sites and Services are operated in the United States and are intended for persons located within the United States. The Company makes no representation that the Sites or Services are appropriate or available for use outside the United States.

20.2 If you access the Sites from outside the United States, you do so on your own initiative and at your own risk, and you consent to the transfer, processing, and storage of your information in the United States, where data protection laws may differ from those of your jurisdiction and may afford lesser protection.

20.3 The Company does not offer goods or services to, and does not monitor the behavior of, data subjects located in the European Economic Area or the United Kingdom, and does not intend to subject itself to the General Data Protection Regulation.

The Sites may contain hyperlinks to websites, applications, or resources operated by third parties. Such links are provided for convenience and informational purposes only and do not constitute an endorsement. The Company exercises no control over, and assumes no responsibility or liability for, the content, privacy practices, security, or availability of any third-party property. Your interaction with any third-party property is governed exclusively by that party's terms and privacy policy.

22.1 The Company reserves the right to amend, modify, supplement, or replace this Policy at any time in its sole discretion. Amendments shall become effective upon posting of the revised Policy to the Sites, at which time the "Last Updated" date shall be revised accordingly.

22.2 Where an amendment materially affects the rights of Clients or Workforce Members, the Company shall provide notice by electronic mail, portal message, or other reasonable means to active Clients and Workforce Members.

22.3 The Company reserves the right to make any change to the NPP effective for all PHI it maintains, including PHI created or received prior to the effective date of the change, in accordance with 45 C.F.R. § 164.520(b)(1)(v)(C).

22.4 Your continued use of the Sites or Services following the effective date of an amendment constitutes acceptance of the amended Policy. Archived versions are available upon written request to the Privacy Officer.

23.1 Governing law. This Policy shall be governed by and construed in accordance with the laws of the State of Georgia and applicable federal law, without regard to conflict-of-laws principles.

23.2 Severability. If any provision of this Policy is held invalid, illegal, or unenforceable by a court or tribunal of competent jurisdiction, such provision shall be severed and the remaining provisions shall continue in full force and effect, and the severed provision shall be reformed to the minimum extent necessary to render it enforceable and consistent with the original intent.

23.3 No third-party beneficiaries. Except as expressly provided herein with respect to Individuals' rights under the HIPAA Rules, this Policy confers no rights or remedies upon any person other than the parties described herein.

23.4 No waiver. No failure or delay by the Company in exercising any right under this Policy shall operate as a waiver thereof, nor shall any single or partial exercise preclude any further exercise of that or any other right.

23.5 Headings; construction. Section headings are for convenience of reference only and shall not affect interpretation. The words "include," "includes," and "including" shall be deemed to be followed by the phrase "without limitation." References to statutes and regulations include all amendments and successor provisions thereto.

23.6 Entire statement. This Policy, together with the NPP, the Company's Terms of Use, any executed Authorizations, and any applicable service or employment agreement, constitutes the entire statement of the Company's privacy practices with respect to the subject matter hereof and supersedes all prior privacy statements published by the Company.

23.7 Survival. Sections 6, 8, 12, 13, 14, 17, 18, and 23 shall survive termination of any treatment or workforce relationship.

Privacy Officer: Respect Behavior Therapy 1115 Mount Zion Road, Suite M Morrow, Georgia 30260

Electronic Mail: [email protected] Telephone: (943) 200-0016

HIPAA privacy requests, access requests, amendment requests, accounting requests, restriction requests, and complaints must include "HIPAA Privacy Request" in the subject line of any electronic mail, or be conspicuously marked as such on any written correspondence.

Written requests submitted by mail should be sent to the attention of the Privacy Officer at the address above. The Company recommends transmission by a method providing proof of delivery.

Respect Behavior Therapy — 1115 Mount Zion Road, Suite M, Morrow, Georgia 30260