Arizona ESA LetterLicensed Arizona clinicians

HIPAA compliance

Your health information is protected by federal law and by the way we build our systems. This page explains both, without the legal fog.

HIPAA Compliant
256-bit SSL Encrypted
FHA Compliant Letters
ADA Compliant Letters
No Charge If Not Approved

Effective September 2, 2026. This page explains, in plain language, how Arizona ESA Letter and the clinicians who work with us protect the health information you share with us.

What HIPAA means here

The Health Insurance Portability and Accountability Act sets national rules for how protected health information is used, stored and shared. The clinicians who evaluate you are covered health care providers under HIPAA, and the systems we use to support them are operated under business associate agreements that hold our vendors to the same standard.

Protected health information means anything that identifies you and relates to your health: your name paired with a symptom, your consultation notes, your letter, your appointment record.

How we protect your information

Encryption in transit

Every page, form and video consultation runs over TLS with 256-bit encryption. Nothing about your evaluation travels in the clear.

Encryption at rest

Stored records are encrypted on disk. Backups are encrypted with the same standard.

Access on a need-to-know basis

Only the clinician handling your evaluation and the small support team who need to help you can reach your record.

Audit logging

Access to records is logged. Unusual access patterns are reviewed.

Vendor agreements

Every vendor that touches health information signs a business associate agreement before it is given access.

Staff training

Everyone who handles client information is trained on privacy and security obligations, and retrained when rules change.

When we may share your information

Only in specific situations:

  • Treatment. With the clinician evaluating you, and with another provider if you ask us to.
  • Payment. With our payment processor, which receives the minimum needed to process your transaction and never receives your clinical information.
  • Operations. With vendors under business associate agreements, such as our secure hosting and scheduling providers.
  • Because you told us to. If you give written authorization for us to send your letter to a landlord, university or airline, we send exactly what you authorized.
  • Because the law requires it. A valid court order, subpoena or legal obligation, or a situation involving a serious and imminent threat to health or safety.

We do not sell your health information. We do not use it for advertising. We do not share it with your landlord, employer or anyone else unless you authorize it in writing.

Your rights over your record

  • See it. Request a copy of your health record.
  • Correct it. Ask us to amend information you believe is inaccurate.
  • Know who saw it. Request an accounting of certain disclosures.
  • Limit it. Request restrictions on how your information is used or shared. We will consider every request, though we cannot always agree.
  • Choose how we contact you. Ask us to reach you at a specific address or by a specific method.
  • Get a paper copy. Request this notice on paper even if you agreed to electronic delivery.
  • Complain. To us, or directly to the HHS Office for Civil Rights. We will never retaliate against you for filing a complaint.

To exercise any of these, email support@arizonaesaletter.org with the subject line "Privacy request". We respond within 30 days, and sooner where we can.

If a breach ever happens

Under the HIPAA Breach Notification Rule we must notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information, notify HHS, and notify media where a breach affects more than 500 residents of a state. We would tell you what happened, what information was involved, what we are doing about it, and what you should do.

How long we keep records

Clinical records are retained for the period required by Arizona law and professional standards, which is generally at least six years for adult records. After that they are securely destroyed. You may request deletion of information we are not legally obliged to retain.

Privacy and HIPAA questions

Will my landlord ever see my medical information?

No, unless you send it to them yourself. Your letter is written to confirm a disability-related need without disclosing your diagnosis or clinical details, which is exactly how a housing accommodation letter should read.

Is a video consultation actually HIPAA compliant?

Yes, when it runs on a platform that supports encryption and operates under a business associate agreement, which is what we use. Consumer video apps without those protections are not used for clinical consultations.

What does 256-bit SSL encryption really mean?

It means the connection between your device and our servers is scrambled with a key long enough that intercepting it is not practical. It protects your information while it moves. Encryption at rest, which we also use, protects it while it sits stored.

Can I get a copy of everything you hold about me?

Yes. Email support with the subject line 'Privacy request' and we will provide your record within 30 days.

Who do I complain to if I think my privacy was violated?

Email us first so we can investigate. You may also file directly with the HHS Office for Civil Rights, and we will not retaliate in any way for doing so.

Official sources for this page

Every legal statement on this page traces back to a primary source. Open any of them and read the original text for yourself.

  1. HHS — HIPAA for IndividualsThe official explanation of your health privacy rights from the U.S. Department of Health and Human Services.
  2. HHS — HIPAA Privacy RuleThe full text and summary of the rule governing use and disclosure of protected health information.
  3. HHS — HIPAA Security RuleThe standards for safeguarding electronic protected health information that our systems are built to.
  4. HHS — Breach Notification RuleThe notification obligations we would follow if a breach of unsecured health information occurred.
  5. HHS Office for Civil Rights — File a Health Information Privacy ComplaintHow to report a suspected privacy or security violation directly to the federal regulator.
  6. 45 CFR Part 164 — Security and PrivacyThe federal regulation text behind the HIPAA Privacy, Security and Breach Notification Rules.
  7. HHS Telehealth — Policy and best practicesFederal guidance on delivering telehealth care in line with privacy requirements.

Ready to start your evaluation?

Pick a time that suits you. Most people finish the consultation in under 20 minutes, and approved letters arrive within 15 minutes of sign-off.

Book my appointmentSee pricing