SoundQuest Station — HIPAA Policy
Notice of Privacy Practices and Security Policy
Effective Date: January 1, 2025
Notice of Privacy Practices
(“Notice”)
This Notice of Privacy Practices (“Notice”) describes how SoundQuest Station — Music Gaming & Beyond Inc. (“SoundQuest Station”), Flourish Foundation Project Inc. (“Flourish Foundation Project”), and all contracted licensed mental health professionals, affiliates, volunteers, and peer support providers (collectively “we,” “our,” or “us”) may use and disclose Protected Health Information (“PHI”) and how you can access your information.
1. Introduction & Scope
This Notice applies to:
- All clinical and telehealth services provided through our app, web app, and websites.
- All records maintained in any format (electronic, paper, or verbal).
- All HIPAA-covered entities within our network.
We are committed to protecting your privacy in accordance with:
- The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations.
- Applicable state privacy laws, including the California Consumer Privacy Act (CCPA) and the New York SHIELD Act.
Clinical services are provided by Flourish Foundation Project Inc. or other contracted, licensed providers in their respective states. Our unsubscribed user version of the app is intended solely for educational and wellness purposes and does not provide clinical services. HIPAA protections apply only to PHI collected during subscribed, clinical services.
2. Definitions
- Protected Health Information (PHI): Any information, including demographic data, that identifies you and relates to your health condition, provision of healthcare, or payment for healthcare.
- Electronic PHI (ePHI): PHI that is created, stored, transmitted, or received electronically.
- Treatment: Provision, coordination, or management of healthcare services.
- Payment: Activities to obtain or provide reimbursement for healthcare services.
- Healthcare Operations: Administrative, financial, legal, and quality improvement activities necessary to run our services.
3. Permitted Uses & Disclosures Without Authorization
We may use or disclose your PHI without your written authorization for:
- Treatment – To coordinate your care between providers.
- Payment – To bill and collect payment for services rendered.
- Healthcare Operations – Quality assessment, staff training, and accreditation.
- Public Health Activities – Reporting communicable diseases or adverse events.
- Abuse, Neglect, or Domestic Violence Reporting – As required by law.
- Judicial & Administrative Proceedings – In response to a court order or subpoena.
- Law Enforcement Purposes – As required by law.
- Research – When approved by an Institutional Review Board and in compliance with HIPAA.
- Serious Threats to Health or Safety – To prevent or lessen a serious threat.
- Specialized Government Functions – Military, national security, or protective services.
- Workers’ Compensation – As authorized by and to the extent necessary to comply with laws.
4. Uses & Disclosures Requiring Written Authorization
We will obtain your written authorization before using or disclosing your PHI for:
- Marketing purposes.
- Sale of your information.
- Disclosure of psychotherapy notes.
You may revoke your authorization in writing at any time, except to the extent that action has already been taken.
5. Your Rights
- Access your PHI in paper or electronic form.
- Request Amendments to your PHI if you believe it is incorrect or incomplete.
- Receive an Accounting of Disclosures made in the six years prior to your request.
- Request Restrictions on certain uses and disclosures.
- Request Confidential Communications by alternative means.
- Obtain a Paper Copy of this Notice upon request.
- File a Complaint without fear of retaliation.
6. Safeguards to Protect Your Information
We maintain:
- Administrative Safeguards: Staff training, confidentiality agreements, and role-based access controls.
- Technical Safeguards: HIPAA-compliant encryption, secure data transmission, and multi-factor authentication.
- Physical Safeguards: Secured offices, locked file storage, and controlled facility access.
7. Special Protections
Certain categories of PHI receive heightened protection under federal and state law, including:
- Psychotherapy notes.
- Substance use disorder treatment records.
- HIV/AIDS-related information.
We will comply with all applicable restrictions before disclosing such information.
8. Breach Notification
If a breach of your unsecured PHI occurs, we will:
- Notify you without unreasonable delay and no later than 60 days after discovery.
- Include a description of the breach, the PHI involved, and recommended steps to protect yourself.
- Notify the U.S. Department of Health & Human Services and, when applicable, the media.
9. Retention & Secure Destruction
We retain PHI for the minimum period required by federal and state laws. After this period, PHI is securely destroyed using approved methods, such as shredding or secure deletion.
10. Minors & Parental Consent
Our services are recommended for users age 18 and older.
- Minors under 18 may only use clinical services with verified parental or legal guardian consent.
- The unsubscribed app version is intended for general wellness education and is not a substitute for clinical care.
- Parents/guardians are responsible for monitoring and consenting to their child’s use.
- We recommend users under 14 not use the app without direct parental oversight.
11. Community Chat Disclaimer
We provide moderated chat spaces for educational and peer support purposes.
- Offensive language filters and location data blocks are in place, but cannot guarantee all prohibited content will be blocked.
- Users should exercise caution and never share personal identifying information.
- We are not responsible for user-generated content.
12. No Emergency Services / 988 Disclaimer
- We do not provide emergency or crisis intervention services.
- If you are in crisis, call or text 988 or use webchat at 988lifeline.org.
- This link is provided as a courtesy; we are not affiliated with 988.
- By clicking the 988 link in our app or site, you will leave our platform.
- You may contact 988 directly at any time.
13. State-Specific Rights
California Residents: Under CCPA, you have the right to know, delete, and opt out of the sale of your personal information. We do not sell personal information. Requests can be made to the contact listed below.
New York Residents: Under the SHIELD Act, we implement reasonable safeguards to protect your private information and will notify you promptly of any data breach.
14. Changes to this Notice
We reserve the right to change this Notice and apply the changes to PHI we already hold. Updates will be posted on our app, web app, and websites.
15. Complaints & Contact Information
If you believe your privacy rights have been violated, you may contact:
SoundQuest Station — Music Gaming & Beyond Inc.Website: www.soundqueststation.app
Email: info@soundqueststation.com Flourish Foundation Project Inc.
Website: www.flourish.foundation
Email: info@flourish.foundation
You may also file a complaint with:
Office for Civil Rights (OCR), U.S. Department of Health & Human ServicesWebsite: www.hhs.gov/ocr/privacy/hipaa/complaints
We will not retaliate for filing a complaint.