Legal Compliance

Privacy Policy

Protecting Your Privacy Is Our Priority

At The Stone Community Health Center (TSCHC), your privacy, dignity, and trust are central to our care. We are committed to protecting your personal health information and ensuring compliance with all applicable federal and state laws — including the Health Insurance Portability and Accountability Act (HIPAA) and 42 CFR Part 2, which protect information about behavioral health and substance use treatment.

Effective Date: January 2025

1. Information We Collect

We collect only the information necessary to provide high-quality medical and behavioral health services, fulfill legal requirements, and maintain accurate health records.

Information collected may include:

  • Personal identification details (name, date of birth, address, phone, email)
  • Medical history, treatment notes, diagnoses, and prescriptions
  • Insurance and billing information
  • Referral or court-mandated documentation (when applicable)
  • Communication records between you and our staff

We do not collect unnecessary information and will never request personal financial data unrelated to your treatment.

2. How We Use Your Information

Your information is used only for authorized healthcare and administrative purposes, such as:

  • Delivering medical, behavioral, and counseling services
  • Coordinating care with your referring provider or agency (with consent)
  • Billing and payment processing with insurance or funding entities
  • Quality assurance, compliance audits, and state reporting
  • Appointment scheduling and follow-up communication

We will not sell, lease, or share your information for marketing purposes without your explicit written consent.

3. Confidentiality Under 42 CFR Part 2

For clients receiving substance use disorder (SUD) or behavioral health treatment, additional federal protections apply under 42 CFR Part 2.

This law prohibits TSCHC from disclosing information that identifies you as receiving SUD services unless:

  • You provide written consent;
  • Disclosure is authorized by a specific court order; or
  • Disclosure is otherwise permitted by law.

These protections ensure that your participation in treatment remains private and confidential.

4. HIPAA Rights and Protections

Under HIPAA, you have the right to:

  • Receive a copy of your medical records
  • Request corrections to inaccurate information
  • Request restrictions on how your information is used or shared
  • Receive an accounting of disclosures
  • File a complaint if you believe your privacy rights have been violated

All requests can be submitted in writing to our Privacy Officer (see contact below).

5. How We Store and Protect Your Information

TSCHC uses strict security measures to protect your data:

  • Encrypted electronic health records and secure cloud storage
  • Role-based access control for staff
  • Secure email and file transmission protocols
  • Physical safeguards in all clinical and administrative areas
  • Regular audits and HIPAA compliance training for employees

We retain records only as long as required by law and securely destroy outdated data.

6. Online Forms and Website Privacy

When you submit information through our website or online forms:

  • Data is transmitted securely via SSL (HTTPS encryption)
  • Submissions are routed only to [email protected] for authorized administrative use
  • We do not track cookies for advertising or analytics beyond standard web security logs
  • Uploaded documents (e.g., referrals, assessments) are stored only long enough to process the request

We encourage partners to send only necessary and authorized data.

7. Sharing Information with Referring Agencies

TSCHC collaborates with courts, probation officers, and treatment agencies to ensure proper client care and compliance.

Information is shared only when:

  • You have signed a valid Release of Information (ROI) form; or
  • Disclosure is legally required (for example, under court order)

Even in these cases, only the minimum necessary information is disclosed.

8. Email, Fax, and Electronic Communication

While we take every measure to secure communication, please be aware that standard email may not be fully encrypted.

Whenever possible, we use secure messaging systems for sensitive health information.

By communicating with us electronically, you acknowledge and accept the associated risks of electronic transmission.

9. Third-Party Service Providers

In some cases, we use trusted vendors to assist with secure data storage, billing, or electronic health record systems.

All third-party vendors are required to sign Business Associate Agreements (BAAs) ensuring they comply with the same privacy and security standards we uphold.

10. Your Choices and Responsibilities

You have full control over your personal health information.

You may:

  • Withdraw consent for disclosures at any time
  • Request a copy of your ROI or treatment records
  • Limit what is shared with outside agencies

We encourage all clients to review and understand their rights during intake and throughout care.

11. Reporting a Privacy Concern

If you believe your privacy has been compromised, please contact us immediately.

We take all privacy concerns seriously and will respond within 10 business days.

Contact:

Privacy Officer – The Stone Community Health Center

423 N Country Club Drive, Suite 45, Mesa, AZ 85201

(480) 659-6359

[email protected]

If your concern is not resolved, you may also file a complaint directly with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) at:

https://www.hhs.gov/ocr/privacy/hipaa/complaints/

12. Updates to This Policy

TSCHC may update this Privacy Policy periodically to reflect changes in laws or organizational practices.

We will post revisions on this page with an updated effective date.

We encourage all visitors and clients to review this policy regularly.

13. Acknowledgment

By receiving services from TSCHC or submitting forms on our website, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.

Visit Us

423 N Country Club Drive
Suite 45
Mesa, AZ 85201

Office Hours

Monday – Friday
9:00 AM – 4:30 PM

"At The Stone Community Health Center, your privacy and trust are the foundation of our care."