NOTICE OF PRIVACY PRACTICES
Effective Date: October 25, 2012 revised September 25, 2013
THIS NOTICE DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW THIS NOTICE CAREFULLY.
If you have any questions about this notice or need further information, please contact our Privacy Officer at (847) 965-1600. Written requests should be addressed to:
Attn: Privacy Officer
8950 Gross Point Road
Skokie, IL 60077
OUR PLEDGE REGARDING YOUR PROTECTED HEALTH INFORMATION:
The privacy of your protected health information or “PHI” is important to us. This notice will tell you about the ways in which we may use and disclose your PHI. This notice describes your rights with respect to your PHI we collect and maintain and also describes certain obligations we have regarding the use and disclosure of your PHI.
We are required by law to:
- Maintain the privacy of your PHI;
- Give you this notice describing our legal duties, privacy practices, and your rights regarding you PHI we collect and maintain;
- Notify you if we discover a breach of any of your PHI that is not secured in accordance with federal guidelines; and
- Follow the terms of the Notice of Privacy Practices that is currently in effect.
YOUR RIGHTS REGARDING YOUR PROTECTED HEALTH INFORMATION:
You have the following rights with respect to your PHI:
- Right to Inspect and Copy: You have the right to inspect and copy all or any part of your medical or health record, as provided by federal regulations. You may request and receive an electronic copy of your PHI if DeliverCareRx, Inc. maintains your PHI in an electronic health record.
To inspect and copy your PHI, you must submit your request in writing to our Privacy Officer at the address listed on the first page of this notice. If you request a copy of your PHI we may charge a reasonable, cost-based fee in accordance with state law for the costs associated with fulfilling your request.
We may deny your request under certain limited circumstances.
- Right to Amend: You have the right to request that we amend your PHI or a medical or health record about you if you feel that health information we have about you is incorrect or incomplete. You have the right to request an amendment for as long as we keep the information. To request an amendment, your request must be made in writing, submitted to our Privacy Officer at the address listed on the first page of this notice, and must provide a reason that supports your request for an amendment. We may deny your request under certain limited circumstances.
- Right to an Accounting of Disclosures: You have the right to request a list accounting for any disclosures of your PHI we have made, except for disclosures made for the purpose of treatment, payment, health care operations and certain other purposes if such disclosures were made through a paper record or other health record that is not electronic, as set forth in federal regulations. If you request an accounting of disclosures of your PHI, the accounting may include disclosures made for the purpose of treatment, payment and health care operations to the extent that disclosures are made through an electronic health record.
To request an accounting of disclosures, you must submit your request in writing to our Privacy Officer at the address listed on the first page of this notice. Your request must state a time period which may not be longer than 6 years and may not include dates before April 14, 2003. The first list you request within a 12 month period will be free. For additional lists, we may charge you for the costs of providing the list. We will notify you of the cost involved and you may choose to withdraw or modify your request at that time before any costs are incurred.
- Right to Request Restrictions: You have the right to request a restriction or limitation on the use and disclosure of your PHI. You also have the right to request a restriction or limitation on the disclosure of your PHI to someone who is involved in your care or the payment for your care, such as a family member or friend. For example, you could ask that we restrict a specified nurse from use of your PHI or that we not disclose information to your spouse about a surgery you had.
If you pay for a service entirely out-of-pocket, you may request that information regarding the service be withheld and not provided to a third party payor for purposes of payment or health care operations. We are obligated by law to abide by such restriction.
To request a restriction on the use and disclosure of your PHI, you must make your request in writing to our Privacy Officer at the address listed on the first page of this notice. In your request, you must tell us what information you want to limit and to whom you want the limitations to apply. We will notify you of our decision regarding the requested restriction. If we do agree to your requested restriction, we will comply with your request unless the information is needed to provide you emergency treatment.
- Right to Receive Confidential Communications: You have the right to request that we communicate with you about your PHI in a certain way or have such communications addressed to a certain location. For example, you can ask that we only contact you at work or by mail to a post office box.
To request confidential communications, you must make your request in writing to our Privacy Officer at the address listed on the first page of this notice. Your request must specify how or where you wish to be contacted.
- Right to a Paper Copy of this Notice: You have the right to obtain a paper copy of this notice at any time upon request. At the time of first service delivery, we are required to provide you with a paper copy of this notice. To obtain a copy of this notice at any other time, please request it from our Privacy Officer at the address listed on the first page of this notice.
- Right to Revoke Authorization: If you execute any authorization(s) for the use and disclosure of your PHI, you have the right to revoke such authorization(s), except to the extent that action has already been taken in reliance on such authorization.
HOW WE MAY USE AND DISCLOSE YOUR PROTECTED HEALTH INFORMATION WITHOUT YOUR AUTHORIZATION:
The following categories describe different ways that we may use and disclose your PHI without your authorization.
- For Treatment: We may use your health information to provide and coordinate the treatment, medications and services you receive. For example, we may contact you regarding medications, equipment, supplies, compliance programs such as drug recommendations, therapeutic substitution, refill reminders, other product or service recommendations such as specialty and infusion therapies, counseling and drug utilization review (DUR), product recalls or disease state management.
- For Payment: We may use your health information for various payment-related functions. For example, we may contact your insurer, pharmacy benefit manager or other health care payer to determine whether it will pay for your medications, equipment and supplies and the amount of your co-payment. We will bill you or a third-party payer for the cost of medications, equipment and supplies dispensed to you. The information on or accompanying the bill may include information that identifies you, as well as the medications you are taking.
- For Health Care Operations: We may use your health information for certain operational, administrative and quality assurance activities. For example, we may use information in your health record to monitor the performance of the staff and pharmacists providing treatment to you. This information will be used in an effort to continually improve the quality and effectiveness of the health care and service we provide. We may disclose health information to business associates if they need to receive this information to provide a service to us and will agree to abide by specific HIPAA rules relating to the protection of health information. We may also use your health information to provide you with information about benefits available to you, and, in limited situations, about health-related products or services that may be of interest to you.
- For Research: We may disclose your PHI for the purpose of research. We will only disclose your PHI for research purposes upon your express authorization or if the research protocol has been approved by an institutional review board that has reviewed the research proposal and established protocols to ensure the privacy of your PHI.
- As Required By Law: We may disclose your PHI when required to do so by federal, state, or local law.
- To Avert a Serious Threat to Health or Safety: We may use and disclose your PHI when necessary to prevent a serious threat to your health and safety or the health and safety of the public or another person.
- Military and Veterans: If you are a member of the armed forces or separated/discharged from military services, we may release your PHI as required by military command authorities or the Department of Veterans Affairs as may be applicable. We may also release health information about foreign military personnel to the appropriate foreign military authorities.
- Workers’ Compensation: We may release your PHI as authorized by, and in compliance with, laws related to workers’ compensation and similar programs established by law that provide benefits for work-related illnesses and injuries without regard to fault.
- Public Health Activities: We may disclose your PHI for public health activities. These activities generally include the following:
- to prevent or control disease, injury, or disability;
- to report births and deaths;
- to report child abuse or neglect;
- to report reactions to medications or problems with products;
- to notify people of recalls of products they may be using;
- to notify person or organization required to receive information on FDA-regulated products; and
- to notify a person who may have been exposed to a disease or may be at risk for contracting or spreading a disease or condition.
- Health Oversight Activities: We may disclose your PHI to a health oversight agency for activities authorized by law. These oversight activities include, for example, audits, investigations, inspections, and licensure. These activities are necessary for the government to monitor the health care system, government programs, and compliance with civil rights laws.
- Lawsuits and Disputes: If you are involved in a lawsuit or a dispute, we may disclose your PHI in response to a court or administrative order. We may also disclose your PHI in response to a subpoena, discovery request, or other lawful process by someone else involved in the dispute, but only if efforts have been made to tell you about the request or to obtain an order protecting the information requested.
- Law Enforcement: We may disclose your PHI to law enforcement officials for law enforcement purposes including the following:
- in reporting certain injuries, as required by law, gunshot wounds, burns, injuries to perpetrators of crime;
- in response to a court order, subpoena, warrant, summons or similar process;
- to identify or locate a suspect, fugitive, material witness, or missing person;
- about the victim of a crime, if the victim agrees to disclose or under certain limited circumstances, we are unable to obtain the person’s agreement;
- about a death we believe may be the result of criminal conduct;
- about criminal conduct at our facility; and
- in emergency circumstances to report a crime; the location of the crime or victims; or the identity, description, or location of the person who committed the crime.
- Organ and Tissue Donation: We may disclose your PHI to organizations involved in the procurement, banking, or transplantation of cadaveric organs, eyes or tissue, for the purpose of facilitating organ and tissue donation where applicable.
- Abuse, Neglect and Domestic Violence: We may disclose your PHI to an appropriate governmental authority if we reasonably believe that you may be a victim of abuse, neglect, or domestic violence. We will only make this disclosure if you agree or when required or authorized by law.
- Coroners, Health Examiners and Funeral Directors: We may disclose your PHI to a coroner or health examiner. This may be necessary, for example, to identify a deceased person or determine the cause of death. We may also disclose your PHI to funeral directors as necessary to carry out their duties.
- National Security and Intelligence Activities: We may disclose your PHI to authorized federal officials for intelligence, counterintelligence, and other national security activities authorized by law, or for the purpose of providing protective services to the President or foreign heads of state.
- Inmates: If you are an inmate of a correctional institution or under the custody of a law enforcement official, we may disclose your PHI to the correctional institution or law enforcement official. This release would be necessary (a) for the institution to provide you with health care; (b) to protect your health and safety or the health and safety of others; or (c) for the safety and security of the correctional institution.
EXAMPLES OF OTHER PERMISSIBLE OR REQUIRED DISCLOSURES OF YOUR PROTECTED HEALTH INFORMATION WITHOUT YOUR AUTHORIZATION:
- Business Associates: Some activities of DeliverCareRx, Inc. are provided on our behalf through contracts with business associates. Examples of when we may use a business associate include coding and claims submission performed by a third party billing company, consulting and quality assurance activities provided by an outside consultant, billing and coding audits performed by an outside auditor, and other legal and consulting services provided in response to billing and reimbursement issues which may arise from time to time. When we enter into contracts to obtain these services, we may need to disclose your PHI to our business associate so that the associate may perform the job which we have requested. To protect your PHI, however, we require our business associate to appropriately safeguard your information.
- Notification: We may use or disclose your PHI to notify or assist in notifying a family member, personal representative, close personal friend, or other person responsible for your care of your location and general condition. DeliverCareRx, Inc. will not disclose your PHI to your family members, personal representative or close personal friends as described in this paragraph if you object to such disclosure. Please notify our Privacy Officer if you object to such disclosures.
- Communication with family members: Health professionals, including those employed by or under contract with DeliverCareRx, Inc. may disclose to a family member, other relative, close personal friend or any other person you identify, health information relative to that person’s involvement in your care or payment related to your care, unless you object to the disclosure.
- Unlawful conduct: Federal law allows for the release of your PHI to appropriate health oversight agencies, public health authorities or attorneys, provided that a work force member or business associate believes in good faith that we have engaged in unlawful conduct or otherwise violated professional or clinical standards and are potentially endangering one or more patients, workers or the public.
WE MAY NOT USE OR DISCLOSE YOUR PROTECTED HEALTH INFORMATION FOR THE FOLLOWING PURPOSES WITHOUT YOUR AUTHORIZATION:
- We must obtain an authorization from you to use or disclose psychotherapy notes unless it is for treatment, payment or health care operations or is required by law, permitted by health oversight activities, to a coroner or medical examiner, or to prevent a serious threat to health or safety.
- We must obtain an authorization for any use or disclosure of your PHI for any marketing communications to you about a product or service that encourages you to use or purchase the product or service unless the communication is either (a) a face-to-face communication or; (b) a promotional gift of nominal value. However, we do not need to obtain an authorization from you to provide refill reminders, information regarding your course of treatment, case management or care coordination, to describe a health-related products or services that we provide, or to contact you in regard to treatment alternatives. We must notify you if the marketing involves financial remuneration.
- We must obtain an authorization for any disclosure of your PHI which constitutes a sale of such PHI.
- We must obtain an authorization for all other uses and disclosures of your PHI not described in this notice.
If you provide us with written authorization to use or disclose your PHI, you may revoke that authorization, in writing, at any time.
CHANGES TO THIS NOTICE:
We reserve the right to change our privacy practices and any terms of this notice. If our privacy practices materially change, we will revise this notice and make copies of the revised notice available upon request. We reserve the right to make the revised or changed notice effective for PHI we already have about you as well as any PHI we receive in the future.
TO MAKE A COMPLAINT:
If you believe your privacy rights have been violated, you may file a complaint with us or with the Secretary of the United States Department of Health and Human Services. To file a complaint with us, contact our Privacy Officer at (847) 965-1600. All complaints must be submitted in writing. There will be no retaliation against you for filing a complaint.
ACKNOWLEDGEMENT OF RECEIPT OF THIS NOTICE:
We will request that you sign a separate form or notice acknowledging you have received a copy of this notice. If you choose, or are not able to sign, a staff member will sign their name, and date. This acknowledgement will be filed with your records.