
Grounded Healing for Mind, Body, and Relationships
You understand the "why" behind your struggles, but your nervous system hasn’t caught up yet. I offer integrative psychotherapy that goes beyond talk therapy, combining Internal Family Systems (IFS), somatic processing, and outdoor ecotherapy to help you feel settled, connected, and whole.
Website & Client Portal Privacy Policy
Effective Date: September 28, 2026
Last Updated: September 28, 2026
Practice Entity: Musenge Selina Luchembe, PLLC (“Practice,” “we,” “us,” or “our”)
Websites & Services Covered: musenge.com and the associated client web portal, mobile application, and telehealth platforms provided via our electronic health records vendor, SimplePractice LLC (collectively, the “Client Portal” or the “Services”).
This Privacy Policy describes how Musenge Selina Luchembe, PLLC collects, uses, protects, and discloses Personal Information and Protected Health Information (PHI) of visitors to our website, clients, prospective clients, supervisees, and consultation participants (“Clients,” “you,” or “your”) when using our website, submitting inquiry forms, accessing our secure Client Portal, or participating in virtual care.
1. Important Note on HIPAA & Notice of Privacy Practices (NPP)
If you are an active or prospective therapy client receiving healthcare services, our collection, use, and disclosure of your individually identifiable health information—referred to as Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA)—is primarily governed by our HIPAA Notice of Privacy Practices (NPP) and applicable state laws in Tennessee and Missouri, rather than this general website policy.
Our software vendor, SimplePractice LLC, acts as our HIPAA Business Associate to provide our secure electronic health records (EHR) system, Client Portal, appointment scheduling, billing, and telehealth features. We have executed a formal Business Associate Agreement (BAA) with SimplePractice ensuring they maintain administrative, physical, and technical safeguards meeting or exceeding federal HIPAA security standards.
2. Personal & Health Information We Collect
“Personal Information” is information that identifies, relates to, describes, or could reasonably be linked directly or indirectly with you or your household. Depending on how you interact with our website and Client Portal, we may collect:
-
Identifiers & Contact Details: Your legal name, preferred name, email address, physical mailing address, telephone numbers, emergency contact details, and IP address. We collect this directly when you submit a website contact inquiry or when you complete initial intake paperwork in the Client Portal.
-
Clinical & Sensitive Health Information: Health status, mental health history, symptoms, therapy notes, family history, relationship dynamics, and confidential intake disclosures submitted in the course of clinical psychotherapy, ecotherapy, or therapy intensives.
-
Billing & Transaction Information: Credit/debit card numbers, billing addresses, invoiced amounts, dates of service, superbill records, and insurance information (if seeking out-of-network reimbursement). Payment transactions are processed securely through our HIPAA-compliant merchant integration (Stripe via SimplePractice); we do not store full credit card numbers on our local practice hardware.
-
Audio, Visual & Telehealth Information: Video streams, audio transmission, and photographs uploaded during secure telehealth sessions or as part of intake/identity verification. Telehealth sessions are conducted over end-to-end encrypted connections and are never recorded without your prior explicit, written informed consent.
-
Appointment Information: Dates, times, frequency, and attendance records of scheduled in-office (Brentwood), ecotherapy (Nashville state parks), or virtual visits.
-
Clinical Supervision & Consultation Data: Professional license numbers, educational history, clinical case logs, and professional consultation notes submitted by trainees and licensed clinicians seeking supervision or IFSI consultation.
-
Internet, Device & Electronic Activity: Browser type, device operating system, referring URL, time spent on pages, and general geographic location (derived from IP address). We collect this in aggregated, non-identifying formats through standard website logging and analytics to ensure our website functions reliably.
3. How We Use Your Information
We collect and process your information exclusively for legitimate clinical, administrative, and legal purposes, including:
-
Delivering Clinical Care: Evaluating clinical fit, conducting psychotherapy sessions, designing treatment plans, providing ecotherapy and therapy intensives, and coordinating care in emergencies.
-
Client Portal Administration: Enabling self-scheduling, delivering automated appointment reminders (via text or email), sending electronic intake forms, and providing a secure platform for client-therapist messaging.
-
Financial & Billing Processing: Processing payments, generating Good Faith Estimates under the No Surprises Act, issuing monthly statements or superbills, and maintaining accurate financial records.
-
Professional Mentorship: Managing clinical supervision contracts, tracking supervision hours for the Tennessee Board (LMFT/LPC), and providing IFSI certification consultation.
-
Practice Operations & Security: Maintaining the technical integrity of our website, protecting against fraudulent, abusive, or unauthorized portal access, and diagnosing server issues.
-
Legal & Regulatory Compliance: Adhering to professional board ethics, complying with mandatory reporting laws (e.g., child or elder abuse, immediate risk of harm to self or others), responding to valid subpoenas, and adhering to Tennessee and Missouri healthcare statutes.
4. How We Disclose Your Information
We do not sell, rent, or trade your personal or health information to third parties, data brokers, or marketing networks. Disclosures occur only in the following limited circumstances:
-
To Business Associates & Trusted Service Providers: We share necessary data with contracted third parties that provide essential infrastructure—most notably SimplePractice LLC (our HIPAA-compliant EHR and Client Portal host), secure Google Workspace (HIPAA BAA-covered email and storage), and our secure website hosting platform (Wix). All such entities are legally and contractually bound to safeguard your data under strict confidentiality obligations.
-
To Protect Safety & Comply with Mandatory Reporting: Under state and federal law, confidentiality must be breached if:
-
There is reasonable suspicion of child, elder, or vulnerable adult abuse or neglect.
-
You communicate an explicit, imminent threat of severe physical harm or suicide toward yourself or another person.
-
We are served with a valid, legally enforceable court order or subpoena signed by a judge (subject to applicable clinical privilege protections).
-
-
With Your Explicit Consent: We will release treatment records, progress summaries, or diagnostic information to third parties (such as psychiatrists, primary care physicians, attorneys, or family members) only upon receipt of a signed, HIPAA-compliant Authorization for Release of Information.
5. Client Portal Access, Rights & Choices
-
Accessing & Correcting Your Records: You may view and edit contact details, billing methods, and completed documents directly within the Client Portal. To request an amendment to your formal clinical health record, you must submit a written request directly to Musenge Selina Luchembe, PLLC.
-
Notification Preferences: You may adjust your preferences for automated appointment reminders (SMS text or email) through the “Notification Settings” inside your Client Portal account.
-
Portal Communication Limits: The secure messaging function within the Client Portal is intended for routine scheduling and brief logistical questions. It is not an emergency hotline and is not monitored 24/7.
-
Medical Record Retention & Deletion: Unlike standard consumer web apps, healthcare regulations (including Tennessee Department of Health and Board rules) require licensed psychotherapists to retain adult clinical records for a minimum of ten (10) years following the termination of treatment (or longer for minor clients). Therefore, requests to delete medical records will be evaluated and limited in accordance with mandatory state clinical retention laws.
6. Website Cookies & Tracking Technologies
Our public website (musenge.com) is hosted on the Wix platform. Wix uses strictly necessary cookies to deliver core site functionality, prevent cross-site request forgery, and monitor system performance.
-
No Behavioral Ad Trackers on Sensitive Pages: We do not employ third-party advertising pixels (such as Meta/Facebook Pixel or invasive behavioral remarketing scripts) across pages containing clinical intake forms or portal logins.
-
Managing Cookies: You can set your web browser to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable cookies, please note that some interactive features of our public website may become inaccessible or fail to function properly.
-
Do Not Track: Our website currently does not respond to automated browser “Do Not Track” (DNT) signals.
7. Data Security & Storage
We implement robust administrative, physical, and technical safeguards to preserve the confidentiality and integrity of your information:
-
Transmission Encryption: All data transmitted to and from our website and the SimplePractice Client Portal utilizes industry-standard Secure Socket Layer / Transport Layer Security (SSL/TLS) encryption.
-
Access Controls: Electronic health records are password-protected, utilize multi-factor authentication (MFA), and are accessible only to authorized practice personnel.
-
Notice Regarding Standard Email & Text: While our primary email provider operates under a HIPAA BAA, standard unencrypted email and cellular SMS messages are inherently subject to interception outside our network. We strongly encourage all active clients to conduct sensitive clinical communications through the encrypted Client Portal rather than public email.
8. State Privacy Disclosures (Tennessee, Missouri & California)
-
Protected Health Information Exemption: State consumer privacy statutes—including the California Consumer Privacy Act (CCPA/CPRA), the Tennessee Information Protection Act (TIPA), and similar consumer laws—expressly exempt Protected Health Information (PHI) collected by covered healthcare entities subject to HIPAA. Those records are protected under HIPAA and state licensing statutes.
-
Non-PHI Website Consumer Rights: To the extent you interact with our public website as a visitor outside a clinical relationship, you may have the right under applicable state law to:
-
Request confirmation of whether we process your non-health personal data.
-
Request correction of inaccurate personal data.
-
Request deletion of consumer data that is not subject to legal record retention requirements.
-
Opt out of the sale of personal data (we do not sell your data).
-
To exercise any applicable privacy rights, please submit your request to info@musenge.com. We will verify your identity before processing any data requests.
9. Emergency & Crisis Disclaimer
This website, our email address, and the Client Portal messaging system are for non-emergency inquiries and scheduled appointments only.
If you are experiencing an acute mental health crisis, suicidal thoughts, or a medical emergency:
-
Call or text 988 to reach the national Suicide & Crisis Lifeline (free, confidential, available 24/7).
-
Call 911 or visit the nearest emergency room.
-
Tennessee Statewide Crisis Line: Call 855-CRISIS-1 (855-274-7471).
10. Children’s Privacy
Our public website is directed toward adults, professionals, and emancipated individuals. We do not knowingly collect personal information online from children under the age of 13 without direct parental or guardian consent within a formal, authorized clinical treatment agreement.
11. Changes to This Privacy Policy
We reserve the right to modify or update this Privacy Policy at our discretion to reflect evolving practice offerings, software vendor updates, or statutory revisions. Any updates will be published to musenge.com/privacy-policy with a revised “Last Updated” date. Significant changes affecting active clients will be communicated via the Client Portal or through email.
12. Contact Information & Privacy Officer
If you have questions regarding this Privacy Policy, your rights, or our privacy safeguards, please reach out to:
Musenge Selina Luchembe, LMFT-S, LPC-MHSP-S
Musenge Selina Luchembe, PLLC
111 Westwood Pl, Suite 300
Brentwood, TN 37027
-
Email: info@musenge.com
-
Phone: (615) 488-8011
-
Practice Website: musenge.com