HIPAA Policy

Effective Date: January 1, 2020

Last Updated: August 2, 2026

HIPAA Privacy Notice

We are required by law to maintain the privacy of your health-related data and we will not disclose your information except in accordance with state and federal law, including the Health Insurance Portability and Accountability Act of 1996 set forth at 42 U.S.C. § 132d et seq. as well as its implementing regulations at 45 C.F.R. Parts 160 & 164 (“HIPAA”), the laws and regulations governing the confidentiality of substance use disorder patient records set forth at 42 U.S.C. § 290dd-2 and 42 C.F.R. Part 2 (“Part 2”), and the California Confidentiality of Medical Information Act (“CMIA”). This HIPAA Privacy Notice combines our Privacy Notice under HIPAA and Patient Notice under Part 2, and any other notices that may be required by the CMIA.  Ascend Healthcare is a “covered entity” under HIPAA and a “Part 2 program” under Part 2. In addition, state law may provide additional restrictions to the use and disclosure of your health information.

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION, INCLUDING PROTECTED HEALTH INFORMATION (collectively, “PHI”), ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

At Ascend, we understand the importance of privacy and are committed to maintaining the confidentiality of your PHI. We make a record of the services we provide and sometimes we may receive PHI about you from third parties, such as your primary care provider or emergency provider, for permissible uses and disclosures under HIPAA, for purposes of healthcare-related treatment, payment, or operations, or as otherwise permitted by HIPAA to provide quality services to you and to transmit to other providers to assist with continuity of care. These records are also used to obtain payment for services provided to you which enables us to meet our professional and legal obligations to operate our organization. Otherwise, we will not use or disclose your PHI without your prior written authorization for any other permissible purposes under HIPAA outside of healthcare treatment, payment, or operations.

This HIPAA Privacy Notice is to provide you with information concerning our legal duties and privacy practices, including notifying affected individuals following a breach of unsecured PHI.

  1. How we may use and disclose your PHI:
  • Treatment: We may use or disclose medical information about you to facilitate medical treatment or services by providers. We may disclose medical information about you to health care providers, including doctors, nurses, technicians, medical students, or other hospital personnel who are involved in taking care of you. For example, we might disclose information about you with physicians who are treating you, such as your primary care provider or emergency provider.
  • Payment: We may use and disclose medical information about you for healthcare billing, to get payment from health plans or other entities, to determine your eligibility for your health plan benefits, to facilitate payment for treatment and services you receive from us, to determine benefit responsibility and coverage with health plans, or to coordinate your coverage for your care. For example, we may disclose information about your medical history to a physician (including your physician) to determine whether a particular treatment is experimental, investigational, or medically necessary, or to decide if a health plan will cover treatment. Additionally, we may share medical information with another entity to assist with the adjudication or subrogation of health claims.
  • Healthcare Operations: We may use and disclose medical information about you for our operations, to run our practice, improve your care, and contact you as needed. For example, we may use medical information in connection with: conducting quality assessments and administration improvements; conducting or arranging for medical review, legal services, audit services, and fraud and abuse detection programs; business planning and development such as cost management; and business management and general administrative activities, such as activities to help us comply with HIPAA requirements, customer service, resolution of internal grievances, and any other activities that are not inconsistent with HIPAA.

We may use and disclose your information to qualified service organizations or business associates who provide services to us for purposes of healthcare-related treatment, payment, or operations. We will always try to ensure that the medical information used or disclosed is limited to a “Designated Record Set” and to the “Minimum Necessary” standard, including a “limited data set,” as defined in HIPAA.

  1. Other Permitted Uses & Disclosures of Your PHI

We may be required to disclose your PHI to the U.S. Department of Health and Human Services, Office for Civil Rights, the primary federal agency that enforces HIPAA, to assist OCR with assessing our compliance with HIPAA requirements. Otherwise, we may also use and disclose your PHI for the following purposes:

  • In response to law enforcement requests, to assist them with fulfilling health oversight activities, pursuant to legal process or as required by law. For example, we may provide your information to law enforcement to report evidence directly related to criminal conduct that occurred on our premises or against program personnel.
  • In response to valid government requests, to assist them with fulfilling health oversight activities. For example, state healthcare agencies with oversight over our organization may request information to carry out their responsibilities.
  • To respond to lawsuits, legal action, subpoenas, or other lawful process. For example, we may receive a subpoena arising out of a pending lawsuit requesting information about you. We will request that proper confidentiality agreements are in place prior to sharing such information.
  • To complete any required mandated government reporting. For example, our clinicians are mandated reporters of child abuse and may use your PHI to report child abuse to government officials.
  • To avert a serious threat to health or safety. For example, health information may be provided in an emergency to paramedics to assure you are treated properly.
  • To our business associates to help us administer your care. We enter into contracts with these entities to keep your information as we are permitted to do so under HIPAA.
  • For public health activities and purposes. For example, we may submit reports to public health authorities to assist with their public health investigations and development of public health interventions.
  • To other individuals or entities as mandated by law.

Uses and disclosures other than those described or listed in this notice will be made only with your consent or prior written authorization, as reasonable and appropriate, and in accordance with legal requirements. You may revoke any consent or authorization you provided at any time, subject to certain conditions such as if we have already taken action in reliance on your consent or authorization, and pursuant to then-existing state and federal laws.

iii. Your HIPAA Rights:

Under HIPAA, you have certain rights with respect to your PHI. Subject to certain exceptions, you have the following rights with respect to your PHI.

  • Inspect and copy – With some exceptions, you have the right to inspect and obtain a digital or hard copy of your health information maintained in your designated record set. We may charge a fee for the associated cost of labor, mailing, or other supplies. We may deny your request to inspect and copy in certain limited circumstances. If you are denied access, you may request a review of the denial.
  • Amend – This means you may request an amendment of health information about you for as long as we maintain this information. In certain cases, we may deny your request for an amendment. If we deny your request for amendment, you have the right to file a statement of disagreement with us and we may prepare a rebuttal to your statement and will provide you with a copy of any such rebuttal. Please contact [email protected] if you have questions about amending your medical record.
  • Accounting of Disclosures – You have the right to request an “accounting of disclosures” (that is, a list of certain disclosures we have made of your PHI). Generally, you may receive an accounting of disclosures if the disclosure is required by law, made in connection with public health activities, or in situations similar to those listed above as “Other Permitted Uses and Disclosures”. You do not have a right to an accounting of disclosures where such disclosure was made:
    • For treatment, payment, or health care operations.
    • To you about your own health information.
    • Incidental to other permitted disclosures.
    • Where authorization was provided.
    • To family or friends involved in your care (where disclosure is permitted without authorization).
    • For national security or intelligence purposes or to correctional institutions or law enforcement officials in certain circumstances.
    • As part of a limited data set where the information disclosed excludes identifying information.
  • Request Restrictions: You have the right to request a restriction or limitation on the medical information we use or disclose about you for treatment, payment, or healthcare operations. You also have the right to request a limit on the medical information we disclose about you to someone involved in your care or the payment for your care, such as a family member or friend. For example, you may ask that we not use or disclose information about a procedure or lab test that you had. We are not required to agree to your request. If we do agree, we will comply with your request unless the information is needed to provide you emergency treatment.
  • Request Confidential Communications – You have the right to request to receive communications of health information by alternate means or at alternative locations. For example, you may request to receive confidential communications, including any mail and telephone calls related to the services we are providing you, only in your home location or an alternative location you identify. We will strive to accommodate all reasonable requests.
  • Paper copy of this Notice – You may request a paper copy of this Notice at any time, even if you have agreed to receive this HIPAA Privacy Notice electronically.

To make any requests connected with your rights, please email us at [email protected] .

  1. Our Duties.

In the event your information is acquired by an unauthorized party, we will provide notification to you.

Notice will be given without unreasonable delay, and will include a description of the incident, the types of information involved in the incident, steps you should take to protect yourself from harm, and a brief description of what we are doing to investigate the incident. We will also provide you with contact information of who you may contact for more information.

We are required by law to maintain the privacy of PHI, to provide you with this HIPAA Privacy Notice of our legal duties and privacy practices with respect to protected PHI/ePHI, and to notify you if you are affected by a breach of unsecured protected health information. We must follow the duties and privacy practices described in this HIPAA Privacy Notice. We will not use or disclose your PHI other than as described in this HIPAA Privacy Notice unless you inform us in writing otherwise.

  1. Changes to this Notice.

We reserve the right to change the terms of our HIPAA Privacy Notice and to make the new HIPAA Privacy Notice provisions effective for all PHI that we maintain. We will send you a copy of the revised notice by email (or, if unavailable, by mail) for existing clients and those who discharged within the past year, and will also post it on our website.

  1. Questions and Complaints. 

You may submit your questions or complaints regarding this HIPAA Privacy Notice to us by contacting us at (310) 598-1840 or by sending an email to [email protected] . You may also submit a complaint the Secretary of the U.S. Department of Health and Human Services, Office for Civil Rights if you believe your privacy rights have been violated. Any violation of the legal and regulatory requirements applicable to our status as a Part 2 program is a crime. You may report any suspected violations of Part 2 requirements to the United States Attorney for the judicial district in which the violation occurs by visiting https://www.justice.gov/usao/find-your-united-states-attorney or to the Substance Abuse and Mental Health Services Administration (SAMHSA) office responsible for opioid treatment program oversight by visiting https://www.samhsa.gov/about-us/contact-us.  We will not take retaliatory action against you if you file a complaint about our privacy practices.