Policies
HIPAA Policy
Written By Why.Help. Last reviewed . 3 min read.
The short answer
why.help is an educational and referral website, not a healthcare provider, health plan, or healthcare clearinghouse. That means we are generally not a "covered entity" under HIPAA (the Health Insurance Portability and Accountability Act), and information you read on this site is not, by itself, subject to HIPAA protection in the way information shared with your doctor or therapist is.
Key points
- why.help is a publisher, not a covered healthcare entity, so HIPAA generally does not apply to this site.
- Do not send health details through our contact form. Nothing here is designed to receive them securely.
- HIPAA protects information you share with an actual treatment provider, not general web browsing.
- Treatment providers can share limited information with family in specific situations, but not by default.
Is why.help a healthcare provider?
why.help is an educational and referral website, not a healthcare provider, health plan, or healthcare clearinghouse. That means we are generally not a "covered entity" under HIPAA (the Health Insurance Portability and Accountability Act), and information you read on this site is not, by itself, subject to HIPAA protection in the way information shared with your doctor or therapist is.
Because of that, do not send us your diagnosis, your treatment history, medication names, or anything else you would consider protected health information. Our contact form is not built to receive or store that kind of detail securely, because it is not meant to.
Where this changes
Once you call a treatment center, book an appointment, or start care with a licensed provider, you are now interacting with an entity that is typically covered by HIPAA. That relationship comes with real protections: your records generally cannot be shared with your employer, your family, or anyone else without your written authorization, except in specific legally defined situations. Ask any provider directly how they handle your records before you disclose anything you are not comfortable having documented.
What we recommend regardless
If any page ever includes a form asking for health details, we commit to encrypted storage, restricted access, and no disclosure to third parties without consent, even in cases where that is not strictly required of us by law. That said, we recommend disclosing sensitive health details to hotlines and licensed providers, such as 988 or the National Problem Gambling Helpline, rather than to a website contact form, even one that takes privacy seriously.
What does HIPAA actually protect, and where?
HIPAA sets rules for how covered entities, meaning doctors, hospitals, clinics, insurers, and their business associates, handle your protected health information. The U.S. Department of Health and Human Services defines those covered entities and the rules that bind them. Once you contact an actual treatment provider, HIPAA generally covers what you tell them and what they record about you, including how they store your records, who inside the organization can see them, and under what circumstances they can share information outside that organization.
How can, and can't, a provider share your information?
Providers can generally share information for your own treatment, for payment processing with your insurer, and for certain limited operational purposes. They can also share it when required by law, such as specific court orders, or in narrow safety situations. What they generally cannot do is share your records with your employer, tell your family you are in treatment without your authorization, or disclose your information to a third party for marketing.
What rights do you have over your health records?
You generally have the right to see and get a copy of your own health records, to request corrections to them, to know who they have been shared with in certain cases, and to request restrictions on how they are used.
What if you believe your privacy was violated?
If a treatment provider shared your information in a way you believe was not permitted, start by asking the provider directly. Most have a privacy officer whose job is to handle exactly this. If that does not resolve it, you can file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.
How does why.help handle any health-adjacent information it receives?
If you mention health details in a contact form message despite our recommendation not to, we treat that message with care: it is stored only as long as needed to respond to you, accessed only by the small team that handles correspondence, and never shared with a third party. But we cannot offer the specific legal protections HIPAA requires of a covered entity, because we are not one. Treat any message to us the way you would treat a message to a magazine, not a message to a clinic.
Sources
Frequently asked questions
You do not have to explain yourself to get help.
Start with the page that matches where you are right now.
See your options