RecoveryBuddy AI Protected Health Information (PHI) Policy
Effective Date: August 1, 2026
Last Updated: August 1, 2026
Platform Owner
Digjy LLC
19580 West Indian School Rd Ste 105 #973
Buckeye, Arizona 85396
United States
Website: https://recoverybuddy.net
Email: [email protected]
Protected Health Information (PHI) Policy
This Protected Health Information (“PHI”) Policy describes how RecoveryBuddy AI, owned and operated by Digjy LLC (“RecoveryBuddy AI,” “we,” “our,” or “us”), safeguards, processes, stores, transmits, and manages Protected Health Information when applicable.
This Policy should be read together with our Terms of Service, Privacy Policy, HIPAA Notice, Business Associate Agreements (where applicable), and other legal policies governing the Platform.
Purpose
RecoveryBuddy AI is committed to protecting the confidentiality, integrity, and availability of Protected Health Information when the Platform is used by healthcare providers, treatment organizations, or other entities subject to applicable healthcare privacy laws.
This Policy establishes the principles governing the handling of PHI throughout the Platform.
Scope
This Policy applies to:
RecoveryBuddy AI website
Mobile applications
WordPress plugin
Artificial intelligence features
Recovery journals
Messaging
Recovery meetings
Provider portals
Organization dashboards
Administrative tools
APIs
Customer support systems
Cloud infrastructure used to operate the Platform
This Policy applies only when information qualifies as Protected Health Information under applicable law.
Definition of Protected Health Information
For purposes of this Policy, Protected Health Information (“PHI”) generally means individually identifiable health information protected under HIPAA and other applicable healthcare privacy laws.
Examples may include:
Medical history
Recovery information
Behavioral health information
Treatment participation
Clinical notes
Assessment results
Appointment information
Medication information
Healthcare provider communications
Progress reports
Wellness information linked to an identifiable individual
Other health-related information protected by law
Collection of PHI
RecoveryBuddy AI may receive PHI when:
A healthcare provider enters information into the Platform.
A treatment organization uploads records.
A user voluntarily provides health-related information.
Authorized integrations transmit healthcare information.
Users communicate with providers through the Platform.
Recovery journals contain health-related information.
Recovery plans include health-related content.
Only information reasonably necessary to provide requested Platform functionality should be collected or entered into the Platform.
Permitted Uses of PHI
Where applicable, PHI may be used to:
Operate the Platform.
Authenticate authorized users.
Facilitate communication.
Support recovery planning.
Provide requested AI-assisted functionality.
Generate summaries.
Support provider collaboration.
Improve workflow efficiency.
Maintain security.
Prevent fraud.
Comply with legal obligations.
Perform functions authorized under applicable agreements.
PHI is processed only as permitted by applicable law, contractual agreements, and user authorizations.
Minimum Necessary Standard
RecoveryBuddy AI seeks to support the HIPAA “Minimum Necessary” principle where applicable.
Authorized users should access, use, or disclose only the minimum amount of PHI reasonably necessary to perform their authorized responsibilities.
Role-based permissions should be configured to limit access appropriately.
Artificial Intelligence and PHI
RecoveryBuddy AI may use artificial intelligence to assist with:
Recovery planning.
Educational information.
Journal organization.
Summaries.
Workflow assistance.
Administrative support.
Artificial intelligence:
Does not replace licensed healthcare professionals.
Does not independently diagnose conditions.
Does not prescribe medications.
Does not establish treatment plans.
Does not replace clinical judgment.
Healthcare providers remain responsible for reviewing AI-generated information before relying upon it in patient care.
Where PHI is processed by AI features, RecoveryBuddy AI implements administrative and technical safeguards appropriate to the services provided and applicable agreements.
Access Controls
RecoveryBuddy AI supports security measures designed to limit access to PHI.
Security measures may include:
Unique user accounts.
Role-based permissions.
Multi-factor authentication.
Session management.
Password policies.
Administrative approval workflows.
Audit logging.
Authentication monitoring.
Organizations are responsible for assigning appropriate user permissions.
Encryption
RecoveryBuddy AI is designed to use encryption technologies where appropriate, including:
Encryption of data in transit using industry-standard protocols.
Encryption of stored data where appropriate.
Secure authentication mechanisms.
Protected communication channels.
Encryption methods may evolve as technology and industry standards develop.
Audit Logging
RecoveryBuddy AI may maintain audit logs relating to:
User authentication.
Account activity.
Administrative actions.
PHI access events.
Security events.
Configuration changes.
File access.
Data exports.
System events.
Audit logs help support security, compliance, investigations, and operational monitoring.
Workforce Responsibilities
Employees, contractors, administrators, and authorized personnel with access to PHI are expected to:
Protect confidential information.
Follow applicable policies.
Use information only for authorized purposes.
Maintain secure credentials.
Report suspected security incidents promptly.
Complete applicable security and privacy training.
Access is limited to authorized individuals with a legitimate business need.
User Responsibilities
Healthcare providers, organizations, and authorized users are responsible for:
Obtaining required patient authorizations where applicable.
Configuring appropriate user permissions.
Protecting account credentials.
Logging out of shared devices.
Verifying recipient identities before sharing information.
Complying with applicable privacy laws.
Exercising independent professional judgment.
RecoveryBuddy AI does not replace organizational privacy or compliance programs.
Disclosure of PHI
RecoveryBuddy AI may disclose PHI only:
As authorized by the user.
As authorized by a healthcare organization.
As required by applicable law.
As permitted by an applicable Business Associate Agreement.
To service providers acting under appropriate contractual obligations.
To protect legal rights where permitted by law.
RecoveryBuddy AI does not disclose PHI for unauthorized purposes.
Data Retention
PHI is retained only as long as reasonably necessary to:
Provide Platform services.
Comply with contractual obligations.
Meet legal or regulatory requirements.
Maintain business records.
Resolve disputes.
Support audits.
Prevent fraud.
Maintain security.
Retention periods vary based on applicable law and contractual obligations.
Secure Disposal
When PHI is no longer required, RecoveryBuddy AI seeks to securely dispose of or de-identify information where appropriate and permitted by law.
Secure disposal methods may include:
Secure deletion.
Cryptographic destruction where applicable.
De-identification.
Controlled archival and expiration.
Destruction of backup media according to established retention schedules.
Security Incidents
RecoveryBuddy AI maintains procedures designed to identify, investigate, document, and respond to suspected security incidents affecting PHI.
Where required by applicable law or contract, notifications regarding reportable incidents will be provided within legally or contractually required timeframes.
Business Associate Agreements
Where applicable, Digjy LLC may enter into Business Associate Agreements with HIPAA-covered entities.
Those agreements govern specific responsibilities relating to PHI processing and supplement this Policy.
Nothing in this Policy creates a Business Associate relationship absent a fully executed written agreement.
International Processing
If PHI is processed across international boundaries, RecoveryBuddy AI seeks to implement appropriate safeguards consistent with applicable law and contractual obligations.
Organizations remain responsible for evaluating cross-border legal requirements applicable to their use of the Platform.
Policy Updates
RecoveryBuddy AI may update this PHI Policy to reflect:
Changes in applicable law.
HIPAA guidance.
Security improvements.
Platform enhancements.
Operational changes.
Industry standards.
Compliance requirements.
Updated versions will be published on the RecoveryBuddy AI website with a revised Last Updated date.
Contact Information
Questions regarding this PHI Policy may be directed to:
Digjy LLC
RecoveryBuddy AI
Privacy & Compliance Office
19580 West Indian School Rd Ste 105 #973
Buckeye, Arizona 85396
United States
Website: https://recoverybuddy.net
Email: [email protected]
Acknowledgment
By using RecoveryBuddy AI in connection with healthcare services, you acknowledge that you have read and understood this PHI Policy.
Healthcare providers, treatment organizations, and other authorized users remain responsible for complying with all applicable healthcare privacy and security laws, professional obligations, and contractual requirements.
Nothing in this Policy modifies or limits obligations contained in applicable Business Associate Agreements, healthcare regulations, or other governing legal requirements.
© 2026 Digjy LLC. All Rights Reserved.