Legal

Privacy Policy

Last updated: May 11, 2026

HIPAA-Compliant Data Practices for Treatment Providers

HIPAA Compliance Statement

Val is designed to operate as a HIPAA-compliant Business Associate for Covered Entities. We maintain administrative, physical, and technical safeguards to protect Protected Health Information (PHI) in accordance with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. A Business Associate Agreement (BAA) is executed with each provider client prior to processing any PHI.

For Treatment Providers

This Privacy Policy describes how Val collects, uses, and protects information when treatment facilities use our post-discharge infrastructure platform. As a Business Associate, Val processes alumni data on behalf of provider organizations to support ongoing engagement, accountability, and outcome tracking.

Information We Process

Provider Information

  • Facility name, contact details, and administrator credentials
  • Staff accounts and access permissions
  • Billing and service agreement information
  • Branding assets for white-label deployment

Alumni Information (PHI)

  • Name, phone number, and contact preferences
  • Enrollment and discharge dates
  • Voice recordings from check-in calls (transcribed and analyzed)
  • AI-generated mood scores, risk indicators, and engagement metrics
  • Interaction history and response patterns

Technical Information

  • Platform usage and access logs
  • System performance and error data
  • Security events and audit trails

How We Use Information

  • Provide daily AI-powered check-in calls to enrolled alumni
  • Transcribe and analyze conversations to identify mood patterns and risk indicators
  • Generate staff dashboard insights and early warning alerts
  • Produce engagement reports and outcome metrics for providers
  • Deliver white-label platform experience with provider branding
  • Maintain security, prevent fraud, and ensure service reliability
  • Comply with legal obligations and regulatory requirements

Voice Data Processing

Alumni check-in calls are recorded and processed through secure AI transcription services. This processing occurs within HIPAA-compliant infrastructure with the following safeguards:

  • End-to-end encryption for voice data in transit and at rest
  • Audio recordings processed in secure, isolated environments
  • Transcriptions stored with access controls and audit logging
  • Voice recordings deleted after transcription unless retention is required
  • All processing under BAA with sub-processors

Phone Number Collection & SMS Messages

We collect your phone number as part of the account registration process. Your phone number is used for the following purposes:

SMS Verification & Authentication

We collect your phone number for account authentication and platform access. SMS or text messages may be sent to your phone number to verify your identity during registration or login. By providing your phone number and creating an account, you consent to receiving these authentication messages. No marketing or promotional SMS messages will be sent to your number.

Post-Discharge Care Coordination SMS Messages

Val also sends post-discharge care coordination SMS messages to patients of Seafield Center and other treatment provider clients. These messages include appointment reminders, follow-up check-ins, and connection to recovery resources. Messages are sent only to patients who have provided prior written consent during the intake process at their treatment facility. Patients may opt out at any time by replying STOP.

AI Check-In Calls

With explicit consent provided at the point of registration, your phone number may also be used to deliver scheduled AI-powered check-in calls as part of the post-discharge support service. These calls are initiated only when you have opted in during account setup.

Consent & Opt-Out

  • Consent to SMS communications is obtained at the point of phone number collection during registration or during the intake process at the treatment facility
  • Authentication SMS messages are transactional and cannot be opted out of while the account is active
  • Care coordination SMS messages can be stopped at any time by replying STOP
  • Check-in call preferences can be modified at any time in your account settings
  • Your phone number is never sold or shared with third parties for marketing purposes
  • Standard message and data rates from your carrier may apply

Data Security Measures

  • AES-256 encryption for all data at rest
  • TLS 1.3 encryption for all data in transit
  • Role-based access controls (RBAC) with least-privilege principles
  • Multi-factor authentication for staff accounts
  • Comprehensive audit logging with tamper detection
  • Regular penetration testing and vulnerability assessments
  • Hosted on SOC 2 Type II certified infrastructure (AWS). Val Care’s own SOC 2 Type II is in progress
  • Automatic session timeouts and access revocation

Data Sharing & Sub-Processors

Val does not sell, rent, or share PHI with third parties for marketing purposes. We work with vetted sub-processors under BAAs for essential service delivery:

  • Cloud infrastructure providers (data storage and computing)
  • AI transcription and analysis services
  • Telephony infrastructure for call delivery
  • Security and monitoring services

A current list of sub-processors is available upon request and included in your BAA.

Data Retention

Data retention periods are configured based on your facility's requirements and regulatory obligations:

  • Alumni engagement data retained per your BAA terms (typically 7 years)
  • Voice recordings deleted after transcription (configurable)
  • Audit logs maintained for minimum 6 years
  • Provider account data retained during active service plus 90 days post-termination
  • Secure deletion using NIST SP 800-88 standards

Provider Rights & Data Access

As a provider client, you have the right to:

  • Access and export all alumni data in your facility's instance
  • Request correction of inaccurate information
  • Receive breach notification in accordance with HIPAA requirements
  • Audit Val's security practices and compliance documentation
  • Terminate service and receive data export per contract terms
  • Designate authorized representatives for data access requests

Breach Notification

In the event of a security incident affecting PHI, Val will notify affected providers within 24 hours of discovery and provide full cooperation with breach investigation and notification requirements under HIPAA and applicable state laws.

Contact & Compliance

For privacy-related inquiries, data access requests, or compliance questions:

Privacy & Security: mk@val.care

Sales & Legal: mk@val.care

General Support: Support Center

To request a copy of our BAA or security documentation, please contact your account representative or email mk@val.care.