Clinician: Michelle Tobin, MA, LMHCA, PMP
Business: Sublime Online PLLC
Address: 1404 NE 134th St, Suite 290, Vancouver, WA 98685
Phone: (360) 207-1957
Email: michelle@sublime.online
THIS NOTICE DESCRIBES HOW INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
I understand that health information about you and your healthcare is personal. I am committed to protecting health information about you. I create a record of the care and services you receive from me. I need this record to provide you with quality care and to comply with certain legal requirements. This Notice will tell you about the ways in which I may use and disclose health information about you. I also describe your rights to the health information I keep about you and certain obligations I have regarding the use and disclosure of your health information.
Protected Health Information:
This Notice applies to protected health information (PHI) created or received by Sublime Online PLLC that identifies you; relates to your past, present, or future physical or mental condition; relates to the care provided; or relates to the past, present, or future payment for your healthcare. For example, PHI includes your demographics, symptoms, test results, diagnoses, treatment, health information from other providers, and billing and payment information relating to these services.
Your Rights:
When it comes to your protected health information (PHI), you have the right to:
• See and receive an electronic or paper copy of your health information. In most cases, you have the right to review and receive a copy of certain healthcare information, including certain medical and billing records. If you request a copy of the information, then I may charge a fee for the costs of copying, mailing, or other supplies associated with your request.
Ask for a change or addition to your health information. If you believe that information in your record is incorrect or that important information is missing, then you have the right to request in writing that I make a correction or add information. You must include a reason for the amendment in your request. I am not required to agree to the amendment of your record, but a copy of your request will be added to your record.
Ask me to contact you in a specific way (for example, home or office phone) or to send mail to a different address. You must make your request in writing (including email). I will grant all reasonable requests. Your request must specify how or where you wish to be contacted.
Ask me to limit what I use or share. You can ask me not to use or share certain health information for treatment, payment, or my operations. I am not required to agree to your request, and I may say "no" if it would affect your care. If you pay for a service or healthcare item out-of-pocket in full, then you can ask me not to share that information for the purpose of payment or my operations with your health insurer. I will say "yes" unless a law requires me to share that information.
Ask for a list of persons or entities outside of Sublime Online PLLC with whom I have shared your health information. Certain instances will not appear on the list, such as disclosures for treatment, payment, or when you have authorized the use or disclosure. Your first accounting of disclosures in a calendar year is free of charge. Any additional request within the same calendar year requires a processing fee.
Ask for a paper or electronic copy of this Notice.
Choose someone to act for you. If you have given medical power of attorney or if someone is your legal guardian, then that person can exercise your rights and make choices about your health information.
My Responsibilities:
• I am required by law to maintain the privacy and security of your PHI.
• I will let you know promptly if a breach occurs that may have compromised the privacy and security of your health information.
• I must follow the duties and privacy practices described in this Notice and give you a copy of it.
• I will not use or share your information other than as described here unless you give me written permission.
Use and Disclosure of Your Health Information:
I may use and disclose your protected health information (PHI) for the following reasons:
Provide treatment. Some examples include, but are not limited to: Your PHI may be used and disclosed by me for the purpose of providing, coordinating, or managing your healthcare treatment and any related services. This may include coordination or management of your healthcare with a third party, consultation, or supervision activities with other healthcare providers, or referral to another provider for healthcare services.
Payment purposes. Some examples include, but are not limited to: I may use your PHI to prepare claims for payment of services you have received or to communicate with other individuals or agencies to receive payment.
Maintain healthcare operations. I may use or disclose your PHI to support the business activities of my professional practice, for example, to monitor and improve healthcare services or for authorized staff to perform administrative activities.
Train staff and students. Staff or students who are in training may assist me with responsibilities.
Conduct research. An Institutional Review Board (IRB) will review each request to use or disclose your PHI to protect the rights, safety, and welfare of research subjects.
Contact you for information. Your personal information may be used to contact you to remind you about appointments, provide diagnostic results, inform you about treatment options, or advise you about other health-related benefits and services.
Consult with business associates. Your health information may be disclosed to individuals or organizations that assist me in my business activities, for example, consultants or attorneys. These business associates are required to protect the confidentiality of your information.
Other Uses and Disclosures:
I also use and disclose your information to enhance healthcare services, protect client safety, safeguard public health, ensure compliance with government and accreditation standards, and when otherwise allowed by federal and state law. For example, I provide or disclose information: 
• To government oversight agencies with data for health oversight activities authorized by law, such as auditing or licensure.
• To appropriate government agencies when I suspect abuse or neglect, as I am a mandated reporter.
• To appropriate agencies or persons when I believe it necessary to avoid a serious threat to health or safety or to prevent serious harm.
• To law enforcement when required or allowed by law.
• For court order or lawful subpoena.
• To government officials when required for specifically identified functions, such as national security.
• When otherwise required by law, such as to the Secretary of the United States Department of Health and Human Services for purposes of determining compliance with my obligations to protect the privacy of your health information. 
I have to meet many standards set forth by the law before I can share your information for these purposes. For more information, please visit: https://hhs.gov/hipaa/for-individuals/notice-privacy-practices/index.html.
Use and Disclosure Requiring Your Authorization:
Other than the uses and disclosures described above, I will not use or disclose your PHI without your written permission. Sublime Online PLLC requires your written authorization for each individual entity for sale of your information, most sharing of psychotherapy notes, and marketing purposes. You can change your mind at any time about how you authorize me to use your PHI unless disclosure is required for me to obtain payment for services already provided, I have otherwise relied on the authorization, or the law prohibits revocation.
In the cases that require your written authorization, you have both the right and choice to give me permission to:
• Share information with your family, close friends, or others involved in your care.
• Share information in a disaster relief situation.
• Contact you for fundraising efforts (but you can tell me not to contact you again).
Additional Protection of Your Health Information:
State and federal laws apply to certain classes of patient health information. For example, additional protections may apply to information about sexually transmitted diseases, drug and alcohol abuse treatment records, mental health records, and HIV/AIDS information. When required by law, I will obtain your authorization before releasing this type of information. For your protection, I adhere to WAC 246-924-363 & RCW 70.02.230.
Electronic Records Disclosure:
I keep and store records for each client in a record-keeping system produced and maintained by SimplePractice LLC. This system is "cloud-based", meaning the records are stored on servers that are connected to the Internet.
Here are the ways in which the security of these records is maintained:
I have entered into a HIPAA Business Associate Agreement with SimplePractice LLC. Because of this agreement, SimplePractice LLC is obligated by federal law to protect these records from unauthorized use or disclosure.
The computers on which these records are stored are kept in secure data centers, where various physical security measures are used to maintain the protection of the computers from physical access by unauthorized persons.
SimplePractice LLC employs various technical security measures to maintain the protection of these records from unauthorized use or disclosure.
I have my own security measures for protecting the devices that I use to access these records.
Here are things to keep in mind about my record-keeping system:
While my record-keeping company and I both use security measures to protect these records, their security cannot be guaranteed.
Some workforce members at SimplePractice LLC, such as engineers or administrators, may have the ability to access these records for the purpose of maintaining the system itself. As a HIPAA Business Associate, SimplePractice LLC is obligated by law to train their staff on the proper maintenance of confidential records and to prevent misuse or unauthorized disclosure of these records. This protection cannot be guaranteed, however.
My record-keeping company keeps a log of my transactions with the system for various purposes, including maintaining the integrity of the records and allowing for security audits. These transactions are kept for as long as Sublime Online PLLC has an account with SimplePractice LLC.
Disclosure for Third-Party Access to Communications:
I cannot guarantee the confidentiality of any form of communication through electronic media, including text, voicemail, and email. Please know that if we use electronic communications, such as text, voicemail, email, and possibly others, then there are various technicians and administrators who maintain these services and may have access to the content of those communications. Phone providers and email providers keep a copy of each text, voicemail, or email on their servers, where it might be accessible to employees, etc. Additionally, people with access to your computer, phone, or other devices may also have access to your text, voicemail, or email. Hacking or misdelivery of text, voicemail, or email to an incorrectly typed phone number or email address are additional risks. Please take a moment to contemplate all the risks involved if any of these persons were to access the messages we exchange with each other before communicating with those methods. If you choose to communicate with me via text, voicemail, or email regarding administrative questions or issues, then I will do so, but please refrain from sharing private or sensitive information, like session content.
Communications Policy:
When you need to contact Sublime Online PLLC, these are the most effective ways to get in touch:
By phone call. If you choose to leave a voicemail, include your name, number, & admin info only.
• By talking with me face-to-face in a scheduled appointment.
The "Client Portal", where you can securely manage appointments, send messages, & view docs.
By email (administrative information only, like questions about services, billing, scheduling)
By text message (administrative information only, like questions about services, billing, scheduling)
I use text, voicemail, and email only with your permission and only for administrative purposes, unless we have made another agreement. That means that text, voicemail, and email with Sublime Online PLLC should be limited to administrative information only, like questions about services, billing, or scheduling. Please do not text, voicemail, or email me about clinical matters, because text, voicemail, and email are less private/secure modes of communication. If you need to discuss a clinical matter with me, then speak with me directly in a phone call or wait so we can discuss it during your next session. The phone call or face-to-face context are more private/secure modes of communication. You are responsible for all phone, text, or email related charges.
While I aim to return calls and messages within 72 hours, I cannot guarantee immediate response and I request that you do not use the above methods of communication to request assistance for emergencies. In the event of an emergency, please:
• Call 9-1-1
• Call the National Suicide Prevention Lifeline at 1-800-273-8255
• Proceed immediately to the nearest emergency room
Regarding social media, I participate in various social networks, both in my professional capacity and personal. If you have an online presence, then there is a possibility that you may encounter me by accident. If that occurs, please discuss it with me during your next session.
I have established business profiles for "Sublime Online PLLC" or "Sublime Online" on various sites, and these profiles are for marketing purposes. You can choose to "like" or "follow" social media pages and content offered by Sublime Online PLLC as part of my professional practice. If you choose to do so, then any comments should not indicate that there is a client-provider relationship. Any comments that potentially disclose such a relationship will be removed immediately if able.
Please refrain from making contact with me using social media messaging systems, because there are risks to privacy and security. I will not request or agree to be a "friend" or "connection" with you on social media sites. If I discover that I have accidentally established a social media relationship with you, then I will cancel that relationship. I do not communicate with or contact my clients through social media platforms. This is because these types of casual social contacts can create significant risks for you.
Further, I will not perform online research on you or others you know for the purpose of gathering information without your permission, because this constitutes a violation of your privacy rights. If you would like to share certain information with me, then you can choose to do so, but I will not seek it out independently and will discuss any implications with you. If you encounter any information about me online or in any other fashion, then please discuss this with me during your next session, as it may potentially impact your treatment.
If we see each other in public accidentally outside of our sessions, then please know that I will not acknowledge you first. If you acknowledge me first, then I may speak briefly with you, but I will not engage in any lengthy discussions with you in public due to privacy concerns.
Talk to me about any concerns you may have about my communication methods.
Contact Information:
I act as my own Privacy and Security Officer. If you have any questions or need more information about this Notice, then please contact: Michelle Tobin, Sublime Online PLLC, 1404 NE 134th St, Suite 290, Vancouver, WA 98685, (360) 207-1957, michelle@sublime.online.
Complaints:
You have the right to complain if you believe your privacy rights have been violated. You may file a complaint with me, as my own Privacy Officer, as specified above. You may file a complaint with the Washington State Department of Health by visiting https://doh.wa.gov/licenses-permits-and-certificates/complaint-and-disciplinary-process. You may file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights by visiting https://hhs.gov/hipaa/filing-a-complaint/index.html. I will not retaliate against you for filing a complaint.
Changes to the Terms of this Notice:
I can change the terms of this Notice, and the changes will apply to all information I have about you as well as any information I may receive in the future. A current version of this Notice is posted at https://sublime.online/notice-of-privacy-practices. For more information, please visit: https://hhs.gov/hipaa/for-individuals/notice-privacy-practices/index.html.
Effective Date of this Notice:
This Notice went into effect on September 26, 2022.
Back to Top