1. Purpose of This Privacy Policy
This Privacy Policy outlines how Lighthouse Legacy Group, LLC (“Company,” “we,” “us,” or “our”) collects, uses, stores, protects, and discloses personal information obtained through our senior placement and transitional support services. This policy is designed to comply with applicable laws and best practices, including those outlined by the State of Oregon Department of Human Services for referral agents.
We are committed to transparency, client dignity, and safeguarding sensitive information. This policy applies to all individuals receiving services from us, including clients, legal representatives, and family members acting on behalf of clients.
2. Scope
This policy applies to:
- Clients seeking placement or transition services
- Family members or representatives providing information
- Care settings, providers, or facilities we interact with on the client’s behalf
- Employees, contractors, and agents of Lighthouse Legacy Group
3. What Information We Collect
We may collect the following categories of information:
A. Personal Identifying Information (PII):
- Full name, address, phone number, email
- Date of birth, Social Security number (if applicable)
- Emergency contacts and legal representatives
B. Health-Related Information:
- Medical diagnoses, cognitive status, physical limitations
- Medication lists, treatment plans, allergies
- Physician contact information
- Advance directives or guardianship documentation
C. Financial Information:
- Income sources (Social Security, pensions, investments)
- Long-term care insurance, VA benefits, Medicaid status
- Monthly care budget and asset disclosure (as provided)
D. Service Usage and Communications:
- Referral history, facility communications
- Email or phone correspondence
- Website interactions (if applicable)
4. How We Collect Information
We collect personal information through the following methods:
- Directly from the client or their authorized representative
- Through assessments, intake forms, and advisory/disclosure forms
- Through secure client portals, phone interviews, and in-person visits
- With client consent, from healthcare providers, attorneys, or financial advisors
We always explain why we need personal information and obtain written consent before collecting or using sensitive data.
5. Use of Personal Information
We use your information solely for the following purposes:
- To assess placement suitability based on care needs and financial capacity
- To communicate with you, your family, and authorized representatives
- To provide referrals to licensed care homes and facilities
- To coordinate and document care transitions
- To comply with legal and licensing obligations
We do not use personal information for profiling, unsolicited marketing, or resale.
6. Disclosure of Information
We only disclose personal information under the following conditions:
- With Written Consent: We will provide you with a clear, written Disclosure and Advisory Form describing how your information will be used. No referrals are made without your affirmative signature.
- To Placement Settings: Personal information is shared only with care settings you are actively being referred to.
- To Legal Entities When Required: We may disclose information as required by law, such as in response to court orders or lawful investigations.
- To Third-Party Service Providers: Contractors and vendors (e.g., encrypted cloud software, compliance consultants) may access data strictly under signed confidentiality agreements.
We never sell or share your personal data with unrelated third parties.
7. Data Security Measures
Lighthouse Legacy Group, LLC is committed to implementing reasonable administrative, technical, and physical safeguards appropriate to the nature of the personal information we maintain, our business size, and the reasonably foreseeable risks to client privacy. While no system can guarantee absolute security, we take commercially reasonable steps to protect personal information against unauthorized access, disclosure, alteration, or destruction.
A. Access Controls
- Access to client information is restricted to authorized personnel with a legitimate business need.
- User accounts, passwords, and credentials are maintained with appropriate complexity requirements.
- Devices used for business purposes are configured, where feasible, to require passcodes, biometric authentication, or other locking mechanisms.
B. Secure Communications
- Sensitive client information is transmitted through secure channels whenever practical and appropriate.
- When transmitting confidential documents electronically, encryption or secure file transfer methods may be used where reasonably feasible.
- Email communications are reviewed and managed to limit unnecessary data retention.
C. Electronic Data Storage
- Client records are stored in secure, password-protected or encrypted electronic environments.
- Cloud-based storage providers or software platforms, when utilized, are selected based on their commitment to recognized security standards.
- Routine data backups are performed to minimize the risk of data loss.
D. Physical Security
- Paper files containing sensitive client information, if maintained, are stored in locked file cabinets or secure office areas with controlled access.
- Documents containing personal information are disposed of using appropriate shredding or secure destruction methods when retention is no longer required.
E. Staff Practices and Awareness
- Personnel are advised of privacy and confidentiality obligations as part of their duties.
- Internal guidelines exist to limit the sharing of confidential information through unsecured devices, public Wi-Fi networks, or unapproved personal systems.
- All employees are expected to exercise reasonable care in handling and protecting client information consistent with these policies.
F. Ongoing Review
- As the company grows or technology evolves, data security practices may be reviewed and updated periodically to maintain commercially reasonable safeguards appropriate to the company’s operations and legal obligations.
8. Data Retention and Destruction
- Signed Disclosure and Advisory Forms are retained for three (3) years from the date of last contact.
- Client intake information is retained only as long as necessary to complete placement services or comply with state audits.
- After the retention period, records are securely destroyed via shredding (for paper records) or digital wiping software (for electronic data).
9. Accuracy and Accountability
We make reasonable efforts to ensure personal information is accurate, complete, and up-to-date. Clients may review, correct, or update their records at any time by contacting us.
You may also request a list of any facilities or individuals your information has been shared with.
10. Your Rights
As a client or authorized representative, you have the right to:
- Access your personal data
- Request corrections
- Withdraw consent for sharing information
- File a complaint about potential misuse of your data
- Request deletion, where permitted by law
To exercise any of these rights, contact us at the address below.
11. Breach Notification Protocol
In the event of a suspected or confirmed data breach:
- We will investigate immediately upon discovery.
- Affected clients will be notified within 10 business days if personal information was compromised.
- Notifications will include the nature of the breach, what data was involved, and steps being taken to mitigate harm.
- Regulatory bodies (e.g., Oregon DHS) will be notified where applicable.
12. Policy Updates
This policy may be updated periodically to reflect changes in laws, technology, or business practices. We will provide notice of changes and request updated consent when material updates occur.
13. Contact Information
To ask questions, exercise your privacy rights, or file a complaint, please contact:
Lighthouse Legacy Group, LLC17085 Chapin Way Lake Oswego, Oregon 97034
Phone: 503.807.6198
Email: hello@thelighthouselegacygroup.com
Website: www.thelighthouselegacygroup.com
