Encryption in transit
Every page, form and video consultation runs over TLS with 256-bit encryption. Nothing about your evaluation travels in the clear.
Your health information is protected by federal law and by the way we build our systems. This page explains both, without the legal fog.
Effective September 2, 2026. This page explains, in plain language, how Arizona ESA Letter and the clinicians who work with us protect the health information you share with us.
The Health Insurance Portability and Accountability Act sets national rules for how protected health information is used, stored and shared. The clinicians who evaluate you are covered health care providers under HIPAA, and the systems we use to support them are operated under business associate agreements that hold our vendors to the same standard.
Protected health information means anything that identifies you and relates to your health: your name paired with a symptom, your consultation notes, your letter, your appointment record.
Every page, form and video consultation runs over TLS with 256-bit encryption. Nothing about your evaluation travels in the clear.
Stored records are encrypted on disk. Backups are encrypted with the same standard.
Only the clinician handling your evaluation and the small support team who need to help you can reach your record.
Access to records is logged. Unusual access patterns are reviewed.
Every vendor that touches health information signs a business associate agreement before it is given access.
Everyone who handles client information is trained on privacy and security obligations, and retrained when rules change.
Only in specific situations:
We do not sell your health information. We do not use it for advertising. We do not share it with your landlord, employer or anyone else unless you authorize it in writing.
To exercise any of these, email support@arizonaesaletter.org with the subject line "Privacy request". We respond within 30 days, and sooner where we can.
Under the HIPAA Breach Notification Rule we must notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information, notify HHS, and notify media where a breach affects more than 500 residents of a state. We would tell you what happened, what information was involved, what we are doing about it, and what you should do.
Clinical records are retained for the period required by Arizona law and professional standards, which is generally at least six years for adult records. After that they are securely destroyed. You may request deletion of information we are not legally obliged to retain.
No, unless you send it to them yourself. Your letter is written to confirm a disability-related need without disclosing your diagnosis or clinical details, which is exactly how a housing accommodation letter should read.
Yes, when it runs on a platform that supports encryption and operates under a business associate agreement, which is what we use. Consumer video apps without those protections are not used for clinical consultations.
It means the connection between your device and our servers is scrambled with a key long enough that intercepting it is not practical. It protects your information while it moves. Encryption at rest, which we also use, protects it while it sits stored.
Yes. Email support with the subject line 'Privacy request' and we will provide your record within 30 days.
Email us first so we can investigate. You may also file directly with the HHS Office for Civil Rights, and we will not retaliate in any way for doing so.
Every legal statement on this page traces back to a primary source. Open any of them and read the original text for yourself.
Pick a time that suits you. Most people finish the consultation in under 20 minutes, and approved letters arrive within 15 minutes of sign-off.