FIND A HOME CARE — PRIVACY POLICY
Last Updated: 12/09/2025
NOTICE AT COLLECTION (Required Under CPRA)
We collect personal information and sensitive personal information to operate our referral platform and connect you with licensed care providers. The categories of information we collect, the purposes for collection, how long we retain the information, and your privacy rights are described in this Privacy Policy.
We do not sell or share your personal information for cross-context behavioral advertising.
You may request access, correction, or deletion of your information at any time using the contact information below.
1. Introduction
Find A Home Care (“FindAHomeCare.com,” “we,” “us,” or “our”) is a non-clinical referral and lead-generation platform that helps families connect with licensed home care providers, assisted living communities, and other senior care resources.
We do not provide medical care or home care services.
We only collect information needed to make secure referrals, and we protect that information in accordance with HIPAA, applicable privacy laws, and our executed Business Associate Agreements (BAAs).
This Privacy Policy explains how we collect, use, disclose, and protect your information.
2. Scope of This Privacy Policy
This Privacy Policy applies to:
- Visitors of FindAHomeCare.com
- Individuals completing intake or referral forms
- Phone, SMS, and email communications
- CRM-based data collection
- Providers accessing our lead portal
- PHI handled under a BAA
This policy does not apply to:
- Care provider operations after they receive a referral
- External websites
- Clinical services or treatment decisions
3. Our Role Under HIPAA
FindAHomeCare.com may act as a Business Associate to certain providers (Covered Entities). When PHI is exchanged for referral purposes, we:
As a Business Associate, we:
- Use or disclose PHI only as allowed under BAAs
- Apply the minimum necessary standard
- Maintain HIPAA-required administrative, physical, and technical safeguards
- Transmit PHI securely to providers for referral purposes
- Provide breach notifications if required by law
We do not:
- Provide medical or clinical advice
- Create or maintain medical records
- Direct, coordinate, or supervise care
- Sell PHI or personal data
4. Information We Collect
A. Categories of Personal Information (CPRA Required Disclosure)
We collect the following categories of personal information:
- Identifiers (name, email address, phone number, ZIP code)
- Internet/network activity (cookies, IP address, analytics data)
- Geolocation (approximate, based on IP or ZIP code)
- Commercial information (service inquiries, referral history)
- Communications (SMS, email, phone records)
- Professional/agency information (for providers using portal)
B. Categories of Sensitive Personal Information (CPRA Required Disclosure)
We collect limited sensitive personal information ONLY for referral purposes:
- Care needs
- Disability or mobility limitations
- Daily living assistance needs
- Conditions relevant to home care matching
We do not use sensitive personal information for advertising, profiling, or cross-context behavioral purposes.
C. Protected Health Information (PHI)
Collected only when needed to complete a referral:
- Type of care requested
- Mobility or support needs
- Urgency of care
- Service preferences
- Basic functional limitations
We avoid collecting detailed medical history unless necessary.
5. How We Collect Information
We collect information through:
- Website intake forms
- Phone consultations
- SMS or email communications
- CRM tools (e.g., secure lead forms)
- Analytics tools such as Google Analytics and Search Console
6. How We Use Information
Referral and Matching
- Understand care needs
- Identify appropriate licensed providers
- Facilitate secure introductions
- Support follow-up communications
Operations & Quality
- Improve website experience
- Maintain CRM records
- Conduct internal audits
- Manage provider reporting requirements
Marketing (Optional & Opt-In Only)
- Email or SMS updates
- Educational content
- Referral-related reminders
We do not sell or rent personal data.
We do not sell or share personal information as defined under CPRA.
7. How We Disclose Information
Permitted Disclosures
We may disclose information:
- To licensed care providers solely for referral purposes
- To HIPAA-compatible CRM and form vendors
- To internal trained staff under confidentiality protections
- To legal counsel for compliance purposes
Prohibited Disclosures
We do NOT:
- Sell PHI or personal information
- Share personal information for cross-context behavioral advertising
- Use PHI for marketing without authorization
- Disclose PHI to unauthorized parties
8. Data Security Measures
We maintain:
- SSL encryption
- Secure CRM systems
- Role-based access control
- Audit logs
- Staff confidentiality agreements
- HIPAA-aligned security programs
9. Data Retention (CPRA REQUIRED)
We retain personal information and PHI only as long as needed for:
- Referral processing
- Provider reporting
- Business Associate Agreement obligations
- Legal compliance
Specific retention periods:
- Intake/referral data: up to 6 years (HIPAA requirement)
- Website analytics: up to 26 months
- Provider portal records: duration of provider relationship + 3 years
Information is securely deleted when no longer needed.
10. Breach Notification
If PHI is compromised, we will:
- Investigate promptly
- Mitigate impact
- Notify affected individuals as required by HIPAA
- Provide documentation of corrective actions
11. Your Rights (Expanded for CPRA Compliance)
You may request:
- Access to the information you provided
- Corrections of inaccurate information
- Deletion of your information (when permitted)
- A copy of this policy
- Restriction of certain uses
- To opt out of marketing
- To limit use of sensitive personal information
- To know what categories of personal information we collect
- To know whether information has been shared and with whom
Non-Discrimination Statement (CPRA Required)
We will not deny services, charge different prices, or provide different service levels if you exercise your privacy rights.
To make a request, contact us using the information below.
12. Third-Party Sites
Links on our website may direct you to third-party sites. We do not control their privacy practices and are not responsible for their content.
13. Children’s Privacy
We do not knowingly collect information from children under 13.
14. Opt-Out Options
You may opt out of:
- Email communications
- SMS/text messages
- Non-essential CRM communications
Each message will include opt-out instructions.
15. Required CPRA Links (Footer Language)
The following statements must appear in the website footer:
- “Privacy Policy”
- “Notice of Privacy Practices (HIPAA)”
- “Do Not Sell or Share My Personal Information”
- “Limit the Use of My Sensitive Personal Information”
16. Updates to This Policy
We may update this Privacy Policy periodically. Changes will be published with a revised “Last Updated” date.
17. Contact Information
If you have questions about this Privacy Policy or how your information is handled, contact:
Find A Home Care — Privacy Office
Phone: (650)-677-1711
Email: info@findahomecare.com
