Your privacy matters to us. This policy describes how we collect, use, and protect your personal and health information in accordance with HIPAA regulations.
Orovia Medical ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal and health information. This Privacy Policy, including our Notice of Privacy Practices under the Health Insurance Portability and Accountability Act (HIPAA), describes how we collect, use, and safeguard information about you.
As a healthcare provider, we understand that your medical information is personal and sensitive. We are dedicated to maintaining the confidentiality of your Protected Health Information (PHI) and complying with all applicable federal and state privacy laws, including:
By using our website and services, you consent to the collection and use of information in accordance with this policy. If you have questions about this policy, please contact our Privacy Officer.
We collect information you provide directly to us, including:
As a healthcare provider, we collect and maintain PHI, which includes:
Diagnoses, treatments, test results, and clinical notes
Prescriptions, allergies, and medication history
Appointment records and billing information
When you visit our website, we automatically collect certain technical information:
Browser type, operating system, device identifiers
Pages visited, time spent, referral sources
General location and network information
Session data and preference storage
Under HIPAA, we may use and disclose your PHI for the following purposes without your explicit authorization:
Providing, coordinating, and managing your healthcare and related services
Billing, collection, and insurance claims processing
Quality assessment, staff training, compliance, and audits
When required by federal, state, or local law
Reporting diseases, vital records, or safety concerns
To appropriate authorities when required
In response to court orders or subpoenas
When necessary to prevent harm
With proper authorization or IRB approval
Your written authorization is required for any use or disclosure of your PHI that is not listed above, including:
You may revoke your authorization at any time by contacting our Privacy Officer in writing.
As a patient, you have the following rights regarding your Protected Health Information:
You have the right to request access to your medical records and PHI. We will provide access within 30 days of your written request.
If you believe your PHI is incomplete or inaccurate, you may request an amendment. We will respond within 60 days.
You may request a list of disclosures we have made of your PHI for purposes other than treatment, payment, or healthcare operations.
You may request restrictions on certain uses and disclosures of your PHI. We will consider all reasonable requests.
You may request that we contact you by alternative means or at an alternative location. We will accommodate reasonable requests.
You have the right to receive a paper copy of this Notice of Privacy Practices at any time, even if you have agreed to receive it electronically.
To exercise any of these rights, please submit a written request to our Privacy Officer. Your request should:
We take the security of your personal and health information seriously. We implement comprehensive administrative, physical, and technical safeguards to protect your information.
In the event of a breach of your unsecured PHI, we will notify you in accordance with HIPAA requirements:
Within 60 days of discovery for breaches affecting 500+ individuals
Breaches affecting fewer than 500 individuals reported annually
All breaches reported to HHS as required by law
We may share your information with trusted third parties and business associates who help us operate our practice, subject to strict confidentiality requirements.
We may share PHI with business associates who perform services on our behalf, including:
External labs for diagnostic testing
Radiology and imaging facilities
Prescription fulfillment services
Claims processing and billing services
Electronic health record and IT support
Other healthcare providers in your care
All business associates are required to sign Business Associate Agreements (BAAs) and maintain the same level of privacy and security protections as required under HIPAA.
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child under 18, please contact us immediately.
We reserve the right to update or modify this Privacy Policy at any time. We will notify you of material changes by:
Last Revised: [Insert Date]
Effective Date: [Insert Date]
| Version | Date | Description |
|---|---|---|
| 1.0 | [Insert Date] | Initial Privacy Policy |
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Primary Contact for Privacy Matters
For Privacy-Related Inquiries
File a complaint if you believe your privacy rights have been violated
www.hhs.gov/hipaaOur team is here to help. Contact our Privacy Officer for any questions, concerns, or to exercise your patient rights.
Your privacy is protected. All inquiries are handled with strict confidentiality.