Serenity Treatment Center
Policy Title: Public Website Privacy Policy
Program Level: All Levels of Care
Effective Date: 8/11/2026
Approved By: All Leadership
Public Website Privacy Policy
Important: This Public Website Privacy Policy describes privacy practices for Serenity’s public website and related online interactions. It supplements Serenity’s internal privacy and security policies and does not replace Serenity’s Notice of Privacy Practices governing Protected Health Information (PHI) or substance use disorder patient records.
1. Introduction and Scope
Serenity Treatment Center, Inc. (“Serenity,” “we,” “our,” or “us”) is committed to protecting the privacy and confidentiality of individuals who visit our website, contact us, seek information about our programs, submit an inquiry or referral, or otherwise interact with us online.
This Public Website Privacy Policy explains the types of information we may collect through our website and public-facing online services, how we may use and disclose that information, the safeguards we use, and choices or rights that may be available to you. By using our website, you acknowledge the practices described in this policy.
This policy is intended to operate alongside Serenity’s internal Privacy Policy, information security policies, patient consents, and Notice of Privacy Practices. If information becomes part of a patient record or is otherwise regulated as PHI or a substance use disorder patient record, the applicable healthcare privacy laws, notices, and patient rights govern that information.
2. Information We May Collect
Information You Provide
We may collect information that you voluntarily provide through website forms, telephone or email follow-up, admissions inquiries, referral requests, insurance verification requests, appointment requests, or other online interactions. This may include:
-
- Name and contact information, including phone number, email address, and mailing address;
-
- Information about the reason you are contacting Serenity or the services you are seeking;
-
- Insurance, benefits, referral, and admissions-related information;
-
- Appointment preferences and information included in messages or forms;
-
- Information submitted by a family member, referral source, healthcare professional, or other authorized person; and
-
- Other information you choose to provide.
Please do not use general website forms or ordinary email for emergencies. Do not submit information about another person unless you have an appropriate basis or authorization to do so.
Automatically Collected Information
When you visit our website, certain technical and usage information may be collected automatically by our website, hosting providers, security tools, analytics services, or similar technologies. Depending on configuration, this may include:
-
- Internet Protocol (IP) address;
-
- Browser, device, and operating system information;
-
- Pages viewed, referring pages, links selected, and approximate time spent on pages;
-
- General geographic information derived from an IP address;
-
- Cookie or device identifiers; and
-
- Other information about interactions with the website.
3. Health Information, HIPAA, and 42 C.F.R. Part 2
Serenity is a healthcare provider and provides substance use disorder treatment services. Information collected in connection with treatment may be protected by the Health Insurance Portability and Accountability Act of 1996 (HIPAA), applicable Maryland law, and other federal or state privacy requirements.
Certain records relating to substance use disorder diagnosis, treatment, or referral for treatment may also be subject to the federal confidentiality protections of 42 C.F.R. Part 2. Where Part 2 applies, Serenity handles those records in accordance with applicable Part 2 requirements, including restrictions on uses and disclosures and applicable patient rights.
This Public Website Privacy Policy is not Serenity’s HIPAA Notice of Privacy Practices or Part 2 patient notice. Serenity’s Notice of Privacy Practices provides additional information about how protected treatment information may be used and disclosed and explains patient rights concerning that information.
4. Website Forms, Admissions Inquiries, and Electronic Communications
Information submitted through a website form may be reviewed by Serenity personnel to respond to your inquiry, coordinate an assessment or admission, verify benefits, communicate with a referral source, or provide information about services.
Submitting a website form does not establish a treatment relationship, guarantee admission, or guarantee an appointment. General website forms, email, and ordinary text messaging may not provide the same privacy protections as a secure patient portal or other healthcare communication system.
Once information is received and incorporated into a patient or clinical record, it will be handled under Serenity’s applicable healthcare privacy practices and legal obligations.
5. Cookies and Similar Technologies
Our website may use cookies, pixels, tags, scripts, local storage, and similar technologies to support website functionality, maintain security, remember preferences, understand website usage, and measure the effectiveness of communications or advertising.
You may be able to control certain cookies through your browser settings or other controls made available on the website. Disabling certain technologies may affect website functionality.
6. Analytics and Advertising Technologies
Serenity may use services such as Google Analytics, Google Tag Manager, Google Ads conversion measurement, Google Business Profile integrations, or similar tools to understand website performance, measure traffic, improve user experience, and evaluate outreach efforts.
Serenity does not intentionally use analytics or advertising technologies to disclose PHI or information protected by 42 C.F.R. Part 2 for advertising purposes. We seek to configure website technologies and third-party services in a manner consistent with applicable healthcare privacy and security obligations.
Third-party analytics and advertising providers may process technical information according to their own terms and privacy practices. Where required, Serenity may use contractual, technical, consent, or configuration safeguards to limit the information made available to third parties.
7. How We Use Information
We may use information collected through the website and public-facing online services to:
-
- Respond to questions, messages, referrals, and requests for information;
-
- Coordinate assessments, admissions, appointments, and requested services;
-
- Verify insurance benefits or facilitate payment-related communications;
-
- Provide, operate, maintain, secure, and improve our website and online services;
-
- Communicate about Serenity programs, services, locations, or operational updates;
-
- Measure website performance and the effectiveness of outreach efforts;
-
- Conduct quality improvement, compliance, security, fraud-prevention, and administrative activities;
-
- Comply with applicable legal, regulatory, licensing, accreditation, and reporting requirements.
8. How We May Share Information
Serenity does not sell personal information for monetary consideration. We may disclose information when appropriate and permitted by applicable law, including:
-
- To service providers and vendors that support website hosting, security, communications, analytics, scheduling, electronic health record systems, payment functions, or other operations;
-
- To healthcare providers, payers, referral sources, or others when permitted or authorized and appropriate for the applicable purpose;
-
- To comply with a legal obligation, court order, regulatory requirement, audit, investigation, or other lawful process;
-
- To protect the rights, safety, security, or integrity of Serenity, our patients, website users, or others; and
-
- With your authorization or direction when authorization is required.
Information is disclosed only as permitted by applicable federal and state law, including HIPAA and, where applicable, the heightened confidentiality requirements governing substance use disorder patient records under 42 C.F.R. Part 2.
9. Service Providers, EHR, Patient Portal, and Other Third-Party Systems
Serenity may use third-party vendors to provide services such as website hosting, forms, secure communications, electronic health records, patient portals, scheduling, insurance verification, payment processing, telehealth, data storage, analytics, and cybersecurity.
When a vendor receives or maintains PHI on Serenity’s behalf and is acting as a business associate under HIPAA, Serenity requires appropriate contractual protections, including a Business Associate Agreement when required by law. Additional terms, privacy notices, or consents may apply when you access an EHR, patient portal, telehealth platform, payment service, or other third-party system.
Links to third-party websites or services are provided for convenience. Serenity is not responsible for the privacy practices, security, availability, or content of unaffiliated third-party websites. You should review the privacy notices applicable to those services.
10. Data Security
Serenity maintains administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, or destruction. Safeguards may include access controls, workforce training, secure technology practices, vendor oversight, and other privacy and security measures appropriate to the information and systems involved.
No website, email system, internet transmission, or electronic storage system can be guaranteed to be completely secure. If you believe information you submitted to Serenity may have been accessed or disclosed improperly, please contact us promptly using the information below.
11. Data Retention
We retain information for as long as reasonably necessary for the purposes described in this policy and as required by applicable healthcare, licensing, contractual, tax, legal, record-retention, or other obligations. Retention periods may vary depending on the type of information and whether it becomes part of a patient or business record.
12. Your Privacy Choices and Rights
Depending on the type of information involved and applicable law, you may have rights to request access to, correction of, deletion of, or restrictions concerning certain personal information, or to obtain information about certain privacy practices. Rights relating to PHI and Part 2 records are described in Serenity’s Notice of Privacy Practices and other applicable patient notices.
Maryland residents may also have rights under the Maryland Online Data Privacy Act (MODPA) for personal data to which that law applies. Those rights can include the ability to request access, correction, deletion, or information about certain processing, and to opt out of certain sale, targeted advertising, or profiling activities. Some information, including certain data maintained in compliance with HIPAA or other laws, may be excluded from MODPA or subject to different requirements.
To submit a privacy request, contact Serenity using the information in Section 17. We may need to verify your identity or authority before completing a request. We will not discriminate against you for exercising a privacy right provided by applicable law.
13. Children’s Privacy
Serenity’s treatment services are intended for adults age 18 and older. Our public website is not directed to children under age 13, and we do not knowingly collect personal information from children under age 13 through general website interactions. If we learn that such information has been collected through the public website without appropriate authorization, we will take reasonable steps to address it.
14. Email, Text Messages, and Telephone Communications
If you provide contact information to Serenity, we may use it to respond to your request or communicate about services, scheduling, admissions, or other matters consistent with your request and applicable law. Email and ordinary text messages can involve privacy or security risks, and you should use secure communication methods made available by Serenity when transmitting sensitive treatment information.
Any separate consent requirements for text messaging, telehealth, patient portal use, or other electronic communications continue to apply.
15. Changes to This Public Privacy Policy
We may update this Public Website Privacy Policy periodically to reflect changes in our website, technology, vendors, services, privacy practices, or legal requirements. The current version will be posted on our website with an updated effective or revision date. We encourage you to review this policy periodically.
16. Relationship to Other Serenity Privacy Documents
This public-facing policy should be read together with Serenity’s internal Privacy Policy and, for patients and protected treatment information, Serenity’s Notice of Privacy Practices and applicable patient consents. Internal policies govern Serenity workforce practices and operational controls; this Public Website Privacy Policy communicates website privacy practices to visitors and members of the public.
If there is a conflict concerning PHI or a substance use disorder patient record, the applicable federal or state law and Serenity’s legally required patient privacy notice will control.
17. Contact Us
Questions about this Public Website Privacy Policy or requests concerning website privacy may be directed to:
Serenity Treatment Center, Inc.
Frederick Phone: (301) 898-2627
Email: info@serenitytreatmentcenter.com
Hagerstown Phone: (301) 732-5328
Website: www.serenitytreatmentcenter.com
For questions about the use or disclosure of treatment records or to exercise rights concerning PHI or Part 2 records, please follow the contact and complaint procedures in Serenity’s Notice of Privacy Practices.