Park Hill Counseling
Privacy Policy
Website Privacy Policy & Notice of Health Information Privacy Practices
Last Updated: August 6, 2026
1. Introduction
Park Hill Counseling ("we," "us," or "our") respects your privacy and is committed to protecting the personal and health information of users who visit our website (https://parkhillcounseling.org) and book services online.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, submit booking requests, or communicate with us online. Because our services involve healthcare and health-related scheduling, our treatment of your information is governed by both state privacy laws and federal regulations, including the Health Insurance Portability and Accountability Act (HIPAA) and the Arkansas Personal Information Protection Act (APIPA).
2. Protected Health Information (PHI) & HIPAA Compliance
When you book HIPAA-sensitive services through our website, any health-related details you provide—such as your medical history, symptoms, treatment preferences, health insurance identifiers, or specific appointment reasons—constitute Protected Health Information (PHI) under HIPAA.
Business Associate Agreements (BAA)
Our online scheduling software, web hosting environment, form builders, and electronic communications channels that handle or transmit PHI are configured to meet HIPAA Security Rule standards and are bound by formal Business Associate Agreements (BAAs) with our vendors.
Separate Notice of Privacy Practices (NPP)
Under HIPAA, you have specific statutory rights regarding your medical records and PHI. While this Privacy Policy covers general website data, our legal obligations regarding your medical treatment and health record disclosures are governed by our formal HIPAA Notice of Privacy Practices (NPP) [Available via link or upon request at our physical office].
3. Information We Collect
A. Information You Provide Directly
-
Personal Identifiers: Name, email address, phone number, mailing address, and date of birth.
-
Booking & Health Information: Appointment dates/times, selected medical/health services, health insurance policy numbers, intake forms, and notes regarding your care request.
-
Payment Data: Credit card or debit card numbers, processed securely via PCI-DSS compliant third-party payment gateways (we do not store raw payment card credentials on our web server).
B. Automatically Collected Information
When you visit our website, our servers and analytics providers may collect standard non-identifying technical data:
-
Log Data: IP address, browser type, operating system, referring URL, and pages viewed.
-
Cookies & Tracking Technologies: We use functional cookies required for booking workflow functionality. Note: We do not deploy third-party advertising tracking pixels (such as Meta Pixel or Google Analytics advertising tools) on pages or forms where PHI is entered or transmitted.
4. How We Use Your Information
We use the information collected through our website for the following operational purposes:
-
Processing, scheduling, and confirming your online appointment bookings.
-
Communicating appointment reminders, pre-service instructions, or transactional messages via email or SMS (with your explicit consent).
-
Verifying insurance coverage and processing payments.
-
Maintaining the technical security, integrity, and operational performance of our web applications.
-
Complying with applicable legal, regulatory, and healthcare reporting obligations.
5. Disclosure & Sharing of Information
We do not sell, rent, or trade your personal information or PHI to third parties for marketing purposes. We disclose information only as follows:
-
Healthcare Service Providers: To our licensed clinicians and staff involved in delivering your care.
-
HIPAA Business Associates: To vetted technology vendors (e.g., electronic health record systems, secure web hosting platforms, encrypted booking engines) who perform services on our behalf under signed BAAs.
-
Legal & Regulatory Requirements: When required by state or federal law, court orders, subpoenas, or health oversight agency investigations.
-
Emergency Situations: To protect the health, safety, or vital interests of a patient or the public.
6. Data Security & Storage
We implement administrative, physical, and technical safeguards designed to maintain the confidentiality, integrity, and availability of your information in compliance with the HIPAA Security Rule and the Arkansas Personal Information Protection Act.
-
Encryption: Data transmitted through online booking forms is encrypted in transit using SSL/TLS protocols, and stored PHI is encrypted at rest.
-
Access Controls: Access to patient booking records is strictly limited to authorized personnel with a clear operational need.
-
Arkansas Breach Notification Standard: In the event of an unauthorized security incident compromising your unencrypted personal information, we will notify affected individuals in accordance with Ark. Code Ann. § 4-110-105 as soon as possible and without unreasonable delay (no later than 45 days post-discovery).
7. Your Privacy Rights
Depending on federal and state law, you have the following rights regarding your information:
-
Access & Inspection: The right to inspect and receive a copy of your health records maintained by us.
-
Corrections: The right to request an amendment to inaccurate or incomplete PHI in your record.
-
Marketing Opt-Out: The right to opt out of non-essential electronic communications (e.g., newsletter updates or feedback requests).
-
Cookie Management: You can set your browser to reject non-essential web cookies; however, disabling functional cookies may impair the online booking feature.
8. Third-Party Links
Our website may contain links to external websites (e.g., patient education resources or payment portals). We are not responsible for the privacy practices or content of third-party sites. We encourage you to review the privacy policies of any third-party service you visit.
9. Contact & HIPAA Privacy Officer
If you have questions, concerns, or requests regarding this Privacy Policy or our health information handling practices, please contact our HIPAA Privacy Officer:
-
Business Name: Park Hill Counseling
-
Attn: HIPAA Privacy Officer
-
Address: 5321 John F. Kennedy Blvd. North Little Rock, AR 72116
-
-
Phone: 501-646-1812
-
Email: admin@parkhillcounseling.org
.png)