Privacy Policy & Notice of Privacy Practices

Effective August 19, 2026

This notice describes how Club Serenity Inc. collects, uses, and protects information, how medical and substance use disorder records about you may be used and disclosed, and how you can get access to this information. Please review it carefully.

1. Scope — which parts apply to you

Some of what we do involves protected health information (PHI) and is covered by the federal HIPAA privacy and security rules; other activities are not. This notice states which sections apply where.

  • HIPAA-covered services: clinical and treatment-related services, the health records we keep about them, the client portal, and billing or funder claims associated with them. Sections 4 and 5 apply.
  • Not HIPAA-covered: browsing this public website, general drop-in center visits and peer support that are not part of a covered service, event sign-ups, contact-form messages, donations and membership, and general mailing lists. Sections 2, 3, 6, and 8 through 12 apply.

Where we are unsure whether a record falls under HIPAA, we apply the stricter protection. Substance use disorder treatment records are additionally protected by federal law described in Section 5.

2. Information we collect

Information you give us:

  • Identity and contact details: name, date of birth, address, phone numbers, email address, and emergency contacts.
  • Demographic information we are asked to report to funders, such as age range, sex, gender, race, ethnicity, veteran status, and county of residence.
  • Service information: check-ins, visits, encounter and service notes, referrals, appointments, and program participation.
  • Recovery housing application information: housing history, recovery history, income and employment, legal history, references, and supporting documents you upload.
  • Consents, releases of information, and signature certificates for forms you sign.
  • Photographs you or staff upload to your record, if you agree to one.
  • Messages you send through the portal or the website contact form.
  • Donation and membership details (processed by our payment provider — we do not store full card numbers).

Information collected automatically when you use the website or portal:

  • Device and browser type, general location derived from IP address, pages viewed, and dates and times of access.
  • Security and audit logs recording sign-ins and, for staff, which records were opened or changed.

Information from others: referral sources, treatment providers, county and state agencies, and family members — where you have consented or the law allows.

3. How we use information

  • To provide, coordinate, and follow up on services, housing, and referrals.
  • To contact you by email, text, or voice call as described in Section 6.
  • To operate our programs: scheduling, staffing, quality improvement, training, safety, and record keeping.
  • To bill for services and process donations and membership.
  • To report to funders and oversight agencies — for grant, county, and state reporting we use aggregate or de-identified counts wherever the report allows.
  • To comply with law, respond to lawful requests, and protect the safety of people at our facilities.

We do not sell your personal information, and we do not share it with advertisers.

4. HIPAA Notice of Privacy Practices (covered services)

For services covered by HIPAA, we may use and disclose your protected health information without your written authorization for:

  • Treatment — sharing with those involved in your care and coordinating referrals.
  • Payment — billing, eligibility, and claims for services provided.
  • Health care operations — quality review, training, audits, and administration.
  • As required by law — including public health activities, reports of suspected abuse or neglect, health oversight, court orders and subpoenas, law enforcement requests permitted by law, coroners, workers' compensation, and to avert a serious and imminent threat to health or safety.

Most other uses and disclosures — including marketing, any sale of PHI, and most psychotherapy notes — require your written authorization, which you may revoke in writing at any time (this does not undo disclosures already made).

Your rights regarding protected health information:

  • Inspect and get a copy of your record, in paper or electronic form.
  • Ask us to correct information you believe is wrong or incomplete.
  • Get an accounting of certain disclosures we have made.
  • Ask us to restrict certain uses or disclosures — including a required restriction on disclosing to a health plan a service you paid for in full out of pocket.
  • Ask us to communicate with you confidentially, at an alternate address or by an alternate method.
  • Get a paper copy of this notice on request.
  • Be notified if a breach occurs involving your unsecured protected health information.
  • Choose someone to act for you, such as a personal representative or a person with a health care power of attorney.

We are required by law to protect your information, to give you this notice, and to follow its terms. To exercise a right or file a complaint, contact Privacy Officer, c/o Club Serenity Inc.. You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at hhs.gov/ocr/privacy/hipaa/complaints. We will never retaliate against you for filing a complaint.

5. Substance use disorder records — 42 CFR Part 2

Federal law (42 U.S.C. § 290dd-2 and 42 CFR Part 2) gives special confidentiality protection to records of the identity, diagnosis, prognosis, or treatment of any person receiving services from a federally assisted substance use disorder program. Where we operate as a Part 2 program, we may not disclose those records — or even confirm that a person attends the program — without that person's written consent.

Disclosure is permitted without consent only in limited circumstances, including:

  • A bona fide medical emergency.
  • Scientific research, audits, and program evaluation conducted under the safeguards the regulation requires.
  • A court order that meets the specific Part 2 requirements — a subpoena alone is not enough.
  • Reports of suspected child abuse or neglect, and crimes committed on program premises or against program staff, as allowed by law.

Written consent under Part 2 must identify who may disclose, who may receive, what may be shared, and its purpose. You may revoke consent at any time, except to the extent it has already been acted on.

Notice to anyone who receives these records: federal law prohibits you from making any further disclosure of the information unless the further disclosure is expressly permitted by the written consent of the person to whom it pertains, or as otherwise permitted by 42 CFR Part 2. A general authorization for the release of medical or other information is NOT sufficient for this purpose. Federal law does not protect any information about a crime committed by a patient either at the program or against any person who works for the program, or about any threat to commit such a crime.

Where HIPAA and Part 2 both apply, we follow the stricter rule.

6. Email, text messages, and voice calls

With your permission we contact you by email, SMS/MMS text message, and telephone — including automated or prerecorded calls — for reminders, follow-up, housing application status, portal and account notices, and program updates. You opt in by providing your phone number or email and selecting the contact method you want. You may also text START to (724) 395-8340 to opt in to text messages.

  • These channels are not secure. Anyone with access to your phone, voicemail, or inbox may be able to read or hear them.
  • We keep the content minimal — we generally avoid including a diagnosis, treatment details, or the nature of a program in reminders and voicemail.
  • You may ask us to contact you only in a specific way, at a specific number or address, or to leave no voicemail. Tell any staff member or contact us and we will honor a reasonable request.
  • To stop texts, reply STOP; reply HELP for help. To stop marketing emails, use the unsubscribe link.
  • Opting out of reminders does not stop communications we are required or permitted to send about your treatment, safety, payment, or legal obligations.

Our messaging, email, and portal vendors act as our service providers and, where they handle protected health information, are required to safeguard it under a business associate agreement.

The full SMS terms and opt-in disclosure are at https://clubserenity.org/sms-terms.

Opt-in disclosure: End users opt-in by visiting https://clubserenity.org and adding their phone number. They then check a box agreeing to receive text messages from Club Serenity Inc.. Additionally, end users can also opt-in by texting START to (724) 395-8340 to opt in. Terms and Conditions at https://clubserenity.org/sms-terms. Privacy Policy at https://clubserenity.org/privacy.

7. Minors, family, and personal representatives

We share information with a parent, guardian, or personal representative when the law allows or requires it. Where a minor may lawfully consent to a service on their own, records of that service are treated as the minor's and are not released to a parent or guardian without the minor's consent, except as the law requires.

Family members, friends, and other supporters receive information only when you have signed a release identifying them, or in the limited circumstances that HIPAA and Part 2 permit.

8. Security, retention, and storage

We use administrative, physical, and technical safeguards intended to protect your information, including access controls, role-based staff permissions, audit logging of record access, and encryption of data in transit. No system can be guaranteed completely secure, and we do not promise that any transmission is risk-free.

We keep records for as long as needed to provide services and to satisfy legal, funder, insurance, and accreditation retention requirements, then dispose of them securely. Typical retention periods:

  • Clinical, treatment, and service records: at least seven years after the last date of service, and for a minor, at least seven years past the age of majority — longer where a funder, insurer, or state requirement applies.
  • Consents, releases of information, and signature certificates: kept with the record they authorize.
  • Recovery housing applications and residency records: at least seven years after the stay ends or the application is closed.
  • Agency referrals submitted through this website: three years from the date received.
  • Website contact-form messages, event sign-ups, and mailing-list entries: two years, or until you ask us to remove you.
  • Donation and membership records: seven years, as required for nonprofit financial and tax reporting.
  • Security and audit logs: at least six years, as HIPAA requires.

Uploaded photographs and documents are stored in private, access-controlled storage and are never publicly linked; when a photo or document is deleted from a record, the stored file itself is deleted, not just its listing.

Our systems and vendors are located in the United States.

9. Service providers and other data recipients

We use a small number of technology vendors to run this platform. They act on our instructions only, may not use your information for their own purposes, and — where they may encounter protected health information — are engaged under a HIPAA business associate agreement or an equivalent confidentiality agreement. The categories we use are:

  • Application hosting, database, authentication, and file storage — stores the records, documents, and photographs described in Section 2.
  • Address verification (Google Address Validation) — receives only the street address entered at check-in or on an application, to confirm it is a real, deliverable address. No name, date of birth, or service information is sent.
  • Mapping and map imagery — receives a property address to display a map of one of our facilities. No client information is sent.
  • SMS/MMS and voice messaging — receives the mobile or phone number and the content of the message we send you.
  • Email delivery — receives the email address and the content of the message we send you.
  • Push notifications to staff devices — receives a device token and a short alert that a visit or task needs attention.
  • Payment processing for donations and membership — receives the payment details you enter; we never receive or store full card numbers.
  • Electronic health record and practice-management exchange, where you have been referred to or from a partner clinical provider under a release you signed.

We do not sell your personal information, we do not share it with advertisers or data brokers, and we do not use it to train anyone's artificial-intelligence models. If we ever add or change a vendor category, this section is updated before the change takes effect.

10. Automated processing

Parts of the platform process information automatically. This is what those steps do:

  • Returning-visitor matching: when you check in, the system compares the name, date of birth, phone, and email you enter against existing records to suggest which record is yours.
  • Duplicate detection: when records are imported or reviewed, the system scores how similar two records are and flags likely duplicates for staff to look at.
  • Address validation: the address you enter is checked against a third-party verification service, as described in Section 9.
  • Automated reminders and staff alerts: scheduled messages and notifications triggered by a check-in, appointment, or application step.

No automated step decides whether you receive services, housing, or benefits. A staff member reviews and confirms every record match, merge, and eligibility decision, and you can ask us to review any automated result that looks wrong.

We do not use generative artificial intelligence to make decisions about your care, and we do not send treatment records, notes, or identifiable health information to a generative AI service. If that ever changes, we will update this notice and, where the law or your consent requires it, we will ask you first.

11. Cookies, analytics, and tracking

The website uses cookies and similar technologies that are necessary for the site and portal to work — for example, keeping you signed in. We may use privacy-respecting analytics to understand how the site is used in aggregate.

We do not use advertising trackers on pages tied to clinical services or the portal, and we do not sell or share information for cross-context behavioral advertising. Most browsers let you block or delete cookies; some parts of the portal will not work if you do. We honor Global Privacy Control signals where required by law.

12. Your rights and how to exercise them

You may ask us at any time to:

  • Give you a copy of your record, in paper or electronic form.
  • Correct or amend information you believe is wrong or incomplete.
  • Tell you who we have disclosed your information to (an accounting of disclosures).
  • Restrict certain uses or disclosures, or communicate with you confidentially at an alternate address or by an alternate method.
  • Delete information about you, to the extent the law allows.
  • Change how and where we contact you, or opt out of non-essential messages.
  • Revoke a release of information or an electronic-records consent, going forward.
  • Ask a question about this notice or file a privacy complaint.

How to make a request: contact the Privacy Officer using the details below, or ask any staff member. Tell us what you want and how to reach you. We may need to verify your identity first. We respond within 30 days and will tell you if we need more time.

About deletion: information you gave us outside of care — a website message, an event sign-up, a mailing-list entry, or an unsubmitted application — is deleted on request. Clinical, housing, funder-reported, and financial records cannot always be deleted, because law, funders, and accreditation require us to keep them for the periods in Section 8. When we cannot delete a record, we will tell you why, delete what we can, and stop using the rest for anything beyond those requirements. Asking to delete a record never affects your ability to receive services.

Depending on where you live, you may have additional rights under state privacy law; contact us and we will tell you how they apply. We will never retaliate against you for making a request or filing a complaint.

Questions, requests, and legal notices may be directed to Privacy Officer, c/o Club Serenity Inc., 702 Fallowfield Avenue · Charleroi, PA · 15022, (724)565-5219, csboard@clubserenity.org.

13. Changes to this notice

We may change this notice and apply the changes to information we already hold. The effective date at the top of this page shows the current version, which is always posted here and available in paper form on request.

These are the statements and commitments of this organization. They are general boilerplate, not legal advice. Contact us with any question about this page.

Privacy Policy & Notice of Privacy Practices