NOTICE OF PRIVACY PRACTICES

Effective Date: January 6, 2026

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

1. Our Commitment to Your Privacy

Recovery Network, Inc. ("Recovery Network," "we," "our") acts as a Business Associate to Covered Entities and processes Protected Health Information (PHI) on their behalf under executed Business Associate Agreements (BAAs). We are required by law to maintain the confidentiality of your PHI and to follow the terms of this Notice.

Our systems are designed to support — not replace — licensed clinical judgment. All data processing occurs within secure, US-based infrastructure under our control.

2. How We Use and Disclose Your Information

We process PHI for treatment, payment, and healthcare operations as directed by your treating facility. This includes:

  • Wearable biometric analysis — heart rate, HRV, sleep, activity, and stress signals
  • Natural language processing (NLP) of patient communications, text, journal entries, and platform interactions, scored against C-SSRS and DAST-10 clinical frameworks
  • AI-generated risk scoring — Critical, High, Moderate, or Low tier assignment
  • Clinical decision-support outputs — advisory alerts routed to your licensed care team

All AI outputs are advisory only and require human oversight before any clinical action is taken. Your PHI is never used to train external or third-party AI models.

3. 42 CFR Part 2 — Substance Use Disorder Records

SUD records receive additional federal protections. Disclosure requires explicit patient consent unless otherwise permitted by law. Redisclosure restrictions apply to all downstream recipients. Data segmentation is enforced where applicable.

4. Human Oversight & AI Transparency

  • No autonomous clinical decisions are made at any tier
  • Critical-tier alerts require licensed clinician review before action
  • You may request a human review of any AI-assisted signal
  • Full decision context and data provenance are preserved in immutable audit logs
  • The AI Council is regularly audited for bias prevention

5. Data Sovereignty and Security

We use industry-standard safeguards to protect your information, including encryption at rest and in transit per HIPAA §164.312, role-based access controls, per-tenant Firestore isolation, immutable audit logging, and U.S.-based secure infrastructure.

Your PHI is not sold, marketed, or exported to foreign AI systems.

6. Your Rights

  • Inspect and obtain copies of your PHI
  • Request corrections or amendments to your records
  • Request restrictions on how your PHI is used or disclosed
  • Request an accounting of PHI disclosures
  • Request human review of any AI-assisted output
  • Request confidential communications via alternative methods

7. Changes to This Notice

We reserve the right to modify this Notice. Updated versions will be made available through our platform and upon request to your facility administrator.

8. Complaints and Contact

If you believe your privacy rights have been violated, you may file a complaint with Recovery Network or the U.S. Department of Health and Human Services Office for Civil Rights. There will be no retaliation for filing a complaint.

Privacy Officer

Recovery Network, Inc.
admin@recoverynetwork.ai · 206.353.8771