ITSCO

ITSCO Privacy Policy

Effective October 4, 2026 · Version 2026-10-04

How ITSCO, LLC handles information when you visit our website, use our portal, complete forms, or communicate with our team.

1. Who this policy covers

This policy applies to ITSCO, LLC (ITSCO, we, us), its website at www.itsco.health, and ITSCO services provided through its portals, forms, and messaging tools, including ITSCO’s use of AuricWell. It does not establish a joint privacy notice for other practices or authorize them to contact you.

AuricWell and its operator, Plot Twist Co, provide technology used by ITSCO. A technology provider is not your treating clinician merely because it hosts a form or delivers a message. Independent organizations have their own privacy obligations.

Our HIPAA Notice of Privacy Practices explains how protected health information is used and disclosed and how you can exercise your health-record rights. That notice and applicable law govern protected health information. This website policy is not an authorization to release medical records. Reading either document does not enroll you in text messaging.

Read the ITSCO HIPAA notice

2. Information we collect

  • Information you provide: your name, contact details, communication preferences, form responses, electronic signatures, appointments, requests, and messages. Enrollment and care workflows may also collect guardian or representative details, health information, insurance information, and billing information.
  • Information received for your care: information from your authorized representative, referring professionals, schools, insurers, and other sources when permitted by law or your authorization.
  • Technical and usage information: IP address, browser and device information, session and authentication data, pages or features used, timestamps, error reports, and security or audit events. Sensitive information can also appear in forms or messages you submit.
  • Communication records: message contents, delivery status, consent and withdrawal records, the version of a disclosure you accepted, and related signature and audit evidence. Calls or sessions are recorded only through a workflow that gives the required notice and obtains any required consent.

3. How we use information

  • Respond to inquiries; coordinate enrollment, referrals, appointments, and care; communicate with clients and authorized representatives; and manage billing and insurance.
  • Operate accounts and portals, verify identity and authority, provide technical assistance, maintain records, protect against misuse, and investigate security incidents.
  • Honor communication choices, deliver requested messages, maintain evidence of consent, and prevent messages after an opt-out.
  • Improve services and meet legal, licensing, recordkeeping, and reporting duties. Uses of protected health information remain subject to the HIPAA notice and applicable law.
  • Send optional ITSCO announcements or promotions only with the required separate consent. Agreeing to reminders or care-team messages does not authorize marketing.

4. When information is shared

Access is limited to the purposes of the service and applicable law. Authorized ITSCO clinicians, administrative staff, supervisors, and support personnel may access information needed for their work. A message addressed to a clinician may be handled by another authorized team member.

Service providers may process information to host the portal, store records, deliver communications, process payments, or provide support and security. Providers must be subject to appropriate contractual restrictions, including a business associate agreement when HIPAA requires one. This processing does not give a vendor permission to market to you independently.

We may disclose information to persons you authorize, for care and payment as described in the HIPAA notice, or when legally required or otherwise permitted by applicable law. We do not treat participation in a school program as blanket permission to release counseling records to the school.

A change in ownership or service provider does not eliminate applicable privacy obligations or turn an existing SMS consent into permission for unrelated marketing.

5. Mobile information and SMS consent

We do not sell personal information. We do not share mobile numbers, text message contents, or SMS opt-in data and consent with third parties or affiliates for their marketing or promotional purposes. SMS consent is not transferable to another brand.

Messaging vendors and carriers may process the information needed to deliver ITSCO messages, operate the service, and honor opt-outs. This is service delivery on our behalf, not permission for their independent marketing. Disclosures required by law remain subject to applicable privacy protections.

Each SMS purpose requires its own affirmative choice. A required choice between Yes and No does not require you to choose Yes; neither option is preselected. You may decline all SMS purposes and still request care. Providing a phone number, signing a treatment waiver, acknowledging the HIPAA notice, or accepting website terms does not itself enroll you in recurring SMS.

Reply STOP to opt out of the messaging program that sent the message. Reply HELP for help, or contact support@itsco.health to update preferences or request another way to communicate. Ordinary SMS may be visible on shared devices, lock screens, carrier systems, or to anyone with access to your phone. Please use the designated portal or contact the team for sensitive clinical information.

Read the SMS terms

6. Cookies, storage, and external services

Our website and portal use browser storage and similar technologies for functions such as sign-in, security, preferences, and reliable operation. Technical logs may also be used to understand errors and website performance. Blocking storage may prevent parts of the portal from working.

Links, maps, videos, payment pages, and other external services may take you to a third party or connect your browser to it. Those services have their own notices. We do not authorize advertising vendors to use patient information or SMS consent for their independent marketing. You can ask us about a particular feature before using it.

7. Clinical technology and assisted documentation

Where ITSCO uses electronic or AI-assisted tools for documentation or administrative work, health-information rules still apply. A clinician remains responsible for reviewing clinical documentation and making care decisions. Removing a name or replacing it with initials does not necessarily make information anonymous.

A recording consent, when required, is requested separately. Contact your clinician to discuss recording, transcription, or technology preferences. This policy does not itself authorize recording, unrestricted AI use, or training a general-purpose AI model on your health information.

8. Security and retention

We use administrative, technical, and physical safeguards appropriate to the information and the service. No website, device, or communication channel can guarantee absolute security. Keep sign-in credentials private, use devices you trust, and report suspected unauthorized access.

We retain information for care, business, consent evidence, and applicable legal or professional recordkeeping requirements. The period depends on the type of record, age of the client, legal holds, and other obligations. Closing an account or withdrawing SMS consent does not necessarily require deletion of clinical records or the evidence needed to honor that withdrawal.

Deleting a working draft or exporting a note does not guarantee immediate deletion of all copies, logs, or backups. Requests to access, correct, restrict, or delete information are evaluated under the law that applies to that information.

9. Your choices and rights

You may request access to or correction of your information, ask about retention, withdraw optional communication consent, or request deletion where applicable law provides that right. We may need to verify your identity and authority before fulfilling a request. Health-record rights and any exceptions are explained in the HIPAA notice.

Additional state privacy rights may apply to information outside HIPAA. If a request is denied, we will explain the reason and any applicable review or appeal process. Exercising a privacy right does not waive your other rights or authorize retaliation.

A parent or guardian does not automatically have access to every minor’s confidential record. We verify representative authority and follow the laws governing the particular service and record. Public website browsing is not a substitute for the appropriate enrollment and consent process for a minor.

10. Updates

We will post revisions here with a new effective date and provide additional notice or seek consent where required. A policy revision does not retroactively expand an SMS consent or a medical-record authorization.

Questions, privacy requests, and help

ITSCO, LLC • Privacy Officer: Michael Mendez • 437 Windchime Place, Colorado Springs, CO 80919.

Privacy questions and requests: PO@ITSCO.health or 833-444-8726. Website, portal, and SMS help: support@itsco.health. Please start with your contact information and the type of assistance you need; do not send detailed health information through ordinary email or text. We can arrange an appropriate way to exchange records.

Email the Privacy Officer

Call the Privacy Officer

Contact ITSCO support