Notice of Privacy Practices & Privacy Policy
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THAT INFORMATION. PLEASE REVIEW IT CAREFULLY.
In accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the federal Privacy Rule (45 CFR parts 160 and 164), and applicable state law, the Practice is committed to maintaining the privacy of your Protected Health Information (PHI).
PHI includes information about your past, present, or future health condition, as well as the care and treatment you receive from the Practice (often referred to as your healthcare or medical record). This Notice explains how your PHI may be used and disclosed to third parties, as well as your legal rights regarding your PHI.
What is Protected Health Information (PHI)?
We collect PHI from you through treatment, payment, healthcare operations, enrollment processes, or from other healthcare providers and health plans.
PHI specifically includes information that contains 18 legal identifiers defined by HIPAA (such as your name, address, Social Security Number, date of birth, phone number, etc.) that could be used to identify you.
How We May Use and Disclose Your PHI
Generally, we may not use or disclose your PHI without your written permission. Once permission is obtained, we must adhere strictly to its terms.
1. Uses & Disclosures Requiring Explicit Authorization
Psychotherapy Notes: Most uses and disclosures require your specific authorization.
Sale of PHI: Any disclosure that constitutes a sale of PHI requires prior authorization.
Marketing Purposes: Requires written authorization, except when the communication:
Occurs face-to-face.
Involves marketing gifts of nominal value.
Is a prescription refill reminder for a currently prescribed drug (where no financial remuneration is received).
Recommends alternative treatments or providers without the Practice receiving financial remuneration.
2. Standard Permitted Uses (No Prior Authorization Needed)
The Practice is permitted by law to use and disclose your PHI for the following core operational purposes:
Treatment
To provide, coordinate, or manage your healthcare.
Examples: Consultations between healthcare providers, referrals to specialists, or care management by our clinical staff.
Payment
To bill and collect payment from you, your insurance company, or third parties.
Examples: Submitting claims to Medicare or health insurance providers, determining coverage eligibility, or utilization reviews.
Healthcare Operations
To support our business activities and maintain high-quality care.
Examples: Quality assessment, clinical guideline development, training staff, auditing functions, legal services, and customer service.
3. Other Permitted or Required Uses & Disclosures
We may also use or disclose your PHI without your consent under the following circumstances:
De-Identified Information: We may use or share health data stripped of all 18 personal identifiers.
Business Associates: We may share PHI with trusted third parties (e.g., billing vendors) who sign agreements promising to safeguard your data.
Family, Friends, or Personal Representatives: We may share relevant PHI with individuals involved in your care or payment for care if you agree, or if professional judgment dictates it is in your best interest during an emergency.
Emergency Situations & Disaster Relief: To obtain emergency treatment or assist disaster relief organizations.
Public Health Activities: To prevent/control disease, report adverse product events to the FDA, or report workplace health surveillance.
Abuse, Neglect, or Domestic Violence: To report suspected abuse to social service or protective agencies as required by law.
Health Oversight Activities: For audits, investigations, licensure, and government oversight.
Judicial & Administrative Proceedings: In response to court orders, warrants, or subpoenas.
Law Enforcement: To identify/locate suspects or missing persons, report crimes, or comply with grand jury subpoenas.
Coroners, Medical Examiners, & Funeral Directors: To identify a deceased individual, determine cause of death, or assist funeral arrangements.
Organ Donation: To organ procurement organizations.
Research: Under strict legal research guidelines and approvals.
Threat to Health or Safety: To prevent or lessen a serious, imminent threat to public or individual safety.
Workers’ Compensation: To comply with laws regarding work-related injuries or illnesses.
Specialized Government Functions: For national security, intelligence, presidential protective services, or military command purposes.
Inmates: To correctional facilities for healthcare delivery, safety, and security.
Text Messaging (SMS) & Mobile Privacy Practices
Mobile Data Protection Notice
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Data Collection & Consent: We collect your mobile phone number when you voluntarily provide it (e.g., via web forms or check-box options). Opting in allows us to send automated operational texts, appointment reminders, and clinical updates.
Strict Privacy Baseline: Text messaging originator opt-in data, mobile numbers, and text consent details are strictly confidential. They will not be sold, rented, leased, or shared with third-party vendors or affiliates for promotional purposes.
Rates & Frequency: Message and data rates may apply depending on your mobile carrier plan. Message frequency varies based on your appointments and interactions with us.
Opt-Out & Support:
Reply STOP to any text message to cancel your SMS enrollment at any time. You will receive a final confirmation text.
Reply HELP or contact our Privacy Office directly for assistance.
Your Rights Regarding Your PHI
Under HIPAA, you hold the following rights regarding your medical records:
RightDescriptionRevoke AuthorizationYou may revoke any written consent/authorization at any time by submitting a written request to our Privacy Officer.Request RestrictionsYou may request restrictions on how we use/disclose your PHI for treatment, payment, or operations. (Note: The Practice is not legally required to agree to all restriction requests).Self-Pay RestrictionYou have the right to restrict disclosures to a health plan if you pay for a service out-of-pocket in full at the time of service.Confidential CommunicationsYou can request to receive communications via alternative means or at an alternative address (e.g., specific mailing addresses or confidential phone lines).Inspect and CopyYou have the right to inspect and receive a physical or electronic copy of your PHI. A reasonable, cost-based fee for copying/postage may apply under state law.Amend Your PHIYou may request an amendment to your records if you believe the information is inaccurate or incomplete. Requests must be in writing and include a supporting reason.Accounting of DisclosuresYou can request a list of disclosures of your PHI made in the last 6 years (excluding routine treatment, payment, operations, or disclosures authorized by you). The first request within 12 months is free.Paper CopyYou have the right to receive a paper copy of this Privacy Notice at any time upon request.
Practice Responsibilities
We are required by law to maintain the privacy of your PHI and provide you with this Notice.
We must abide by the terms of this Notice currently in effect.
We reserve the right to change our privacy practices and update this Notice. Any revised terms will apply to all PHI we maintain.
Revised notices will be made available on our website and upon request prior to implementation.
We will not retaliate against you for filing a complaint.
Questions and Complaints
If you believe your privacy rights have been violated, or if you have questions regarding this Notice, please contact our Privacy Officer.
Filing a Complaint: You may file a written complaint with our Practice's Privacy Officer or directly with the Secretary of the U.S. Department of Health and Human Services (DHHS).
Timeframe: Complaints must be submitted within 180 days of when you knew (or should have known) the act or omission occurred.
Breach Notification: As required by law, we will notify you in the event of any unauthorized access, acquisition, use, or disclosure (breach) of your unencrypted PH