HIPAA Notice of Privacy Practices

How medical information about you may be used and disclosed.

THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY.

Effective Date: January 1, 2026

1. How PHI is Used

  • For Treatment: We use Protected Health Information (PHI) to provide, coordinate, and manage speech therapy services and consultations with other trusted providers.
  • For Payment: We share PHI with insurance companies to accurately obtain payment for services rendered.
  • Healthcare Operations: We use PHI securely for internal quality improvement, staff training, licensing, and auditing purposes.

2. Patient Rights Under HIPAA

  • Right to Access PHI: Patients (and parents of minor patients) can request a copy of their health records. We will generally provide this within 30 days.
  • Right to Amend: Patients may request corrections to their PHI if they believe documents are inaccurate or incomplete.
  • Right to an Accounting of Disclosures: Patients can request a detailed list of when and to whom their PHI was disclosed outside of standard treatment, payment, or operations.
  • Right to Request Restrictions: Patients can request that certain uses or disclosures of PHI be restricted (though we are not always legally required to agree).
  • Right to Confidential Communications: Patients can request to receive sensitive communications (e.g., appointment reminders) by a specific method or at a specific location.
  • Right to Complain: Patients may file a formal complaint directly with our practice or with the U.S. Department of Health & Human Services (HHS). Absolute non-retaliation is guaranteed.

3. Special Disclosures & Uses

  • Required By Law: We are legally mandated to report suspected abuse (highly relevant to pediatric and autism services), public health reporting, and responses to judicial/legal proceedings.
  • School-Based Disclosures: Sharing clinical reports with school IEP teams securely requires separate written consent from the guardian (and complies with FERPA).
  • Research: PHI is utilized in academic research only under IRB approval or via full, irreversible de-identification.
  • Psychotherapy & Behavioral Notes: If our clinicians document behavioral/therapeutic notes, these receive elevated protection and require specific authorization for release.

4. Our Obligations as a Provider

  • Business Associate Agreements (BAAs): Every third-party vendor with access to PHI (EHR, telehealth platforms, cloud storage) operates under a strict, signed BAA.
  • Breach Notification: If PHI is breached, patients will be notified strictly within 60 days. Breaches affecting over 500 individuals will be actively reported to HHS and local media.
  • Minimum Necessary Standard: We enforce strict controls to only internally share the minimum amount of PHI necessary for the task at hand.
  • Designated Privacy Officer: For any privacy-related questions and complaints, our Dedicated Privacy Officer can be reached directly at [email protected].

For autism and pediatric patients: HIPAA rights generally belong to the parent/guardian until the minor reaches adulthood. Certain state laws may grant minors specific privacy rights regarding sensitive services.

5. Telehealth & Digital Security

  • HIPAA-Compliant Telehealth: We only utilize strictly secured platforms with actively executed BAAs for all remote sessions.
  • Encryption: All PHI transmitted digitally across our infrastructure is fully encrypted in transit (TLS 1.3) and natively encrypted at rest (AES-256).
  • Email & Messaging: Because traditional unencrypted email is not HIPAA-compliant, we strongly enforce that all PHI messaging occur explicitly through our secure patient portal messaging interface.