Privacy Policy, Terms and Conditions
Effective Date: 6/25/26
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
Flourish Health, Inc. ("Flourish Health," "we," "our," or "us") provides behavioral and mental health services for adolescents, young adults, and families. This Notice of Privacy Practices ("Notice") describes how we may use and disclose your protected health information ("PHI"), your rights regarding your PHI, and our legal duties under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), 42 CFR Part 2 where applicable, and other applicable federal and state laws.
Your Information. Your Rights. Our Responsibilities.
We are required by law to maintain the privacy and security of your PHI, provide you with this Notice of our legal duties and privacy practices with respect to PHI, and follow the terms of this Notice currently in effect.
We will notify you promptly if a breach occurs that may have compromised the privacy or security of your information. Notifications will be provided without unreasonable delay and no later than 60 days following discovery of a breach of unsecured PHI, as required by law.
You may request a paper copy of this Notice at any time, even if you agreed to receive it electronically.
Your Rights
You have the right to:
- Get a copy of your medical record
- Request corrections to your medical record
- Request confidential communications
- Ask us to limit certain uses or disclosures
- Obtain an accounting of disclosures
- Designate an authorized representative to act on your behalf
- Receive a copy of this Notice
- File a complaint without retaliation
Access to Medical Records
You may request an electronic or paper copy of your medical record and other health information we maintain about you or direct us to send a copy of your PHI to another person designated by you in writing.
Requests should be submitted in writing to the Privacy Officer. We may request identity verification before releasing records.
We will provide access within 30 days when required by law. If we need additional time, we will notify you in writing. We may charge a reasonable, cost-based fee for copies.
Certain records may be excluded from access under applicable law, including psychotherapy notes and information compiled for legal proceedings.
Requesting Amendments
If you believe information in your medical record is incorrect or incomplete, you may request an amendment.
Requests must be submitted in writing and explain the reason for the request.
We may deny your request in certain circumstances permitted by law, including if:
- We did not create the information
- The information is accurate and complete
If denied, we will provide a written explanation within 60 days.
Confidential Communications
You may request that we contact you in a specific way or at a specific location.
Examples include:
- Calling only a specific phone number
- Sending mail to a different address
- Communicating through secure portal messaging only
We will accommodate reasonable requests.
Requesting Restrictions
You may request restrictions on certain uses or disclosures of your PHI for treatment, payment, and health care operations. You may also request to opt out of participation in Health Information Exchanges ("HIEs").
We are not required to agree to requested restrictions except where:
- The disclosure is to a health plan for payment or healthcare operations;
- You paid for the item or service out-of-pocket in full; and
- The disclosure is not otherwise required by law.
If we agree to a restriction, we will comply unless disclosure is necessary for emergency treatment or otherwise required by law.
Accounting of Disclosures
You may request a list (an accounting) of certain disclosures we made of your PHI during the previous six years. We will include all the disclosures except for those about treatment, payment, and health care operations, and certain other disclosures (such as any you asked us to make).
The first accounting within a 12-month period is free. Additional requests may incur a reasonable fee.
Authorized Representatives
Parents, legal guardians, individuals with medical power of attorney, and other authorized persons (known as "personal representatives") may exercise any of the rights described above on your behalf consistent with applicable law.
We may request documentation verifying authority of a personal representative to act on your behalf.
Special Rules for Minors and Adolescent Privacy
Because Flourish Health provides behavioral health services to minors and adolescents, additional privacy protections may apply under state law.
Depending on the nature of services provided and applicable law:
- Certain records may be confidential between the minor patient and provider
- Parents or guardians may have full or limited access to certain treatment information
- Minor patients may have rights to consent to specific categories of care
- Substance use disorder records may receive additional protections
We will comply with all applicable state and federal confidentiality laws governing minors' health information, including laws regarding access to such records.
Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with us at the contact information provided below or with the U.S. Department of Health and Human Services Office for Civil Rights by visiting the website listed below.
We will not retaliate against you for filing a complaint.
HHS Complaint Information:
https://www.hhs.gov/hipaa/filing-a-complaint/index.html
Contact Information
Privacy Officer: Josh Gachnang, CTO
Email: it@flourish.health
Phone: 910-517-0097
Mailing Address: [INSERT MAILING ADDRESS]
To exercise any privacy rights described herein, please contact us using the information above. Requests may be required in writing and we may request verification of identity before processing requests.
Our Uses and Disclosures
We may use and disclose your PHI without your written authorization for the purposes listed below. Not every use or disclosure in a category will be listed. Your PHI may be stored in paper, electronic or other form and may be disclosed electronically and by other methods.
Treatment
We may use or disclose information to treat you. For example, we may share information with other healthcare professionals involved in your treatment and care coordination.
Payment
We may use and disclose information to bill and receive payment from health plans, Medicaid, insurers, or other payers. For example, we may give information about you to your health insurance plan so it will pay for your services.
Healthcare Operations
We may use information to perform those activities necessary and related to our providing of health care services to you. For example, we may use and disclose information to:
- Conduct quality assessment and improvement activities
- Conduct training and supervision
- Perform care coordination
- Evaluate provider performance
- Maintain licensing and accreditation
- Operate our organization
Business Associates
We may share PHI with vendors and service providers that are business associates performing services on our behalf, including:
- Electronic health record providers
- Cloud hosting providers
- Billing vendors
- Secure communications vendors
- Telehealth platform providers
These entities are contractually required to safeguard PHI in accordance with HIPAA.
Individuals Involved in Your Care or Payment for Your Care and/or Notification Purposes
We may release PHI to a friend or family member who is involved in your health care or who helps pay for your care or to notify, or assist in the notification of (including identifying or locating), a family member, your personal representative, or another person responsible for your care of your location and general condition. In addition, we may disclose health information about you to an entity assisting in a disaster relief effort in order to assist with the provision of this Notice.
We may make incidental disclosures of limited PHI. Incidental uses and disclosures are by-products of otherwise permitted uses or disclosures which are limited in nature and cannot be reasonably prevented.
Public Health and Safety
We may disclose PHI when required or permitted by law to:
- Prevent or control disease
- Report abuse, neglect, or domestic violence
- Prevent serious threats to health or safety
- Comply with public health obligations
- Report cause of death or other vital statistics for deceased patients
Legal, Government & Other Requests
We may disclose information:
- In connection with judicial or administrative proceedings, such as in response to court orders or subpoenas
- For law enforcement purposes
- For national security or government functions
- For workers' compensation claims
- To coroners, medical examiners, or funeral directors
- To federal, state, and local government agencies for health oversight purposes
- As required by law. For example, we may disclose PHI about you to the U.S. Department of Health and Human Services if it requests such information to determine that we are complying with federal privacy law
Research
We may use or disclose PHI for research purposes when permitted by law, including:
- With your authorization
- Pursuant to Institutional Review Board (IRB) or Privacy Board approval
- Using de-identified information
- Using limited data sets subject to required protections
Health Information Exchanges
We may participate in one or more HIEs and may electronically share your protected health information for treatment, payment or healthcare operations and other permitted purposes with other participants of the HIE. HIEs allow your healthcare providers to efficiently access and use your identifiable health information as necessary for treatment and other lawful purposes.
Fundraising
We may contact you regarding fundraising activities permitted by law.
You may opt out of fundraising communications at any time.
If we have your substance use disorder patient records, subject to 42 CFR Part 2, we will give you clear and obvious notice in advance and a choice about whether to receive fundraising communications that use your Part 2 information.
Uses Requiring Written Authorization
We will obtain your written authorization before:
- Most disclosures of psychotherapy notes
- Marketing communications where authorization is required
- Selling PHI
- Other uses or disclosures not otherwise permitted by law
You may revoke an authorization at any time in writing, except to the extent we have already acted in reliance on it.
Psychotherapy Notes
Psychotherapy notes receive special protections under HIPAA.
Most uses and disclosures of psychotherapy notes require written authorization, except for certain limited situations permitted by law, including:
- Use by the originating provider for treatment
- Internal training programs
- Legal defense by the provider
- Oversight activities authorized by law
- Preventing serious threats to health or safety
Substance Use Disorder Records (42 CFR Part 2)
Certain records related to substance use disorder diagnosis, treatment, or referral may be protected under 42 CFR Part 2.
These records generally may not be disclosed without your written consent unless otherwise permitted or required by law.
Federal law prohibits unauthorized redisclosure of Part 2 records unless expressly permitted by the written consent of the individual or otherwise authorized by law.
You may revoke consent for future disclosures in writing, subject to legal limitations.
If we receive records from substance use disorder treatment programs subject to federal privacy restrictions found at 42 CFR Part 2, such records or testimony about their content cannot be used or disclosed in civil, criminal, administrative, or legislative proceedings against the individual unless based on written consent or we receive a court order entered after notice and an opportunity to be heard is provided to the individual or us, as provided by 42 CFR Part 2. A court order authorizing use or disclosure must be accompanied by a subpoena or other legal requirement compelling disclosure before the requested substance use disorder record is used or disclosed.
De-Identified Information
We may use or disclose health information that has been de-identified in accordance with HIPAA standards. De-identified information does not identify individual patients and is not considered PHI.
Data Retention
We retain medical and personal information for the periods required by applicable federal and state laws, contractual obligations, accreditation standards, and operational requirements.
When records are no longer required to be retained by such requirements, we may securely destroy or de-identify them in accordance with applicable law.
Use of Analytics and Advertising Technologies
Flourish Health may use website and application analytics tools, including advertising and marketing technologies, to better understand how our websites and applications are used, measure the effectiveness of our marketing efforts, and improve our services.
We do not use advertising or marketing technologies to collect, disclose, or share your Protected Health Information (PHI). Information used for advertising or analytics purposes is limited to data that is not PHI and is not reasonably capable of identifying you as a patient. Examples may include aggregated or de-identified usage statistics, general website interactions, or anonymous device and browser information.
Where required by law, we will obtain your consent before using cookies or similar technologies for analytics or advertising purposes. You may also manage certain tracking preferences through your browser settings or other available privacy controls.
Changes to This Notice
We reserve the right to revise this Notice and make revised terms effective for all information we maintain.
Updated versions will be posted on our website and made available upon request.
Data Security
We implement administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and disclosure.
However, no method of transmission or storage is completely secure.
Electronic Communications and Telehealth
Electronic communications may involve certain security risks despite reasonable safeguards.
If you communicate with us electronically or participate in telehealth services, you acknowledge:
- Email and SMS may not always be encrypted
- Messages could potentially be accessed by unauthorized persons
- Technical failures may occur
We use commercially reasonable safeguards and HIPAA-compliant platforms where required.
Additional telehealth consent forms and patient portal terms may apply.