Privacy Policy

This Privacy Policy (“Policy”) applies to 1250 Old Soldier Cr Rd, Kirksey, KY 42054 and 1338 SR 121 South, Murray, KY 42071, and Neartown Inc. (“Company”) and governs data collection and usage. For the purposes of this Privacy Policy, unless otherwise noted, all references to the Company include 1250 Old Soldier Cr Rd, Kirksey, KY 42054 and 1338 SR 121 South, Murray, KY 42071. The Company’s website is an informational site. By using the Company website, you consent to the data practices described in this statement. This Policy describes how the Company handles personal information it collects, both through its website and offline, as described in the “Scope of This Policy” section below. It does not modify or replace the Notice of Privacy Practices that governs protected health information created or received in connection with treatment. Information that identifies a person as receiving substance use disorder treatment is also protected under federal law, including the HIPAA Privacy Rule (45 C.F.R. Parts 160 and 164) and the Confidentiality of Substance Use Disorder Patient Records regulations (42 C.F.R. Part 2), which in many cases impose stricter limits on use and disclosure than this Policy. If this Policy conflicts with HIPAA or 42 C.F.R. Part 2, the more protective standard controls.

Scope of This Policy; Information Collected Offline

This Policy applies to personal information the Company collects about you, whether collected through the website, by telephone, by email or mail, or in person. The Company collects personal information offline as well as online, including when you call us, request information or a referral, complete an admissions or insurance verification process, make a payment or donation, sign up for a newsletter or event, or interact with the Company as a vendor, contractor, or job applicant.

This Policy is organized in two parts. The sections that follow describe how the Company handles general personal information, such as contact details, communications, payment information, and website usage, however that information is collected. Protected health information and substance use disorder treatment records, including information collected during intake, screening, assessment, billing, and treatment, are governed by the “Protection of Patient Data and Compliance with HIPAA Guidelines” and “Substance Use Disorder Records (42 C.F.R. Part 2)” sections below, by our Notice of Privacy Practices, and by HIPAA and 42 C.F.R. Part 2. Where those laws apply, they control over this Policy.

If you contact the Company to ask about treatment for yourself or another person, the fact that you have done so may itself be protected as a substance use disorder record under 42 C.F.R. Part 2, and the Company handles that information accordingly.

Privacy Compliance Certification
The Company is accredited by CARF International.

Collection of your Personal Information

We do not collect personal information about you through our website unless you voluntarily provide it. You may provide personal information when you: (a) request information about our programs or services; (b) complete a contact, admissions, or insurance verification form; (c) send us an email or other message; or (d) submit payment information for products or services. We use the information you provide to respond to your request and to provide the services you ask for. We do not enroll website visitors in sweepstakes or contests, and we do not sign you up to receive offers from third parties. Any health information you submit through the website is handled in accordance with the “Protection of Patient Data” provisions below.

Sharing Information with Third Parties

The Company does not sell, rent, or lease its customer lists to third parties.

The Company may share data with trusted partners to help perform statistical analysis, send you email or postal mail, provide customer support, or arrange for deliveries. All such third parties are prohibited from using your personal information except to provide these services to the Company, and they are required to maintain the confidentiality of your information. The Company does not sell, share, or otherwise disclose your personal information for cross-context behavioral advertising or for any third party’s own marketing purposes. Where a service provider may access protected health information, the Company first enters into a Business Associate Agreement as required by HIPAA, and, where the service provider may access substance use disorder records, a written agreement that satisfies 42 C.F.R. 2.11 and 2.12(c)(4).

The Company may disclose your personal information, without notice, if required to do so by law or in the good faith belief that such action is necessary to: (a) conform to the edicts of the law or comply with legal process served on the Company or the site; (b) protect and defend the rights or property of the Company; and/or (c) act under exigent circumstances to protect the personal safety of users of the Company, or the public. This paragraph does not apply to protected health information or substance use disorder treatment records. The Company uses and discloses that information only as permitted by HIPAA and 42 C.F.R. Part 2. The Company will not respond to a subpoena, warrant, or other legal process by disclosing substance use disorder records unless the disclosure is authorized by your written consent or by a court order that meets the requirements of 42 C.F.R. Part 2, Subpart E, and the Company will not disclose more information than the order or consent permits.

Cookies and Website Analytics

The Company may use cookies and similar technologies to operate its website, remember your preferences, and understand how visitors use the site so that we can improve it. The Company does not use advertising trackers, pixels, or similar technologies that disclose information about your visit to third parties for those parties’ own advertising purposes, and the Company does not use information about your activity on the website to deliver targeted or interest-based advertising. We are especially careful not to share any information that could indicate an interest in addiction or substance use disorder treatment. You can set your browser to refuse cookies or to alert you when cookies are being sent, although some parts of the website may not function properly if you do.

Automatically Collected Information

The Company may automatically collect information about your computer hardware and software. This information can include your IP address, browser type, domain names, access times, and referring website addresses. This information is used for the operation of the service, to maintain quality of the service, and to provide general statistics regarding the use of the Company’s website. The Company does not combine this website usage information with any patient treatment records.

Links

This website contains links to other sites. Please be aware that we are not responsible for the content or privacy practices of such other sites. We encourage our users to be aware when they leave our site and to read the privacy statements of any other site that collects personally identifiable information.

Requests to Delete Website Information

Subject to certain exceptions set out below, on receipt of a verifiable request from you, we will: This section applies to personal information collected through our website. It does not apply to medical, treatment, or billing records, which the Company is required to retain and protect under HIPAA, 42 C.F.R. Part 2, and Kentucky law, and which cannot be deleted on request except as those laws allow. On receipt of a verifiable request, the Company will:

  • Delete your personal information from our records; and
  • Direct any service providers to delete your personal information from their records.

Please note that we may not be able to comply with requests to delete your personal information if it is necessary to:

  • Complete the transaction for which the personal information was collected, fulfill the terms of a written warranty, or otherwise perform a contract between you and the Company;
  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity;
  • Debug to identify and repair errors that impair existing intended functionality;
  • Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law;
  • Comply with applicable federal or Kentucky electronic communications privacy laws;
  • Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest, where you have provided informed consent and deletion may seriously impair the research;
  • Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with the Company;
  • Comply with an existing legal obligation; or
  • Otherwise use your personal information, internally, in a lawful manner that is compatible with the context in which you provided it.

Children Under Thirteen

The Company does not knowingly collect personally identifiable information from children under the age of 13. If you are under the age of 13, you must ask your parent or guardian for permission to use this website. This paragraph concerns information collected through the website. Where the Company provides treatment to a minor, it handles the minor’s health information in accordance with HIPAA, 42 C.F.R. Part 2, and Kentucky law governing consent for the care of minors and the confidentiality of their records.

Email Communications

From time to time, the Company may contact you via email for the purpose of providing announcements, promotional offers, alerts, confirmations, surveys, and/or other general communication.

If you would like to stop receiving marketing or promotional communications via email from the Company, you may opt out of such communications by clicking on the unsubscribe button.

SMS/Text Messaging

We offer SMS/text messaging to individuals who opt in. When you opt in, we collect your mobile number and your consent, and we keep records of the messages we send and of your opt-in and opt-out requests. We use your number only to send the categories of messages you agreed to receive, which may include pre-admission inquiries, appointment reminders, alumni program outreach, and patient satisfaction and outcome surveys.

We do not share your mobile phone number or your SMS consent with third parties for their own marketing purposes. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging opt-in data and consent are not shared with any third parties. We share your number only with service providers that help us operate the messaging program, such as our messaging platform and telecommunications carriers, and only as needed to deliver the messages you requested.

Because we are a substance use disorder treatment provider, text messages are not a secure or confidential channel and may be visible to anyone with access to your device. Information that identifies you as a patient is protected by HIPAA and 42 C.F.R. Part 2, and we send messages that could identify you as a patient only with your written consent and in accordance with those laws. You may withdraw consent and stop messages at any time by replying STOP, or reply HELP for help.

Changes to This Statement

The Company reserves the right to change this Policy from time to time. For example, when there are changes in our services, changes in our data protection practices, or changes in the law. When changes to this Policy are significant, we will inform you. You may receive a notice by sending an email to the primary email address you have provided to us, by placing a prominent notice on our website, and/or by updating any privacy information. Your continued use of the website and/or services available after such modifications will constitute your: (a) acknowledgment of the modified Policy; and (b) agreement to abide and be bound by that Policy.

Privacy Policy: Protection of Patient Data and Compliance with HIPAA Guidelines

At Neartown Inc., we are committed to safeguarding the privacy and security of our patients’ personal and health information. We understand the sensitive nature of the information we handle and the importance of maintaining strict confidentiality. This section outlines our practices and procedures for protecting patient data and ensuring compliance with the Health Insurance Portability and Accountability Act (HIPAA) and 42 C.F.R. Part 2.

Collection and Use of Patient Data

We collect only the personal and health information necessary to provide care and services to our patients. This data may include, but is not limited to, medical history, treatment plans, diagnostic information, and personal identifiers such as names, addresses, and contact details. We use this information solely for purposes directly related to patient care, treatment, billing, and health care operations.

Data Protection Measures

We employ a combination of administrative, technical, and physical safeguards to protect patient data from unauthorized access, disclosure, alteration, and destruction. Our data protection measures include:

  1. Encryption: We use encryption technologies to secure electronic patient records during storage and transmission.
  2. Access Controls: Access to patient information is restricted to authorized personnel only. We implement role-based access controls and require strong authentication methods.
  3. Training: All employees undergo regular training on data privacy and security practices, including HIPAA compliance.
  4. Audit Trails: We maintain detailed audit logs to monitor access and changes to patient information, ensuring accountability and traceability.
  5. Secure Storage: Physical patient records are stored in secure, access-controlled environments to prevent unauthorized access.

Compliance with HIPAA Guidelines

Our privacy practices are designed to comply with HIPAA, which sets the standard for protecting sensitive patient data. Key aspects of our HIPAA compliance include:

  1. Notice of Privacy Practices: We provide patients with a Notice of Privacy Practices, outlining how their information may be used and shared, and their rights regarding their health information.
  2. Patient Rights: Patients have the right to access their health records, request corrections, and obtain a record of disclosures of their information. They can also request restrictions on certain uses and disclosures.
  3. Breach Notification: In the unlikely event of a data breach, we have procedures in place to promptly notify affected patients and take appropriate steps to mitigate the impact, consistent with the HIPAA Breach Notification Rule and applicable Kentucky law.
  4. Business Associate Agreements: We require all third-party service providers who handle patient information on our behalf to sign Business Associate Agreements, ensuring they also comply with HIPAA standards.

Confidentiality and Disclosure

We do not disclose patient information to third parties without the patient’s written consent, except as permitted or required by law. For substance use disorder records, the stricter limits of 42 C.F.R. Part 2 apply, as described in the “Substance Use Disorder Records” section below. Any disclosure we make is limited to the minimum necessary and is made in accordance with HIPAA, 42 C.F.R. Part 2, and our internal privacy policies.

Substance Use Disorder Records (42 C.F.R. Part 2)

Neartown operates one or more substance use disorder treatment programs. Records that would identify a person, directly or indirectly, as having applied for, received, or been diagnosed or treated for a substance use disorder are protected by the federal regulations at 42 C.F.R. Part 2 (“Part 2”), which are generally stricter than HIPAA. The following describes how the Company handles those records.

General rule. Except as Part 2 expressly permits, the Company will not disclose any information that would identify you as having a substance use disorder without your written consent. A valid consent must contain the elements required by 42 C.F.R. 2.31. You may revoke a consent at any time, except to the extent the Company has already acted in reliance on it.

Treatment, payment, and health care operations. If you sign a single written consent for disclosures for treatment, payment, and health care operations, the Company and its lawful recipients may use and disclose your records for those purposes as Part 2 permits until you revoke that consent.

Disclosures without your consent. The Company may use or disclose Part 2 records without your consent only in the limited circumstances Part 2 allows, which include: (a) a bona fide medical emergency; (b) disclosures to qualified personnel for audit, evaluation, or research, subject to the safeguards Part 2 requires; (c) a court order entered under Part 2, Subpart E, together with a subpoena or other lawful process; (d) reporting suspected child abuse or neglect as required by Kentucky law; and (e) reporting a crime committed on program premises or against program personnel.

Use in legal proceedings. Part 2 records may not be used to initiate or substantiate any criminal charge against you, or to conduct any criminal investigation of you, and may not be used or disclosed in any civil, criminal, administrative, or legislative proceeding against you, without your written consent or a qualifying court order.

Notice and prohibition on redisclosure. The Company gives each patient the written summary of Part 2 rights required by 42 C.F.R. 2.22. Each permitted disclosure is accompanied by a notice prohibiting further redisclosure unless Part 2 or your written consent permits it.

Complaints. You may file a complaint about the Company’s privacy practices using the contact information below, or with the Secretary of the U.S. Department of Health and Human Services. The Company will not retaliate against you for filing a complaint.

Ongoing Monitoring and Improvement

We continuously review and update our privacy and security practices to ensure they remain effective and compliant with evolving legal and regulatory requirements. Regular risk assessments and audits are conducted to identify potential vulnerabilities and implement necessary improvements.

Governing Law

This Policy is governed by the laws of the Commonwealth of Kentucky and by applicable federal law, including HIPAA and 42 C.F.R. Part 2, without regard to conflict-of-laws principles. To the extent any state consumer privacy law applies to information that is not otherwise exempt, such as information that is not protected health information or a Part 2 record, the Company will honor the rights that law grants to residents of that state.

Contact Information

The Company welcomes your questions or comments regarding this Policy. If you believe that the Company has not adhered to this Policy, please contact the Company at:

Neartown Inc.

1250 Old Soldier Cr Rd, Kirksey, KY 42054

Attn: Privacy Officer (HIPAA and 42 C.F.R. Part 2 Compliance)

Email Address: info@neartownmurray.org

Phone Number: (270) 632-9379

Effective as of June 23, 2026