Legal
Privacy & HIPAA Practices
Mindward Collective is a marketing agency, not a healthcare provider. This page explains our role in relation to HIPAA and protected health information.
Effective Date: August 20, 2026Last Updated: August 20, 2026
This page explains Mindward Collective’s relationship to health information and to HIPAA. It is written for the healthcare organizations we work with, and for anyone who arrives here looking for a healthcare provider’s privacy notice.
This is not a Notice of Privacy Practices
A Notice of Privacy Practices is a document that healthcare providers and health plans give to patients. Mindward is neither. If you are a patient looking for your provider’s Notice of Privacy Practices, or for information about your own medical records, please contact that healthcare organization directly.
Mindward is not a healthcare provider
Mindward Collective is a marketing agency. We provide marketing strategy, media buying, search and content services, creative, web design and development, analytics and related technology services to mental health, behavioral health and healthcare organizations.
We do not provide, and nothing on this website should be taken as an offer to provide:
- Medical care of any kind
- Mental health treatment
- Behavioral health or substance use treatment
- Diagnosis or clinical assessment
- Medication management
- Crisis, emergency or urgent care services
- Case management, referrals to treatment, or clinical advice
Mindward is not a covered entity under HIPAA. We are not a health plan, a healthcare clearinghouse or a healthcare provider.
Where HIPAA does apply to our work
Some client engagements require Mindward to create, receive, maintain or transmit protected health information (“PHI”) on behalf of a healthcare client. Where that happens, Mindward may function as a business associate under HIPAA with respect to that engagement.
When we act as a business associate:
- We enter into a business associate agreement with the client where one is required.
- Our handling of PHI is governed by that agreement, by the HIPAA Rules as they apply to business associates, and by other applicable law.
- We use and disclose PHI only as the agreement and applicable law permit, and for the purposes the client has engaged us to perform.
- We remain accountable to the client for the obligations we accept in that agreement.
Not every engagement involves PHI. Many do not. Whether HIPAA applies to a particular piece of work is a question we and the client address at the outset, before the work begins.
We describe our experience working inside HIPAA-regulated environments, and the safeguards that apply when we act as a business associate. We do not represent that Mindward holds a HIPAA certification — no such certification exists — or that any particular engagement, platform or vendor is compliant without the specific review that question deserves.
PHI and marketing
Marketing that touches PHI carries restrictions that ordinary marketing does not. HIPAA limits the use and disclosure of PHI for marketing purposes, and in many cases requires patient authorization.
Our position is straightforward:
- We do not use PHI we receive from a client to market unrelated products or services to that client’s patients.
- We do not sell patient lists, patient records or PHI, and we do not acquire them for our own use.
- Where a client asks us to support a communication that involves PHI, we look to the client — as the covered entity — to determine what HIPAA permits, what requires authorization, and what the applicable state law requires.
Minimum necessary
Where the HIPAA minimum necessary standard applies, requests for and uses of PHI should be limited to the information reasonably needed for the purpose at hand. In practice this means we would rather receive de-identified or aggregated information than PHI, and we ask for access to a client’s systems only where the work genuinely requires it and only at the level it requires.
Tracking technologies on healthcare websites
This deserves its own section, because it is the area where healthcare marketing most often goes wrong.
Analytics platforms, advertising pixels, conversion tags, session-recording tools, chat widgets and similar technologies work by transmitting information to a third party. On a healthcare organization’s website, the information transmitted can include more than it appears to — for example:
- IP addresses, which regulators have treated as identifying in a health context
- Device and browser identifiers, and advertising cookie identifiers
- The URL of the page being viewed, which may itself reveal a condition, service line or treatment program
- URL parameters, including terms carried over from a search or a campaign
- Form field contents, where a tool captures them
- Appointment, scheduling or portal interactions
Where a page relates to a specific condition or service, the combination of an identifier and the page being viewed may be enough to constitute PHI. That is why these tools require deliberate review on a healthcare client’s website before they are deployed, rather than being installed by default.
Our practice is to raise this question with clients, to distinguish between pages that carry that risk and pages that do not, and to look for configurations that meet the client’s measurement needs without transmitting information that should not leave their environment. Decisions about what a covered entity deploys on its own website rest with that covered entity.
A cookie banner does not, by itself, resolve any of this. Consent tooling can be a useful part of a privacy program, but website consent is not the same thing as a HIPAA authorization, and presenting a banner does not make an otherwise impermissible disclosure of PHI permissible.
Information about the tracking technologies used on this website — Mindward’s own site — is set out in our Privacy Policy.
Website forms
There is an important difference between a marketing contact form and a form built to collect patient information.
The form on our contact page is a business inquiry form. It exists so that organizations can start a conversation with us, and it collects business contact details and whatever the sender chooses to write. It is not designed, configured or intended to receive PHI, and we ask that it not be used for that purpose.
Forms intended to collect patient information — intake forms, appointment requests, eligibility or insurance forms — require different handling: appropriate agreements with the vendors involved, appropriate transmission and storage arrangements, and appropriate limits on where submissions are routed and what else on the page can observe them. When we build or advise on those forms for a client, we treat them as a distinct category of work.
Vendors and subcontractors
Where a vendor or subcontractor would create, receive, maintain or transmit PHI in the course of work we perform for a healthcare client, appropriate contractual protections should be in place before that happens, including a business associate agreement where one is required. Selecting and approving vendors for a covered entity’s environment is a decision made with the client, not one we make unilaterally on their behalf.
Security
We maintain reasonable administrative, technical and organizational safeguards appropriate to the work we perform, including access controls, limiting access to information to those who need it, and reviewing our practices from time to time. Where a business associate agreement imposes specific requirements, those requirements govern.
No safeguard is absolute, and we do not guarantee that information will never be subject to unauthorized access.
Security incidents
If we become aware of a security incident affecting a client’s PHI in our possession, our practice is to investigate promptly, take reasonable steps to contain and mitigate it, and notify the affected client in accordance with the applicable business associate agreement and applicable law. The healthcare organization, as the covered entity, generally leads any determination about whether a breach occurred and any notification to individuals or regulators, and we support that process as required.
Patient requests
Patients should contact their healthcare provider directly — not Mindward — regarding:
- Access to, or copies of, medical records
- Requests to amend a record
- Requests to restrict a use or disclosure
- An accounting of disclosures
- Requests for confidential communications
- Questions about a provider’s Notice of Privacy Practices
- HIPAA privacy complaints
Mindward does not hold or control patient records and cannot act on these requests. Where a client asks us to assist with a request, and our agreement and applicable law permit it, we will support the client in doing so.
Individuals also have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights.
No medical or emergency services
This website is not a route to care. Do not use this website, our contact form, our email addresses or our phone numbers to seek treatment, clinical advice or emergency assistance. If you are experiencing a medical or mental health emergency, call 911 or go to your nearest emergency department. In the United States, the 988 Suicide & Crisis Lifeline can be reached by calling or texting 988.
Changes to this page
We may update this page as our practices, our services or the applicable rules develop. When we do, we will revise the “Last Updated” date at the top.
Contact us
Questions about this page, about our role on a particular engagement, or about a business associate agreement can be sent to info@mindwardcollective.com.