Privacy Policy
Redstone Behavioral Health (“Redstone,” “we,” “us,” or “our”) is an outpatient addiction and mental health treatment provider in Bowling Green, Kentucky. Protecting your privacy is part of protecting your recovery, and we treat that responsibility seriously.
This Privacy Policy (“Policy”) explains how we collect, use, disclose, and safeguard information, including your protected health information (“PHI”), in accordance with the Health Insurance Portability and Accountability Act (“HIPAA”), the federal confidentiality rules for substance use disorder patient records at 42 C.F.R. Part 2 (“Part 2”), and applicable Kentucky law.
Who This Policy Applies To
This Policy covers:
- Visitors to our website, including anyone who submits a contact or insurance verification form
- Prospective clients who call, text, or otherwise reach our admissions team
- Current and former clients of our partial hospitalization (PHP), intensive outpatient (IOP), and outpatient (OP) programs
- Family members, referral partners, and others who share information with us in connection with a client’s care
Information We Collect
Information you give us directly. When you call us, complete a form on our site, or begin the admissions process, we may collect your name, phone number, email address, insurance provider and policy information, the reason you are reaching out, and anything else you choose to tell us.
Protected health information. If you enter our care, we collect the information necessary to treat you and to bill for that treatment. This includes medical and behavioral health history, assessment results, diagnoses, treatment and progress notes, medication and prescribing records, drug screening results, records from other providers, insurance and payment records, and emergency contact information.
Sensitive personal information. Depending on your circumstances, this may include a Social Security number, driver’s license or state identification number, financial account information, and demographic information such as date of birth.
Information collected automatically. When you visit our website, our servers and service providers may log your IP address, device and browser type, operating system, pages viewed, time spent on the site, referring page, and general geographic region. We also use cookies and similar technologies as described below.
How We Use Your Information
We use PHI for treatment, payment, and health care operations, and otherwise as permitted or required by law. In practice, that means we use it to:
- Provide, coordinate, and manage your clinical care, including with outside providers involved in your treatment
- Verify your insurance benefits, obtain prior authorizations, and bill your health plan
- Run quality improvement, accreditation, licensing, audit, training, and compliance activities
- Respond to your admissions inquiry and follow up about care you asked us about
- Contact you about appointments, treatment alternatives, and aftercare
- Operate, secure, and improve our website
- Meet our legal, regulatory, and accreditation obligations
We do not sell your personal information or your PHI. We do not use or disclose PHI for marketing purposes, and we do not disclose PHI to advertising platforms, without your written authorization.
Special Protections for Substance Use Disorder Records
Records that identify you as someone who has applied for, received, or been referred for substance use disorder treatment receive protection under federal law that is stronger than HIPAA alone. Under 42 C.F.R. Part 2:
- We generally may not tell anyone outside our program that you are a client here, or disclose any information identifying you as having a substance use disorder, without your written consent.
- That protection applies to family members, employers, schools, and anyone else who contacts us about you, unless you have signed a consent naming them.
- Federal law and regulations do not protect any information about a crime committed by a client either at the program or against any person who works for the program, or about any threat to commit such a crime.
- Federal law and regulations do not protect any information about suspected child abuse or neglect from being reported under state law to appropriate state or local authorities.
- Your records may not be used to investigate or prosecute you in a criminal matter unless a court issues an order that meets the specific requirements of Part 2.
- Limited exceptions allow disclosure without consent, including a bona fide medical emergency, disclosures to a qualified service organization that provides services to our program, program audits and evaluations, and research conducted under federal safeguards.
Under the 2024 revisions to Part 2, a single consent can, if you choose, permit disclosure for treatment, payment, and health care operations on an ongoing basis, and you may revoke that consent in writing at any time except to the extent it has already been acted on. We will provide you with our Notice of Privacy Practices describing these rights in full, and you may request a copy at any time.
How and When We Share Information
We share information only as needed and only as the law allows:
- With people involved in your care, such as treating providers, laboratories, pharmacies, and, where you have consented, family members or a designated support person
- With your health plan, for verification, authorization, claims, and payment
- With business associates and qualified service organizations, such as our electronic health record vendor, billing company, and IT providers, each of which is bound by a written agreement requiring them to protect your information
- For public health and safety, including reporting suspected abuse or neglect, responding to a serious and imminent threat to your health or safety or that of another person, and required public health activities
- As required by law, including in response to a valid court order, subpoena, or lawful government request, and to the U.S. Department of Health and Human Services when it is reviewing our compliance
Any disclosure not described in this Policy or in our Notice of Privacy Practices will be made only with your written authorization, which you may revoke at any time.
Cookies, Analytics, and Website Tracking
Our website uses cookies and similar technologies to keep the site working properly, remember your preferences, measure traffic, and understand which pages people find useful. Some of these tools are provided by third parties, such as web analytics providers.
We take particular care with tracking technologies on a behavioral health website. We do not knowingly configure advertising or analytics tools in a way that discloses your PHI or identifies you as a current or prospective client to a third party.
You can disable or delete cookies through your browser settings, and most analytics providers offer their own opt out tools. Blocking cookies may affect how parts of the site function. Where required, we honor recognized browser based opt out signals, such as Global Privacy Control.
Calls, Texts, and Forms
When you submit a form or send us your phone number, you are giving us permission to contact you about your inquiry by phone, text, or email. Message and data rates may apply, and you can opt out at any time by replying STOP or by telling the person you are speaking with. Consent to be contacted is never a condition of receiving treatment.
Please do not include detailed clinical information in a website form or an unencrypted email. Standard email and text messaging are not fully secure. If you need to share sensitive details, call us and we will find a secure way to receive them.
Your Rights Under HIPAA
You have the right to:
- Access. Inspect and obtain a copy of your health record, in electronic form where we maintain it that way.
- Amend. Ask us to correct information you believe is inaccurate or incomplete.
- An accounting of disclosures. Receive a list of certain disclosures we have made of your information.
- Request restrictions. Ask us to limit how we use or disclose your information. We will honor a request to withhold information from your health plan when you pay for a service in full out of pocket.
- Confidential communications. Ask us to contact you at a specific number, address, or in a specific way.
- A paper copy. Receive a paper copy of our Notice of Privacy Practices, even if you agreed to receive it electronically.
- Revoke an authorization. Withdraw permission you previously gave, in writing, except where we have already acted on it.
- Breach notification. Be notified if your unsecured PHI is involved in a breach.
- Complain. File a complaint with us or with federal or state authorities without fear of retaliation.
Your Rights Under Kentucky Law
The Kentucky Consumer Data Protection Act, which took effect on January 1, 2026, gives Kentucky residents rights over certain personal data, including the right to confirm whether we process your data, access and obtain a copy of it, correct inaccuracies, request deletion, and opt out of targeted advertising, the sale of personal data, and certain profiling.
Information governed by HIPAA and 42 C.F.R. Part 2 is handled under those federal frameworks rather than under the state statute, and your rights in that information are the HIPAA and Part 2 rights described above, which are broader in most respects. For information outside those frameworks, such as data collected from general website visitors, you may exercise your Kentucky rights by contacting us using the details below. We will respond within the time the statute allows and will tell you how to appeal if we decline your request.
Data Security
We maintain an information security program with administrative, technical, and physical safeguards designed to protect your Personal Information and PHI against unauthorized access, use, disclosure, alteration, and destruction. These measures include role based access controls, unique user credentials, encryption of data in transit and at rest where appropriate, secure disposal of records, workforce training on confidentiality and Part 2 requirements, business associate and qualified service organization agreements, and ongoing risk assessment.
No system is perfectly secure. If a breach of unsecured PHI or of personally identifiable information occurs, we will notify affected individuals and the appropriate authorities as required by the HIPAA Breach Notification Rule, 42 C.F.R. Part 2, and Kentucky’s data breach notification statute, KRS 365.732.
How Long We Keep Information
We retain clinical records for the period required by Kentucky licensing rules, federal regulation, and our accreditation standards, and we retain other information only as long as it serves the purpose it was collected for or as long as the law requires. When a record reaches the end of its retention period, we destroy it in a way that protects confidentiality.
Third Party Service Providers
We work with vendors who need access to information to do their jobs, including our electronic health record system, billing and revenue cycle partners, laboratory services, IT and hosting providers, and communication platforms. Each is bound by a business associate agreement, a qualified service organization agreement, or both, and each is required to protect your information under the same standards that apply to us and to use it only for the purpose we engaged them for.
Links to Other Websites
Our site may link to resources operated by others, such as insurance carriers, government agencies, or community organizations. We do not control those sites and are not responsible for their privacy practices. We encourage you to read the privacy policy of any site you visit.
Children’s Privacy
Our programs serve adults, and our website is not directed to children. We do not knowingly collect personal information from children under 13. If you believe a child has provided us information through our website, please contact us and we will delete it.
Changes to This Policy
We review this Policy at least annually and revise it whenever our practices or the law change in a meaningful way. The current version is always posted on this page with its effective date. We reserve the right to make changes effective for information we already maintain, and we will notify you of material changes affecting how we handle your PHI.
Contact Us
To ask a question about this Policy, exercise any of the rights described above, or request a copy of our Notice of Privacy Practices, contact our Privacy Officer:
[Privacy Officer Name], Privacy Officer
Redstone Behavioral Health
[Street Address]
Bowling Green, KY [ZIP]
[Phone Number]
[Email Address]
Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with our Privacy Officer, or directly with:
U.S. Department of Health and Human Services, Office for Civil Rights
200 Independence Avenue SW, Washington, D.C. 20201
1-877-696-6775 | ocrportal.hhs.gov/ocr/complaints
Complaints about the confidentiality of substance use disorder records under 42 C.F.R. Part 2 may also be submitted to the Department of Health and Human Services. Questions about your rights under Kentucky consumer privacy law may be directed to the Kentucky Office of the Attorney General, Consumer Protection Division, at ag.ky.gov.
We will never retaliate against you, deny you care, or treat you differently for filing a complaint.