M3 Review — Privacy Policy
M3MentalHealth.org
M-3 Information, LLC · 155 Gibbs Street, Rockville, MD 20850
Effective Date / Last Modified: July 8, 2026
1. Overview and Scope
This Privacy Policy describes how M-3 Information, LLC and its parents, subsidiaries, affiliates, and operating ventures (“M3,” “we,” “us,” or “our”) collect, use, disclose, and protect information in connection with M3MentalHealth.org and any related websites, applications, and services we operate (the “Services”), including the M3 Review, the M3 Checklist, and other M3 Assessments. This Privacy Policy is incorporated into and forms part of our Terms and Conditions. By using the Services, you agree to this Privacy Policy as it may be amended from time to time in our sole discretion; the current version is always posted on the Services.
Related notices. When we act as a healthcare provider or otherwise handle protected health information (“PHI”) subject to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 C.F.R. Parts 160 and 164 (“HIPAA”), including the Privacy, Security, and Breach Notification Rules, our Notice of Privacy Practices governs that information and controls over this Policy in the event of a conflict. Consumer health data of Washington and Nevada residents is additionally addressed in our Washington Consumer Health Data Privacy Policy. Both documents are posted at M3MentalHealth.org.
2. Information We Collect
2.1 Information You Provide
Contact and account information, such as name, email address, telephone number, postal address, username, and password, when you voluntarily provide it (for example, when registering or contacting us);
Demographic information, such as age, sex or gender, and ZIP code;
Assessment information, including your responses to Assessment questions, resulting scores, and reports. Assessment information is health-related information and is treated as sensitive data under this Policy and applicable law;
Payment and eligibility information, such as insurance or Medicare eligibility details, where applicable; and
Communications, such as emails or messages you send us.
2.2 Information Collected Automatically
Device and usage information, such as IP address, browser type, operating system, device identifiers, pages viewed, links clicked, referring URLs, and dates and times of access; and
Cookies and similar technologies, as described in Section 8.
2.3 Information from Third Parties
We may receive information from service providers that support the Services, such as payment processors, insurance or Medicare eligibility verification services, analytics providers, and identity or fraud-prevention services.
3. How We Use Information
To provide the Services, including administering Assessments, generating scores and reports, and delivering results;
To verify insurance or Medicare eligibility and process payments, where applicable;
To operate, maintain, secure, and improve the Services, including troubleshooting, analytics, and product development;
To communicate with you, respond to inquiries, and provide support;
To conduct research and quality-improvement activities, primarily using deidentified data as described in Section 4;
To detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activity;
To comply with legal obligations and enforce our Terms and other agreements; and
For any other purpose stated at the point of collection or with your consent.
We do not use or disclose personal information for purposes materially different from those described in this Policy without providing notice or obtaining any legally required consent. We collect personal information only when you voluntarily provide it or as described in this Policy, and we use each category of information only as described here or as stated on the page where it is collected.
4. Deidentified Data; Research and AI Training
To advance mental health research and improve our services, we may deidentify and aggregate information collected through the Services, including Assessment responses and scores. Deidentification is performed in accordance with recognized standards, including the HIPAA deidentification standard at 45 C.F.R. § 164.514 (the “safe harbor” method or expert determination), so that the data cannot reasonably be used to identify you or be linked back to you.
Deidentified and aggregated data may be used, alone or with collaborators, for the following purposes:
Scientific, clinical, epidemiological, and public health research and analysis, including studies to validate and improve screening instruments and to enhance mental health practices and outcomes, and publication of aggregate findings;
Training, development, testing, and validation of statistical models, large language models (LLMs), and other artificial intelligence systems intended to improve mental health assessment accuracy and support services; and
Benchmarking, quality assurance, and service improvement.
We commit that: (a) we will not attempt to re-identify deidentified data; (b) we contractually require any recipient of deidentified data to refrain from attempting re-identification; and (c) no personally identifiable information will be shared or disclosed as part of these research or AI-training activities. Where state privacy laws (such as the California Consumer Privacy Act, as amended) impose requirements on the use of deidentified data, we maintain and use such data in compliance with those requirements.
5. How We Share Information
We do not share personal identifying information, or information at the individual level, except as described in this Policy. We may share information as follows:
Service providers and processors that perform services on our behalf (such as hosting, analytics, payment processing, and eligibility verification), under contracts that restrict their use of the information;
Professional advisors, such as lawyers, auditors, and insurers, where reasonably necessary;
Legal and safety purposes: to comply with law, regulation, legal process, or governmental request; to enforce our Terms; or to protect the rights, property, or safety of M3, our users, or others;
Corporate transactions: in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business or assets, subject to standard confidentiality protections;
Deidentified and aggregated data, as described in Section 4; and
With your consent or at your direction.
We do not sell your personal information for monetary consideration, and we do not sell or share consumer health data or use it for targeted advertising without any consent or authorization required by applicable law, including the Washington My Health My Data Act and Nevada Senate Bill 370. If our practices change, we will update this Policy and provide any legally required notice and opt-out or consent mechanisms before doing so.
6. Applicable Standards and Legal Frameworks
We maintain our privacy program with reference to the federal and state standards currently applicable to online mental health screening services, including:
HIPAA (45 C.F.R. Parts 160 and 164), including the Privacy, Security, and Breach Notification Rules, where we act as a covered entity or business associate (see our Notice of Privacy Practices);
The Federal Trade Commission Act, Section 5 (prohibiting unfair or deceptive practices), and FTC guidance on health data;
The FTC Health Breach Notification Rule (16 C.F.R. Part 318), as amended effective 2024, which applies to vendors of personal health records and related entities not covered by HIPAA, including health websites and applications;
State comprehensive consumer privacy laws in effect as of 2026, including those of California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Florida, Delaware, New Hampshire, New Jersey, Kentucky, Nebraska, Minnesota, Maryland (Maryland Online Data Privacy Act), and Rhode Island;
State consumer health data laws, including the Washington My Health My Data Act (RCW ch. 19.373), Nevada SB 370, and the health data provisions of the Connecticut Data Privacy Act; and
The Children’s Online Privacy Protection Act (COPPA) and the CAN-SPAM Act.
Because our principal place of business is in Maryland, we give particular attention to the Maryland Online Data Privacy Act, which among other things imposes data-minimization requirements and restricts the sale of sensitive data, including health data.
7. Your Privacy Rights
7.1 State Privacy Rights
Depending on your state of residence, you may have some or all of the following rights with respect to your personal information:
To confirm whether we process your personal information and to access a copy of it, in a portable format where required;
To correct inaccuracies in your personal information;
To delete personal information you provided or that we obtained about you;
To opt out of the sale of personal information, targeted advertising, and certain profiling (we do not currently sell personal information);
To limit the use of sensitive personal information (California) or to require consent before sensitive data is processed (most other states); and
To appeal a refusal to act on a request, and, if the appeal is denied, to contact your state Attorney General.
To exercise these rights, email privacy@m3information.com or call 301-641-8045. We will verify your identity before acting on a request and will respond within the time required by your state’s law (generally 45 days, extendable once where permitted). You may authorize an agent to submit requests on your behalf where your state’s law allows. We will not discriminate or retaliate against you for exercising your rights.
7.2 Consumer Health Data Rights (Washington, Nevada, Connecticut)
If you are a resident of Washington or Nevada, or your consumer health data is collected in those states, you have additional rights under the Washington My Health My Data Act and Nevada SB 370, including the rights to confirm collection and sharing of consumer health data, to withdraw consent, and to have consumer health data deleted, and the right not to have your health data sold without valid authorization. These rights, and our related practices, are described in our Washington Consumer Health Data Privacy Policy posted at M3MentalHealth.org. Connecticut residents have analogous protections for consumer health data under the Connecticut Data Privacy Act.
7.3 HIPAA Rights
Where your information is PHI subject to HIPAA, you have the rights described in our Notice of Privacy Practices, including rights of access, amendment, accounting of disclosures, restriction requests, and confidential communications.
8. Cookie Policy
We and our partners use cookies and similar technologies. There are generally four categories of cookies, and we may use each on the Services:
Strictly Necessary Cookies. Essential to enable you to move around the Services and use their features, such as accessing secure areas. Because they are essential, they cannot be disabled through our cookie controls.
Performance Cookies. Collect information about how you use the Services, such as which pages you visit, to help us operate our infrastructure efficiently, serve fresher content, measure aggregate usage in an anonymized fashion, and test new features.
Functionality Cookies. Remember choices you make, such as login state and preferences, so we can tailor and enhance the Services. Information collected by these cookies does not track your browsing on other sites.
Targeting Cookies. We, our advertising partners, or other third parties may use these cookies to deliver advertising relevant to your interests and to measure campaign effectiveness. These cookies may recognize your device across sites, and related information may be shared with advertising networks and other partners. Because Assessment responses are sensitive health information, we do not permit targeting cookies to collect or receive your Assessment responses or scores, and where consumer health data laws apply we obtain any required consent before using advertising technologies with such data.
Managing cookies. Most browsers let you refuse or delete cookies through browser settings. Disabling cookies may affect the functioning of the Services.
8.1 Opt-Out Preference Signals and Do Not Track
Where required by applicable state law (including California and Colorado), we honor browser-based universal opt-out preference signals, such as the Global Privacy Control (GPC), as a valid request to opt out of sale or targeted advertising for the browser or device sending the signal. Except for such recognized signals, the Services do not currently respond to “Do Not Track” browser settings.
9. Data Security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and disclosure, appropriate to the sensitivity of the data, with reference to recognized frameworks such as the HIPAA Security Rule and the NIST Cybersecurity Framework. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials.
10. Breach Notification
If we experience a breach of unsecured health information, we will notify affected individuals, and regulators and media where required, in accordance with applicable law, including the HIPAA Breach Notification Rule (where PHI is involved), the FTC Health Breach Notification Rule (16 C.F.R. Part 318) (which requires notice without unreasonable delay and no later than 60 calendar days after discovery), and applicable state breach notification statutes, including the Maryland Personal Information Protection Act.
11. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, to comply with legal, regulatory, tax, accounting, or reporting obligations, to resolve disputes, and to enforce our agreements. Retention periods vary by data category and legal requirement. When personal information is no longer needed, we delete it or deidentify it in accordance with Section 4.
12. Children
The Services are intended solely for individuals 18 years of age or older. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect personal information from children under 13 within the meaning of COPPA. If you believe a person under 18 has provided personal information to us, contact privacy@m3information.com and we will delete it.
13. Third-Party Sites and Services
The Services may contain links to third-party websites and services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. Review the privacy policies of any third-party service before providing information to it.
14. Changes to This Privacy Policy
We may revise this Privacy Policy from time to time in our sole discretion. The Effective Date above reflects the most recent revision. Material changes will be posted on the Services, and where required by law we will provide additional notice or obtain consent. Your continued use of the Services after a revision constitutes acceptance of the revised Policy.
15. Contact Us
Privacy Officer, M-3 Information, LLC · 155 Gibbs Street, Rockville, MD 20850 · 301-641-8045 · privacy@m3information.com
See also our Notice of Privacy Practices, Washington Consumer Health Data Privacy Policy, and Terms and Conditions, each posted at M3MentalHealth.org.