HIPAA Compliance & Notice of Privacy Practices
How CEREVITY Health, Inc. safeguards protected health information (PHI) across our network and the rights you have over your information.
In Plain English
HIPAA is the federal law that protects medical information. Your therapy records are held to that standard throughout CEREVITY's network: the licensed clinicians who treat you are bound by HIPAA and state confidentiality law in their own right, and CEREVITY runs its systems and administration to the same privacy and security standards, backed by written agreements. The Notice beginning in Section 5 describes how your protected health information ("PHI") may be used, the rights you have over it, and how you will be notified if there is ever a breach.
Our HIPAA Commitment
CEREVITY Health, Inc. ("CEREVITY") is committed to protecting the privacy and security of protected health information (PHI) handled anywhere in our network. We build and operate our privacy and security program to the standards of the HIPAA Privacy Rule (45 CFR Part 164, Subpart E), the HIPAA Security Rule (45 CFR Part 164, Subpart C), and the HITECH Act, including breach notification, and we contractually require everyone who handles PHI through our network to meet obligations no less protective than those standards.
Our Role & Our Network
Care through CEREVITY is delivered by independent licensed clinicians. Each clinician is independently responsible for the clinical records of the clients they treat and is subject to HIPAA and to the confidentiality and record-keeping laws of the states in which they practice. CEREVITY administers the network that supports that care, including matching, scheduling, technology, and billing support.
As a condition of network participation, every clinician agrees in writing to privacy and security obligations no less protective than HIPAA's requirements, and CEREVITY applies the same standards to its own personnel and systems. Whether a particular obligation applies to CEREVITY, to your clinician, or to both depends on the role each plays in your care; the protections described in this Notice apply to your information across the network either way.
Safeguards & Security
Administrative Safeguards
Designated Privacy and Security Officers, written policies and procedures, workforce training, role-based access controls, and ongoing risk analysis.
Technical Safeguards
Encryption of PHI in transit and at rest where applicable, unique user authentication, audit logging, automatic session timeout, and telehealth and electronic health record systems operated to HIPAA security standards.
Physical Safeguards
Restricted access to facilities and devices that store or transmit PHI, secure disposal of media, and workstation security policies.
Organizational Safeguards
Written agreements with vendors and clinicians, ongoing monitoring, sanctions for non-compliance, and an incident response plan.
Business Associates & Vendors
We engage trusted vendors to help deliver and support our services. Each vendor that handles PHI is bound by a written agreement, including a Business Associate Agreement where HIPAA requires one, obligating it to safeguard PHI in accordance with HIPAA standards and to use it only for permitted purposes. Categories include electronic health records, telehealth platforms, secure messaging and communication, payment processing, IT and hosting, and administrative support.
Notice of Privacy Practices
This Notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
Effective Date: May 3, 2025
This Notice is provided by CEREVITY Health, Inc. and is modeled on the content requirements of 45 CFR § 164.520. It describes the privacy practices applied to PHI created or maintained within our network by CEREVITY and by the independent licensed clinicians who deliver care. Your treating clinician may also provide their own privacy notice for the records they maintain; where both apply, the more protective practice governs. Information that is not PHI is covered by our Privacy Policy.
Uses & Disclosures of PHI
Uses & Disclosures Without Your Authorization
PHI may be used and disclosed without your specific authorization for the following purposes, as permitted by HIPAA:
- Treatment: coordinating and providing care, consulting with other clinicians, and referrals
- Payment: billing, processing payments, and verifying coverage
- Health Care Operations: quality improvement, training, credentialing, audits, compliance, and business management
- Required by Law: when disclosure is required by federal, state, or local law
- Public Health Activities: reporting to public health authorities for disease prevention and control
- Health Oversight Activities: for licensure, audits, investigations, and regulatory inspections
- Judicial & Administrative Proceedings: in response to a valid subpoena, court order, or legal process
- Law Enforcement: as permitted by law for limited law-enforcement purposes
- Serious Threat to Health or Safety: to prevent a serious and imminent threat to you or others, including mandatory reporting obligations
- Workers' Compensation: as authorized by workers' compensation laws
- Coroners, Medical Examiners, Funeral Directors: as required by law
- Abuse, Neglect, or Domestic Violence: reporting as required by mandatory reporting statutes
Uses & Disclosures Requiring Your Written Authorization
Your written authorization will be obtained before PHI is used or disclosed for purposes other than those described above, including:
- Most uses and disclosures of psychotherapy notes
- Marketing communications (other than face-to-face communications or promotional gifts of nominal value)
- Sale of PHI
You may revoke a written authorization at any time, in writing, except to the extent action has already been taken in reliance on it.
Your Privacy Rights
With respect to your PHI, you have the following rights:
To exercise any of these rights, contact our Privacy Officer using the information in Section 11. Most requests will be addressed within thirty (30) days.
Our Duties
CEREVITY and the clinicians in our network are obligated, by applicable law and by the agreements that govern our network, to:
- Maintain the privacy and security of your PHI
- Provide you with this Notice describing the privacy practices that apply to your PHI
- Notify you if a breach of unsecured PHI occurs
- Abide by the terms of the Notice currently in effect
We reserve the right to change this Notice and to make the revised Notice effective for all PHI we maintain. We will post the current Notice on our website and provide a copy upon request.
Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with us using the contact information in Section 11, or with the Secretary of the U.S. Department of Health and Human Services:
- Online: hhs.gov/hipaa/filing-a-complaint
- Mail: U.S. Department of Health and Human Services, Office for Civil Rights, 200 Independence Avenue S.W., Room 509F HHH Bldg., Washington, D.C. 20201
- Phone: 1-877-696-6775
You will not be retaliated against for filing a complaint.
Breach Notification
In the event of a breach of unsecured PHI, notification will be provided in accordance with applicable breach notification requirements, including HIPAA's Breach Notification Rule (45 CFR Part 164, Subpart D) and applicable state law: notice to affected individuals without unreasonable delay and within 60 days of discovery, notice to the Secretary of HHS where required, and where required, notice to prominent media outlets.
Contact Us
To exercise any privacy right, ask a question, or file a complaint, contact our Privacy Officer:
CEREVITY Health, Inc., Privacy Officer
Privacy-related inquiries are addressed within 30 days.
Suite 319
Lakewood, CA 90712
Attn: Privacy Officer
⚠️ Crisis Resources
If you are experiencing a mental health crisis or having thoughts of suicide, please reach out immediately:
988 Suicide & Crisis Lifeline: Call or text 988
Crisis Text Line: Text HOME to 741741
National Alliance on Mental Illness (NAMI): 1-800-950-NAMI (6264)
