Privacy Policy

Privacy & Data Stewardship Policy

Effective Date: January 6, 2026

Recovery Network is committed to safeguarding personal, clinical, and organizational data with the highest standards of care. We process data as a Business Associate to Covered Entities under executed Business Associate Agreements (BAAs), in full compliance with HIPAA and 42 CFR Part 2.

Data Collected

The platform collects only data necessary to provide clinical support, operational insights, and system functionality. Data categories include:

  • Patient communications — text input, journal entries, and platform interactions
  • Clinical data — wearable biometrics (heart rate, HRV, sleep, activity, stress)
  • System logs — access records, audit trails, and session activity

AI Processing

Data is analyzed using natural language processing (NLP) and AI models operating under validated clinical frameworks (C-SSRS, DAST-10) to generate:

  • Risk tiers — Critical, High, Moderate, or Low classification
  • Alerts — automated signals routed to licensed clinical care teams
  • Care recommendations — advisory outputs requiring human review before any action

All AI outputs are advisory only. No autonomous clinical decisions are made. Final authority rests with licensed professionals at your facility. AI scoring supports — and does not replace — licensed clinical judgment.

42 CFR Part 2 — Substance Use Disorder Records

SUD records receive additional federal protections beyond standard HIPAA requirements:

  • Disclosure requires explicit patient consent unless otherwise permitted by law
  • Redisclosure restrictions apply to all downstream recipients
  • Data segmentation is enforced where technically applicable

Data Storage & Security

  • All data encrypted at rest and in transit per HIPAA §164.312
  • Dedicated, US-based GCP infrastructure with per-tenant Firestore isolation
  • Role-based access controls — authorized personnel only
  • Immutable audit logs across all PHI access and AI signal events
  • PHI never leaves the tenant boundary

Data Usage

Data is used solely to:

  • Support authorized clinical workflows within the treating facility
  • Improve system reliability, safety, and clinical accuracy
  • Generate aggregated, de-identified insights for operational learning

Recovery Network does not sell patient data and does not export identifiable clinical data to third-party AI labs, foreign systems, or advertising platforms.

Data Sharing

PHI is shared only with Covered Entities and authorized parties as directed by executed BAAs. No PHI is used to train external AI models or third-party systems.

Data Retention

Raw wearable and communication data is retained for the duration of patient enrollment plus 30 days. Aggregated, de-identified insights are retained as part of the clinical record. Patients may request deletion of raw data at any time through their care team.

Internal vs. External Learning

Internal system learning operates on de-identified, aggregated patterns and cannot modify patient records or system governance. External research and intelligence sources are evaluated separately and never blended into patient-specific data.

Your Rights

Authorized users may request access, correction, restriction, or deletion of data associated with their records, subject to applicable law and contractual agreements. Requests are coordinated through the treating Covered Entity.

Questions?

Contact our Privacy Officer at admin@recoverynetwork.ai