Blooming Sprigs (“we,” “us,” or “our”), operated by Natasha Mitchner-Soares, LICSW,
provides clinical social work and counseling services in Rhode Island. This Privacy
Policy explains how we collect, use, protect, and share information when you visit
bloomingsprigs.com (the “Site”) or contact us through it.
This policy covers the website only. Information you share with us as a client in
the course of treatment is protected health information (“PHI”) governed by our
Notice of Privacy Practices under HIPAA, which is provided to clients separately
and takes precedence for all treatment-related information.
—
1. Information We Collect
a. Information you provide through our secure contact form
Our contact and consultation-request form is provided by **LuxSci SecureForm**, a
HIPAA-compliant secure form service with whom we maintain a Business Associate
Agreement (BAA). When you submit the form, the information you enter — such as your
name, email address, phone number, and the reason for your inquiry — is transmitted
in encrypted form directly to LuxSci’s secure infrastructure and delivered to us
through encrypted channels. This information is not stored on the Site’s own server.
Because inquiries to a therapy practice may themselves reveal health-related
information, we treat all form submissions with the same care as PHI, whether or
not you become a client.
b. Information collected automatically
Like most websites, the Site collects certain technical information automatically
when you browse:
– Browser type, device type, and operating system
– Pages visited, time spent, and referring website
– IP address (which may indicate your approximate geographic location)
– Cookies and similar technologies (see Section 4)
This automatic collection applies to general Site browsing. It is separate from,
and never includes the contents of, secure form submissions.
2. How We Use Information
We use information collected through the Site to:
– Respond to your inquiries and schedule consultations
– Provide, improve, and secure the Site
– Understand, in aggregate, how visitors use the Site
– Comply with legal obligations
We do **not** sell, rent, or trade your personal information. We do not use
information submitted through the secure contact form for marketing.
3. HIPAA and Your Health Information
If you become a client, our collection, use, and disclosure of your health
information is governed by HIPAA and described in our **Notice of Privacy
Practices**, available upon request and provided at intake. Nothing in this website
Privacy Policy limits the protections that apply to PHI.
Website inquiries submitted through the LuxSci SecureForm are handled under
HIPAA-compliant safeguards: encryption in transit and at rest on LuxSci systems,
access limited to Natasha Mitchner-Soares, and a signed Business Associate Agreement
with LuxSci Inc.
Please do not submit detailed health information through any channel other than
the secure form (for example, do not include sensitive details in a standard email
or social media message).
4. Cookies, Analytics, and Embedded Content
The Site uses the following third-party technologies on general (non-form) pages:
– **Google Analytics** — collects aggregate usage statistics (pages visited,
session duration, approximate location from IP). Google may set cookies such as
`_ga`. You can opt out via Google’s browser add-on
(https://tools.google.com/dlpage/gaoptout) or your browser’s cookie settings.
– **Meta (Facebook) Pixel** — may collect page-visit events for advertising
measurement. You can limit ad tracking through your Facebook ad preferences and
browser settings.
– **YouTube embedded video** — pages with embedded video load content from
YouTube/Google, which may set its own cookies when you play a video.
These tools receive technical browsing data only. They do not receive the contents
of secure form submissions. [Confirm before publishing — see operator note 1.]
You can disable cookies in your browser settings; the Site remains usable with
cookies disabled.
5. How We Share Information
We share information only:
– **With service providers** who help operate the Site and our practice (secure
form provider LuxSci; website hosting provider BlueHost, bound by
confidentiality obligations and, where PHI is involved, Business Associate
Agreements
– **When required by law**, including mandatory reporting obligations that apply to
licensed clinical social workers, court orders, or lawful requests by public
authorities
– **To protect safety**, where disclosure is necessary to prevent serious harm,
consistent with applicable law and professional ethics
6. Data Retention
Website inquiry information is retained only as long as needed to respond and, if
you become a client, is incorporated into your clinical record, which is retained
as required by Rhode Island law and professional regulations. Aggregate analytics
data is retained according to the third-party provider’s schedule.
7. Security
We use commercially reasonable safeguards to protect information collected through
the Site, including HTTPS encryption across the Site, a HIPAA-compliant encrypted
form service for all inquiries, and restricted access to submitted information. No
method of transmission over the Internet is 100% secure, but inquiries submitted
through the secure form receive protections designed for health information.
8. Children’s Privacy
The Site is not directed to children under 13, and we do not knowingly collect
personal information from children under 13 through the Site. Clinical services
for children and adolescents are arranged by a parent or legal guardian, and all
related information is handled under HIPAA and our Notice of Privacy Practices.
9. Your Rights and Choices
Depending on your circumstances and applicable law, you may:
– Request access to, correction of, or deletion of personal information we hold
about you from Site interactions
– Opt out of analytics cookies (Section 4)
– If you are a client, exercise the rights described in our Notice of Privacy
Practices (including access to your records and requests for restrictions)
To exercise any of these rights, contact us using the details in Section 12.
10. Third-Party Links
The Site may link to other websites (for example, professional resources). We are
not responsible for the privacy practices of other sites and encourage you to read
their policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last Updated” date above
reflects the most recent revision. Material changes will be posted on this page.
12. Contact Us
Blooming Sprigs
Natasha Mitchner-Soares
Rhode Island
Email: [email protected]
Phone: (401) 479-0725
