Gray Matters Alliance, LLC — Notice of Privacy Practices
Effective Date: July 7, 2026 · Version 2.0 · Last Updated: July 19, 2026
This notice describes how medical information about you may be used and disclosed and how you can get access to this information. Please review it carefully.
Who This Notice Covers
This Notice of Privacy Practices (“Notice”) describes how Gray Matters Alliance, LLC (“GMA,” “we,” “us,” or “our”) may use and disclose your protected health information (“PHI”) and how you can access that information. “PHI” is information about you, including demographic information, that may identify you and that relates to your past, present, or future physical or mental health or condition, the provision of services to you, or payment for those services.
This Notice applies to GMA and its entire workforce and covers PHI created or received in connection with the services and technology GMA provides, including the MyCompass App, the Compass Care Calling App, the Compass Care Alerts App, the MyCompass Web Portal, the Compass Care Command Center, Nora Caregiver Intelligence, and the connected components of the MyCompass System (collectively, the “Services”). GMA is a Covered Entity under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended by the HITECH Act (together, “HIPAA”).
If you receive services through another provider organization. This Notice describes GMA’s practices for individuals GMA serves directly as a Covered Entity. Some individuals use the MyCompass System because another provider agency or organization delivers their services using GMA’s technology, including the Compass Care Command Center. For those individuals, that organization is the covered entity responsible for their PHI and its own Notice of Privacy Practices applies; GMA handles their PHI as that organization’s Business Associate under a Business Associate Agreement, and requests to exercise HIPAA rights should be directed to that organization. GMA will promptly forward to the responsible organization any such request it receives.
This Notice works together with GMA’s Mobile App & Platform Privacy Policy. Where that Privacy Policy and this Notice address the same subject, this Notice governs GMA’s formal HIPAA obligations.
Our Legal Duties
GMA is required by law to:
- Maintain the privacy and security of your PHI;
- Provide you with this Notice of our legal duties and privacy practices with respect to your PHI;
- Follow the terms of the Notice that is currently in effect;
- Notify you following a breach of unsecured PHI, as required by law; and
- Obtain your written authorization for uses and disclosures not described in this Notice, and honor your right to revoke that authorization.
We will not use or disclose your PHI without your written authorization except as described in this Notice or as otherwise permitted or required by law.
How We May Use and Disclose Your PHI Without Your Authorization
The following categories describe the ways we may use and disclose your PHI. For each category we explain what we mean and give an example. Not every use or disclosure in a category is listed, but all permitted uses and disclosures fall within one of these categories.
For Treatment. We may use and disclose your PHI to provide, coordinate, and manage your remote support services and care. We may share PHI with the members of your support team, including guardians, clinicians, care coordinators, and authorized caregivers, so they can carry out your support plan.
Example: We may disclose your goals, schedule, or a safety alert (such as a fall or elopement notification) to an authorized caregiver so they can respond to your needs.
For Payment. We may use and disclose your PHI to obtain payment for the services we provide. This includes verifying your eligibility and benefits, obtaining prior authorizations, documenting the medical necessity of services, submitting and adjudicating claims, coordinating benefits among payers, and responding to audits or recoupment reviews. We may disclose PHI to government and commercial payers, including Medicaid, TRICARE, and other government health programs, their contractors and administrators, and to clearinghouses and billing vendors that act as our Business Associates.
Example: We may send a claim containing your diagnosis, the services delivered, and supporting documentation to Medicaid, a Medicaid managed-care organization, or Humana Government Business (for TRICARE) so that we can be paid for your services.
For Health Care Operations. We may use and disclose your PHI to run our organization and make sure you receive quality services. This includes quality assessment and improvement, training and evaluating our workforce, care coordination, compliance and audit activities, and general administration.
Example: We may review service records to evaluate how well our alerting features perform and to improve the safety and accessibility of the MyCompass System.
To Business Associates. We may disclose PHI to third parties that perform functions on our behalf, such as cloud hosting, communication and notification services, mobile device management, AI infrastructure (AWS Bedrock, which supports Nora Caregiver Intelligence), billing and revenue-cycle services, and clearinghouses. Each Business Associate is bound by a written agreement requiring it to protect your PHI and to use it only for the services it performs for us.
To Persons Involved in Your Care. Unless you object, we may share PHI with a family member, guardian, personal representative, or other person you identify who is involved in your care or payment for your care, to the extent relevant to that involvement. We may also share PHI to notify such a person of your location or general condition in an emergency.
Reminders and Care-Related Communications. We may contact you or your representative with service reminders, schedule prompts, wellness check-ins, or information about treatment alternatives or other health-related benefits and services that may be of interest to you. These communications are part of your care and are not marketing.
Other Uses and Disclosures Permitted or Required by Law
We may use or disclose your PHI without your authorization in the following circumstances, subject to the conditions and limitations the law requires:
- As Required by Law: when federal, state, or local law requires the use or disclosure.
- Public Health Activities: to public-health authorities for activities such as preventing disease, reporting reactions to medications, or reporting certain events.
- Victims of Abuse, Neglect, or Exploitation: to appropriate government authorities, including adult protective services, if we reasonably believe a person is a victim of abuse, neglect, or exploitation, consistent with mandatory-reporting laws that protect vulnerable adults and children.
- Health Oversight Activities: to oversight agencies for audits, investigations, licensure, and other activities authorized by law, including Medicaid and other program-integrity reviews.
- Judicial and Administrative Proceedings: in response to a court or administrative order, or a subpoena or discovery request where the required assurances are provided.
- Law Enforcement: for limited law-enforcement purposes permitted by law, such as helping to locate a missing vulnerable adult or responding to valid legal process.
- Coroners, Medical Examiners, and Funeral Directors: as necessary for them to carry out their duties.
- To Avert a Serious Threat to Health or Safety: to prevent or lessen a serious and imminent threat to the health or safety of a person or the public.
- Specialized Government Functions: for military and veterans’ activities (for example, as required by appropriate military command authorities for Armed Forces personnel and TRICARE beneficiaries), national security and intelligence, and protective services.
- Workers’ Compensation: as authorized by and to the extent necessary to comply with workers’-compensation laws.
- Research: for research that has been approved through a process that protects your privacy, or with your authorization.
- Others Permitted by Law: and other uses and disclosures permitted by 45 CFR Section 164.512 under the conditions that section requires.
Uses and Disclosures That Require Your Written Authorization
The following uses and disclosures will be made only with your written authorization:
- Psychotherapy notes, where we maintain them;
- Marketing, as defined by HIPAA; and
- Any sale of PHI.
Most other uses and disclosures not described in this Notice will also be made only with your written authorization. If you give us authorization, you may revoke it at any time, in writing, and we will stop the uses and disclosures it covers going forward. Revocation will not apply to uses or disclosures we already made in reliance on your authorization, and it will not apply where we are legally required to continue.
GMA does not sell your PHI and does not use your PHI for marketing, advertising, fundraising, or profiling. We do not use your information to train artificial-intelligence models.
Your Rights Regarding Your PHI
You have the following rights with respect to your PHI. To exercise any of these rights, contact our Privacy Officer using the information at the end of this Notice.
Right to Request Restrictions. You have the right to request that we restrict how we use or disclose your PHI for treatment, payment, or health care operations, or to persons involved in your care. We are not required to agree to every requested restriction, but if we do agree, we will honor it unless the information is needed to provide you emergency treatment or the law requires the disclosure.
Mandatory restriction (self-pay). We must agree to your request to restrict disclosure of PHI to a health plan if the disclosure is for payment or health care operations and the item or service involved has been paid for in full, out of pocket, by you or on your behalf, unless the disclosure is otherwise required by law.
Right to Confidential Communications. You have the right to ask that we communicate with you about your PHI by alternative means or at an alternative location, for example, by a particular phone number, email, or address. We will accommodate reasonable requests.
Right to Inspect and Copy. You have the right to inspect and obtain a copy of the PHI we maintain about you in a designated record set, including the right to receive a copy in a readable electronic format where we maintain it electronically, and to direct us to send a copy to a third party you designate in writing. We will respond within the time HIPAA requires (generally 30 days, with one 30-day extension where permitted). We may charge a reasonable, cost-based fee as allowed by law. In limited circumstances we may deny a request, and where the law provides, you may have the denial reviewed.
Right to Amend. If you believe PHI we maintain about you is incorrect or incomplete, you have the right to request that we amend it. We will respond within the time HIPAA requires (generally 60 days, with one 30-day extension where permitted). We may deny your request in certain cases; if we do, we will explain why in writing and you may submit a statement of disagreement.
Right to an Accounting of Disclosures. You have the right to request an accounting of certain disclosures of your PHI that we made. The accounting does not include disclosures for treatment, payment, or health care operations; disclosures made to you or with your authorization; and certain other disclosures excluded by law.
Right to a Paper Copy of This Notice. You have the right to a paper copy of this Notice at any time, even if you have agreed to receive it electronically. You may request a copy from our Privacy Officer.
Right to Be Notified of a Breach. You have the right to be notified if we (or one of our Business Associates) discover a breach of your unsecured PHI, as required by law.
Right to Choose Someone to Act for You. If you have a legal guardian, hold a valid power of attorney for health care, or have another personal representative authorized under law, that person may exercise your rights and make choices about your PHI, within the scope of their authority. We will require documentation of that authority, and we will honor court-ordered or statutory limits on a representative’s access.
Accessibility and Language Assistance
Consistent with Section 1557 of the Affordable Care Act, the Americans with Disabilities Act, and Section 504 of the Rehabilitation Act, we provide this Notice and related materials, on request and at no cost, in plain language, in accessible formats (such as large print or screen-reader-compatible electronic formats), and with language-assistance services for individuals with limited English proficiency.
Special Protections and More-Protective Laws
Some categories of information receive additional protection under federal or state law. Where a law that applies to your information is more protective than HIPAA, we follow the more protective law. For example, and where applicable, we follow the additional protections that apply to substance-use-disorder treatment records under 42 CFR Part 2, to genetic information under the Genetic Information Nondiscrimination Act (GINA), and to any records governed by the Family Educational Rights and Privacy Act (FERPA). We treat information that reveals disability or health status with heightened protection and do not use it to unlawfully discriminate against you.
Changes to This Notice
We reserve the right to change this Notice and to make the revised Notice effective for PHI we already maintain as well as any PHI we receive in the future. When we make a material change, we will post the revised Notice, make it available on request, and publish it at our practice locations and on our website. Each Notice will show its effective date.
Complaints
If you believe your privacy rights have been violated, you may file a complaint with GMA’s Privacy Officer or with the Secretary of the U.S. Department of Health and Human Services, Office for Civil Rights (OCR). To file with GMA, contact the Privacy Officer below. To file with OCR, visit hhs.gov/hipaa/filing-a-complaint or call 1-800-368-1019. We will not retaliate against you for filing a complaint.
Contact, Privacy Officer
For questions about this Notice, to exercise any of your rights, or to file a complaint, contact:
Kyle Dortch
Chief Administrative Officer & HIPAA Privacy Officer
Gray Matters Alliance, LLC
Email: privacy@graymattersalliance.com
Phone: 314-266-2678
Mailing Address: 119 S Main Street, St. Charles, MO 63301, United States
Acknowledgment of Receipt of Notice of Privacy Practices
By signing below, I acknowledge that I have received a copy of Gray Matters Alliance, LLC’s Notice of Privacy Practices. I understand that GMA may change its privacy practices and that a current copy of the Notice is available on request and at GMA’s website.
End User (client) name: ______________________________
Signature of End User (if able to sign): ______________________________ Date: ____________
If signed by a Legally Authorized Representative (guardian, parent, power of attorney, or other authorized representative):
Signature of Legally Authorized Representative: ______________________________ Date: ____________
Printed name of representative: ______________________________ Relationship / basis of authority: ______________________
For GMA use only, if written acknowledgment was not obtained: If we were unable to obtain a written acknowledgment, describe the good-faith effort made and the reason it was not obtained: ______________________________ Staff member / description of good-faith effort: ______________________ Date: __________