Privacy & Security Policy
Weingarden Psychological Services ยท Last updated August 18, 2026
Platform Suite: weingardenpsychologicalservices.com (including insuranceaudit.* and behaviorplan.* subdomains)
Operator: Weingarden Psychological Services
1. Introduction & Scope
Weingarden Psychological Services ("we," "our," or "us") operates a unified mental health tech suite and software launchpad. This policy governs all associated subdomains and integrated services, including:
- The Insurance Audit Platform: An administrative tool for clinicians and billing specialists to cross-reference and reconcile health insurance Electronic Remittance Advices (ERAs) against actual bank statement deposits.
- The Behavior Plan Platform: A clinical diary, behavioral contingency tracking, and relapse-prevention tool designed by a licensed psychologist for client self-monitoring and therapist-guided behavioral chain analysis (BCA).
By using any application within our suite, you consent to the data collection, security protection, and privacy practices outlined in this policy.
2. Information We Collect & Process
To support the independent features of our multi-app workspace, we process distinct data categories:
A. Administrative & Practice Information (All Apps). Account registration credentials, professional email addresses, practice entity titles, and role-based permissions.
B. Financial & Transactional Ingestion (Insurance Audit).
- Uploaded Payout Materials: Financial and insurance payment reports uploaded by users via CSV or PDF formats containing insurer credit tracking codes, posting dates, and billing totals.
- Connected Bank Metadata (Plaid Integration): With explicit user consent, we connect via Plaid Inc. ("Plaid") to ingest business bank account transaction histories, specifically deposit amounts, transaction credits, and raw deposit descriptions representing electronic fund transfers (EFTs).
C. Clinical Self-Monitoring & Behavioral Records (Behavior Plan).
- Behavioral Contingencies: User-defined target behaviors, tracking schedules, custom triggers, coping interventions, custom vulnerability factors, and baseline barriers.
- Daily Reflection Journals: Daily self-monitoring logs evaluating subjective mood, physical health, cognition, and motivational states on structured 1-10 matrices.
- Behavior Chain Analysis (BCA): In-depth structural breakdowns of clinical slip-ups, tracking chronological links, emotional cues, and cognitive themes.
3. How We Utilize Your Data
Data within our platform suite is never mixed or shared across unrelated modules. It is used strictly for its intended clinical or operational workspace:
- Automated Reconciliation Auditing: To programmatically cross-reference insurer payout entries with actual bank deposits to immediately flag older, unmatched entries.
- Clinical Progress Tracking & Psychoeducation: To display daily "Today's Routine" cadences, unlock scheduled tracking windows, and visualize progress patterns over weekly or monthly duration thresholds.
- Therapist & Accountability Networks: When explicitly configured by the client, the platform securely shares designated behavior plans, daily logs, and completed BCAs with an assigned therapist or an "accountabilibuddy" via secure, role-restricted dashboard views.
5. Health Data Integrity & Legal Disclaimers
- Not Psychotherapy: The Behavior Plan application utilizes tenets of psychology to provide structured habit tracking. It is a journal application; it does not constitute psychotherapy or medical intervention, and information stored within the self-monitoring dashboard does not serve as a formal electronic medical record (EMR).
- Data Isolation (HIPAA Alignment): Because files or logs may reference billing codes or clinical notes, we enforce strict physical, technical, and administrative controls. Client data visibility is dynamically masked by internal backend configurations according to the user's role (for example, clinician, billing agent, client, or accountability partner). All uploaded files reside in private, segmented cloud containers hidden from public view.
6. Technical Protections & Cryptographic Standards
We implement unified security controls across our software launchpad infrastructure:
- In Transit: All network traffic between client browsers, mobile devices, app endpoints, and third-party APIs (such as Plaid) requires Transport Layer Security (TLS 1.2 or higher).
- At Rest: All user profiles, financial collections, behavior logs, and access tokens are encrypted at rest using industry-standard Advanced Encryption Standard 256-bit (AES-256) encryption.
- Secrets Isolation: API client credentials, master developer keys, and production database environments are centrally isolated as server-side environment variables and are completely hidden from front-facing client interfaces.
7. Account Deletion & Data Retention
All users hold absolute authority over their personal and clinical records. Upon deleting an account or unlinking an integration from our platform, active database collections, cached transactional logs, and clinical logs are systematically scrubbed and deleted from our production environments.
8. Contact Information
For any security or privacy inquiries, please connect with:
Weingarden Psychological Services
Email: administrative-support@weingardenpsychologicalservices.com
Master Portal: weingardenpsychologicalservices.com