Privacy Policy
Effective Date: September 1, 2025
1. Introduction
Eva Carlston Academy respects the privacy of all individuals who visit our website and is committed to protecting personal and health information. Because we provide clinical care, some of the information we collect may be considered Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). This Privacy Policy explains how we collect, use, disclose, and safeguard your information, both general personal data and PHI, in compliance with HIPAA and other applicable laws.
2. Information We Collect
a. Personal Information You Provide
When you submit an inquiry or contact form, we may collect the following:
Name
Email address
Phone number (if provided)
Interests or inquiry details
Any other information you choose to provide in your message
b. Protected Health Information (PHI)
If you choose to share health-related details (for example, your child’s medical or therapeutic needs), this information may be considered PHI. We treat such information with the highest level of confidentiality and safeguard it in accordance with HIPAA.
c. Automatically Collected Information
We may automatically collect certain technical data, such as:
Device IP address
Browser type and version
Pages visited on our site and time spent on each page
Referring and exit URLs
Date and time of site use
Standard log data
d. Cookies and Tracking Technologies
We may use cookies or similar technologies to improve the website experience. These do not collect PHI. You can disable cookies through your browser settings, but this may affect site functionality.
3. How We Use Your Information
We use collected information to:
Respond to inquiries or requests
Provide information about admissions and programs
Maintain and improve website functionality
Send communications if you opt in
Comply with legal and regulatory obligations
For PHI specifically, we will only use or disclose this information as permitted or required by HIPAA, such as for treatment, payment, healthcare operations, or with your explicit authorization.
4. How We Share Your Information
We may share your information with:
Service providers who support our website and operations, bound by agreements requiring data protection
Clinical staff or admissions staff, but only as necessary to respond to your inquiry or provide services
Legal or regulatory authorities when required by law
We will not share PHI without your authorization unless permitted by HIPAA, such as in cases of medical emergencies, public health reporting, or compliance with lawful requests.
5. Data Security
We implement administrative, physical, and technical safeguards designed to protect both personal information and PHI. These safeguards include secure servers, restricted access, encryption where appropriate, and staff training in HIPAA compliance. While we take all reasonable steps to safeguard data, no method of transmission or storage is entirely secure.
6. Data Retention
We retain information only as long as needed to fulfill the purposes described in this policy or as required by law. PHI is retained and disposed of in compliance with HIPAA regulations.
7. Your Rights Under HIPAA
You have specific rights regarding PHI, including:
The right to access and receive a copy of your PHI
The right to request amendments to your PHI if inaccurate
The right to request restrictions on how your PHI is used or disclosed
The right to request an accounting of certain disclosures
The right to receive communications through alternative means if requested
The right to file a complaint if you believe your HIPAA rights have been violated
To exercise these rights, please contact us using the information below.
8. Children’s Privacy
Our site is not directed to children under age 13. We do not knowingly collect personal information from children without parental consent. Any health information about minors is treated as PHI under HIPAA and handled accordingly.
9. Updates to This Policy
We may update this Privacy Policy periodically. When updates are made, we will revise the “Effective Date” above and post the updated version here. Significant changes may be communicated through additional notices.
10. Contact Us
If you have questions about this Privacy Policy, wish to exercise your rights, or need to report a concern, please contact:
Eva Carlston Academy
4943 S Wasatch Boulevard
Salt Lake City, Utah 84124
Phone: 801-449-0089
Email: info@evacarlston.com
If you believe your HIPAA privacy rights have been violated, you also have the right to file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights.