Talkspace is a third-party mental health app that matches patients with providers that fit their needs. The app states that it is fully HIPAA compliant. Still, in recent years, data breaches have placed Talkspace in the spotlight along with its competitors.
Talkspace protects US users' data per HIPAA and HITECH Act requirements. As they comply with HIPAA, their privacy policy outlines how PHI is handled. These notices apply to PHI and provide information on how your data is used, disclosed, and protected. This includes:
This privacy policy applies specifically to Talkspace services but does not cover the third-party applications, software, or websites users can access through Talkspace. Furthermore, Talkspace may collect personal data and medical information during registration and throughout the use of its services. This information is used to provide the services, match users with therapists, process payments, support users, conduct research (with explicit authorization), and ensure quality and compliance.
In a 2022 report by Mozilla, the privacy and security measures of mental health apps were assessed. Among the apps assessed, Talkspace was among the worst offenders for having a vague privacy policy with several loopholes negatively impacting user data. Talkspace was found to collect users' chat transcripts with therapists, which are considered PHI containing medical diagnoses, treatments, and patient information.
The 2023 update to the report found that the questionnaire supplied during registration asked users personal questions about their diagnosis (such as depression), which was then used for marketing purposes.
A report from The New York Times raised concerns about the handling of user data by mobile therapy company Talkspace. Former employees claim that client conversations were routinely reviewed and mined for insights, with common phrases resulting from the data mining being shared with company marketing. Talkspace's interventions in client-therapist interactions were also questioned, with claims that the company instructed therapists to keep clients within the app.
Related: Is online tracking HIPAA compliant?
While Talkspace denies using transcripts for marketing purposes, it acknowledges sharing insights internally. It has stated that it maintains HIPAA and HITECH Act compliance and has implemented security and privacy measures to protect user data.
Mental health apps often fall outside the scope of HIPAA, and despite Talkspaces' compliant status, there have been cases of data not being adequately protected. As such, users must protect their own data. These measures include:
Related: HIPAA compliant email: A definitive guide