Client Confidentiality and Privacy Notice

Effective Date: January 2, 2026

Last Updated: August 3, 2026

Commonwealth Education Group, LLC ("Commonwealth Education Group," "we," "us," or "our") provides special education advocacy, educational consulting, communication-access consulting, training, and related professional services to clients throughout the United States. Our work often requires families to entrust us with sensitive information about students, disabilities, health, communication, education, family circumstances, and disputes with schools or other institutions.

This Notice explains how we collect, use, protect, disclose, retain, and dispose of information obtained in connection with a prospective or active client relationship. It supplements the applicable service agreement. If this Notice conflicts with a signed service agreement, the service agreement will control to the extent permitted by law.

A.    Our Professional Commitment

Commonwealth Education Group adheres to the Council of Parent Attorneys and Advocates (COPAA) Voluntary Code of Ethics for Special Education Advocates. Consistent with that commitment, we maintain client confidentiality, maintain complete, accurate, and current case records, communicate honestly, identify potential conflicts of interest, and use client information only for legitimate professional and business purposes.

Commonwealth Education Group is not a law firm. Our services do not create an attorney-client relationship, and information shared with us is not protected by attorney-client privilege merely because it concerns legal rights or a dispute. We are generally not a covered entity under the Health Insurance Portability and Accountability Act (HIPAA), and records in our possession are not necessarily education records governed by the Family Educational Rights and Privacy Act (FERPA). We nevertheless treat client and student information as confidential and sensitive in accordance with our ethical commitments, contractual obligations, and applicable law.

B.     Information Covered by This Notice

Client information may include:

  • client and student names, contact information, dates of birth, and family relationships;

  • school, school district, grade, placement, program, and service information;

  • disability, medical, mental-health, therapy, behavioral, sensory, motor, and communication information;

  • educational evaluations, private evaluations, IEPs, Section 504 plans, progress reports, school records, disciplinary records, and work samples;

  • information about augmentative and alternative communication, letter-board access, communication partners, regulation, and access needs;

  • correspondence, meeting notices, notes, recordings when lawfully made, transcripts, draft documents, and communications with schools or other professionals;

  • complaints, mediation, hearings, settlement discussions, investigations, and other dispute-related information;

  • intake information, conflict-check information, signed agreements, authorizations, billing records, invoices, and payment status;

  • information provided by parents, guardians, adult students, attorneys, schools, evaluators, therapists, advocates, experts, witnesses, or other authorized persons; and

  • our work product, notes, research, analyses, recommendations, and case-management records.

C.     How We Obtain Client Information

We may receive information:

  • directly from a client, prospective client, adult student, parent, or guardian;

  • from another person the client authorizes us to contact;

  • from schools, school districts, attorneys, evaluators, therapists, providers, agencies, experts, or other members of a student's team;

  • through records, meetings, observations, evaluations, correspondence, public records, or lawful research; and

  • through scheduling, billing, payment, document-storage, videoconferencing, and other systems used to provide services.

We provide a secure, HIPAA-compliant client portal. Clients should provide only information relevant to the engagement and should use this portal for sensitive records. A client who provides information about another person represents that the client is authorized to provide it for the purposes of the engagement.

D.    How We Use Client Information

 We may use client information to:

  • evaluate a request for services and conduct a conflict check;

  • establish, administer, and conclude a professional engagement;

  • understand the student, family, educational history, access needs, and requested outcomes;

  • review records and provide fact-based advice, advocacy, consultation, training, or other agreed services;

  • prepare for and participate in meetings, observations, evaluations, negotiations, complaints, mediation, hearings, or other proceedings within the agreed scope of work and as permitted by law;

  • communicate with the client and persons authorized to participate in the matter;

  • prepare correspondence, reports, timelines, presentations, training materials, recommendations, or other work product for the client matter;

  • schedule services, process payments, send invoices, and maintain accurate case and business records;

  • comply with professional, contractual, legal, tax, insurance, and regulatory obligations;

  • protect the safety, security, rights, and property of the client, student, Commonwealth Education Group, or others; and

  • establish, exercise, or defend legal claims and resolve billing or service disputes.

 We do not use identifiable client or student information for advertising, public presentations, training examples, testimonials, media communications, public comments, or published materials without appropriate written authorization. When practical, we use de-identified or aggregated information for education, professional development, quality improvement, and general business analysis.

E.     Confidentiality and Authorized Disclosures

We do not disclose identifiable client information outside Commonwealth Education Group except:

  • as directed or authorized by the client or another legally authorized person;

  • as reasonably necessary to carry out the agreed scope of services, including communications with persons whom the client has authorized us to contact;

  • to service providers and professional advisers described below;

  • when required by law, subpoena, court order, or other lawful process;

  • when reasonably necessary to address a serious threat to a person's safety, suspected fraud or unlawful activity, or the security of our systems;

  • to establish, exercise, or defend legal claims, including a dispute concerning services or payment; or

  • in connection with a merger, reorganization, financing, sale of assets, or similar business transaction, subject to appropriate confidentiality protections.

Whenever reasonably possible, we seek the client's written authorization before communicating with a school, school district, attorney, evaluator, therapist, provider, expert, or other third party about the client matter. A general authorization may cover recurring communications reasonably related to the engagement. A client may revoke an authorization prospectively by written notice, but revocation does not affect information already disclosed in reliance on the authorization and may limit our ability to continue providing services.

 When disclosure is required by compulsory legal process, we will disclose only information reasonably responsive to the request. When legally permitted and appropriate, we will attempt to notify the affected client so the client may seek legal advice or object to the disclosure.

F.     Service Providers and Professional Advisers

We may use third parties to provide secure document storage, email, videoconferencing, scheduling, electronic signatures, payment processing, accounting, case or customer management, transcription, data backup, cybersecurity, technical support, and similar operational services. We limit access to what is reasonably necessary for the provider to perform its function and select providers with consideration for confidentiality and security.

We may also consult attorneys, accountants, insurers, information-security professionals, or other advisers about legitimate business, compliance, risk-management, or legal matters. These advisers are expected to maintain confidentiality as required by their professional duties, contracts, or applicable law.

We do not sell client information. We do not use client or student information for targeted advertising or disclose it to data brokers.

G.    Use of Technology and Artificial Intelligence

We may use technology to organize information, search records, transcribe or summarize material, improve accessibility, prepare drafts, or support other aspects of our work. We will use reasonable care in selecting and configuring technology used with client information.

We will not knowingly submit identifiable client records or confidential client information to a publicly available artificial-intelligence system for model training. If an artificial-intelligence or automated tool processes client information on our behalf, we will use a business, enterprise, or comparably controlled service when reasonably available and will limit the information provided to what is reasonably necessary. We remain responsible for reviewing work product and exercising professional judgment rather than relying solely on automated output.

H.    Communications and Meetings

Commonwealth Education Group provides a secure, HIPAA-compliant client portal for transmitting and storing sensitive client documents. Clients should use the portal, rather than ordinary email or text messaging, to send educational records, evaluations, medical or therapy information, and other confidential materials. Although the portal is designed to meet HIPAA security requirements, Commonwealth Education Group’s use of a HIPAA-compliant system does not mean that Commonwealth Education Group is a HIPAA-covered entity or that every record maintained by us is legally governed by HIPAA.

Email, text messaging, videoconferencing, shared documents, and cloud storage involve some risk even when reasonable safeguards are used. By choosing or agreeing to use a communication method, the client acknowledges its ordinary privacy risks. Clients should avoid sending Social Security numbers, full payment-card information, account passwords, or unrelated highly sensitive information.

We do not record a private client meeting or call without notice and any consent required by applicable law. Meetings involving schools, public bodies, or third parties may be subject to different recording and records rules. Any recording by Commonwealth Education Group will be handled as a client record. 

I.      Security Safeguards

We use reasonable administrative, technical, and physical safeguards designed to protect client information from unauthorized access, loss, misuse, alteration, or disclosure. Depending on the system and the nature of the information, safeguards may include:

  • access controls and password-protected accounts;

  • multifactor authentication when supported and appropriate;

  • encryption provided by our systems or service providers;

  • secure methods for document exchange;

  • backups and device-security practices;

  • confidentiality expectations for contractors and service providers;

  • vendor review and appropriate contractual protections; and

  • procedures for responding to suspected security incidents.

 No electronic system or transmission can be guaranteed to be completely secure. If we become aware of a breach affecting client information, we will investigate and provide any notice required by applicable law. Clients should notify us promptly if they believe information or an account used in the engagement has been compromised.

J.      Case Records, Retention, and Disposition

We maintain case records reasonably necessary to provide services, document our work, meet professional obligations, administer the engagement, address disputes, and comply with legal, tax, insurance, and business requirements.

Client files are retained for the period stated in the service agreement or records-retention policy. If no period is stated, we retain the file for a reasonable period based on the nature of the matter, the age of the student, possible future need for the records, professional and insurance guidance, and applicable law. Different categories of records may be retained for different periods.

At the conclusion of the engagement, the client may request a copy of client-supplied documents and final work product, subject to the service agreement, applicable law, technical feasibility, and any outstanding obligations that lawfully affect release. Internal administrative materials, conflict-check information, security records, proprietary templates, duplicate documents, and certain internal notes may not be included in the client copy.

When the applicable retention period ends, we may securely delete, destroy, or de-identify records without further notice unless the client has made another written arrangement with us or retention is required by law. Backup copies may remain temporarily until overwritten or securely deleted in the ordinary course.

K.     Privacy Requests

A client, adult student, parent, guardian, or other legally authorized person may contact us to request access to, correction of, or deletion of personal information, or to ask how information has been used or disclosed. 

  • We may need to verify the requester's identity and authority. We may deny or limit a request when necessary to:

  • protect the confidentiality, safety, or legal rights of another person;

  • maintain accurate case, billing, tax, insurance, security, or business records;

  • comply with a service agreement, law, court order, or professional obligation;

  • prevent fraud or misuse;

  • preserve information relevant to an anticipated or existing dispute; or

  • establish, exercise, or defend legal claims. 

We will honor any additional rights and appeal procedures required by applicable law and will not discriminate against a person for exercising an applicable privacy right.

L.     Changes to This Notice

We may update this Notice to reflect changes in our services, technology, professional practices, or legal obligations. We will provide the current version to clients or make it available electronically. If a material change affects an active engagement or how we use previously collected client information, we will provide additional notice or obtain consent when required by the service agreement or applicable law.

M.   Questions or Concerns

Questions, concerns, and privacy requests may be directed to:

Commonwealth Education Group, LLC: info@commonwealtheducationgroup.com

Please do not include confidential student records, Social Security numbers, full payment-card information, or detailed medical information in an email.