Privacy Policy

Last Updated: October 2025

1. Introduction

At Little Steps Behavior Therapy PLLC ("we," "our," or "us"), we take your privacy seriously. This policy explains what information we collect, how we use it, and how you can control it.

2. Information We Collect

Personal Information

When you fill out our contact or appointment forms, we collect only what's necessary—your name, email address, phone number, and any clinical details you choose to share. All clinical information you provide is treated as Protected Health Information (PHI) under HIPAA.

Cookies & Tracking

We use cookies and similar technologies to keep our website secure and understand how visitors use our site. Because we are a HIPAA-regulated healthcare provider, we do NOT use advertising or tracking cookies that could identify you or link you to health-seeking behavior.

  • Strictly necessary cookies keep the site functioning (for example, remembering your cookie consent preference and securing your session).
  • Analytics cookies (via Google Analytics with HIPAA safeguards) help us understand aggregate website traffic patterns in a way that cannot identify individual visitors. We have configured Google Analytics to:
    • Anonymize your IP address
    • Disable advertising features and cross-device tracking
    • Prevent data sharing with Google's advertising networks

These cookies are only activated after you provide consent through our cookie banner. You can withdraw or change your preferences at any time. For more information, see our Cookie Policy.

Important: We do NOT use cookies to collect, store, or track Protected Health Information (PHI). We do NOT use advertising cookies, remarketing pixels, or any tracking technology that could identify you as seeking behavioral health services.

3. How We Use Your Information

To Provide Services

We use your PHI to schedule appointments, conduct assessments, and deliver ABA therapy.

To Communicate

We may email or call you about appointments, billing questions, or updates to our services. You can opt out of non-essential messages at any time.

For Analytics Only

With your consent, we use Google Analytics (configured with HIPAA-compliant settings) to understand aggregate website usage patterns. This helps us improve our website experience. We do NOT use advertising tracking or conversion pixels.

For Security & Compliance

We maintain audit logs and secure server configurations to comply with HIPAA and protect your data.

4. Data Sharing & Disclosure

We will never sell, rent, or share your personal information with third parties for unrelated marketing purposes. We may share PHI only with:

  • Your Insurer: For billing and authorization purposes, with your permission.
  • Business Associates: Such as our secure email or cloud-storage providers, each bound by a Business Associate Agreement (BAA) to handle PHI safely.
  • Google Analytics: For HIPAA-compliant website analytics only. We have signed a Business Associate Agreement (BAA) with Google and configured Analytics to anonymize visitor data and disable all advertising features. Learn more about Google Analytics' privacy practices.
  • Legal Requirements: If required by law (e.g., a court order), but only after we've sought to limit disclosure whenever possible.

5. Data Retention & Security

We retain your records only as long as required by law and professional guidelines. We use industry-standard technical safeguards—including encryption in transit, access controls, and regular risk assessments—to keep your information secure.

6. Your Rights

Under HIPAA and Texas privacy regulations, you have the right to:

  • Access or obtain copies of your PHI
  • Request corrections to any errors in your records
  • Receive an accounting of certain disclosures we've made
  • Restrict communications or billing disclosures to insurance (where applicable)

To exercise any of these rights, please contact us at:

  • Little Steps Behavior Therapy PLLC
  • Phone: (817) 601-7526
  • Email: compliance@ls-bt.com

7. What We Do NOT Do

To protect your privacy and comply with HIPAA regulations, we explicitly DO NOT:

  • Use advertising cookies or pixels to track you
  • Share your data with advertising networks
  • Use remarketing or retargeting to follow you around the internet
  • Track you across devices or websites
  • Sell or rent your personal information
  • Use social media tracking pixels (Facebook Pixel, LinkedIn Insight Tag, etc.)

8. Children's Privacy

Our services are designed for children, but our website is directed toward parents and guardians. We do not knowingly collect personal information from children under 13 through our website. Any health information about children is collected through our secure intake process and protected under HIPAA.

9. Updates to This Policy

We may update this policy from time to time. The "Last Updated" date at the top will reflect the most recent revision. We encourage you to check back periodically.

10. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

  • Phone: (817) 601-7526
  • Email: compliance@ls-bt.com
  • Mail: Little Steps Behavior Therapy PLLC, Grapevine, TX 76051