How we use and protect your health information.
Protected health information includes identifiable information related to a person's health, treatment, or payment for care. HIPAA defines when that information may be used or disclosed and when additional written authorization is required.
01
Information connected to you and your care.
Protected health information, or PHI, includes information that identifies a person and relates to their health or healthcare.
This can include clinical notes, diagnoses, treatment plans, and billing records created during detox, residential treatment, or outpatient care.
Information that has been properly de-identified so it cannot reasonably be connected to a specific person falls outside this definition.
02
Some uses don't require new permission each time.
HIPAA permits PHI to be used for treatment, payment, and healthcare operations without obtaining separate written authorization for every use.
This can include coordination between members of the treatment team, processing insurance claims, staff training, and internal quality activities.
Only the information needed for the task should be shared where the minimum necessary standard applies.
03
Other uses require your permission first.
Certain uses outside routine treatment, payment, and operations require written authorization.
This may include sharing information with an employer, releasing records outside the care team, or using a client's information for marketing.
The authorization must identify what information will be shared, with whom, and for what purpose. It can also be withdrawn after it has been given.
04
Limited exceptions are defined by law.
Certain circumstances may permit or require disclosure without written authorization, including mandated reporting of abuse or neglect, a serious and immediate safety threat, health oversight activities, or a valid court order.
These are specific legal exceptions and do not create general permission to share a client's information.
Your health information belongs to you.
HIPAA gives patients specific rights over their health information, including the ability to access records, request corrections, ask about certain disclosures, and request how information is communicated.
How to exercise your rights.
Requests to inspect, correct, or restrict protected health information should be submitted in writing to the Healing Sands Privacy Officer.
Requests are handled within the timeframes required by federal regulation. If a request is denied, you will receive an explanation along with information about any applicable review process.
Contact the Healing Sands Privacy Officer when you want to:
Inspect or obtain your records
Request a correction
Request restrictions on certain uses or disclosures
Request information about certain disclosures
Change how we communicate with you
If a breach involving unsecured protected health information occurs, affected individuals will be notified under the HIPAA Breach Notification Rule.
The notification will explain what happened, the type of information involved, and the steps being taken in response. Required notification will be provided without unreasonable delay.
Questions or concerns about your privacy rights.
If you believe your protected health information has been handled improperly, you have the right to file a complaint. You may contact Healing Sands or file directly with the U.S. Department of Health and Human Services Office for Civil Rights.
Filing a complaint will not affect the care you receive, and retaliation for filing a complaint is prohibited.
You can raise a concern without retaliation.
Common questions about your privacy rights.
Tell us a little, and we'll take it from there.