RecoveryBuddy AI Protected Health Information (PHI) Policy

Effective Date: August 1, 2026

Last Updated: August 1, 2026

Platform Owner

Digjy LLC

19580 West Indian School Rd Ste 105 #973

Buckeye, Arizona 85396

United States

Website: https://recoverybuddy.net

Email: [email protected]


Protected Health Information (PHI) Policy

This Protected Health Information (“PHI”) Policy describes how RecoveryBuddy AI, owned and operated by Digjy LLC (“RecoveryBuddy AI,” “we,” “our,” or “us”), safeguards, processes, stores, transmits, and manages Protected Health Information when applicable.

This Policy should be read together with our Terms of Service, Privacy Policy, HIPAA Notice, Business Associate Agreements (where applicable), and other legal policies governing the Platform.


Purpose

RecoveryBuddy AI is committed to protecting the confidentiality, integrity, and availability of Protected Health Information when the Platform is used by healthcare providers, treatment organizations, or other entities subject to applicable healthcare privacy laws.

This Policy establishes the principles governing the handling of PHI throughout the Platform.


Scope

This Policy applies to:

  • RecoveryBuddy AI website

  • Mobile applications

  • WordPress plugin

  • Artificial intelligence features

  • Recovery journals

  • Messaging

  • Recovery meetings

  • Provider portals

  • Organization dashboards

  • Administrative tools

  • APIs

  • Customer support systems

  • Cloud infrastructure used to operate the Platform

This Policy applies only when information qualifies as Protected Health Information under applicable law.


Definition of Protected Health Information

For purposes of this Policy, Protected Health Information (“PHI”) generally means individually identifiable health information protected under HIPAA and other applicable healthcare privacy laws.

Examples may include:

  • Medical history

  • Recovery information

  • Behavioral health information

  • Treatment participation

  • Clinical notes

  • Assessment results

  • Appointment information

  • Medication information

  • Healthcare provider communications

  • Progress reports

  • Wellness information linked to an identifiable individual

  • Other health-related information protected by law


Collection of PHI

RecoveryBuddy AI may receive PHI when:

  • A healthcare provider enters information into the Platform.

  • A treatment organization uploads records.

  • A user voluntarily provides health-related information.

  • Authorized integrations transmit healthcare information.

  • Users communicate with providers through the Platform.

  • Recovery journals contain health-related information.

  • Recovery plans include health-related content.

Only information reasonably necessary to provide requested Platform functionality should be collected or entered into the Platform.


Permitted Uses of PHI

Where applicable, PHI may be used to:

  • Operate the Platform.

  • Authenticate authorized users.

  • Facilitate communication.

  • Support recovery planning.

  • Provide requested AI-assisted functionality.

  • Generate summaries.

  • Support provider collaboration.

  • Improve workflow efficiency.

  • Maintain security.

  • Prevent fraud.

  • Comply with legal obligations.

  • Perform functions authorized under applicable agreements.

PHI is processed only as permitted by applicable law, contractual agreements, and user authorizations.


Minimum Necessary Standard

RecoveryBuddy AI seeks to support the HIPAA “Minimum Necessary” principle where applicable.

Authorized users should access, use, or disclose only the minimum amount of PHI reasonably necessary to perform their authorized responsibilities.

Role-based permissions should be configured to limit access appropriately.


Artificial Intelligence and PHI

RecoveryBuddy AI may use artificial intelligence to assist with:

  • Recovery planning.

  • Educational information.

  • Journal organization.

  • Summaries.

  • Workflow assistance.

  • Administrative support.

Artificial intelligence:

  • Does not replace licensed healthcare professionals.

  • Does not independently diagnose conditions.

  • Does not prescribe medications.

  • Does not establish treatment plans.

  • Does not replace clinical judgment.

Healthcare providers remain responsible for reviewing AI-generated information before relying upon it in patient care.

Where PHI is processed by AI features, RecoveryBuddy AI implements administrative and technical safeguards appropriate to the services provided and applicable agreements.


Access Controls

RecoveryBuddy AI supports security measures designed to limit access to PHI.

Security measures may include:

  • Unique user accounts.

  • Role-based permissions.

  • Multi-factor authentication.

  • Session management.

  • Password policies.

  • Administrative approval workflows.

  • Audit logging.

  • Authentication monitoring.

Organizations are responsible for assigning appropriate user permissions.


Encryption

RecoveryBuddy AI is designed to use encryption technologies where appropriate, including:

  • Encryption of data in transit using industry-standard protocols.

  • Encryption of stored data where appropriate.

  • Secure authentication mechanisms.

  • Protected communication channels.

Encryption methods may evolve as technology and industry standards develop.


Audit Logging

RecoveryBuddy AI may maintain audit logs relating to:

  • User authentication.

  • Account activity.

  • Administrative actions.

  • PHI access events.

  • Security events.

  • Configuration changes.

  • File access.

  • Data exports.

  • System events.

Audit logs help support security, compliance, investigations, and operational monitoring.


Workforce Responsibilities

Employees, contractors, administrators, and authorized personnel with access to PHI are expected to:

  • Protect confidential information.

  • Follow applicable policies.

  • Use information only for authorized purposes.

  • Maintain secure credentials.

  • Report suspected security incidents promptly.

  • Complete applicable security and privacy training.

Access is limited to authorized individuals with a legitimate business need.


User Responsibilities

Healthcare providers, organizations, and authorized users are responsible for:

  • Obtaining required patient authorizations where applicable.

  • Configuring appropriate user permissions.

  • Protecting account credentials.

  • Logging out of shared devices.

  • Verifying recipient identities before sharing information.

  • Complying with applicable privacy laws.

  • Exercising independent professional judgment.

RecoveryBuddy AI does not replace organizational privacy or compliance programs.


Disclosure of PHI

RecoveryBuddy AI may disclose PHI only:

  • As authorized by the user.

  • As authorized by a healthcare organization.

  • As required by applicable law.

  • As permitted by an applicable Business Associate Agreement.

  • To service providers acting under appropriate contractual obligations.

  • To protect legal rights where permitted by law.

RecoveryBuddy AI does not disclose PHI for unauthorized purposes.


Data Retention

PHI is retained only as long as reasonably necessary to:

  • Provide Platform services.

  • Comply with contractual obligations.

  • Meet legal or regulatory requirements.

  • Maintain business records.

  • Resolve disputes.

  • Support audits.

  • Prevent fraud.

  • Maintain security.

Retention periods vary based on applicable law and contractual obligations.


Secure Disposal

When PHI is no longer required, RecoveryBuddy AI seeks to securely dispose of or de-identify information where appropriate and permitted by law.

Secure disposal methods may include:

  • Secure deletion.

  • Cryptographic destruction where applicable.

  • De-identification.

  • Controlled archival and expiration.

  • Destruction of backup media according to established retention schedules.


Security Incidents

RecoveryBuddy AI maintains procedures designed to identify, investigate, document, and respond to suspected security incidents affecting PHI.

Where required by applicable law or contract, notifications regarding reportable incidents will be provided within legally or contractually required timeframes.


Business Associate Agreements

Where applicable, Digjy LLC may enter into Business Associate Agreements with HIPAA-covered entities.

Those agreements govern specific responsibilities relating to PHI processing and supplement this Policy.

Nothing in this Policy creates a Business Associate relationship absent a fully executed written agreement.


International Processing

If PHI is processed across international boundaries, RecoveryBuddy AI seeks to implement appropriate safeguards consistent with applicable law and contractual obligations.

Organizations remain responsible for evaluating cross-border legal requirements applicable to their use of the Platform.


Policy Updates

RecoveryBuddy AI may update this PHI Policy to reflect:

  • Changes in applicable law.

  • HIPAA guidance.

  • Security improvements.

  • Platform enhancements.

  • Operational changes.

  • Industry standards.

  • Compliance requirements.

Updated versions will be published on the RecoveryBuddy AI website with a revised Last Updated date.


Contact Information

Questions regarding this PHI Policy may be directed to:

Digjy LLC

RecoveryBuddy AI

Privacy & Compliance Office

19580 West Indian School Rd Ste 105 #973

Buckeye, Arizona 85396

United States

Website: https://recoverybuddy.net

Email: [email protected]


Acknowledgment

By using RecoveryBuddy AI in connection with healthcare services, you acknowledge that you have read and understood this PHI Policy.

Healthcare providers, treatment organizations, and other authorized users remain responsible for complying with all applicable healthcare privacy and security laws, professional obligations, and contractual requirements.

Nothing in this Policy modifies or limits obligations contained in applicable Business Associate Agreements, healthcare regulations, or other governing legal requirements.

© 2026 Digjy LLC. All Rights Reserved.

error: Content is protected !!