New York ESA LetterLicensed New York clinicians

HIPAA compliance

Your health information is protected by federal law and by the way we build our systems. This page explains both, without the legal fog.

HIPAA Compliant
256-bit SSL Encrypted
FHA Compliant Letters
ADA Compliant Letters
No Charge If Not Approved

In effect since September 2, 2026. Rather than list legal obligations in the abstract, this page walks through your information as it actually moves: what gets collected at each step, who can see it, and where it ends up.

Step one: booking

When you reserve an appointment we capture a name, an email address, a phone number and a chosen time slot. Payment card details go directly to our processor and never reach our servers. At this stage nothing about your health has been recorded, so nothing here is protected health information yet.

Step two: the screening form

The moment you describe a symptom, everything changes. From that point the record is protected health information under the Health Insurance Portability and Accountability Act, and the clinician evaluating you is a covered health care provider. The form travels over TLS with 256-bit encryption and is written to storage already encrypted.

Step three: the consultation

Your video or phone consultation runs on a platform operating under a business associate agreement, which binds that vendor to the same safeguards we are held to. Consultations are not recorded for marketing, training or any other secondary purpose. Your clinician takes notes; those notes are part of your clinical record.

Step four: the letter

An approved letter is generated, signed and emailed to you. Note what it deliberately leaves out: it confirms that a licensed New York clinician has evaluated you and that a disability-related need exists. It does not name your diagnosis, quote your notes or describe your treatment. That omission is intentional, because your landlord or co-op board is entitled to documentation of need and nothing beyond it.

Step five: storage

Your record sits encrypted at rest. Access is limited to the clinician who treated you and the small support team who need it to help you, and every access is logged and periodically reviewed. Clinical records are retained for the period New York law and professional standards require, generally at least six years for an adult record, then securely destroyed.

The people and companies who can see any of this

Your clinician

Full access to your record, because they cannot evaluate you without it.

Support staff

Limited access, only where needed to resolve something you have raised with us.

Our vendors

Hosting, scheduling and video providers, each under a business associate agreement. Our payment processor sees billing data only, never clinical information.

Anyone you authorise

If you sign an authorisation for us to send your letter to a managing agent, board or university, we send exactly what you specified and nothing more.

Nobody else, with four narrow exceptions

We disclose protected health information without your authorisation only where a valid court order or subpoena compels it, where a specific law requires reporting, where there is a serious and imminent threat to someone's safety, or where a health oversight authority is exercising lawful powers. We do not sell health information, we do not use it for advertising, and we do not volunteer it to your landlord, board or employer.

The rights you can exercise, and how

Email support@newyorkesaletter.org with the subject "Privacy request". We verify your identity first and respond within 30 days, usually sooner.

  • Get a copy of your health record, electronically or on paper.
  • Ask for a correction where you believe something is wrong.
  • See an accounting of certain disclosures we have made.
  • Request a restriction on how information is used or shared. We consider every request and tell you plainly when we cannot agree.
  • Choose the channel we use to contact you.
  • Complain to us or directly to the HHS Office for Civil Rights. Retaliation for filing a complaint is prohibited and would be an obvious breach of trust besides.

If something goes wrong

Under the Breach Notification Rule, a breach of unsecured protected health information obliges us to notify affected individuals without unreasonable delay and no later than 60 days from discovery, notify HHS, and notify media where more than 500 residents of a state are affected. In that situation you would hear what happened, which information was involved, what we did about it and what we recommend you do.

Privacy and HIPAA questions

Will my co-op board or landlord see my diagnosis?

Not from us. The letter is written to confirm a disability-related need without naming a condition or describing treatment. A housing provider in New York is entitled to documentation of the need, not to your medical file.

Are the video consultations recorded?

Not for marketing, training or any secondary purpose. Your clinician takes notes, and those notes form part of your clinical record with the same protections as everything else.

What does a business associate agreement actually do?

It contractually binds a vendor that handles health information on our behalf to the same safeguards we are held to, and makes them directly accountable for breaches. Any vendor that touches your health information signs one before it gets access.

How long do you hold my record?

Clinical records are kept for the period New York law and professional standards require, generally at least six years for an adult record, then securely destroyed. Non-clinical data we are not obliged to retain can be deleted on request.

What happens to my card details?

They go straight to our payment processor and never reach our servers. We receive a confirmation and the last four digits, which is all we need to find your transaction.

Official sources for this page

Nothing legal on this page is asserted without a source behind it. Open them and read the originals rather than taking our summary on trust.

  1. HHS — HIPAA for IndividualsThe official explanation of your health privacy rights from the U.S. Department of Health and Human Services.
  2. HHS — HIPAA Privacy RuleThe rule governing how protected health information may be used and disclosed.
  3. HHS — HIPAA Security RuleThe safeguards standard our encryption, access control and logging are built against.
  4. HHS — Breach Notification RuleThe notification obligations described in the final section of this page.
  5. HHS Office for Civil Rights — File a ComplaintHow to report a suspected privacy or security violation directly to the federal regulator.
  6. New York State Department of Health — Patient rights and recordsState-level guidance on medical records and patient rights in New York.
  7. 45 CFR Part 164The federal regulation text behind the Privacy, Security and Breach Notification Rules.

Ready to start your evaluation?

Choose a slot that works for you. The consultation usually runs under 20 minutes, and an approved letter reaches your inbox 15 minutes after sign-off.

Book my appointmentSee pricing