New patient appointments available this week|Same-day visits for self-pay patients, as availableCall or text (713) 987-7828Patient portal
Mosaic Mental Healthand WellnessBook an appointment
Privacy

Your privacy, in plain terms.

How Mosaic Mental Health and Wellness collects, uses and protects information on this website, and how that differs from the Protected Health Information covered by our Notice of Privacy Practices.

Last updated May 26, 2026

Patient records are covered by our Notice of Privacy Practices, which you receive at intake and can request at any time. This page covers the website.

This Privacy Policy describes our policies and procedures on the collection, use and disclosure of your information when you use the Service, and tells you about your privacy rights and how the law protects you. We use your Personal Data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

Health information and HIPAA

Mosaic Mental Health, PLLC is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The handling of Protected Health Information (PHI) is governed primarily by a separate Notice of Privacy Practices, which patients receive at intake and which is available on request.

This Website Privacy Policy describes information collected through the website at www.mosaicmentalhealthtx.com. PHI collected as part of patient care is addressed in the Notice of Privacy Practices, not in this Website Privacy Policy. If you are a current or prospective Mosaic patient, please request a copy of the Notice of Privacy Practices for full information about how PHI is handled and about your rights under HIPAA.

Definitions

  • Account: a unique account created for you to access the Service.
  • Company: Mosaic Mental Health, PLLC, 440 Cobia Drive, Suite 602, Katy, TX 77494.
  • Personal Data: information relating to an identified or identifiable individual.
  • Protected Health Information (PHI): individually identifiable health information created or maintained by Mosaic.
  • Service: the Website.
  • Website: Mosaic Mental Health at www.mosaicmentalhealthtx.com.
  • You: the individual accessing or using the Service.

The information we collect

Personal Data

The Service may ask you for personally identifiable information, including your email address, first and last name, phone number, address, state, province, ZIP or postal code and city, and bank account information for payment processing. For bank transfer payments we may also request a date of birth, a passport or national ID card, a bank card statement, or other information that links you to an address.

Information you provide as part of becoming a patient, including intake forms, medical history, insurance information and clinical communications, is Protected Health Information and is handled under HIPAA and our Notice of Privacy Practices.

Usage Data

Usage Data is collected automatically when you use the Service. It may include your device's Internet Protocol address, browser type and version, the pages you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data. When you use a mobile device we may also collect the device type, its unique ID, its IP address, the mobile operating system, the type of mobile browser and other unique device identifiers.

Cookies and tracking technologies

We use cookies and similar tracking technologies to track activity on our Service and to store certain information. Cookies are small files placed on your device. You can instruct your browser to refuse all cookies, though some parts of the Service may then not work. Web beacons are small electronic files, also called clear gifs, pixel tags and single pixel gifs, that let us count users and gather site statistics.

Session cookies are deleted when you close your browser. Persistent cookies stay on your device when you go offline. We use necessary cookies to provide the Service, authenticate users and prevent fraudulent use of accounts; acceptance cookies to record whether you have accepted cookie use; and functionality cookies to remember choices such as your login details or language preference. Where the law requires it, we use non-essential cookies, such as analytics, advertising and remarketing cookies, only with your consent.

How we use your information

We may use Personal Data to provide and maintain the Service and monitor its use, to manage your account and registration, to perform a contract for products or services you have purchased, to contact you about updates, security information and services you have contracted for, to provide news and general information about similar services unless you have opted out, to manage your requests, in connection with a business transfer, and for data analysis that helps us identify trends and improve the Service.

PHI is used and disclosed for treatment, payment and health care operations, as those terms are defined under HIPAA, and as otherwise permitted or required by HIPAA. The full description of permitted uses and disclosures of PHI appears in the Notice of Privacy Practices.

Who we share it with

  • Service providers, to monitor and analyse use of the Service, process payments and contact you. Service providers that handle PHI sign Business Associate Agreements as HIPAA requires.
  • Business transfers, in connection with a merger, sale of assets, financing or acquisition.
  • Affiliates, who are required to honour this Privacy Policy.
  • Business partners, to offer products, services or promotions.
  • Other users, where you share information in a public area of the Service.
  • With your consent, for any other purpose.

Text messages

If you give us your mobile phone number and consent to receive text messages from Mosaic, you may receive appointment reminders and confirmations, refill notifications, important practice updates and replies to your messages. Your consent is voluntary and is not a condition of receiving care from Mosaic.

Message and data rates may apply, depending on your carrier, and message frequency varies with your appointments and needs. To opt out at any time, reply STOP to any message or write to info@mosaicmentalhealthtx.com. After you opt out you may still receive transactional messages that are required for your care. For help, reply HELP to any message or contact the office. We do not share your phone number with third parties for marketing purposes.

Telehealth

Mosaic offers telehealth, meaning video visits, as part of patient care. We use HIPAA-compliant video platforms with encrypted transmission. Sessions are not recorded unless you agree in writing in advance and there is a clinical reason. You are responsible for being in a private place during your visit. Standard HIPAA protections apply to telehealth visits. If you have concerns about the privacy of a telehealth visit, please raise them with your provider.

How long we keep it

We retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy, to comply with legal obligations, to resolve disputes and to enforce our agreements. Where we can, we shorten retention or reduce data by deleting, aggregating or anonymising it.

  • User accounts: for the life of the account relationship, plus up to 24 months after closure.
  • Support tickets, correspondence and chat transcripts: up to 24 months from closure.
  • Website analytics and server logs: up to 24 months.
  • Payment information: not stored on our servers; it is processed by payment service providers.
  • Transaction, billing and invoice records: up to 10 years, for tax and financial compliance.
  • Adult medical and clinical records: at least 7 years from the date of last treatment, consistent with Texas Medical Board rule 22 Tex. Admin. Code section 165.1.
  • Minor patients' medical and clinical records: until the patient turns 21, or 7 years from the date of last treatment, whichever is longer.

We may keep Personal Data longer where the law requires it, where it is necessary to establish, exercise or defend a legal claim, where you ask us to, or where copies remain in encrypted backups that are on a routine deletion schedule. When a retention period ends, data is securely deleted or anonymised. Residual copies in backups are not restored except for security, disaster recovery or legal compliance.

Transfers, deletion and disclosure

Your information is processed at the Company's operating offices and anywhere else the parties involved in the processing are located, which may be outside your state or country, where data protection laws can differ. Where the law requires it, we make sure international transfers are subject to appropriate safeguards. We take all steps reasonably necessary to keep your data secure and to treat it in accordance with this Privacy Policy.

You have the right to delete, or ask us to help you delete, the Personal Data we have collected about you. You can update, amend or delete your information by signing in to your account and visiting account settings, or by contacting us. We may need to retain certain information where we have a legal obligation or another lawful basis to do so. Your rights to access, amend or restrict the use of Protected Health Information are governed by HIPAA and described in the Notice of Privacy Practices.

We may disclose your Personal Data if we are required to do so by law, or in response to valid requests by public authorities such as a court or a government agency. We may also disclose it in the good faith belief that doing so is necessary to comply with a legal obligation, to protect and defend the rights or property of the Company, to prevent or investigate possible wrongdoing connected with the Service, to protect the personal safety of users of the Service or the public, or to protect against legal liability.

Security

The security of your Personal Data matters to us, but no method of transmission over the internet and no method of electronic storage is completely secure. While we use commercially reasonable means to protect your Personal Data, we cannot guarantee absolute security.

As a HIPAA covered entity we implement the administrative, physical and technical safeguards required by the HIPAA Security Rule to protect Protected Health Information. These include access controls, encryption of PHI in transit and at rest where appropriate, staff training on privacy and security, and regular review of our security practices. In the unlikely event of a breach affecting unsecured PHI, we will provide notification consistent with the HIPAA Breach Notification Rule and any applicable state law.

Service providers

The service providers we use may have access to your Personal Data. Those that process PHI do so under appropriate agreements, including Business Associate Agreements where HIPAA requires them.

Service providerPurpose
IntakeQPractice management, scheduling and electronic health records
Spruce HealthSecure messaging with patients and providers
SquarePayment processing, limited billing information
Aithaghoni BillingInsurance claim submission and payment processing
Google WorkspaceEmail and document management
Zoom, healthcare tier with a BAAVideo telehealth visits

We require service providers that handle PHI to maintain safeguards consistent with HIPAA and applicable law. We do not sell or rent PHI to third parties.

We may offer paid products or services and use third-party payment processors. We do not store or collect your payment card details; that information goes directly to the payment processor, whose use of your information is governed by its own privacy policy. Payment processors follow PCI-DSS standards. Square's privacy policy is at squareup.com/legal/privacy-no-account.

California privacy rights

This section supplements the rest of this Privacy Policy and applies only to visitors and users who live in California.

In the past twelve months we have collected identifiers, the categories of personal information listed in the California Customer Records statute at Cal. Civ. Code section 1798.80(e), commercial information, internet or other network activity, and sensitive personal information. We have not collected protected classification characteristics, biometric information, geolocation data, sensory data, professional or employment information, non-public education information, or inferences used for profiling.

Personal information does not include publicly available information from government records, deidentified or aggregated information, or information excluded from the scope of the CCPA and CPRA, such as health information covered by HIPAA and the California Confidentiality of Medical Information Act, or information covered by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, the California Financial Information Privacy Act or the Driver's Privacy Protection Act of 1994.

We obtain personal information directly from you, indirectly from you by observing your activity on the Service, automatically through cookies, and from service providers. We use and disclose it for the business and commercial purposes described above. We do not sell or share your personal information as most people understand those terms, meaning we do not disclose it in exchange for money or other payment.

California residents have the right to notice, the right to know and access, the right to opt out of any sale or sharing, the right to correct inaccurate information, the right to limit the use and disclosure of sensitive personal information, the right to delete, and the right not to be discriminated against for exercising these rights. To exercise them, write to info@mosaicmentalhealthtx.com. Only you, or a person registered with the California Secretary of State whom you authorise, may make a verifiable request about your personal information. Your request must give us enough information to verify that you are the person we collected information about, and enough detail for us to understand and respond. We will respond within 45 days of a verifiable request, and may extend that period once by another 45 days where it is reasonably necessary, with notice to you. Disclosures cover the 12 months before we receive the request.

We do not knowingly collect personal information from minors under the age of 16 through the Service, and we do not sell the personal information of consumers we know are under 16. If you believe a child under 16 has given us personal information, please contact us with enough detail for us to delete it.

Children's privacy

Our Service does not address anyone under the age of 16, and we do not knowingly collect personally identifiable information from anyone under 16 through it. If you are a parent or guardian and you know that your child has provided Personal Data, please contact us. If we learn that we have collected Personal Data from anyone under 16 without verified parental consent, we take steps to remove that information from our servers.

Mosaic Mental Health provides clinical services to children, adolescents and adults. Information provided as part of clinical care for a minor patient is handled under HIPAA, Texas law and our Notice of Privacy Practices, with parental or guardian involvement consistent with Texas law on minor patients and confidentiality. The age threshold above relates to use of the website, not to eligibility for care.

Our Service may contain links to websites we do not operate. If you click a third-party link you will be taken to that third party's site. We strongly advise you to review the privacy policy of every site you visit. We have no control over, and assume no responsibility for, the content, privacy policies or practices of any third-party site or service.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the new policy on this page, update the date at the top, and where appropriate let you know by email or by a prominent notice on the Service before the change takes effect. Please review this policy periodically. Changes are effective when they are posted on this page.

Contact us

If you have questions about this Privacy Policy, write to info@mosaicmentalhealthtx.com or call (713) 987-7828. For questions about your Protected Health Information, or to exercise your rights under HIPAA, please refer to our Notice of Privacy Practices, or write to the same address and say that your question concerns PHI.

Questions about any of this?

Call or text (713) 987-7828, Monday to Friday, 9 AM to 5 PM, or send a message and we will answer in writing.

New patient visits this weekCall or text
Mosaic Mental Healthand Wellness
Book
Privacy

Your privacy, in plain terms.

How Mosaic Mental Health and Wellness collects, uses and protects information on this website, and how that differs from the Protected Health Information covered by our Notice of Privacy Practices.

Last updated May 26, 2026

Patient records are covered by our Notice of Privacy Practices, which you receive at intake and can request at any time. This page covers the website.

This Privacy Policy describes our policies and procedures on the collection, use and disclosure of your information when you use the Service, and tells you about your privacy rights and how the law protects you. We use your Personal Data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

Health information and HIPAA

Mosaic Mental Health, PLLC is a covered entity under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The handling of Protected Health Information (PHI) is governed primarily by a separate Notice of Privacy Practices, which patients receive at intake and which is available on request.

This Website Privacy Policy describes information collected through the website at www.mosaicmentalhealthtx.com. PHI collected as part of patient care is addressed in the Notice of Privacy Practices, not in this Website Privacy Policy. If you are a current or prospective Mosaic patient, please request a copy of the Notice of Privacy Practices for full information about how PHI is handled and about your rights under HIPAA.

Definitions

  • Account: a unique account created for you to access the Service.
  • Company: Mosaic Mental Health, PLLC, 440 Cobia Drive, Suite 602, Katy, TX 77494.
  • Personal Data: information relating to an identified or identifiable individual.
  • Protected Health Information (PHI): individually identifiable health information created or maintained by Mosaic.
  • Service: the Website.
  • Website: Mosaic Mental Health at www.mosaicmentalhealthtx.com.
  • You: the individual accessing or using the Service.

The information we collect

Personal Data

The Service may ask you for personally identifiable information, including your email address, first and last name, phone number, address, state, province, ZIP or postal code and city, and bank account information for payment processing. For bank transfer payments we may also request a date of birth, a passport or national ID card, a bank card statement, or other information that links you to an address.

Information you provide as part of becoming a patient, including intake forms, medical history, insurance information and clinical communications, is Protected Health Information and is handled under HIPAA and our Notice of Privacy Practices.

Usage Data

Usage Data is collected automatically when you use the Service. It may include your device's Internet Protocol address, browser type and version, the pages you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data. When you use a mobile device we may also collect the device type, its unique ID, its IP address, the mobile operating system, the type of mobile browser and other unique device identifiers.

Cookies and tracking technologies

We use cookies and similar tracking technologies to track activity on our Service and to store certain information. Cookies are small files placed on your device. You can instruct your browser to refuse all cookies, though some parts of the Service may then not work. Web beacons are small electronic files, also called clear gifs, pixel tags and single pixel gifs, that let us count users and gather site statistics.

Session cookies are deleted when you close your browser. Persistent cookies stay on your device when you go offline. We use necessary cookies to provide the Service, authenticate users and prevent fraudulent use of accounts; acceptance cookies to record whether you have accepted cookie use; and functionality cookies to remember choices such as your login details or language preference. Where the law requires it, we use non-essential cookies, such as analytics, advertising and remarketing cookies, only with your consent.

How we use your information

We may use Personal Data to provide and maintain the Service and monitor its use, to manage your account and registration, to perform a contract for products or services you have purchased, to contact you about updates, security information and services you have contracted for, to provide news and general information about similar services unless you have opted out, to manage your requests, in connection with a business transfer, and for data analysis that helps us identify trends and improve the Service.

PHI is used and disclosed for treatment, payment and health care operations, as those terms are defined under HIPAA, and as otherwise permitted or required by HIPAA. The full description of permitted uses and disclosures of PHI appears in the Notice of Privacy Practices.

Who we share it with

  • Service providers, to monitor and analyse use of the Service, process payments and contact you. Service providers that handle PHI sign Business Associate Agreements as HIPAA requires.
  • Business transfers, in connection with a merger, sale of assets, financing or acquisition.
  • Affiliates, who are required to honour this Privacy Policy.
  • Business partners, to offer products, services or promotions.
  • Other users, where you share information in a public area of the Service.
  • With your consent, for any other purpose.

Text messages

If you give us your mobile phone number and consent to receive text messages from Mosaic, you may receive appointment reminders and confirmations, refill notifications, important practice updates and replies to your messages. Your consent is voluntary and is not a condition of receiving care from Mosaic.

Message and data rates may apply, depending on your carrier, and message frequency varies with your appointments and needs. To opt out at any time, reply STOP to any message or write to info@mosaicmentalhealthtx.com. After you opt out you may still receive transactional messages that are required for your care. For help, reply HELP to any message or contact the office. We do not share your phone number with third parties for marketing purposes.

Telehealth

Mosaic offers telehealth, meaning video visits, as part of patient care. We use HIPAA-compliant video platforms with encrypted transmission. Sessions are not recorded unless you agree in writing in advance and there is a clinical reason. You are responsible for being in a private place during your visit. Standard HIPAA protections apply to telehealth visits. If you have concerns about the privacy of a telehealth visit, please raise them with your provider.

How long we keep it

We retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy, to comply with legal obligations, to resolve disputes and to enforce our agreements. Where we can, we shorten retention or reduce data by deleting, aggregating or anonymising it.

  • User accounts: for the life of the account relationship, plus up to 24 months after closure.
  • Support tickets, correspondence and chat transcripts: up to 24 months from closure.
  • Website analytics and server logs: up to 24 months.
  • Payment information: not stored on our servers; it is processed by payment service providers.
  • Transaction, billing and invoice records: up to 10 years, for tax and financial compliance.
  • Adult medical and clinical records: at least 7 years from the date of last treatment, consistent with Texas Medical Board rule 22 Tex. Admin. Code section 165.1.
  • Minor patients' medical and clinical records: until the patient turns 21, or 7 years from the date of last treatment, whichever is longer.

We may keep Personal Data longer where the law requires it, where it is necessary to establish, exercise or defend a legal claim, where you ask us to, or where copies remain in encrypted backups that are on a routine deletion schedule. When a retention period ends, data is securely deleted or anonymised. Residual copies in backups are not restored except for security, disaster recovery or legal compliance.

Transfers, deletion and disclosure

Your information is processed at the Company's operating offices and anywhere else the parties involved in the processing are located, which may be outside your state or country, where data protection laws can differ. Where the law requires it, we make sure international transfers are subject to appropriate safeguards. We take all steps reasonably necessary to keep your data secure and to treat it in accordance with this Privacy Policy.

You have the right to delete, or ask us to help you delete, the Personal Data we have collected about you. You can update, amend or delete your information by signing in to your account and visiting account settings, or by contacting us. We may need to retain certain information where we have a legal obligation or another lawful basis to do so. Your rights to access, amend or restrict the use of Protected Health Information are governed by HIPAA and described in the Notice of Privacy Practices.

We may disclose your Personal Data if we are required to do so by law, or in response to valid requests by public authorities such as a court or a government agency. We may also disclose it in the good faith belief that doing so is necessary to comply with a legal obligation, to protect and defend the rights or property of the Company, to prevent or investigate possible wrongdoing connected with the Service, to protect the personal safety of users of the Service or the public, or to protect against legal liability.

Security

The security of your Personal Data matters to us, but no method of transmission over the internet and no method of electronic storage is completely secure. While we use commercially reasonable means to protect your Personal Data, we cannot guarantee absolute security.

As a HIPAA covered entity we implement the administrative, physical and technical safeguards required by the HIPAA Security Rule to protect Protected Health Information. These include access controls, encryption of PHI in transit and at rest where appropriate, staff training on privacy and security, and regular review of our security practices. In the unlikely event of a breach affecting unsecured PHI, we will provide notification consistent with the HIPAA Breach Notification Rule and any applicable state law.

Service providers

The service providers we use may have access to your Personal Data. Those that process PHI do so under appropriate agreements, including Business Associate Agreements where HIPAA requires them.

Service providerPurpose
IntakeQPractice management, scheduling and electronic health records
Spruce HealthSecure messaging with patients and providers
SquarePayment processing, limited billing information
Aithaghoni BillingInsurance claim submission and payment processing
Google WorkspaceEmail and document management
Zoom, healthcare tier with a BAAVideo telehealth visits

We require service providers that handle PHI to maintain safeguards consistent with HIPAA and applicable law. We do not sell or rent PHI to third parties.

We may offer paid products or services and use third-party payment processors. We do not store or collect your payment card details; that information goes directly to the payment processor, whose use of your information is governed by its own privacy policy. Payment processors follow PCI-DSS standards. Square's privacy policy is at squareup.com/legal/privacy-no-account.

California privacy rights

This section supplements the rest of this Privacy Policy and applies only to visitors and users who live in California.

In the past twelve months we have collected identifiers, the categories of personal information listed in the California Customer Records statute at Cal. Civ. Code section 1798.80(e), commercial information, internet or other network activity, and sensitive personal information. We have not collected protected classification characteristics, biometric information, geolocation data, sensory data, professional or employment information, non-public education information, or inferences used for profiling.

Personal information does not include publicly available information from government records, deidentified or aggregated information, or information excluded from the scope of the CCPA and CPRA, such as health information covered by HIPAA and the California Confidentiality of Medical Information Act, or information covered by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, the California Financial Information Privacy Act or the Driver's Privacy Protection Act of 1994.

We obtain personal information directly from you, indirectly from you by observing your activity on the Service, automatically through cookies, and from service providers. We use and disclose it for the business and commercial purposes described above. We do not sell or share your personal information as most people understand those terms, meaning we do not disclose it in exchange for money or other payment.

California residents have the right to notice, the right to know and access, the right to opt out of any sale or sharing, the right to correct inaccurate information, the right to limit the use and disclosure of sensitive personal information, the right to delete, and the right not to be discriminated against for exercising these rights. To exercise them, write to info@mosaicmentalhealthtx.com. Only you, or a person registered with the California Secretary of State whom you authorise, may make a verifiable request about your personal information. Your request must give us enough information to verify that you are the person we collected information about, and enough detail for us to understand and respond. We will respond within 45 days of a verifiable request, and may extend that period once by another 45 days where it is reasonably necessary, with notice to you. Disclosures cover the 12 months before we receive the request.

We do not knowingly collect personal information from minors under the age of 16 through the Service, and we do not sell the personal information of consumers we know are under 16. If you believe a child under 16 has given us personal information, please contact us with enough detail for us to delete it.

Children's privacy

Our Service does not address anyone under the age of 16, and we do not knowingly collect personally identifiable information from anyone under 16 through it. If you are a parent or guardian and you know that your child has provided Personal Data, please contact us. If we learn that we have collected Personal Data from anyone under 16 without verified parental consent, we take steps to remove that information from our servers.

Mosaic Mental Health provides clinical services to children, adolescents and adults. Information provided as part of clinical care for a minor patient is handled under HIPAA, Texas law and our Notice of Privacy Practices, with parental or guardian involvement consistent with Texas law on minor patients and confidentiality. The age threshold above relates to use of the website, not to eligibility for care.

Our Service may contain links to websites we do not operate. If you click a third-party link you will be taken to that third party's site. We strongly advise you to review the privacy policy of every site you visit. We have no control over, and assume no responsibility for, the content, privacy policies or practices of any third-party site or service.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the new policy on this page, update the date at the top, and where appropriate let you know by email or by a prominent notice on the Service before the change takes effect. Please review this policy periodically. Changes are effective when they are posted on this page.

Contact us

If you have questions about this Privacy Policy, write to info@mosaicmentalhealthtx.com or call (713) 987-7828. For questions about your Protected Health Information, or to exercise your rights under HIPAA, please refer to our Notice of Privacy Practices, or write to the same address and say that your question concerns PHI.

Questions about any of this?

Call or text (713) 987-7828, Monday to Friday, 9 AM to 5 PM, or send a message and we will answer in writing.