Terms & Conditions
Terms of Service
Effective Date: May 29, 2026
Governing Regulations: Health Insurance Portability and Accountability Act (HIPAA); 42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records)
This Addendum supplements and forms part of the organization’s existing Privacy Policy and Terms of Service (collectively, the “Policy”). In the event of a conflict between this Addendum and the Policy, the more protective provision with respect to patient privacy shall govern. This Addendum establishes the organization’s practices and obligations with respect to the use of Short Message Service (SMS) text messaging as a modality for communicating protected health information (PHI) and substance use disorder (SUD) treatment-related information to patients.
1. Scope and Applicability
This Addendum applies to all SMS text message communications initiated by the organization to patients who have provided prior written consent to receive such communications. It governs the collection, use, transmission, storage, and protection of any PHI or SUD treatment information conveyed via SMS.
2. Patient Consent
The organization will send SMS text messages containing care-related information only to patients who have provided explicit, informed, and documented written consent. Consent shall be obtained in accordance with HIPAA requirements and, where applicable, the heightened consent standards of 42 CFR Part 2.
Consent will specify, at minimum:
- The types of information that may be communicated via SMS (e.g., appointment reminders, care coordination updates, treatment-related notifications);
- That consent to receive SMS messages is voluntary and not a condition of receiving treatment;
- The patient’s right to withdraw consent at any time by replying “STOP” to any text message or by submitting a written request to the organization; and
- That standard message and data rates from the patient’s wireless carrier may apply.
Consent records will be retained in the patient’s file in accordance with applicable federal and state record retention requirements. The organization will not send care-related SMS messages to any patient who has not provided such consent, has revoked consent, or whose consent cannot be verified.
3. Permitted Uses of SMS Communication
SMS text messages may be used to communicate the following categories of care-related information to consenting patients:
- Appointment scheduling, reminders, and confirmations;
- Medication reminders and adherence support (where clinically indicated and approved by a licensed clinician);
- Care coordination and follow-up communications;
- Administrative notifications related to the patient’s course of treatment; and
- Other communications consistent with the patient’s treatment plan and the purpose for which consent was obtained.
All SMS content will be limited to the minimum necessary information required to achieve the stated purpose of the communication, consistent with the HIPAA Minimum Necessary Standard and the confidentiality protections of 42 CFR Part 2.
4. Prohibition on Third-Party Disclosure
The organization will not sell, license, rent, trade, disclose, or otherwise share any PHI or SUD treatment information transmitted via SMS with any third party for any commercial, marketing, or non-treatment-related purpose.
Information communicated via SMS will not be disclosed to third parties except under the following strictly limited circumstances:
- To Business Associates (as defined under HIPAA) who have executed a valid Business Associate Agreement (BAA) with the organization, solely to the extent necessary to provide contracted services;
- As required by applicable federal or state law, including valid court orders or lawful government requests; or
- With the patient’s separate, explicit written authorization consistent with HIPAA and, where applicable, 42 CFR Part 2.
Patient consent to receive SMS communications does not constitute authorization for the disclosure of PHI or SUD treatment information to third parties. Any such disclosure requires independent authorization in accordance with applicable law.
5. HIPAA-Compliant Platforms and Business Associate Agreements
All SMS communications containing PHI or SUD treatment information will be transmitted through and stored on technology platforms that are designed, operated, and contractually obligated to comply with applicable HIPAA Security Rule and Privacy Rule requirements.
Specifically, the organization will ensure that:
- All third-party SMS platform vendors who create, receive, maintain, or transmit PHI on behalf of the organization will be classified as Business Associates under HIPAA;
- A fully executed Business Associate Agreement (BAA) will be in place with each such vendor prior to any transmission of PHI through that platform;
- Each BAA will, at minimum, comply with the requirements set forth at 45 CFR § 164.504(e), including provisions governing the use and disclosure of PHI, safeguards, reporting of breaches, and return or destruction of PHI upon termination;
- Platforms will maintain appropriate administrative, physical, and technical safeguards consistent with the HIPAA Security Rule (45 CFR Part 164, Subpart C) to protect the confidentiality, integrity, and availability of electronic PHI; and
- The organization will conduct or obtain documentation of reasonable vendor due diligence to verify that platform security practices meet applicable regulatory standards prior to onboarding and on a periodic basis thereafter.
The organization will not utilize any SMS platform for the transmission of PHI where a BAA cannot be or has not been executed. In the event that a Business Associate Agreement is terminated, expires, or a vendor is determined to be non-compliant, the organization will take prompt remedial action, including transitioning to a compliant platform.
6. Data Retention and Disposal
SMS communications containing PHI will be retained only for the period necessary to fulfill the purpose for which they were sent, or as required by applicable federal and state law, whichever is longer. Upon expiration of the applicable retention period, such communications will be disposed of in a secure manner consistent with HIPAA requirements and the organization’s data retention and destruction policies.
7. Patient Rights
Patients retain all rights afforded under HIPAA and 42 CFR Part 2 with respect to information communicated via SMS, including but not limited to the right to access, amend, and request an accounting of disclosures of their PHI. Patients may withdraw consent to receive SMS communications at any time without affecting the legality of prior communications or their right to continue receiving treatment services.
8. Amendments
The organization reserves the right to amend this Addendum at any time to reflect changes in applicable law, regulatory guidance, or organizational practice. Material amendments will be communicated to patients in accordance with the Notice of Privacy Practices update procedures required under HIPAA.
Comments
When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Cookies
If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Who we share your data with
If you request a password reset, your IP address will be included in the reset email.
How long we retain your data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
SMS Program Enrollment and Call to Action
How patients enroll. Patients opt in to receive SMS text messages from Steadfast Health by completing and signing the written Patient Consent for Communications form in person during the intake process at a Steadfast Health clinic location. A copy of the consent form is available at https://steadfasthealth.com/communication-consent. Consent is affirmative, voluntary, and is not a condition of receiving treatment or any other service.
Call to action. By providing your mobile telephone number and signing the Patient Consent for Communications form, you consent to receive 1-to-1 SMS text messages from a Steadfast Health outreach liaison. Message frequency varies based on your care needs and appointments. Message and data rates may apply. Reply STOP to unsubscribe at any time. Reply HELP for assistance. Mobile opt-in information will not be shared with third parties for marketing purposes.
Types of messages. Patients who enroll may receive text messages relating to patient outreach, care coordination, appointment scheduling, reminders and confirmations, and treatment-related follow-up communications consistent with the patient’s treatment plan. The program is conversational and 1-to-1; it is not used for marketing, promotional, or bulk messaging.