1. Who this policy covers
Empowered Services, Inc. ("Empowered Services," "we," "us," or "our") is an Oregon Office of Developmental Disabilities Services (ODDS)-licensed agency serving individuals with intellectual and developmental disabilities (IDD) statewide and through active local support in 11 Oregon counties. We are a HIPAA covered entity under 45 CFR Parts 160 and 164. This document is the Notice of Privacy Practices required by 45 CFR § 164.520, combined with our website privacy disclosures, in a single page. It applies to:
- Individuals we serve, family members, and authorized representatives;
- Direct Support Professionals (DSPs), Empowered Choice Program (ECP) caregivers, applicants, and contractors;
- Visitors to https://empowered-services.org and any subdomain we operate;
- Referral partners (Services Coordinators, Personal Agents, schools, hospitals, community organizations).
2. Information we collect
Protected Health Information (PHI)
PHI may include your name, date of birth, address, contact details, Medicaid/Medicare numbers, IDD diagnosis and supports needed, Individual Support Plan (ISP), behavior support plans, medication lists, incident and progress notes, photos used in your records, and Care Coordinator communications.
Personal information from our website and forms
When you contact us, complete an intake or interest form, or apply for a role, we collect the data fields on that form (for example: name, address, phone, email, county, relationship to the individual seeking services, employment history). When you simply browse the site we collect standard log data — IP address, browser type, internet service provider, time stamp, referring/exit pages, and click data — used only for site security, troubleshooting, and aggregate analytics.
Cookies and similar technologies
Our site uses (a) essential cookies that are required for the site to function; (b) analytics cookies (only if you opt in) to understand which pages help visitors find services; (c) functional cookies that remember preferences such as language. We do not use cookies to sell or share your personal data for cross-site behavioral advertising. See Section 9.
3. How we use information
Under HIPAA, we may use and disclose PHI without your written authorization only for these purposes:
- Treatment — coordinating your supports with DSPs, behavioral health, primary care, and other providers in your circle of support.
- Payment — billing Medicaid (Oregon Health Plan), private payers, or another responsible party.
- Health-care operations — quality assurance, compliance, training, audits, accreditation, internal investigations.
- Required by law — mandatory abuse reporting (ORS 430.735–765), public-health reporting, court orders, subpoenas with appropriate process, and law-enforcement purposes permitted by HIPAA.
- Health and safety threats — to prevent or lessen a serious and imminent threat.
- Workers' compensation and specialized government functions as permitted by 45 CFR 164.512.
All other uses or disclosures of PHI — including marketing, fundraising tied to your treatment, sale of PHI, or psychotherapy notes — require your written authorization, which you may revoke at any time in writing.
4. When we share information
We may share your PHI with:
- Other treatment providers in your circle of support;
- Your Personal Agent or Services Coordinator (CDDP/Brokerage);
- Oregon Department of Human Services / ODDS, only as required for funding, licensing, audits, mandatory reporting, or program eligibility;
- Business Associates that perform services on our behalf under a written agreement (see Section 13);
- Family members, friends, or others involved in your care, but only the information directly relevant to that person's involvement and only if you have not objected.
We do not sell your personal information or PHI. We do not share PHI for marketing or third-party advertising.
5. Substance use disorder records (42 CFR Part 2)
Effective February 16, 2026, our handling of substance use disorder (SUD) records complies with the 2024 HHS final rule aligning 42 CFR Part 2 with HIPAA. Re-disclosure of SUD records is prohibited unless permitted by 42 CFR Part 2. You will be given a separate Patient Notice describing your Part 2 rights, including the right to file a Part 2 complaint with HHS.
6. Your rights under HIPAA
| Right | How to use it |
|---|---|
| See and get a copy of your record (within 30 days; one 30-day extension allowed). | Submit a written request to the Privacy Officer (see Section 17). Reasonable copying fees may apply. |
| Ask us to amend a record you believe is wrong or incomplete. | Submit a written amendment request describing the change and reason. |
| Get an accounting of certain disclosures from the past 6 years. | Submit a written request; one free request per 12-month period. |
| Request restrictions on uses or disclosures (e.g., not sharing with a specific family member). | Submit a written request. We will accommodate where required by law (for example, when you pay for a service in full out-of-pocket and ask we not bill insurance). |
| Request confidential communications at an alternate phone, address, or email. | Submit a written request describing how and where you want to be contacted. |
| Receive a paper copy of this Notice of Privacy Practices, even if you also got it electronically. | Ask any staff member or the Privacy Officer. |
| Be notified of a breach involving your unsecured PHI. | We will notify you in writing without unreasonable delay, and within 60 days of discovery, in compliance with 45 CFR 164.404. |
| Revoke an authorization you previously gave. | Submit a written revocation. We will stop using or sharing your PHI under that authorization, except for actions already taken in reliance on it. |
7. Oregon health-information rights
In addition to HIPAA, we comply with Oregon's Policy for Protected Health Information (ORS 192.553–192.581), the confidentiality requirements of OAR 411-323-0060 for ODDS provider agencies, and the Oregon Consumer Information Protection Act (ORS 646A.600 et seq.) for breach notification of personal information that is not PHI.
8. Oregon Consumer Privacy Act rights
Under the Oregon Consumer Privacy Act (ORS 646A.570–589), Oregon consumers have the right to:
- Confirm whether we process your personal data and access it;
- Receive a list of specific third parties to whom we have disclosed personal data;
- Correct inaccurate personal data;
- Request deletion of personal data;
- Obtain a portable copy of your personal data;
- Opt out of (a) the sale of your personal data, (b) targeted advertising, and (c) profiling that produces legal or significant effects.
Effective January 1, 2026, we honor universal opt-out preference signals (such as Global Privacy Control) sent by your browser. Effective the same date, we will not sell the personal data of any consumer we know to be under 16, and we will not sell precise geolocation data. To exercise OCPA rights, email info@empowered-services.org, call (503) 855-3581, or use our privacy rights request form. We respond within 45 days and you have a right to appeal a denial.
9. Website data, cookies, & analytics
Our cookie banner lets you accept or reject non-essential cookies. We disclose, in the banner and in our cookie inventory, every category of cookie used (essential, analytics, functional). We do not embed third-party advertising trackers. We do not knowingly include any technology that "sells" personal data as that term is defined in OCPA.
A "Do Not Sell or Share My Personal Information" link appears in the footer of every page so you can opt out without creating an account.
10. Children & minors
We do not knowingly collect personal information online from children under 13 (COPPA). For consumers known to be under 16, effective January 1, 2026, we will not sell personal data and will not engage in targeted advertising. Parents or legal guardians who believe their child's information was submitted to our website may contact the Privacy Officer to request deletion.
11. How we protect information
In compliance with the HIPAA Security Rule (45 CFR §§ 164.302–164.318), we maintain reasonable and appropriate administrative safeguards (workforce training, access controls, role-based permissions, vendor risk reviews), physical safeguards (facility access controls, secured paper records, device disposal), and technical safeguards (encryption in transit and at rest, unique user IDs, automatic log-off, audit logging, multi-factor authentication for systems holding PHI). We perform a documented Security Risk Analysis at least annually and after any material system change.
12. How long we keep information
We retain PHI for at least 6 years after the date of last contact (HIPAA minimum) or as required by Oregon ODDS record-retention rules, whichever is longer. Website analytics data is aggregated within 14 months. Personal data subject to OCPA is retained only as long as needed for the disclosed purpose, then securely destroyed.
13. Vendors & Business Associates
We use vetted vendors for website hosting, email, electronic health records, billing, secure messaging, document storage, and SMS delivery. Any vendor that may create, receive, maintain, or transmit PHI on our behalf signs a Business Associate Agreement that meets 45 CFR 164.504(e). We do not sell personal data to vendors. A current list of vendor categories is available on request.
14. If there is a breach
If we discover that unsecured PHI has been impermissibly used or disclosed, we will notify you in writing without unreasonable delay and no later than 60 calendar days after discovery (45 CFR 164.404). Notice will describe what happened, the types of information involved, the steps you should take, what we are doing to investigate and mitigate, and how to contact us. We will also notify the HHS Office for Civil Rights and, where required, prominent media outlets and the Oregon Attorney General consistent with ORS 646A.604.
15. Accessibility & language access
Empowered Services provides, free of charge, qualified sign language interpreters; large print, Braille, audio, and accessible electronic formats; qualified interpreters and translated materials for individuals with limited English proficiency; and reasonable modifications of policies, practices, or procedures. Call (503) 855-3581 or use Oregon Relay 711. Our website conforms to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. Report accessibility issues to info@empowered-services.org.
16. Changes to this policy
We may revise this policy at any time. The current version, with effective date, is posted at empowered-services.org/privacy-policy/. Material changes are highlighted at the top of the page for at least 30 days. We review this policy at least annually.
17. Complaints & how to contact us
HIPAA Privacy Officer
Empowered Services, Inc.
8101 SW Nyberg Street, Suite 217
Tualatin, OR 97062
Phone: (503) 855-3581 | Oregon Relay: 711
Email: info@empowered-services.org
U.S. Department of Health and Human Services, Office for Civil Rights (HIPAA & Section 1557)
Online complaint portal: hhs.gov/ocr/complaints
Region X (Seattle): 1-800-368-1019 | TDD: 1-800-537-7697
Oregon Department of Human Services / ODDS
Customer Service Line: 1-800-282-8096
Adult Abuse Reporting (24/7): 1-855-503-SAFE (1-855-503-7233)
Oregon Attorney General — Consumer Privacy
Phone: 1-877-877-9392 | Online: justice.oregon.gov/consumer
No retaliation
You will never be denied services, treated differently, or otherwise penalized for filing a privacy complaint, requesting your records, or exercising any right described above.
