Found Recovery, Inc. – Privacy Policy

Last Updated: [October 21, 2025]


1. Introduction

Found Recovery, Inc. (“Found Recovery,” “we,” “our,” or “us”) is committed to safeguarding the privacy, security, and confidentiality of all individuals who receive our services. This Privacy Policy explains how we collect, use, disclose, and protect personal and health information in accordance with:

  • The Health Insurance Portability and Accountability Act (HIPAA)

  • 42 CFR Part 2 (Confidentiality of Substance Use Disorder Treatment Records)

  • Applicable federal and state privacy laws

  • LegitScript Certification standards

By using our services or website, you acknowledge and consent to the practices described herein.


2. HIPAA Compliance

Found Recovery adheres to the highest standards of HIPAA compliance. We maintain administrative, technical, and physical safeguards to ensure the confidentiality, integrity, and availability of all Protected Health Information (PHI).

  • All PHI is encrypted and stored on secure, access-controlled systems.

  • Access is restricted to authorized personnel who require information to perform their job duties.

  • We conduct regular audits, risk assessments, and training to maintain compliance with current regulations.

Our ongoing commitment to HIPAA ensures your health information remains protected and handled with integrity.


3. Information We Collect

We may collect and maintain the following types of information:

  • Personal Information: Name, address, phone number, email, date of birth, emergency contact

  • Health Information: Medical history, diagnoses, treatment plans, progress notes, medications

  • Insurance and Billing Information: Provider name, policy number, payment details

  • Digital Information: IP address, browser data, and usage activity through our website or secure patient portal

All information is collected directly from you, your authorized representative, or your insurance provider.


4. How We Use Your Information

We use your information solely for legitimate business, clinical, and legal purposes, including:

  • Delivering clinical and therapeutic services

  • Coordinating care and communicating with other authorized providers

  • Billing and insurance processing

  • Meeting regulatory, licensing, and quality assurance requirements

  • Conducting internal audits and improving program effectiveness

We will never sell, rent, or trade your personal or health information.


5. Confidentiality and Disclosure

Your treatment information will not be disclosed without your written consent, except as permitted or required by law. Permitted disclosures include:

  • Medical emergencies

  • Authorized government audits or inspections

  • Court orders or legal requirements under 42 CFR Part 2

  • Communication with entities or individuals you have specifically authorized

All disclosures are documented in compliance with federal and state law.


6. Your Rights

You have the legal right to:

  • Access and obtain copies of your medical and billing records

  • Request corrections to inaccurate or incomplete information

  • Restrict disclosures of your information where legally permissible

  • Revoke consent for sharing information at any time (subject to prior actions taken)

  • File a complaint if you believe your privacy rights have been violated

Requests may be submitted in writing to our Privacy Officer at the contact information below.


7. Data Security

We employ industry-standard safeguards to protect all PHI, including:

  • HIPAA-compliant encrypted systems

  • Secure data transmission protocols (SSL/TLS)

  • Role-based access controls

  • Continuous monitoring and system updates

  • Secure storage of physical records in locked facilities

In the event of a data breach, affected individuals will be notified promptly in accordance with applicable laws.


8. Communication

We may contact you via phone, email, mail, or text message to coordinate care, appointments, or program updates. You may opt out of digital communications at any time by notifying our staff.


9. Telehealth and Online Services

If you receive telehealth or online services, all communications occur through secure, HIPAA-compliant platforms. You are responsible for using a private and secure internet connection to protect your confidentiality.


10. Updates to This Policy

We may revise this Privacy Policy periodically to reflect regulatory or operational updates. The most current version will always be available on our website, with the effective date clearly noted.


11. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or your rights under HIPAA and 42 CFR Part 2, please contact:


Found Recovery, Inc.
27489 Agoura Rd. Suite 205
Agoura Hills, CA 91301
Phone: (805) 624-3373
Email: cainan@foundrecovery.org