EvrBranch LLC
Notice of Privacy Practices
Last Updated: September 24, 2026
Your privacy rights as someone receiving CFSS Consultation Services.
Purpose
The purpose of this policy is to inform individuals receiving CFSS Consultation Services of their rights under applicable privacy laws and regulations, including the Minnesota Government Data Practices Act (MGDPA), the Health Insurance Portability and Accountability Act (HIPAA), and other state and federal requirements governing the use, protection, and disclosure of private data. This policy outlines how the provider collects, uses, safeguards, shares, and grants access to protected information.
Policy
The provider is committed to protecting the privacy and confidentiality of all individual information received during the provision of CFSS Consultation Services. The provider maintains strict safeguards to ensure that all private data — including health, demographic, financial, and service-related information — is used and disclosed only as permitted or required by law or with the individual's informed, written authorization.
The provider provides all individuals with a Notice of Privacy Practices (NPP) at the start of services. The NPP outlines how information may be used or shared, the individual's privacy rights, and the provider's responsibilities. Individuals may request a paper or electronic copy of the NPP at any time.
Information Collected
The provider may collect and maintain information necessary to provide CFSS consultation services, including:
- Personal identification and demographic information
- Eligibility and assessment information
- Service delivery plans and related documentation
- Communications, inquiries, and grievances
- Authorizations or consent forms
- Other information required by CFSS program rules or DHS
All information is collected only for purposes related to service delivery, billing, quality assurance, and legal compliance.
Permitted Uses and Disclosures
The provider may use or disclose individual information for the following purposes:
- Service delivery: To develop, review, and submit CFSS service delivery plans
- Administrative functions: Scheduling, communication, training, documentation, billing
- Coordination with DHS or the lead agency: For approvals, audits, data collection, or surveys
- Compliance and oversight: Reporting fraud, abuse, maltreatment, or other mandated reporting requirements
- Operations: Quality assurance, complaint resolution, accreditation, policy review
- Legal requirements: When required by state or federal law, court order, or regulatory authority
No information will be disclosed for marketing, sales, or any purpose not permitted under applicable privacy regulations.
When Written Authorization Is Required
The provider will obtain written authorization from the individual before using or sharing information for any purpose not allowed by law, including:
- Sharing information with outside parties not involved in CFSS
- Releasing information for employment, housing, or non-service–related requests
- Sharing sensitive information beyond what is required for CFSS service delivery
Individuals may revoke authorization at any time unless the information has already been used or disclosed based on that permission.
Individual Rights Under This Policy
Individuals receiving CFSS Consultation Services have the right to:
- Receive a copy of the Notice of Privacy Practices
- Request restrictions on how their information is used or shared
- Request confidential communication methods (e.g., phone, email, text, mail)
- Access, review, and request corrections to their private information
- Receive an accounting of disclosures made without their authorization
- File a complaint with the provider or DHS if they believe their privacy rights were violated
- Receive services without retaliation for exercising privacy rights
The provider will respond to all privacy-related requests in a timely manner as required by law.
Safeguards
The provider maintains administrative, technical, and physical safeguards designed to:
- Protect against unauthorized access or disclosure
- Maintain data accuracy and integrity
- Secure electronic communications and storage
- Limit access to staff who require information to perform their duties
All staff receive training on privacy laws, confidentiality, documentation rules, and procedures for protecting private data.
Breach Notification
If a breach of unsecured protected information occurs, the provider will:
- Immediately investigate
- Take steps to reduce or prevent further harm
- Notify affected individuals as required by state and federal law
- Implement corrective actions to prevent recurrence
Responsibilities
The provider is responsible for:
- Ensuring compliance with all privacy regulations
- Providing individuals with an updated Notice of Privacy Practices
- Training staff on privacy policies and data protection procedures
- Maintaining required documentation and safeguards
- Responding to privacy-related requests or complaints
Availability of This Notice
This Notice of Privacy Practices is:
- Provided during admission
- Available upon request at any time
- Updated as required to reflect changes in laws or agency practice
