Privacy Policy
Effective Date: [To be inserted upon website launch]
Last Updated: [To be inserted upon website launch]
INTRODUCTION
Rise Neurorehab Institute (“Rise,” “we,” “us,” or “our”) is committed to protecting your privacy and safeguarding your personal information. This Privacy Policy explains how we collect, use, disclose, and protect information when you visit our website (riseneuro.org), contact us, or receive services from us.
Rise Neurorehab Institute is a 501(c)(3) non-profit organization operating under D1Strong–The Journey Foundation, providing comprehensive neurorehabilitation services in Atlanta, Georgia.
By using our website or services, you consent to the practices described in this Privacy Policy.
SCOPE OF THIS POLICY
This Privacy Policy applies to:
- Information collected through our website (riseneuro.org)
- Information collected when you contact us via phone, email, or contact forms
- Information collected when you attend events or make donations
- Information collected when you volunteer with Rise
- Information collected in connection with employment applications
For Patients: If you are a patient or are inquiring about patient services, please also refer to our Notice of Privacy Practices (HIPAA Notice), which specifically addresses how we handle Protected Health Information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA).
INFORMATION WE COLLECT
1. Information You Provide Directly
Contact Information: When you contact us through our website, by phone, or in person, we may collect:
- Name
- Email address
- Phone number
- Mailing address
- Preferred contact method
Inquiry Information:
- Nature of your inquiry
- Service interests
- Condition or diagnosis (optional)
- Message content
- How you heard about Rise
Donation Information:
- Name and contact information
- Donation amount and method
- Billing information (processed securely through third-party payment processors)
- Tribute or memorial information
- Recognition preferences
Volunteer Information:
- Name and contact information
- Areas of interest
- Skills and experience
- Availability
- Background check information (as required)
Employment Application Information:
- Resume/CV
- Cover letter
- References
- Licenses and certifications
- Employment history
- Education information
Event Registration Information:
- Name and contact information
- Event preferences
- Dietary restrictions or accessibility needs
- Payment information (for paid events)
2. Information Collected Automatically
Website Usage Information: When you visit our website, we may automatically collect:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and time spent
- Referring website
- Date and time of visit
- Click patterns and navigation paths
Cookies and Similar Technologies: We may use cookies, web beacons, and similar technologies to collect information about your website usage. See our “Cookies Policy” section below for more information.
3. Protected Health Information (PHI)
For Patients and Service Recipients: If you become a patient or receive services at Rise, we will collect Protected Health Information (PHI) as necessary to provide care. This includes:
- Medical history
- Diagnosis and treatment information
- Insurance information
- Clinical notes and assessments
- Test results and reports
- Billing and payment information
PHI is subject to strict protections under HIPAA. Please refer to our Notice of Privacy Practices (HIPAA Notice) for detailed information about how we collect, use, and protect your health information.
HOW WE USE YOUR INFORMATION
General Uses
We use the information we collect for the following purposes:
To Respond to Your Inquiries:
- Answer questions about our services
- Provide information about programs and events
- Schedule consultations or appointments
- Follow up on contact form submissions
To Provide Services:
- Deliver neurorehabilitation services
- Coordinate care and treatment
- Process insurance claims and billing
- Communicate about your care
To Process Donations:
- Accept and process contributions
- Send donation receipts
- Acknowledge gifts appropriately
- Provide donor updates and impact information
To Manage Volunteers:
- Process volunteer applications
- Schedule and coordinate volunteer activities
- Communicate about opportunities and events
- Conduct required background checks
To Recruit Employees:
- Review employment applications
- Schedule interviews
- Conduct background checks and credentialing
- Communicate about employment opportunities
To Improve Our Website and Services:
- Analyze website usage and traffic patterns
- Improve user experience
- Develop new services and programs
- Conduct research and quality improvement
To Communicate with You:
- Send newsletters and updates (if you’ve opted in)
- Notify you about events and opportunities
- Share impact stories and organizational news
- Provide service-related communications
To Comply with Legal Obligations:
- Respond to legal processes
- Comply with applicable laws and regulations
- Protect rights, property, and safety
- Prevent fraud and security incidents
HOW WE SHARE YOUR INFORMATION
We Do Not Sell Your Information
Rise does not sell, rent, or trade your personal information to third parties for marketing purposes.
When We May Share Information
We may share your information in the following circumstances:
With Service Providers: We work with trusted third-party service providers who assist us with:
- Website hosting and maintenance
- Payment processing (donations, event registration)
- Email communication services
- Customer relationship management (CRM)
- Background check services
- IT support and security
These service providers are contractually obligated to protect your information and use it only for the purposes we specify.
With Healthcare Partners: For patient care coordination, we may share information with:
- Referring physicians and healthcare providers
- Insurance companies (for billing and authorization)
- Community partner organizations (with your consent)
- Other healthcare facilities (as needed for continuity of care)
All healthcare information sharing complies with HIPAA regulations.
With Donors’ Permission: We may publicly recognize donors by name (unless you request anonymity) in:
- Annual reports
- Donor recognition displays
- Website donor lists
- Event programs
- Social media and communications
You have complete control over your recognition preferences.
As Required by Law: We may disclose information when required to:
- Comply with legal process (court orders, subpoenas)
- Respond to lawful requests from government authorities
- Protect rights, property, and safety of Rise, our patients, staff, or others
- Prevent fraud or security threats
- Comply with mandatory reporting requirements
Business Transfers: In the unlikely event of a merger, acquisition, or sale of assets, your information may be transferred to the new entity. We will notify you if this occurs.
With Your Consent: We may share information in other circumstances with your explicit consent.
YOUR PRIVACY CHOICES AND RIGHTS
Email Communications
Opting In: You will only receive email communications from Rise if you:
- Subscribe to our mailing list
- Make a donation
- Submit a contact form requesting information
- Register for an event
- Agree to receive updates
Opting Out: You can unsubscribe from marketing emails at any time by:
- Clicking the “unsubscribe” link in any email
- Emailing us at [general email]
- Calling us at 404-596-RISE (7473)
Note: Even if you opt out of marketing emails, we may still send you:
- Service-related communications (appointment reminders, care information)
- Transactional emails (donation receipts, registration confirmations)
- Legally required notifications
Donor Recognition
You have the right to:
- Remain anonymous
- Be recognized by first name only
- Be recognized by full name
- Change your recognition preferences at any time
Contact us at 404-596-RISE (7473) to update your preferences.
Access and Correction
You have the right to:
- Request access to the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information (subject to legal retention requirements)
- Request a copy of your information
To exercise these rights, contact us at: Phone: 404-596-RISE (7473)
Email: [Privacy contact email]
California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including:
- Right to know what personal information we collect and how it’s used
- Right to delete personal information
- Right to opt out of sale of personal information (note: we do not sell information)
- Right to non-discrimination for exercising your rights
For more information or to exercise your CCPA rights, contact us at the information above.
COOKIES POLICY
What Are Cookies?
Cookies are small text files stored on your device when you visit websites. They help websites function properly and provide information about website usage.
How We Use Cookies
Essential Cookies: Required for website functionality, including:
- Session management
- Security features
- Form submissions
- Load balancing
Analytics Cookies: Help us understand how visitors use our website:
- Google Analytics (to track traffic and usage patterns)
- Page views and navigation paths
- Time spent on pages
- Referring websites
Functional Cookies: Remember your preferences:
- Language preferences
- Accessibility settings
- Form data (to prevent re-entry)
Managing Cookies
You can control cookies through your browser settings:
- Block all cookies
- Accept only certain cookies
- Delete cookies after browsing
Note: Blocking cookies may affect website functionality.
Google Analytics Opt-Out: You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout
DATA SECURITY
How We Protect Your Information
Rise takes data security seriously and implements appropriate technical and organizational measures to protect your information, including:
Technical Safeguards:
- Secure Socket Layer (SSL) encryption for data transmission
- Firewalls and intrusion detection systems
- Regular security updates and patches
- Secure data backup systems
- Access controls and authentication
Organizational Safeguards:
- Staff training on privacy and security
- Confidentiality agreements
- Limited access to personal information (need-to-know basis)
- Regular privacy and security audits
- Incident response procedures
HIPAA Compliance: For Protected Health Information (PHI), we implement additional safeguards required by HIPAA, including:
- Encrypted electronic health records
- Secure messaging systems
- Business Associate Agreements with vendors
- Strict access controls
- Audit trails
No Guarantee
While we implement reasonable security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.
Data Breach Notification
In the event of a data breach that affects your information, we will notify you as required by applicable laws and regulations, including HIPAA breach notification requirements for health information.
DATA RETENTION
How Long We Keep Information
General Information: We retain personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Patient Health Information: We retain medical records and health information in accordance with HIPAA requirements and applicable state laws, typically:
- Adult records: 7 years after last service
- Pediatric records: Until age of majority plus 7 years
- Longer if required for legal or regulatory purposes
Donation Records: We retain donor information for tax compliance and stewardship purposes, typically:
- 7 years for financial records (IRS requirement)
- Indefinitely for donor relationship management (unless you request deletion)
Employment Records: We retain employment applications and records in accordance with employment laws and regulations.
Secure Deletion
When information is no longer needed, we securely delete or destroy it using appropriate methods to prevent unauthorized access.
CHILDREN’S PRIVACY
Our website is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13 without parental consent.
If you believe we have inadvertently collected information from a child under 13, please contact us immediately at 404-596-RISE (7473), and we will delete the information.
For Pediatric Patients: If your child is receiving services at Rise, parental consent is required for treatment, and parents/guardians have rights to access their child’s health information as permitted by law and HIPAA regulations.
THIRD-PARTY LINKS
Our website may contain links to third-party websites, including:
- Partner organizations
- Community resources
- Social media platforms
- Payment processors
- Donation platforms
We are not responsible for the privacy practices of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect:
- Changes in our practices
- Legal or regulatory requirements
- Technological developments
- Organizational changes
When we make changes:
- We will update the “Last Updated” date at the top of this policy
- Significant changes will be communicated via email or website notice
- Continued use of our website after changes constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically.
HIPAA NOTICE OF PRIVACY PRACTICES
Separate Notice for Patients
If you are a patient receiving services at Rise, you will receive our Notice of Privacy Practices, which provides detailed information about:
- How we use and disclose your health information
- Your rights regarding your health information
- Our obligations under HIPAA
- How to file a complaint if you believe your privacy rights have been violated
The Notice of Privacy Practices is available:
- Upon your first visit to Rise
- Posted in our facility
- On our website at [link to HIPAA Notice]
- Upon request at any time
For a copy of our HIPAA Notice of Privacy Practices: Phone: 404-596-RISE (7473)
Email: [Compliance email]
CONTACT US
Questions or Concerns About Privacy
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Rise Neurorehab Institute
Phone: 404-596-RISE (7473)
Email: [Privacy contact email]
Mail:
[Physical Address]
[City, State ZIP]
Privacy Officer: [Name/Title – TBD]
Filing a Complaint
If you believe your privacy rights have been violated, you have the right to file a complaint:
With Rise: Contact our Privacy Officer using the information above.
With Government Agencies:
- For HIPAA complaints: U.S. Department of Health and Human Services, Office for Civil Rights
Website: www.hhs.gov/ocr/privacy
Phone: 1-877-696-6775
- For other privacy concerns: Federal Trade Commission
Website: www.ftc.gov/complaint
Phone: 1-877-FTC-HELP
We will not retaliate against you for filing a complaint.
CONSENT
By using our website, contacting us, or receiving services from Rise Neurorehab Institute, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your information as described.
For patient services: Separate consent forms will be provided for treatment and use of Protected Health Information in accordance with HIPAA requirements.
LEGAL DISCLAIMER
This Privacy Policy does not create a contract or legal rights beyond those provided by applicable privacy laws. Rise reserves the right to modify this policy at any time in accordance with applicable laws and regulations.
Rise Neurorehab Institute
A 501(c)(3) Non-Profit Organization
Fundraising by D1Strong–The Journey Foundation
Opening Fall 2026 in Atlanta, Georgia
404-596-RISE (7473)
[General email]
riseneuro.org
[Home] [About Us] [Services] [Connect] [Donate]
Last Updated: [Date]
Effective Date: [Date]
SUMMARY OF KEY POINTS
This summary provides key highlights but is not a substitute for reading the full Privacy Policy.
✓ We respect your privacy and are committed to protecting your personal information.
✓ We don’t sell your information to third parties for marketing purposes.
✓ You control your email preferences and can opt out at any time.
✓ We use secure methods to protect your information.
✓ You have rights to access, correct, and delete your information.
✓ Patient health information is protected under HIPAA with additional safeguards.
✓ Donors control recognition preferences (full name, first name, or anonymous).
✓ You can contact us anytime with privacy questions or concerns at 404-596-RISE (7473).
KEYWORD INTEGRATION SUMMARY
Primary Keywords:
- privacy policy (throughout)
- HIPAA (8 instances)
- personal information (15+ instances)
- Protected Health Information (8 instances)
- privacy (25+ instances)
Organization:
- Rise Neurorehab Institute (10+ instances)
- D1Strong-The Journey Foundation (2 instances)
- Atlanta, Georgia (2 instances)
- 501(c)(3) (1 instance)
Contact:
- 404-596-RISE (7473) (8 instances)
- Email placeholders throughout
Service-Related:
- patient (10+ instances)
- services (8 instances)
- healthcare (5 instances)
- medical records (3 instances)
- neurorehabilitation (1 instance)
Total Word Count: ~3,400 words
EMAIL SUBJECT LINE
Important: Privacy Policy for Rise Neurorehab Institute
LEGAL DISCLAIMER NOTE
This privacy policy template should be reviewed and customized by legal counsel before publication to ensure compliance with:
- HIPAA (Health Insurance Portability and Accountability Act)
- HITECH Act
- State privacy laws
- CCPA (California Consumer Privacy Act)
- Other applicable regulations
- Specific organizational practices and systems
Items requiring attorney review/completion:
- Effective date
- Email addresses (privacy contact, general, compliance)
- Physical address
- Privacy Officer name and title
- Specific third-party service providers used
- Payment processor details
- Specific cookie implementations
- Any state-specific requirements
- Notice of Privacy Practices (separate HIPAA document)