Effective Date: August 4, 2026
| Thrive collects and uses personal information only as needed to provide services, operate our organization, meet reporting and legal obligations, and protect the people and information entrusted to us. |
Thrive Community Health Network, the public-facing name of Tri-County Health Network, is committed to protecting the privacy, confidentiality, and security of personal, health, financial, and other sensitive information. This policy explains the information we may collect, how we use and share it, the safeguards we maintain, and the choices and rights that may be available to you. Throughout this policy, “Thrive,” “we,” “our,” and “us” refer to Thrive Community Health Network.
Scope of This Policy
This policy applies to personal information collected through Thrive programs, services, websites, online and paper forms, phone and email communications, text messaging, referrals, appointments, events, donations, applications, and other interactions with our organization. It may apply to clients, program participants, parents or guardians, community members, donors, volunteers, job applicants, employees, contractors, partners, and website visitors.
Some programs, services, or relationships may have additional privacy notices, consent forms, authorizations, contracts, or legal requirements. When a more specific notice or requirement applies, it supplements this policy and may control how particular information is handled.
Information We May Collect
We seek to collect only the information reasonably necessary for the applicable service, activity, or organizational purpose. Depending on your relationship with Thrive, this may include:
- Identification and contact information, such as your name, address, email address, telephone number, preferred language, and communication preferences
- Demographic, household, and eligibility information used to determine or document participation in programs and services
- Health, behavioral health, dental, insurance, benefits, care coordination, and referral information, including Protected Health Information (PHI) when applicable
- Financial, billing, reimbursement, payment, or donation information
- Immigration, legal, identification, or supporting documents that you provide for requested services
- Information about children or youth, parents, guardians, schools, or authorized representatives when relevant to a service
- Program participation, appointment, service, case, referral, outcome, and communication records
- Information submitted through forms, surveys, applications, email, text messages, telephone calls, or in-person interactions
- Employment, volunteer, contractor, board, or partnership information when you apply for or maintain one of those relationships
- Technical information associated with website use, such as internet protocol address, browser or device type, pages viewed, referring page, and date and time of access
How We Receive Information
We may receive information directly from you or from a parent, guardian, authorized representative, referring organization, health plan, healthcare provider, school, government agency, community partner, vendor, or other source involved in a requested service or organizational activity. We may also receive limited technical information automatically when you use our website or online services.
How We Use Information
Thrive may use personal information to:
- Provide services, coordinate care, and respond to requests for assistance
- Determine eligibility and support applications, enrollment, benefits, referrals, appointments, and follow-up
- Provide health insurance enrollment and benefits assistance
- Support behavioral health, community health, dental, legal, immigration, advocacy, and other community-based programs
- Communicate with you about services, appointments, deadlines, events, resources, and next steps
- Process billing, reimbursement, payments, donations, and related financial activities
- Maintain appropriate program, service, business, employment, volunteer, and operational records
- Conduct program evaluation, quality improvement, service planning, and outcome measurement
- Meet grant, contract, audit, accreditation, billing, reporting, and regulatory requirements
- Operate, maintain, secure, and improve our website, systems, communications, and services
- Prevent, detect, investigate, and respond to fraud, misuse, safety concerns, privacy incidents, and cybersecurity threats
- Comply with applicable laws and fulfill other purposes you authorize or that are permitted by law
Protected Health Information and HIPAA
Some information handled by Thrive may qualify as Protected Health Information under the Health Insurance Portability and Accountability Act (HIPAA) or may be subject to other health privacy requirements. HIPAA does not apply to every Thrive program or every type of information we maintain.
When HIPAA or another health privacy requirement applies, Thrive uses and discloses information only as authorized by the individual, permitted by applicable law, or allowed under an applicable agreement with a healthcare provider, health plan, or other covered organization. Additional notices, consent forms, authorizations, or partner privacy practices may apply to that information.
How We Share Information
Thrive does not sell or rent personal information. We may share information only when reasonably necessary and appropriate, including:
- At your direction or with your authorization
- With Thrive workforce members who have a legitimate need to access the information for their work
- With healthcare providers, health plans, schools, community partners, referral organizations, government agencies, or program administrators involved in providing or coordinating a requested service
- With contractors, technology vendors, payment processors, consultants, auditors, or other service providers that support Thrive and are subject to appropriate confidentiality, security, or Business Associate Agreement requirements
- For treatment, payment, healthcare operations, program administration, billing, reimbursement, evaluation, or reporting when permitted by law or an applicable agreement
- To comply with federal, state, or local law, a valid legal process, an audit, or a regulatory or oversight inquiry
- To prevent or address a serious threat to health or safety when disclosure is legally permitted
- To investigate and respond to suspected fraud, misuse, privacy violations, security incidents, or other threats to Thrive, the people we serve, or others
We seek to limit disclosures to the minimum information reasonably necessary for the purpose. When practical, program evaluation, grant reporting, and public reporting use aggregated or de-identified information.
Website Information, Cookies, and External Services
Our website and service providers may use cookies, server logs, or similar technologies to support essential website functions, accessibility, preferences, security, performance, and basic usage analysis. Your browser may allow you to block or delete cookies, although doing so may affect some website features.
Our website may link to websites, forms, portals, payment services, or resources operated by other organizations. Those services have their own privacy and security practices. Thrive is not responsible for the content or privacy practices of external websites that we do not operate.
Email, Text Messaging, and Other Electronic Communications
Thrive uses organization-approved systems and reasonable safeguards for electronic communication. Email, standard SMS or MMS text messaging, and other electronic methods may not always be encrypted during transmission. Please use care when sending medical, financial, immigration, identification, or other sensitive information. A Thrive staff member may ask you to use a more secure method for certain information or documents.
For information specifically related to text messaging, review our SMS Messaging Privacy Policy and SMS/Text Messaging Terms and Conditions.
How We Protect Information
Thrive maintains administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, loss, theft, or destruction. These safeguards include, as appropriate:
- Role-based or need-to-know access to confidential information
- Privacy, confidentiality, HIPAA, and cybersecurity training for workforce members
- Confidentiality requirements for employees, volunteers, contractors, and service providers
- Organization-approved systems, secure cloud services, password protections, and multi-factor authentication where applicable
- Anti-malware protections, system backups, security updates, patch management, and device safeguards
- Procedures for reporting, investigating, containing, documenting, and responding to privacy and security incidents
No organization or electronic system can guarantee complete security. Thrive reviews its safeguards and updates policies, procedures, training, and systems as technology, operations, legal requirements, and risks change.
Privacy and Security Incidents
Thrive investigates suspected loss, theft, unauthorized access, disclosure, or compromise of personal information. We take reasonable steps to contain the incident, assess its scope and impact, restore secure operations, and implement corrective actions. When notification is required by law, contract, HIPAA, grant requirements, or another applicable obligation, Thrive will notify affected individuals, partners, regulators, insurers, law enforcement, or other parties within the required timeframe.
Retention and Disposal
Thrive retains information only as long as reasonably necessary for operational, program, contractual, grant, legal, regulatory, audit, billing, healthcare, employment, or funding requirements. Retention periods vary based on the type of record and applicable obligations. When records are no longer required, Thrive uses appropriate methods to securely delete, destroy, or otherwise dispose of confidential information.
Your Privacy Choices and Rights
Depending on the information involved, the program, and applicable law, you may ask Thrive to:
- Provide access to personal information maintained about you
- Correct or amend information that you believe is inaccurate or incomplete
- Provide information in an available electronic format or transfer it to an authorized organization when applicable
- Delete information when deletion is permitted by law and consistent with applicable retention requirements
- Restrict certain uses or disclosures when a right to request a restriction applies
- Explain how information is used, disclosed, and protected
- Update your contact information or communication preferences
- Review or withdraw an authorization when permitted, subject to actions already taken in reliance on that authorization
- Submit a privacy complaint or concern without fear of retaliation
Thrive may need to verify your identity and authority before completing a request. We generally acknowledge privacy requests or complaints within five business days and make reasonable efforts to respond or complete the request within 30 calendar days. More complex matters or requirements imposed by another organization or law may take additional time.
A request may be denied or limited when information must be retained or disclosed for legal, regulatory, contractual, grant, audit, billing, healthcare, safety, employment, or operational reasons. When appropriate, Thrive will explain the outcome of the request.
Children and Youth
Some Thrive programs serve children and youth. We may collect and use information about a minor when necessary to provide a requested service, coordinate with a parent, guardian, school, provider, or other authorized person, or meet program and legal requirements. Consent, authorization, access, and communication practices may vary based on the individual’s age, the service involved, and applicable law.
Privacy Complaints and Non-Retaliation
You may raise a concern about confidentiality, unauthorized disclosure, data security, access or correction, staff conduct involving confidential information, or another perceived privacy violation. Thrive prohibits retaliation against anyone who requests access, exercises a privacy right, reports a concern, files a complaint, or participates in an investigation.
Contact Us or Submit a Privacy Request
Privacy requests and complaints may be submitted by email, telephone, written correspondence, in person, through a website contact form, or through a Thrive staff member or partner organization. Please provide enough information for us to understand your request and contact you. Do not send highly sensitive information in an initial unencrypted email.
| Privacy Officer Thrive Community Health Network Legal entity: Tri-County Health Network 238 East Colorado Avenue, Suite 8, Telluride, CO 81435 Phone: 970-708-7096 Email: info@tchnetwork.org Website: tchnetwork.org |
Changes to This Policy
We may update this policy to reflect changes in our services, technology, legal obligations, or privacy practices. Revised policies become effective when posted publicly. The effective date at the beginning of this document identifies the most recent version.