THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.
Each time that you visit a hospital, a physician, or another health care provider, the provider makes a record of your visit. Typically, this record contains your health history, current symptoms, examination and test results, diagnoses, treatment, and plan for future care or treatment. This information, often referred to as your medical record, serves as the following:
Understanding what is in your health record and how your health information is used helps you to—
Although your health records are the physical property of the health care provider who completed the records, you have the following rights with regard to the information contained therein:
Request restriction on uses and disclosures of your health information for treatment, payment, and health care operations. “Health care operations” consist of activities that are necessary to carry out the operations of the provider, such as quality assurance and peer review. The right to request restriction does not extend to uses or disclosures permitted or required under the following sections of the federal privacy regulations: § 164.502(a)(2)(i) (disclosures to you), § 164.510(a) (for facility directories, but note that you have the right to object to such uses), or § 164.512 (uses and disclosures not requiring a consent or an authorization). The latter uses and disclosures include, for example, those required by law, such as mandatory communicable disease reporting. In those cases, you do not have a right to request restriction. The consent to use and disclose your individually identifiable health information provides the ability to request restriction. We do not, however, have to agree to the restriction, except in the situation explained below. If we do, we will adhere to it unless you request otherwise or we give you advance notice. You may also ask us to communicate with you by alternate means, and if the method of communication is reasonable, we must grant the alternate communication request. You may request restriction or alternate communications on the consent form for treatment, payment, and health care operations. If, however, you request restriction on a disclosure to a health plan for purposes of payment or health care operations (not for treatment), we must grant the request if the health information pertains solely to an item or a service for which we have been paid in full.
Obtain a copy of this notice of information practices. Although we have posted a copy in prominent locations throughout the facility and on our website, you have a right to a hard copy upon request.
Inspect and copy your health information upon request. Again, this right is not absolute. In certain situations, such as if access would cause harm, we can deny access. You do not have a right of access to the following:
In other situations, we may deny you access, but if we do, we must provide you a review of our decision denying access. These “reviewable” grounds for denial include the following:
For these reviewable grounds, another licensed professional must review the decision of the provider denying access within 60 days. If we deny you access, we will explain why and what your rights are, including how to seek review. If we grant access, we will tell you what, if anything, you have to do to get access. We reserve the right to charge a reasonable, cost-based fee for making copies.
Request amendment/correction of your health information. We do not have to grant the request if the following conditions exist:
If we deny your request for amendment/correction, we will notify you why, how you can attach a statement of disagreement to your records (which we may rebut), and how you can complain. If we grant the request, we will make the correction and distribute the correction to those who need it and those whom you identify to us that you want to receive the corrected information.
Obtain an accounting of nonroutine uses and disclosures, those other than for treatment, payment, and health care operations until a date that the federal Department of Health and Human Services will set after January 1, 2011. After that date, we will have to provide an accounting to you upon request for uses and disclosures for treatment, payment, and health care operations under certain circumstances, primarily if we maintain an electronic health record. We do not need to provide an accounting for the following disclosures:
We must provide the accounting within 60 days. The accounting must include the following information:
The first accounting in any 12-month period is free. Thereafter, we reserve the right to charge a reasonable, cost-based fee.
Revoke your consent or authorization to use or disclose health information except to the extent that we have taken action in reliance on the consent or authorization.
In addition to providing you your rights, as detailed above, the federal privacy standard requires us to take the following measures:
We will not use or disclose your health information without your consent or authorization, except as described in this notice or otherwise required by law. These include most uses or disclosures of psychotherapy notes, marketing communications, and sales of PHI. Other uses and disclosures not described in this notice will be made only with your written authorization.
Business associates.
We provide some services through contracts with business associates. Examples include certain diagnostic tests, a copy service to make copies of medical records, and the like. When we use these services, we may disclose your health information to the business associates so that they can perform the function(s) that we have contracted with them to do and bill you or your third-party payer for services provided. To protect your health information, however, we require the business associates to appropriately safeguard your information. After February 17, 2010, business associates must comply with the same federal security and privacy rules as we do.
Directory.
Unless you notify us that you object, we may use your name, location in the facility, general condition, and religious affiliation for directory purposes. This information may be provided to members of the clergy and, except for religious affiliation, to other people who ask for you by name.
Notification.
We may use or disclose information to notify or assist in notifying a family member, a personal representative, or another person responsible for your care, location, and general condition.
Communication with family.
Unless you object, we, as health professionals, using our best judgment, may disclose to a family member, another relative, a close personal friend, or any other person that you identify health information relevant to that person’s involvement in your care or payment related to your care.
Research.
We may disclose information to researchers when their research has been approved by an institutional review board that has reviewed the research proposal and established protocols to ensure the privacy of your health information.
Funeral directors.
We may disclose health information to funeral directors consistent with applicable law to enable them to carry out their duties.
Marketing/continuity of care.
We may contact you to provide appointment reminders or information about treatment alternatives or other health-related benefits and services that may be of interest to you. If we contact you to provide marketing information for other products or services, you have the right to opt out of receiving such communications. Contact Aces Physical Therapy at 508-967-7938. If we receive compensation from another entity for the marketing, we must obtain your signed authorization.
Fundraising.
We may contact you as a part of a fundraising effort. You have the right to request not to receive subsequent fundraising materials. Contact Aces Physical Therapy at 508-967-7938.
Food and Drug Administration (“FDA”).
We may disclose to the FDA health information relative to adverse effects/events with respect to food, drugs, supplements, product or product defects, or postmarketing surveillance information to enable product recalls, repairs, or replacement.
Workers compensation.
We may disclose health information to the extent authorized by and to the extent necessary to comply with laws relating to workers compensation or other similar programs established by law.
Public health.
As required by law, we may disclose your health information to public health or legal authorities charged with preventing or controlling disease, injury, or disability.
Correctional institution.
If you are an inmate of a correctional institution, we may disclose to the institution or agents thereof health information necessary for your health and the health and safety of other individuals.
Law enforcement.
We may disclose health information for law enforcement purposes as required by law or in response to a valid subpoena.
Health oversight agencies and public health authorities.
If members of our work force or business associates believe in good faith that we have engaged in unlawful conduct or otherwise violated professional or clinical standards and are potentially endangering one or more patients, workers, or the public, they may disclose your health information to health oversight agencies and/or public health authorities, such as the Department of health.
The federal Department of Health and Human Services (“DHHS”).
Under the privacy standards, we must disclose your health information to DHHS as necessary to determine our compliance with those standards.
WE RESERVE THE RIGHT TO CHANGE OUR PRACTICES AND TO MAKE THE NEW PROVISIONS EFFECTIVE FOR ALL INDIVIDUALLY IDENTIFIABLE HEALTH INFORMATION THAT WE MAINTAIN. IF WE CHANGE OUR INFORMATION PRACTICES, WE WILL MAIL A REVISED NOTICE TO THE ADDRESS THAT YOU HAVE GIVEN US.
Note: The above form is only a guide to get covered entities started with developing a notice of privacy practices. It may need editing/additions/deletions. As with any sample of this nature, qualified legal counsel should review and approve the final version. Some entities like to put the effective date of the policy or notice in a footer on every page so that people will know whether they have the latest version.
HIPAA Documents Resource Center CD, 6th ed.
© 2001-2014 Jonathan P. Tomes, Veterans Press, Inc., and EMR Legal, Inc. All rights reserved.