top of page

Website Privacy Policy

Effective Date: August 01, 2026
Last Updated: August 01, 2026
 

This Website Privacy Policy explains how In Situ Counseling & Coaching, LLC (“In Situ,” “we,” “us,” or “our”) handles information collected through or generated by www.insitucounseling.com and related public website features. It applies primarily to general website activity and information submitted by website visitors.

Protected health information maintained in connection with covered counseling services is also governed by our Notice of Privacy Practices and applicable federal and Illinois health-privacy law. When this Website Privacy Policy and a health-privacy requirement overlap, the more protective applicable requirement controls.

1. Information You Choose to Provide

Depending on the website features you use, you may provide information such as:

 

Name

Email address

Phone number

Preferred contact information

Scheduling or consultation information

A message or brief description of why you are contacting the practice

Other information you voluntarily submit through an active website feature

Please do not place detailed diagnoses, medication information, trauma history, medical records, safety plans, emergency information, or other unnecessary sensitive clinical details in a general website message field.

Submitting a website form or inquiry does not by itself create a therapist-client relationship. However, identifiable health information submitted to or collected by a covered health care provider may be protected by HIPAA or other privacy law even before a formal treatment relationship is established.

2. Information Collected Automatically

When you visit the website, the website platform and configured service providers may automatically process technical information needed to operate, secure, and maintain the site. Depending on the settings and tools actually enabled, this may include:

 

IP address

Browser and device information

Operating system

Approximate geographic region derived from technical data

Pages or features viewed

Referring page or source

Date and time of visits

Security, fraud-prevention, diagnostic, and performance data

Cookie identifiers and similar technical information

This information is generally used to understand how the website functions, maintain security, diagnose technical issues, and improve website performance and usability.

3. Cookies and Similar Technologies

The website may use cookies and similar technologies for essential operation, security, functionality, and limited site-performance or analytics purposes. Optional technologies should be configured consistently with applicable privacy requirements.

Where the website provides cookie controls, you may use those controls to manage optional categories. You may also be able to block or delete cookies through your browser. Disabling certain technologies may affect website functions.

4. HIPAA and Online Tracking Technologies

Health care websites require special care when analytics, pixels, session-replay tools, advertising technologies, tag managers, or similar tracking tools are used. A visitor's information may become PHI when identifiable information is connected to the person's health, health care, or payment for health care.

In Situ does not rely on a cookie banner, privacy policy, or general website consent as a substitute for a HIPAA-compliant authorization. We do not intentionally disclose PHI to a tracking or analytics vendor unless the disclosure is permitted by HIPAA and other applicable law and the required safeguards, including a Business Associate Agreement when required, are in place.

Pages or features capable of receiving PHI should not be configured to transmit that PHI to an unrelated analytics, advertising, or tracking vendor without a valid legal basis.

5. Wix Website Platform and PHI Protection

This website is hosted on Wix. When a Wix feature is used to collect, store, or process PHI on behalf of the practice, In Situ's policy is to use Wix's HIPAA-capable configuration, including PHI Protection and a Business Associate Agreement, and to use only features appropriate for PHI.

Visitors should understand that Wix and any other technology provider may process technical information as part of providing hosting, security, and website functions. In Situ remains responsible for configuring its site and connected services consistently with applicable privacy and security requirements.

6. How We Use Website Information

We may use website information for legitimate practice and website purposes, including to:

  • Respond to questions or requests

  • Provide requested information

  • Arrange or facilitate consultation and scheduling requests

  • Operate, maintain, secure, and troubleshoot the website

  • Understand general website performance and usability

  • Prevent misuse, fraud, or security incidents

  • Maintain appropriate business and compliance records

  • Comply with legal obligations and enforce lawful rights

If information becomes part of a clinical, billing, or other protected health record, it will be handled under the applicable health-privacy requirements, including the Notice of Privacy Practices.

7. How We Share Website Information

We do not sell PHI. We do not sell personal information submitted through the website for monetary payment, and we do not use PHI for cross-context behavioral advertising.

We may disclose website information only as reasonably necessary and legally permitted to:

  • Provide website hosting, security, email, communications, scheduling, billing, analytics, or administrative functions through service providers configured for the applicable type of information

  • Respond to your request or carry out an action you ask us to take

  • Protect the rights, safety, security, or property of In Situ, a visitor, a client, or another person when permitted by law

  • Investigate fraud, misuse, or a security incident

  • Comply with applicable law, lawful process, regulatory obligations, or legally enforceable requests

  • Complete a lawful business reorganization, transfer, or succession subject to applicable confidentiality and privacy obligations

When a vendor creates, receives, maintains, or transmits PHI on behalf of In Situ as a HIPAA business associate, In Situ requires the relationship and disclosure to be handled in accordance with HIPAA, including a Business Associate Agreement when required.

8. External Scheduling, Billing, Directory, and Other Services

The website may link to third-party services such as Headway, directories, insurers, payment services, maps, social-media platforms, or other external resources. When you leave the In Situ website and interact directly with an independent third party, that third party's privacy policy and terms generally govern its collection and use of information.

A third-party link does not mean that all information handled by that service is controlled by In Situ. Where a third party acts as our business associate or otherwise handles PHI on our behalf, applicable HIPAA and contractual requirements also apply.

9. Email and Electronic Communications

Ordinary email and general website messaging should be used for limited administrative communication unless the applicable system has been configured for the information being transmitted. Do not use general electronic communications for emergencies.

No electronic transmission or storage method is completely risk free. In Situ uses safeguards required by applicable law and limits access to information based on legitimate practice needs.

10. Data Security

In Situ maintains reasonable administrative, technical, and physical safeguards appropriate to the type of information it maintains and as required by applicable law. These measures are intended to reduce risks of unauthorized access, acquisition, destruction, use, modification, or disclosure.

If a breach or security incident triggers notification duties under HIPAA, the Illinois Personal Information Protection Act, or another applicable law, In Situ will provide required notifications.

11. Data Retention and Disposal

Website-related information is retained only for as long as reasonably necessary for the purpose for which it was collected, for legitimate business or security needs, or to satisfy legal, contractual, insurance, billing, or record-retention requirements.

Information incorporated into a clinical or billing record may be subject to different retention requirements. When personal information is disposed of, In Situ uses methods designed to render the information unreadable, unusable, or otherwise inaccessible as required by applicable law.

12. Children's Privacy

The general public website is not directed to children under 13, and In Situ does not knowingly use ordinary public website features to solicit personal information directly from children under 13. This statement does not prevent the practice from providing counseling to adolescents when appropriate consent, authorization, confidentiality, and other legal requirements are satisfied.

A parent or legal guardian who believes a child under 13 submitted personal information through the general website may contact In Situ so the matter can be reviewed.

13. Your Website-Privacy Requests

Subject to applicable law and legitimate record-retention requirements, you may contact us to:

  • Ask what general website information you previously submitted

  • Request correction of inaccurate contact information

  • Request deletion of website-submitted information when deletion is legally and operationally appropriate

  • Withdraw from optional nonclinical email communications

  • Ask questions about website privacy practices

  • Report a privacy or security concern

Requests involving PHI, clinical records, or HIPAA rights will be handled under the Notice of Privacy Practices and the applicable clinical-record procedures rather than solely under this Website Privacy Policy.

14. Privacy Rights Based on Your Location

Privacy rights vary by jurisdiction and may depend on the nature of the information, the purpose for which it is processed, and whether a particular privacy law applies to In Situ. We will respond to legally applicable privacy requests as required. Nothing in this policy limits a right that cannot lawfully be waived.

15. Changes to This Policy

We may revise this Website Privacy Policy when website features, vendors, business practices, or legal requirements change. The current version will be posted on the website with an updated effective or last-updated date. Material changes affecting PHI will also be addressed through the Notice of Privacy Practices when required.

16. Contact Us About Website Privacy

In Situ Counseling & Coaching, LLC

Ron Henson, LCPC

2710 College Avenue

Alton, Illinois 62002

Phone: 618-539-2149

Email: ron@insitucounseling.com

Website: www.insitucounseling.com

bottom of page