Privacy Policy
Effective Date: May 23, 2026
​
Important Notice
This Privacy Policy serves as both our general website privacy policy and our HIPAA Notice of Privacy Practices as required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations. Please read this document carefully.
Â
1. Who We Are
Mirabelle Care (formerly KidsChoice Therapy and Play Center) is a HIPAA-covered healthcare provider specializing in applied behavior analysis (ABA) therapy and play-based therapeutic services for children. We are committed to protecting the privacy and security of all information entrusted to us.
For questions or concerns regarding this Privacy Policy, contact us at:
-
Email: contact@mirabellecare.com
-
Website: mirabellecare.com
Â
2. Information We Collect
Protected Health Information (PHI)
As a healthcare provider, we collect and maintain Protected Health Information (PHI) which may include:
-
Patient name, date of birth, and contact information
-
Diagnosis and treatment information
-
Insurance and billing information
-
Clinical notes and progress records
-
Any other information that identifies a patient and relates to their health or treatment
Â
Website and Contact Form Information
When you interact with our website or contact forms, we may collect:
-
Name and contact details you voluntarily provide
-
Information submitted through our intake or inquiry forms
-
Technical information such as browser type and IP address for website security purposes
Â
Important Notice Regarding Online Forms: Our website may contain forms that collect health-related information. Any information submitted through these forms is transmitted to and stored within Microsoft 365 services, which operate under a Business Associate Agreement (BAA) with Mirabelle Care as required by HIPAA. While we take reasonable measures to protect your information, please be aware that internet transmission carries inherent risks. Do not submit highly sensitive clinical information through public web forms unless specifically directed by our staff.
Â
3. How We Use Your Information
Â
Permitted Uses Under HIPAA
We may use and disclose your PHI without your authorization for the following purposes:
-
Treatment: Providing, coordinating, and managing your care and related services
-
Payment: Processing billing, insurance claims, and payment for services rendered
-
Healthcare Operations: Quality assessment, compliance activities, staff training, and business management
-
As Required by Law: Disclosures required by federal, state, or local law
-
Public Health Activities: Reporting to public health authorities as required
-
Abuse or Neglect Reporting: As required by law for child abuse or neglect
-
Health Oversight Activities: Audits, investigations, and inspections by government agencies
-
Judicial Proceedings: In response to court orders or legal process
-
Law Enforcement: Under specific circumstances as permitted by law
-
Serious Threat to Health or Safety: To prevent or lessen a serious and imminent threat
Â
Uses Requiring Your Authorization
We will obtain your written authorization before using or disclosing your PHI for:
-
Marketing purposes
-
Sale of your PHI
-
Psychotherapy notes (where applicable)
-
Any other purpose not described in this notice
You may revoke any authorization in writing at any time, except where we have already acted in reliance on it.
Â
4. Your HIPAA Rights
As a patient or guardian of a patient, you have the following rights regarding PHI:
Â
Right to Access
You have the right to inspect and obtain a copy of your PHI maintained in our records. Requests must be submitted in writing. We may charge a reasonable fee for copies.
Â
Right to Amend
You may request that we amend your PHI if you believe it is incorrect or incomplete. We may deny your request under certain circumstances and will provide written explanation if denied.
Â
Right to an Accounting of Disclosures
You have the right to request a list of disclosures we have made of your PHI, except for disclosures made for treatment, payment, or healthcare operations.
Â
Right to Restrict
You may request restrictions on how we use or disclose your PHI. We are not required to agree to all requests but will consider each individually.
Right to Confidential Communications
You may request that we communicate with you in a specific way or at a specific location. We will accommodate reasonable requests.
Â
Right to a Paper Copy of This Notice
You may request a paper copy of this Notice at any time, even if you have received it electronically.
Â
Right to be Notified of a Breach
You have the right to be notified in the event of a breach of unsecured PHI affecting your information.
Â
5. How We Protect Your Information
Mirabelle Care implements comprehensive administrative, physical, and technical safeguards to protect your PHI in accordance with the HIPAA Security Rule, including:
-
Microsoft 365 Business Premium platform with active HIPAA Business Associate Agreement
-
Multi-factor authentication required for all staff accessing patient data
-
Conditional Access policies restricting unauthorized access
-
Data Loss Prevention policies to prevent unauthorized PHI disclosure
-
Encryption of data in transit and at rest
-
Regular security assessments and staff training
-
Audit logging and monitoring of all system activity
-
Remote wipe capability on all devices used for patient care
Â
6. Business Associates
We may share your PHI with third-party vendors and service providers (Business Associates) who assist us in providing services. All Business Associates are required to sign a Business Associate Agreement obligating them to protect your PHI in accordance with HIPAA.
Our current Business Associates include Microsoft Corporation (cloud services and email), and other vendors as required for clinical operations. A full list is available upon request.
Â
7. Cookies and Website Tracking
Our website may use cookies and similar tracking technologies for basic website functionality and security. We do not use tracking technologies that would expose PHI to third parties without appropriate authorization. We do not sell your personal information or use it for advertising purposes.
Â
8. Children's Privacy
Mirabelle Care primarily serves children with autism spectrum disorder and related conditions. All PHI for patients under 18 is governed by the privacy rights of the parent or legal guardian in accordance with applicable law. We take additional care to protect information regarding minors and comply fully with applicable federal and state laws regarding children's health privacy.
Â
9. State Law
Where state law provides greater privacy protections than HIPAA, we will comply with the more protective state law. Patients in Oklahoma are additionally protected by applicable state healthcare privacy regulations.
Â
10. Changes to This Notice
We reserve the right to change this Notice and make the new provisions effective for all PHI we maintain. If we make material changes, we will post the updated Notice on our website and make copies available at our clinic locations. The effective date at the top of this document reflects the most recent revision.
Â
11. Complaints
If you believe your privacy rights have been violated, you may file a complaint with us or with the U.S. Department of Health and Human Services Office for Civil Rights. You will not be retaliated against for filing a complaint.
To file a complaint with us, contact:
-
Email: contact@mirabellecare.com
-
Address: Available upon request at any clinic location
Â
To file a complaint with HHS OCR:
-
Website: hhs.gov/ocr/privacy/hipaa/complaints
-
Phone: 1-800-368-1019
Â
12. Contact Us
For questions about this Privacy Policy or to exercise your rights, please contact us at:
-
Email: contact@mirabellecare.com
-
Website: mirabellecare.com
Â
This Notice of Privacy Practices is required by HIPAA (45 CFR 164.520) and describes how Mirabelle Care may use and disclose your Protected Health Information and your rights regarding that information. Mirabelle Care is required by law to maintain the privacy of your PHI, to provide you with notice of our legal duties and privacy practices, and to notify you following a breach of your unsecured PHI.

.png)