Overview
Our reading is that Her Mood Mentor is not a HIPAA covered entity, and that this is the less important half of the answer.
Her Mood Mentor takes no insurance, files no claims, and runs no eligibility checks. The founder confirmed on 2026-08-11 that the business has never billed insurance and has never made any inquiry to any insurer or payer, at any point, through any intermediary. Under 45 CFR 160.103 the presence of a covered transaction is the whole test for a provider, so on these facts HIPAA does not reach the business. We want that confirmed in writing.
The consequence is the part that matters. Falling outside HIPAA removes the exemption that HIPAA-regulated data enjoys under the newer consumer health privacy laws. Washington's My Health My Data Act reaches wellness and nutrition businesses by design, has no revenue or headcount threshold, and carries a private right of action. Being outside HIPAA makes that law more relevant, not less.
Operating profile
What the business actually does, who the practitioners are, how money moves, what data is collected and where it lives. The facts counsel would otherwise have to extract by interview.
Read the profile →HIPAA covered entity analysis
Why we read HMM as outside HIPAA, the one fact that would flip it, and the business associate question on lab ordering.
Read the analysis →Washington My Health My Data Act
The highest-exposure regime we have identified. No thresholds, explicitly aimed at wellness and nutrition, private right of action, and compliance deadlines that already passed.
Read the analysis →FTC: breach rule and Section 5
The amended Health Breach Notification Rule reaches non-HIPAA health apps. Separately, the tracker finding above sits squarely in the FTC's recent enforcement pattern.
Read the analysis →Other state and international law
Montana, California, and the general state privacy regimes, plus the question of international clients.
Read the analysis →MHMDA compliance plan
What HMM actually has to do, in priority order, with the statutory basis for each item. Includes the finding that no privacy policy is currently published anywhere.
Read the plan →Draft consumer health data privacy policy
A complete first draft of the document the statute requires, written against HMM's actual data practices, for counsel to review rather than draft.
Read the draft →Questions for counsel
Nine questions, written so most can be answered yes or no. This is the section to bill against.
Read the questions →Facts we still need to confirm internally
Open items on our side. These should be nailed down before the brief goes out, because several of them change the analysis.
Read the list →Operating profile
Everything in this section is fact about how the business runs, not analysis. Items marked confirm are ones we have not independently verified and are flagged again under facts to confirm.
The business
| Item | Detail |
|---|---|
| Business | Her Mood Mentor. Direct-to-consumer education and coaching for premenstrual dysphoric disorder (PMDD) and related cycle symptoms. |
| Legal entity | Her Mood Mentor LLC, 25157 US Highway 93 S, Rollins, MT 59931. Confirm state of formation is Montana. |
| Client geography | Nationwide United States, plus a distinct international offering priced separately. |
| Reach | Roughly 10,000 email subscribers, 85,000 Instagram followers, roughly 5,000 podcast downloads per month. |
| Insurance | None, confirmed by the founder 2026-08-11. HMM has never billed insurance and has never made any inquiry to any insurer or payer. No claims, no eligibility or benefits checks, no prior authorization, no claim status inquiries, no remittance received. One client has requested a paid receipt in order to seek reimbursement from her own health savings account. |
Practitioners and staff
| Person | Role | Credential |
|---|---|---|
| Jes Fleming | Founder, primary practitioner. Delivers the 1:1 program and authors course content. | Board Certified Nutritional Therapy Practitioner (NTP). Not a licensed medical provider. |
| Izzy | Onboarding specialist. Runs paid introductory calls, which function as the sales conversation for the 1:1 program. | No clinical credential. |
| Maria | Coaching staff. | confirm |
| Shawn | Operations and technical infrastructure. Not client-facing. | n/a |
The business positions itself publicly as wellness coaching. Internal editorial policy already distinguishes between general wellness-coach language for the app and marketing, and Jes's broader NTP scope for her own course and clinical content. Neither lane diagnoses, prescribes, or claims to treat disease.
Services and how money moves
| Offering | Price | Processor |
|---|---|---|
| Introductory session, 45 minutes, with Izzy | $90 | Currently Kajabi. Migrating to Stripe. |
| 1:1 coaching, 90 days, United States | $3,999 | Stripe, live |
| 1:1 coaching, 90 days, international | $3,200 | Stripe, live |
| PMDD Rehab course and app subscription tiers | $9.99 to $79.99 monthly | Kajabi and in-app |
| Digital workbooks | $27 to $54 | Kajabi, migrating to Stripe |
All payment is direct from the client by card or buy-now-pay-later. No third-party payer is ever involved.
What the 1:1 program includes
This is the offering with the most clinical texture, and the one most likely to shape counsel's view:
- Five one-to-one video sessions over 90 days, plus daily messaging on weekdays.
- Facilitated laboratory testing. Clients choose a pathway among blood, DUTCH hormone, or stool testing, plus hair tissue mineral analysis. HMM arranges the testing and reviews results. The ordering mechanics and the contracting party with the lab are confirm.
- A recorded video review of lab results with a written protocol and dietary recommendations.
- A personalized nutrition protocol, plus food and mood analysis.
- Referral links to a practitioner supplement dispensary (Fullscript) and a supplement brand (Marea). Confirmed 2026-08-11: these are affiliate links only. The client shops with those companies directly and HMM transmits no client data to either. Note for counsel as an adjacent matter: affiliate compensation on recommended products raises an endorsement disclosure question under the FTC endorsement guides, which is separate from privacy and is not analyzed in this brief.
- Lifetime access to the PMDD Rehab course and the app.
What data is collected
| Source | Data | Sensitivity |
|---|---|---|
| Mobile app | Mood and symptom check-ins, menstrual cycle dates, free-text journal entries, photographs of meals, course progress | Health data by any definition in play |
| Intake questionnaires | Health history, symptoms, medications, goals. Currently collected in Practice Better. | Most sensitive category held |
| Laboratory results | Hormone, blood, stool, and mineral panels | Clinical results |
| Coaching agreements | Signed client agreements | Contractual, identifying |
| Session recordings | Recorded video sent to clients | Contains clinical discussion |
| Marketing | Email list, Instagram audience, podcast analytics | Not health data unless correlated |
Where data lives today
| System | Hosting | Holds |
|---|---|---|
| Practice Better | Third-party cloud, $200 per month | Intake forms, client records, agreements. Being retired. |
| Kajabi | Third-party cloud | Course delivery, email, current checkout. Being retired. |
| Supabase | Third-party cloud (Postgres) | App accounts, check-ins, journal entries, subscriptions, booking records |
| Cal.com | Self-hosted on premises, published through a Cloudflare tunnel | Scheduling |
| TrueNAS server | On premises, ZFS mirror, encrypted dataset for labs | Laboratory reports and clinical documents |
| Mac Mini | On premises | Local large-language-model analysis of lab reports. Clinical text is processed locally and does not leave the building for analysis. |
| Stripe | Third-party cloud | Payments. No health data by design. |
The change under consideration
HMM intends to retire Practice Better and build a client portal on its own infrastructure: Supabase for accounts and data, Cloudflare for hosting and video delivery. That portal would hold signed agreements, intake questionnaires, protocol documents, and recorded videos. This brief is being prepared because that decision should not be made before the regulatory position is settled.
HIPAA covered entity analysis
Our confidence: high, subject to one fact
The test
Under 45 CFR 160.103, a covered entity is a health plan, a health care clearinghouse, or a health care provider who transmits health information in electronic form in connection with a transaction covered by the HIPAA rules. The covered transactions are enumerated at 45 CFR Part 162 and are administrative and financial in nature: claims, eligibility inquiries, prior authorization, claim status, enrollment, premium payment, referral certification, remittance advice, and coordination of benefits.
The trigger is the electronic transaction, not the clinical service. A practice that provides health services but never transmits a covered transaction is not a covered entity.
Applying it
Her Mood Mentor accepts no insurance. It submits no claims, checks no eligibility, and receives no electronic remittance. Every dollar arrives directly from the client through Stripe or Kajabi. On those facts, no covered transaction is ever transmitted, and HMM is not a covered entity.
A nuance worth stating plainly so it does not surprise anyone: Jes may well satisfy HIPAA's separate and quite broad definition of health care provider, which reaches any person who furnishes, bills, or is paid for health care in the normal course of business. That definition alone does not create covered entity status. Provider status plus a covered transaction does. We believe the second element is absent.
The one adjacent fact, disclosed for completeness
One client has asked HMM for a paid receipt so that she could seek reimbursement from her own health savings account. We do not believe this affects the analysis, for two independent reasons. First, the client is the party submitting, not HMM, so HMM transmits nothing. Second, an HSA is a custodial account holding the client's own funds rather than a health plan adjudicating a claim, so reimbursement from it is not among the transactions enumerated at 45 CFR Part 162 in the first place. We raise it only so that counsel is not surprised by it later.
Superbills
HMM does not issue superbills. For the record, had it done so, our reading is that a superbill handed to a client who submits it herself leaves the client as the transmitting party and does not trigger coverage. Only HMM transmitting on a client's behalf would change the analysis.
Business associate status
Separately from covered entity status, an organization can be pulled into HIPAA as a business associate when it performs functions on behalf of a covered entity involving protected health information. The relevant relationship here is laboratory testing. Our reading is that HMM acts as a customer and ordering party rather than performing a service on the laboratory's behalf, which would not create business associate status. We flag it because the lab relationship is the only place HMM touches an entity that is itself likely covered, and because the contracting mechanics are not fully documented on our side.
Why this conclusion is not the end of the analysis
The newer consumer health privacy statutes generally exempt data that is already regulated as protected health information under HIPAA. A business outside HIPAA does not get that exemption. Concluding that HMM is not a covered entity therefore moves the exposure rather than eliminating it, and it moves it toward the regimes described in the next two sections.
Washington My Health My Data Act
Our confidence: high that it applies
Why we think it reaches HMM
The Act applies to any legal entity that either conducts business in Washington or provides products or services targeted to Washington consumers, and that determines the purpose and means of collecting, processing, sharing, or selling consumer health data. There is no revenue threshold and no minimum number of consumers. Practitioner commentary on the Act specifically identifies providers of fitness, wellness, and nutrition products as falling within scope.
HMM markets nationally to an audience of roughly 85,000 followers and 10,000 email subscribers, and sells to consumers in any state. It is not realistic to assume there are no Washington clients.
What counts as consumer health data
The definition is deliberately broad: personal information linked or reasonably linkable to a consumer that identifies the consumer's past, present, or future physical or mental health status, including individual health conditions, treatments, diseases or diagnoses, and any information used to associate a consumer with health status.
Symptom check-ins, cycle tracking, journal entries about mood, intake questionnaires, and lab results all sit comfortably inside that. So, arguably, does the mere fact that someone purchased a PMDD program.
Obligations we understand to attach
- A consumer health data privacy policy published as a separate and distinct link on the homepage, which may not contain any information beyond what the Act requires. A general privacy policy does not satisfy this.
- Consent before collecting consumer health data beyond what is necessary to provide a service the consumer requested.
- Separate and specific written authorization before any sale of consumer health data, where sale is defined broadly.
- Rights of access and deletion, including a duty to pass deletion requests to downstream recipients.
- A prohibition on geofencing around facilities providing health services.
Enforcement
A violation of the Act is a per se violation of the Washington Consumer Protection Act. That means enforcement by the Attorney General with civil penalties reported at up to $7,500 per violation, and, unusually among modern privacy statutes, a private right of action. The private right of action is the reason this deserves attention disproportionate to Washington's share of the client base.
What we propose to do about it
We have written the plan out rather than leaving it open. See the compliance plan for the prioritized version with statutory citations, and the draft consumer health data privacy policy for a complete first draft of the document the statute requires.
The headline from that work: HMM currently publishes no privacy policy at all, on either the main site or the Kajabi properties. That is the first thing to fix and it is not solely a Washington issue.
FTC exposure
Health Breach Notification Rule
Our confidence: high that it applies to the app
The FTC finalized amendments to the Health Breach Notification Rule in April 2024, published them in May 2024, and they took effect on July 29, 2024. The amendments were written specifically to reach direct-to-consumer health applications and connected devices that are not regulated by HIPAA. The HMM mobile app, which collects symptom, mood, and cycle data, appears to be exactly the class of product contemplated.
The change with the sharpest edge is to the definition of a breach of security. It now includes any unauthorized disclosure of identifiable health information, not only disclosure resulting from a cybersecurity intrusion. A voluntary disclosure that the consumer did not authorize can itself be a reportable breach. That converts a marketing tag misconfiguration into a notification event.
Section 5 and the tracker finding
Our confidence: this is the most likely real-world exposure
The FTC has pursued unfair and deceptive practices claims against consumer health companies for disclosing health data to advertising platforms through tracking pixels and software development kits. GoodRx settled for $1.5 million. BetterHelp settled for $7.8 million, and its order bans sharing health information for advertising, requires affirmative express consent before disclosure to certain third parties, requires directing third parties to delete data already shared, and imposes a retention schedule.
We checked HMM's own properties against this pattern:
| Property | Third-party scripts observed | Read |
|---|---|---|
hermoodmentor.comWebflow marketing site, including health-topic blog pages and the contact page |
No advertising or analytics tags found. Scripts resolve to Webflow's own CDN, jsDelivr, Google's hosted jQuery, and an Instagram feed widget at cdn.lightwidget.com. |
Clean. The Instagram widget is a third party that observes visitors, but no health-data collection occurs on these pages. |
courses.hermoodmentor.comKajabi page titled "Book Your Introductory Session," the paid checkout for a PMDD coaching call |
Two Google Analytics 4 properties, G-3E0XFP3CNB and G-GTBWYV09JY, loaded via gtag.js. Also cdn.checkoutjoy.com and a hosted polyfill service. No Google Tag Manager container and no advertising pixel of any kind. |
Resolved. G-3E0XFP3CNB is HMM's own property and has no Google Ads links configured, verified 2026-08-11. Analytics only, with no path to advertising. |
gtag.js loading two Google Analytics 4 properties. That is analytics only. There is no Meta pixel and no advertising tag on the page.
The residual question was narrow, and it has been answered. Google Analytics data becomes advertising data only if a GA4 property is linked to a Google Ads account with remarketing enabled. Verified 2026-08-11:
G-3E0XFP3CNB is HMM's own property, in the "Her Mood Mentor" account under the "PMDD Rehab" property, and its Google Ads links list is empty. No linked ads account, therefore no remarketing and no audience building from health page traffic.
G-GTBWYV09JY, which does not belong to HMM's Analytics account and is therefore almost certainly Kajabi's own platform analytics. That is a vendor data-handling question rather than a configuration HMM controls, and it disappears entirely when HMM leaves Kajabi. Counsel may still wish to look at Kajabi's data processing terms.
What remains genuinely worth counsel's view is narrower and unrelated to advertising: the page title and URL themselves disclose that the visitor is purchasing PMDD care, and that string is transmitted to Google Analytics as ordinary page data. Whether that constitutes sharing consumer health data under the Washington statute is a question we would rather ask than assume.
The mobile app, audited 2026-08-11
The app sends product analytics to PostHog, a third-party analytics provider, and it calls identify() with the user's account ID. The events are therefore tied to an identified person rather than an anonymous session. Among the events currently sent:
| Event | Properties | What it reveals |
|---|---|---|
symptom_mapping_daily_checkin_submitted | severity_counts | Symptom severity for an identified person |
symptom_mapping_period_recorded | none | Menstrual cycle events |
symptom_mapping_mood_saved | mood properties | Mental health status over time |
symptom_mapping_crisis_sheet_shown | none | That the user reached a crisis resource screen |
symptom_mapping_onboarding_completed | symptom_count | Symptom burden at intake |
intro_session_checkout_completed | booking_id | Purchase of PMDD care |
Free-text journal content does not appear to be transmitted, which matters and is to HMM's credit. But severity counts, period events, mood, and a crisis-screen event, all linked to an identified user, sit squarely inside the Washington definition of consumer health data: information linked to a consumer that identifies past, present, or future physical or mental health status.
RCW 19.373.030, sharing consumer health data requires consent unless it is necessary to provide the service the consumer requested, and product analytics is not necessary to deliver symptom tracking. We found no consent gate in the analytics module. Separately, under the amended FTC Health Breach Notification Rule, an unauthorized disclosure of identifiable health information can constitute a reportable breach, and disclosure to a processor the consumer never agreed to is the scenario that amendment contemplates. Fixing this before launch costs a day. Fixing it after costs a notification obligation.
PostHog is a processor under contract rather than an advertising platform, which is a materially better starting posture than the companies in the FTC enforcement actions. The analytics itself is also worth keeping: retention measurement is load-bearing for HMM's product decisions. The two goals are compatible, because the retention metrics do not require the health-bearing properties.
Our proposed remedy, pending advice: gate all symptom, mood, cycle, and crisis events behind an explicit opt-in; strip health-bearing properties from any event that remains ungated; and confirm PostHog's data processing terms and hosting region.
Practical consequence for the build
Whatever counsel concludes, the design rule we would adopt is that no advertising or third-party analytics tag should load on any page where a client enters health information or purchases care. That is cheap to enforce in a portal we control, and it is one more argument for moving off Kajabi.
Other state and international law
Montana, the home state
Our confidence: likely below threshold
The Montana Consumer Data Privacy Act took effect October 1, 2024, and was substantially amended by SB 297 effective October 1, 2025. The amendments lowered the applicability threshold to controlling or processing the personal data of at least 25,000 Montana consumers per year, raised penalties to $7,500 per violation with no overall cap, and removed the sixty-day cure period. The right to cure sunsets April 1, 2026.
Montana's entire population is roughly 1.1 million. HMM's national email list is about 10,000. It is very unlikely HMM processes the data of 25,000 Montana residents, so our read is that the Act does not currently apply despite Montana being home. Worth confirming because it is the state whose regulator is nearest.
California
Our confidence: moderate, needs counsel
California's Confidentiality of Medical Information Act was extended so that a business offering a personal health record or similar digital tool designed to maintain medical information is subject to it. A symptom and cycle tracking app arguably falls inside that description. CMIA matters more than a general privacy statute because of its damages provisions. California is also likely HMM's largest state market by client count.
The general state privacy regimes
Most comprehensive state privacy laws, including California, Colorado, Connecticut, Virginia, Texas, and Oregon, classify health data as sensitive and require opt-in consent to process it, along with privacy notices and consumer rights. Applicability thresholds vary and HMM may fall below several of them at current scale. Nevada and Connecticut have also enacted consumer health data provisions modeled in part on Washington's.
International clients
Our confidence: low, we lack the facts
HMM sells a distinct international package at $3,200 and hand-delivers that link to clients abroad. We do not know where those clients are located. If any are in the European Union or the United Kingdom, health data is special category data under Article 9 of the GDPR and requires an explicit lawful basis, along with transfer mechanisms for moving data to the United States. This could be nothing, or it could be a separate workstream. The client list will answer it.
Adjacent, and deliberately out of scope here
Scope of practice and state nutrition licensure are separate questions from privacy. We are not raising them in this brief, but counsel should know that an NTP delivering individualized nutrition guidance to clients in all fifty states touches state licensure regimes that vary considerably. If that is worth its own review, we would rather hear so now.
MHMDA compliance plan
Statutory citations are to RCW 19.373. Everything below is our proposed plan, not counsel's advice. The point of writing it is so counsel can correct a plan rather than build one.
We checked. hermoodmentor.com serves a 404 at /privacy, /privacy-policy, /terms, and every other conventional path, and the homepage contains no policy link. The Kajabi checkout page contains no policy link either. Whatever else follows, this is the gap to close first, and it reaches beyond Washington: most state privacy laws require a notice, and Apple will require a privacy policy URL when the app is submitted to the App Store.
Classification
HMM is a small business under RCW 19.373.010, which covers entities handling consumer health data of fewer than 100,000 consumers in a calendar year. HMM is far below that. The classification matters less than it sounds: small businesses carry materially the same obligations, and only the original compliance date differed. That date was June 30, 2024 and has passed.
Priority 0, close immediately
1. Publish two separate documents
RCW 19.373.020 requires a consumer health data privacy policy, prominently linked from the homepage as its own distinct link. It must not be folded into a general privacy policy, and commentary is consistent that the link should point to a document containing only what the statute requires.
So HMM needs a general privacy policy covering everything else, plus a standalone consumer health data privacy policy. A complete draft of the second one is at draft CHD policy.
2. Stop sending health page traffic to Google Analytics
Under RCW 19.373.030, collecting or sharing consumer health data requires consent unless it is necessary to provide a product or service the consumer requested. Analytics on a page titled "Book Your Introductory Session" for a PMDD program is not necessary to deliver that service.
This is a different question from the FTC one, and it survives the good news there. No advertising is involved and no ads account is linked, but the page URL and title still travel to Google as ordinary page data, and they disclose the nature of the purchase. Whether that is "sharing consumer health data" is a fair question for counsel, and the cheapest resolution is not to argue it. Remove analytics from health purchase and intake pages, or gate it behind consent.
This also settles a design rule for the portal: no third-party analytics on any page where a client enters health information or buys care.
Priority 1, before the portal launches
3. Build the rights request mechanism
RCW 19.373.040 gives consumers the right to confirm whether their consumer health data is collected, shared, or sold, to access it, to obtain a list of all third parties and affiliates it has been shared with along with contact information for each, to withdraw consent, and to delete it.
export-user-data and delete-user, which is a real head start. Both need widening. The export currently covers only profiles, mood_logs, and community_posts, which is narrower than the health data the app holds. The delete function calls auth.admin.deleteUser and relies on foreign key cascade, which handles Supabase but reaches nothing outside it and notifies no downstream processor. Extending these is cheaper than starting over.
Deletion is the demanding one. It reaches all records and systems, requires notifying every downstream recipient and processor, and those recipients must honour it. The response deadline is 45 days, extendable once by a further 45. Archived and backup systems get up to six months.
Practically that means three things we do not have: a request intake path, a tracked clock, and a documented appeal process for refusals. It also means knowing, for any given client, every system her data reached. That is an argument for consolidating onto Supabase rather than leaving data spread across Practice Better, Kajabi, and the NAS.
4. Restrict staff access by role
RCW 19.373.050 requires restricting access to consumer health data to those employees, processors, and contractors for whom access is necessary, and maintaining administrative, technical, and physical safeguards meeting industry standards.
This resolves the earlier question about giving Jes, Maria, and Izzy a database console. Handing three people unrestricted Supabase Studio access to client health records would not meet this standard. A staff console with role-based access enforced in row level security is not a nicety, it is how this requirement gets satisfied.
5. Get processor terms in place
RCW 19.373.060 governs processors, who may only process consumer health data per a binding contract with the regulated entity. HMM needs to confirm what terms exist with each vendor that touches this data: Supabase, Cloudflare, Kajabi, Practice Better, Resend, Kit, and any laboratory.
Priority 2, ongoing practice
6. Record consent as data, not as a checkbox
Where consent is the basis for collection or sharing, HMM should be able to show what a given client agreed to and when. That means storing the consent event, the version of the policy in force at the time, and a timestamp, in the database. Retrofitting this later is far harder than building it in.
7. Write the deletion runbook
Deletion has to actually work across Supabase, the encrypted NAS archive, ZFS snapshots, any recorded video on Cloudflare Stream, and email systems. The six-month allowance for backups exists precisely because this is hard. Write the procedure before the first request arrives, not after.
8. Do not sell consumer health data
HMM does not, and the simplest posture is to state so plainly and keep it true. If that ever changes, RCW 19.373.070 requires a separate signed authorization naming the specific data, the seller, the purchaser, the purpose, a statement that service cannot be conditioned on signing, revocation instructions, a redisclosure warning, and an expiration date no more than one year out. Copies must be retained for six years.
9. Geofencing, confirmed not applicable
RCW 19.373.080 makes it unlawful to geofence an entity providing in-person health care services in order to identify consumers, collect their health data, or serve them advertising. HMM runs no location-targeted advertising and delivers no in-person care. Noted for completeness so counsel can see it was considered.
What this costs
Items 1, 2, 8, and 9 are documentation and configuration, achievable in days. Items 3, 4, 6, and 7 are engineering work that should be folded into the portal build rather than bolted on afterwards, which is the strongest practical argument for settling the regulatory position before that build starts. Item 5 is vendor paperwork.
Draft consumer health data privacy policy
Drafted against the five disclosure requirements at RCW 19.373.020 and the rights at RCW 19.373.040. Bracketed items need a decision or a fact from HMM.
Consumer Health Data Privacy Policy
Her Mood Mentor · Effective [date]
This policy describes how Her Mood Mentor collects, uses, and shares consumer health data, and the rights you have over that data. It applies to residents of Washington State and to anyone whose consumer health data we collect in Washington. It exists separately from our general privacy policy because Washington law requires it to.
The consumer health data we collect, and why
We collect the following categories of consumer health data in order to provide the coaching, education, and app services you ask us for, and to communicate with you about them:
- Symptom and mood information you record, including symptom types, severity, and how you are feeling.
- Menstrual cycle information, including period dates and cycle timing.
- Journal entries and free text you write in the app or send to our team, which may describe your physical or mental health.
- Photographs of meals you submit for nutritional feedback.
- Health history and intake information you provide when you begin a coaching program, including symptoms, health background, medications and supplements, and your goals.
- Laboratory test results, where you have chosen to have testing arranged through a coaching program.
- Information about the programs, sessions, and content you purchase or use, which can indicate that you are seeking support for premenstrual or hormonal health.
- Your communications with our coaching team.
We use this data to deliver the services you requested, to prepare for and conduct your sessions, to produce your personalized protocol and lab review, to operate and improve the app, and to provide customer support. [Confirm whether health data is ever used to select marketing content. If it is, that use must be described here and requires consent.]
Where we collect it from
- Directly from you, through the app, intake forms, messages, and sessions.
- From laboratories, where you have authorized testing and the release of your results to us.
- Automatically from your device when you use our app, limited to usage information about how the app is used.
The consumer health data we share
We share consumer health data only where it is necessary to provide a service you have requested, or where you have consented. Specifically we may share:
- Intake, symptom, and health history information with the service providers who host and operate our systems, so that the systems function.
- Information necessary to arrange testing with the laboratory performing that testing, when you have chosen laboratory testing.
We do not share your consumer health data with supplement retailers. Where we point you to a dispensary or a supplement brand, we do so by giving you a link to shop with them directly. You transact with them, not through us, and we send them nothing about you.
We do not sell consumer health data, and we do not share it with advertising platforms or use it to target advertising to you.
Who we share it with
The categories of third parties, and the specific affiliates, with whom we share consumer health data:
- Infrastructure and hosting providers that store and serve our data and applications: Supabase and Cloudflare.
- Practice and course management platforms used to deliver programs and hold client records: Kajabi and Practice Better, while those remain in use.
- Communication providers used to send email relating to your care: Resend and Kit.
- Product analytics providers used to understand how our app is used: PostHog. [Pending the consent decision. If analytics is gated behind opt-in, this entry should say so explicitly.]
- Laboratories performing the testing you have chosen, limited to what they need to run and return your test.
We do not share consumer health data with supplement retailers, including Fullscript and Marea. Our relationship with them is a referral link only.
Our scheduling system is operated by us on our own hardware rather than by a third party.
Our payment and subscription providers do not receive consumer health data. They receive only the information required to process a payment or manage a subscription.
We do not share consumer health data with any affiliate.
Your rights
If you are a Washington resident, or if we collected your consumer health data in Washington, you have the right to:
- Confirm whether we collect, share, or sell your consumer health data, and to access that data.
- Obtain a list of all third parties and affiliates with whom we have shared your consumer health data, together with contact information for each.
- Withdraw your consent to our collection and sharing of your consumer health data.
- Have your consumer health data deleted, including by our service providers and anyone else we shared it with.
How to exercise them
Email privacy@hermoodmentor.com with your request. We will respond within 45 days of receiving it. If we need more time, we may extend by a further 45 days and will tell you why before the first period ends. Where data sits in archived or backup systems, deletion may take up to six months to complete, and we will tell you if that applies to your request.
If we refuse a request, we will explain why and how to appeal. To appeal, reply to our response or email privacy@hermoodmentor.com with "Appeal" in the subject line. We will decide the appeal and respond in writing within 45 days. If we deny your appeal, you may contact the Washington State Attorney General at atg.wa.gov/file-complaint.
Changes
If we change how we collect, use, or share consumer health data, we will update this policy and, where the law requires it, obtain your consent before the new practice begins.
Contact
Her Mood Mentor LLC
25157 US Highway 93 S
Rollins, MT 59931
privacy@hermoodmentor.com
Notes on the draft
- On naming versus categorising third parties.
RCW 19.373.020requires the categories of third parties and the specific affiliates. Only affiliates must be named. We have named the software vendors, because that list is short and stable enough to maintain and transparency costs nothing there, but we have kept laboratories at category level since the panel mix changes and a policy that names a lab HMM no longer uses is worse than one that does not. Counsel should tell us if the stricter reading is warranted. - Naming still matters internally.
RCW 19.373.040entitles a consumer to a list of every third party and affiliate her data was shared with, including contact details for each. HMM therefore needs an internal, current register of laboratories and vendors with contacts, ready to produce on request within 45 days. That register is an operational requirement, not a published one. - The analytics question is deliberately absent. The draft says HMM does not share consumer health data with advertising platforms. That is true today. It becomes cleaner still once analytics is removed from health pages, which is item 2 of the plan. Publish the policy after that change, not before, so the statement is unambiguous.
- A general privacy policy is still needed separately, covering payment data, marketing email, website analytics, and everything that is not consumer health data.
- Decide on the street address before publishing. The address supplied appears to be residential. Publishing it puts a home address on a public page belonging to a business that serves people in acute mental health distress, some of whom reach a crisis screen inside the product. The statute wants a working contact method, and the email satisfies that. A registered agent address, a PO box, or a commercial mail address would serve the same purpose without the exposure. This is a judgment call for HMM, but it should be a deliberate one rather than a default.
Questions for counsel
Written so that most can be answered yes, no, or yes-with-a-caveat. If our reading is right, this should be a short engagement.
On the facts in the operating profile, do you concur that Her Mood Mentor is not a HIPAA covered entity, and will you confirm that in writing?
Does the laboratory testing relationship create business associate status, or any other route into HIPAA that we have missed?
Do you agree that the Washington My Health My Data Act applies to HMM, and that the separate homepage consumer health data privacy policy link is required? We have drafted that policy ourselves at draft CHD policy and would like it reviewed rather than redrafted.
Does our compliance plan miss anything material, and is the priority order sensible? We would rather be told the plan is wrong now than discover it after building the portal around it.
Does sending a page URL and title such as "Book Your Introductory Session" to Google Analytics constitute sharing consumer health data under the Act, where no advertising account is linked? We intend to remove analytics from those pages regardless, but the answer affects how we describe past practice.
Under MHMDA, does the consent requirement reach the ordinary act of a client filling out an intake questionnaire she requested, or is that within the necessary-to-provide-the-service carve-out?
Is the HMM mobile app a vendor of personal health records subject to the FTC Health Breach Notification Rule as amended in 2024? If so, what does the notification obligation practically require us to have ready in advance?
Given the GoodRx and BetterHelp orders, what is the standard we should hold ourselves to for advertising and analytics tags on pages where clients enter health information or purchase care? We would like a rule we can hand to an engineer.
Does California's CMIA reach the HMM app as a digital tool maintaining medical information?
We are choosing between holding intake questionnaires and lab data in a cloud database versus keeping clinical detail on premises with only non-clinical records in the cloud. Does that choice change our legal exposure enough to justify the added complexity, or is proper encryption and access control in the cloud sufficient?
What do we owe clients contractually? Specifically, is a click-through or typed-signature coaching agreement enforceable for our purposes, and does the agreement need privacy terms beyond the privacy policy?
Facts to confirm internally
These are ours to answer, not counsel's. Several of them change the analysis, so they should be settled before the brief goes out.
- Has HMM ever transmitted a HIPAA standard transaction electronically? Answered 2026-08-11: no. Never billed insurance, never inquired with any insurer or payer, directly or through any intermediary. One client requested a paid receipt to submit to her own HSA, which does not disturb the analysis.
- Does HMM issue superbills? Answered 2026-08-11: no.
- Entity structure. Answered 2026-08-11: Her Mood Mentor LLC, 25157 US Highway 93 S, Rollins, MT 59931. State of formation still to confirm.
- Decide whether to publish the Rollins street address. It appears to be a residential address. See the note on the draft policy page before this goes live.
- Laboratory mechanics. Whose account are labs ordered under, who signs the requisition, what agreement exists with each lab, and what client data is transmitted to them.
- Supplement dispensary and brand partnership. Answered 2026-08-11: Fullscript and Marea are affiliate referral links only. No client data is transmitted to either.
- Are the GA4 properties on the Kajabi checkout page linked to Google Ads? Answered 2026-08-11: no.
G-3E0XFP3CNBis HMM's property and its Google Ads links list is empty.G-GTBWYV09JYis not in HMM's Analytics account and is presumed to be Kajabi's own. - What analytics the mobile app sends, what is in each event payload, and whether any of it is health data.
- Where international clients are located. Specifically whether any are in the European Union or United Kingdom.
- Is a privacy policy published? Checked 2026-08-11: no. Neither
hermoodmentor.comnor the Kajabi properties publish a privacy policy, terms of service, or any policy link. Conventional paths return 404. What client agreement exists inside Practice Better is still to be established. - Verify every factual claim in the draft policy, especially the third-party list, before it is published. See the bracketed items at draft CHD policy.
- Practice Better exit. What data comes out, in what format, and what the vendor retains after termination.