Privacy Policy for HCANA.com
Effective Date: 11/11/2025
At HCANA.com, your privacy is our priority. This Privacy Policy explains how we collect, use, protect, and share your information — especially any Protected Health Information (PHI) — in compliance with the Health Insurance Portability and Accountability Act (HIPAA) and LegitScript certification requirements.
1. Information We Collect
We may collect the following types of information through our website:
a. Personal and Health Information
- Name, email address, phone number, and other contact details you provide through forms
- Information related to your health condition, treatment interests, or inquiries
- Any other PHI voluntarily submitted
b. Automatically Collected Information
- IP addresses
- Browser type and device info
- Website usage statistics via cookies and analytics tools (see Section 6)
2. How We Use Your Information
Your information is used only for the purposes for which you provided it. This may include:
- Responding to inquiries about treatment or services
- Coordinating admissions or consultations
- Sending requested information or updates
- Internal analysis to improve our website or services
- Maintaining HIPAA-compliant records where required
We do not use your PHI for marketing purposes without your explicit written authorization.
3. HIPAA Compliance
We comply with all applicable regulations under HIPAA, including:
- Data encryption: All sensitive data is encrypted in transit and at rest.
- Access controls: Only authorized staff or business associates have access to PHI.
- Audit trails: We maintain audit logs of PHI access and updates.
- Minimum necessary standard: We collect and use only the minimum information necessary to fulfill your request or inquiry.
4. LegitScript Compliance
HCANA.com is committed to following LegitScript certification standards, which ensure that:
- The website content is truthful and not misleading
- We provide accurate contact information for transparency
- We display this privacy policy in a clear and accessible manner
- Any mention of treatment services reflects actual licensure, location, or accreditation
5. How We Share Information
We do not sell or rent your information.
We may share PHI only under the following circumstances:
- With your explicit consent or authorization
- With HIPAA-compliant service providers or business associates
- When required by law, such as during legal processes or reporting obligations
- For medical emergencies or public health purposes
All third-party partners are vetted for HIPAA and LegitScript compliance.
6. Use of Cookies and Tracking Technologies
HCANA.com uses cookies and analytics tools (e.g., Google Analytics, Call Tracking Metrics) to understand how users interact with the site. These tools may collect:
- Pages visited
- Time spent on site
- Geographic location
- Referral sources
We do not associate this data with your PHI. You may opt out of cookies using your browser settings.
7. Data Security Measures
To protect your personal and health information, we implement:
- SSL encryption across all pages
- Firewall and malware protection
- Secure server infrastructure
- Regular vulnerability assessments
8. Your Rights
You have the right to:
- Request access to or correction of your PHI
- Request deletion of your information (where legally allowed)
- Withdraw your consent at any time
- File a complaint with the U.S. Department of Health and Human Services (HHS) if you believe your rights under HIPAA have been violated
To exercise these rights, contact us at 828-481-9204.
9. Children’s Privacy
HCANA.com is not intended for users under the age of 13. We do not knowingly collect PHI from children without verified parental consent.
10. Changes to This Privacy Policy
We may update this policy from time to time. The “Effective Date” at the top of this page will reflect the latest version. Your continued use of the site indicates your acceptance of any changes.
11. Contact Us
If you have any questions or concerns about this policy or how your information is handled, please contact:
HCANA Privacy Officer
Email: [Insert secure email address]
Phone: 828-481-9204
Mailing Address: [Insert address if applicable]
